Last Updated: September 4, 2026
This Data Processing Addendum (“DPA”) forms part of the applicable agreement between SE TN Consultants (“Southeast TN Consultants, LLC,” “Processor,” “Service Provider,” “we,” “us,” or “our”) and the client identified in that agreement (“Client,” “Controller,” or “Business”) where SE TN Consultants processes Personal Data on behalf of the Client.
This DPA supplements the applicable Master Services Agreement (“MSA”), Statement of Work (“SOW”), proposal, service agreement, or other written agreement between the parties (collectively, the “Agreement”).
1. Purpose
SE TN Consultants may process Personal Data on behalf of Client while providing consulting, digital marketing, website development, ecommerce, analytics, advertising, automation, technology, software, support, or related professional services.
This DPA establishes the parties' respective responsibilities concerning such processing.
2. Definitions
For purposes of this DPA:
“Applicable Data Protection Law” means privacy and data-protection laws applicable to the processing of Personal Data under the Agreement.
“Personal Data” means information relating to an identified or identifiable individual, or other information treated as personal information or personal data under Applicable Data Protection Law.
“Processing” means any operation performed on Personal Data, including collection, access, storage, organization, alteration, transmission, analysis, disclosure, deletion, or other use.
“Controller” includes a person or organization that determines the purposes and means of processing Personal Data and, where applicable, includes similar concepts such as “Business.”
“Processor” includes an entity that processes Personal Data on behalf of a Controller and, where applicable, includes similar concepts such as “Service Provider” or “Contractor.”
“Subprocessor” means a third party engaged by SE TN Consultants to process Personal Data on behalf of Client in connection with the Services.
3. Roles of the Parties
Client determines the purposes and means of processing Client Personal Data and is generally the Controller or Business.
SE TN Consultants processes Client Personal Data on Client's behalf and is generally the Processor or Service Provider with respect to such processing.
Each party is independently responsible for complying with Applicable Data Protection Law applicable to its activities.
4. Client Instructions
SE TN Consultants will process Client Personal Data only:
- As necessary to provide the Services;
- According to Client's documented instructions;
- As described in the Agreement;
- As reasonably necessary to maintain security and prevent fraud or abuse; or
- As otherwise required by applicable law.
The Agreement, SOW, Client's documented requests, configurations, and reasonable instructions concerning the Services constitute documented processing instructions.
If SE TN Consultants reasonably believes an instruction violates Applicable Data Protection Law, we may notify Client and suspend the affected processing while the parties address the issue.
5. Client Responsibilities
Client represents that it has appropriate authority and lawful grounds to provide Personal Data to SE TN Consultants and instruct us to process it.
Client is responsible for:
- Providing legally required notices;
- Obtaining legally required consents or authorizations;
- Establishing lawful processing purposes;
- Responding to individuals concerning Client's privacy practices;
- Determining appropriate retention requirements;
- Configuring Client-controlled systems appropriately; and
- Ensuring its instructions comply with Applicable Data Protection Law.
SE TN Consultants does not independently determine the legality of Client's underlying collection or use of Personal Data except as required by law.
6. Nature and Purpose of Processing
Processing may include accessing, collecting, organizing, storing, analyzing, modifying, transmitting, retrieving, displaying, reporting, deleting, or otherwise processing Personal Data as necessary to provide the Services.
Purposes may include:
- Website operation and development;
- Ecommerce;
- CRM management;
- Digital marketing;
- Email marketing;
- Advertising;
- Search marketing;
- Analytics and reporting;
- Marketing automation;
- Business process automation;
- AI-assisted analysis;
- Technical support;
- Software configuration;
- Data migration;
- Integration management;
- Security and troubleshooting; and
- Other services described in the applicable SOW or Agreement.
7. Categories of Personal Data
Depending upon the Services, Client Personal Data may include:
- Names;
- Business contact information;
- Email addresses;
- Telephone numbers;
- Mailing addresses;
- Customer identifiers;
- CRM records;
- Lead information;
- Ecommerce customer information;
- Transaction-related information;
- Marketing preferences;
- Email subscriber information;
- Website activity;
- Analytics identifiers;
- Advertising audience information;
- Support communications; and
- Other Personal Data supplied or made accessible by Client.
The parties may identify additional categories in an applicable SOW.
8. Categories of Data Subjects
Depending upon the engagement, Personal Data may relate to:
- Client customers;
- Prospective customers and leads;
- Website visitors;
- Email subscribers;
- Ecommerce customers;
- Client employees or contractors;
- Business contacts; and
- Other individuals whose information Client makes available through the Services.
9. Confidentiality
SE TN Consultants will ensure that persons authorized to process Client Personal Data are subject to appropriate confidentiality obligations.
Access will be limited to personnel, contractors, and service providers who reasonably require access to perform the Services or support applicable business operations.
10. Security Measures
SE TN Consultants will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Personal Data and the Services.
Depending upon the applicable systems and Services, safeguards may include measures relating to:
- Access controls;
- Authentication;
- Credential management;
- Encryption where appropriate;
- Secure communications;
- System and software updates;
- Malware protection;
- Backup practices;
- Vendor management;
- Logging and monitoring;
- Incident response; and
- Personnel access limitations.
Client acknowledges that no information system can be guaranteed to be completely secure.
11. Subprocessors
Client authorizes SE TN Consultants to use Subprocessors reasonably necessary to provide the Services.
Subprocessors may include providers of:
- Hosting and cloud infrastructure;
- Ecommerce systems;
- CRM systems;
- Email and communications;
- Analytics;
- Advertising;
- Payment services;
- Software and licensing infrastructure;
- Data storage;
- Security;
- Automation;
- Artificial intelligence or technology services; and
- Other infrastructure necessary to perform the Services.
SE TN Consultants will require Subprocessors that process Client Personal Data on our behalf to maintain data-protection obligations appropriate to the services they provide.
Where required by Applicable Data Protection Law or the Agreement, SE TN Consultants will provide information concerning relevant Subprocessors or material changes to Subprocessors.
12. Client-Selected Platforms
Client may instruct SE TN Consultants to access or use third-party platforms selected, contracted, or controlled by Client.
Such platforms may include advertising accounts, ecommerce platforms, CRMs, email systems, hosting providers, analytics services, cloud platforms, or other technologies.
Where Client independently selects such a provider and directs SE TN Consultants to use it, Client remains responsible for its contractual and privacy relationship with that provider.
13. Data Subject Requests
If SE TN Consultants receives a request from an individual relating to Client Personal Data that we process solely on Client's behalf, we may direct the individual to Client.
Taking into account the nature of the processing, SE TN Consultants will provide reasonable assistance to Client in responding to legally valid data-subject requests where required by Applicable Data Protection Law and where the information is reasonably available to us.
Client remains primarily responsible for responding to requests concerning Client-controlled Personal Data.
14. Security Incidents
If SE TN Consultants becomes aware of unauthorized access to or acquisition, disclosure, alteration, or loss of Client Personal Data within systems under our responsibility that constitutes a reportable personal-data breach or similar security incident under Applicable Data Protection Law, we will notify Client without undue delay as required by applicable law or contract.
Where reasonably available, notification may include information concerning:
- The nature of the incident;
- Categories of affected information;
- Known or reasonably estimated scope;
- Remediation actions taken or planned; and
- Information reasonably necessary for Client to evaluate its obligations.
Notification of an incident does not constitute an admission of fault or liability.
15. Assistance With Compliance
Taking into account the nature of the processing and information reasonably available to us, SE TN Consultants will provide reasonable assistance where legally required concerning Client's obligations relating to:
- Data-subject rights;
- Security;
- Personal-data breaches;
- Data protection impact assessments; and
- Regulatory consultations.
Material assistance outside the ordinary scope of the Services may be subject to reasonable additional fees unless the need for assistance results from SE TN Consultants' breach of this DPA.
16. Data Retention, Return and Deletion
SE TN Consultants will retain Client Personal Data only for as long as reasonably necessary to provide the Services, fulfill the Agreement, maintain required business records, comply with applicable law, resolve disputes, or meet legitimate security requirements.
Upon termination or expiration of the applicable Services, SE TN Consultants will, upon Client's reasonable request and where technically and legally practicable, return or delete Client Personal Data under our control unless continued retention is required or permitted by applicable law.
Personal Data contained in routine backup systems may remain until overwritten or deleted according to normal backup retention cycles, provided it remains protected and is not restored for ordinary business use except where reasonably necessary.
17. International Data Transfers
Client acknowledges that SE TN Consultants and its service providers may process Personal Data in the United States and other jurisdictions.
Where Applicable Data Protection Law requires a specific mechanism for an international transfer of Personal Data, the parties will cooperate in implementing an appropriate lawful transfer mechanism.
Where applicable, this may include standard contractual clauses or other legally recognized safeguards.
18. Artificial Intelligence and Automated Processing
Where AI or automated technologies are used to process Client Personal Data on Client's behalf, SE TN Consultants will treat such processing according to the same confidentiality, security, and data-processing obligations applicable to other Subprocessors or service technologies.
SE TN Consultants will not intentionally submit passwords, private keys, payment credentials, or similar confidential credentials to public generative AI systems as part of ordinary processing.
Where the Client specifically directs use of a particular AI platform, the provisions concerning Client-selected third-party platforms also apply.
19. Sale and Use of Client Personal Data
SE TN Consultants will not sell Client Personal Data processed solely on Client's behalf in exchange for monetary consideration.
SE TN Consultants will not use Client Personal Data for purposes materially unrelated to providing the Services except where permitted by the Agreement, Client's instructions, or applicable law.
Where Applicable Data Protection Law imposes additional restrictions upon a Processor, Service Provider, or Contractor, SE TN Consultants will comply with those restrictions to the extent applicable to the processing.
20. Audits and Compliance Information
Upon reasonable written request, SE TN Consultants will provide information reasonably necessary to demonstrate compliance with applicable obligations under this DPA.
Where Applicable Data Protection Law requires audit rights, the parties will cooperate in good faith to satisfy those requirements while minimizing unreasonable disruption, security risk, disclosure of confidential information, and expense.
Audits must not provide Client access to information belonging to other clients or compromise the security of SE TN Consultants or third-party systems.
21. Duration
This DPA remains in effect for as long as SE TN Consultants processes Client Personal Data subject to the Agreement.
Obligations relating to confidentiality, security, and retained Personal Data survive termination for as long as SE TN Consultants retains applicable Client Personal Data.
22. Order of Precedence
This DPA supplements the Agreement.
If there is a conflict between this DPA and the Agreement specifically concerning the processing and protection of Client Personal Data, this DPA controls with respect to that subject matter unless the parties expressly agree otherwise in writing.
Applicable mandatory law will control where it cannot lawfully be modified by contract.
23. Changes
SE TN Consultants may update its standard DPA to reflect changes in law, technology, security practices, or Services.
Changes that materially reduce contractual data-protection obligations applicable to an active Client engagement will be handled in accordance with the applicable Agreement and Applicable Data Protection Law.
24. Contact
Questions concerning this DPA or Client Personal Data may be directed to:
Southeast TN Consultants, LLC
Website: https://setnconsultants.com
PO Box 2261 Fort Oglethorpe, GA 30742
For matters involving an active Client engagement, please identify the applicable Client or project so the request can be routed appropriately.
