Data Processing Addendum
Last Updated: September 17, 2026
This Data Processing Addendum (“DPA”) forms part of the Launch Navigation System Subscription and Terms of Service Agreement (the “Agreement”) between The Aligned Biz Co, LLC, a Wyoming limited liability company (“Company,” “LNS,” “Processor,” or “Service Provider”) and the customer identified in the applicable order, checkout, or account record (“Customer,” “Controller,” or “Business”).
This DPA applies when Company processes Personal Data on Customer’s behalf in connection with Customer’s use of the Launch Navigation System (“Service”). Capitalized terms not defined in this DPA have the meanings given in the Agreement or applicable Data Protection Law.
If there is a conflict between this DPA and the Agreement regarding the processing or protection of Personal Data, this DPA controls to the extent of the conflict. All other terms of the Agreement remain in effect.
2. Definitions
For purposes of this DPA:
- “Customer Personal Data” means Personal Data that Company processes on behalf of Customer through the Service, including information submitted by or about Customer’s leads, prospects, clients, customers, course students, Community Members, support requestors, website or funnel visitors, registrants, appointment participants, and other end users.
- “Data Protection Law” means any privacy or data protection law applicable to the relevant processing under this DPA, including, where applicable, the EU General Data Protection Regulation (GDPR), UK data protection law, the California Consumer Privacy Act as amended (CCPA), and other applicable U.S. state privacy laws.
- “Personal Data” includes “personal data,” “personal information,” and similar terms defined by applicable Data Protection Law.
- “Process” or “Processing” has the meaning given under applicable Data Protection Law and includes collecting, storing, organizing, accessing, using, transmitting, disclosing, deleting, or otherwise handling Personal Data.
- “Subprocessor” means a third party engaged by Company to process Customer Personal Data on Company’s behalf in providing the Service.
- “Security Incident” means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as routine scans, pings, blocked attacks, or unsuccessful login attempts.
3. Roles of the Parties
3.1 Customer as Controller/Business.
Customer determines the purposes for which Customer Personal Data is collected and used through Customer-created forms, quizzes, funnels, websites, course pages, CRM records, My Contacts records, email marketing, Interaction Agents, My Community, Support Desk, booking calendars, workflows, webhooks and API integrations, embeddable widgets, and other Customer-configured features. Customer is responsible for the lawfulness of its collection, use, disclosure, and transfer of Customer Personal Data.
3.2 Company as Processor/Service Provider.
To the extent Company processes Customer Personal Data solely to provide the Service on Customer’s behalf, Company acts as Customer’s processor, service provider, contractor, or equivalent role under applicable Data Protection Law.
3.3 Independent Processing.
Company may act as an independent controller/business for Personal Data it collects and uses for its own legitimate business purposes, such as Customer account administration, subscription billing, fraud prevention, security, legal compliance, and direct support relationships. Such processing is governed by the LNS Privacy Policy and is outside the processor-only obligations of this DPA to the extent permitted by law.
4. Customer Instructions and Responsibilities
4.1 Documented Instructions.
Customer instructs Company to process Customer Personal Data as necessary to provide, maintain, secure, support, and improve the Service in accordance with the Agreement, this DPA, Customer’s configuration and use of the Service, and any additional documented instructions mutually agreed by the parties.
4.2 Lawful Instructions.
Customer will not instruct Company to process Personal Data in violation of applicable law. If Company reasonably believes an instruction violates Data Protection Law, Company may suspend the affected processing and notify Customer unless prohibited by law.
4.3 Customer Responsibilities.
Customer is responsible for:
- providing legally sufficient privacy notices to its leads, customers, students, visitors, and other data subjects;
- obtaining any consent or other lawful basis required for the collection, use, email marketing, recording, or other processing Customer enables through LNS;
- collecting only Personal Data appropriate for the intended business purpose;
- maintaining the accuracy of Customer-created knowledge bases, forms, quizzes, records, and other data sources;
- responding to privacy rights requests received directly from Customer’s data subjects, with Company assistance as described below;
- not using the Service to collect or process categories of data prohibited by the Agreement or Acceptable Use Policy;
- not knowingly using the Service to market or sell products or services to individuals under age 18, create or permit accounts or access credentials for them, enroll them in courses, communities, paid-access areas, or other LNS-hosted experiences, or knowingly collect or process their Personal Data through the Service;
- selecting, configuring, and lawfully using any third-party integration, webhook endpoint, tracking technology, custom code, or external service Customer connects to the Service; and
- ensuring that Personal Data exported from or transmitted through LNS to a Customer-selected third party is transferred and handled in accordance with applicable law.
5. Processing Requirements
Company will:
- process Customer Personal Data only on documented instructions from Customer, except where processing is required by applicable law;
- ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
- implement and maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Service and the risks presented by the processing;
- assist Customer, taking into account the nature of the processing and information available to Company, with obligations concerning data subject rights, security, breach response, and legally required privacy assessments where applicable;
- make information reasonably necessary to demonstrate compliance with this DPA available to Customer, subject to appropriate confidentiality, security, and scope limitations; and
- delete or return Customer Personal Data at the end of the applicable retention period as described in the Agreement, this DPA, and Annex A, unless retention is required by law.
6. CCPA and U.S. State Privacy Requirements
Where the CCPA or another applicable U.S. state privacy law treats Company as a service provider, contractor, processor, or equivalent role for Customer Personal Data, Company will process that Personal Data only for the limited and specified purposes described in the Agreement, this DPA, and Customer’s documented instructions, and will comply with restrictions required for that role under applicable law.
Company will not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising on Company’s own behalf where prohibited by applicable law. Company will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted or required by applicable law and the parties’ agreements.
Company will notify Customer if Company determines it can no longer meet an applicable obligation imposed on it in its processor/service-provider role. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
7. Subprocessors
7.1 General Authorization.
Customer provides general written authorization for Company to engage Subprocessors to provide the Service.
7.2 Subprocessor Obligations.
Company will enter into written terms with each Subprocessor that impose data protection obligations appropriate to the services performed and, where required by applicable law, protections no less protective in substance than the obligations applicable to Company under this DPA.
7.3 Responsibility.
Company remains responsible for the performance of its Subprocessors to the extent required by applicable Data Protection Law.
7.4 Changes.
Company will maintain a current list of material Subprocessors and will provide notice of material additions or replacements in a manner reasonably designed to inform affected Customers. Where applicable law requires an opportunity to object, Customer may object on reasonable data-protection grounds.
8. Security
8.1 Safeguards.
Company will maintain reasonable security measures designed to protect Customer Personal Data against unauthorized or unlawful access, use, alteration, disclosure, loss, or destruction, taking into account the nature of the processing, available technology, implementation costs, and the risks presented by the processing.
8.2 Security Program.
The categories of safeguards intended for the Service are summarized in Annex B. Company may update safeguards over time so long as the overall level of protection is not materially reduced during Customer’s active subscription.
8.3 Customer Security.
Customer is responsible for maintaining the confidentiality of its credentials, limiting account access to authorized users, using available security controls, and promptly notifying Company of suspected compromise of its account.
9. Security Incidents
9.1 Notice.
Company will notify Customer without undue delay after becoming aware of a Security Incident involving Customer Personal Data, to the extent required by applicable Data Protection Law.
9.2 Information and Cooperation.
As information becomes reasonably available, Company will provide information appropriate to assist Customer in understanding the nature of the Security Incident, the categories of affected data where known, mitigation steps taken or planned, and other information reasonably necessary for Customer to meet applicable legal obligations.
9.3 No Admission.
Security Incident notification does not constitute an admission of fault or liability by Company.
9.4 Customer Notifications.
Unless applicable law requires Company to notify affected individuals or authorities directly, Customer is responsible for determining whether notifications to data subjects, regulators, or other third parties are legally required.
10. Data Subject Requests
If Company receives a request from a person seeking to exercise privacy rights regarding Customer Personal Data, Company will, where reasonably identifiable as Customer-controlled data, direct the requester to Customer or notify Customer unless prohibited by law. Taking into account the nature of the processing, Company will provide reasonable technical or organizational assistance to help Customer respond to valid requests, including access, correction, deletion, restriction, portability, or objection requests where applicable.
Customer remains responsible for verifying the requester’s identity, determining whether a request is valid, and providing the substantive response unless applicable law requires otherwise.
11. Government and Legal Requests
If Company receives a legally binding demand from a governmental authority for Customer Personal Data, Company may disclose information as legally required. Where legally permitted, Company will notify Customer before disclosure so Customer may seek appropriate protection or other relief.
12. Audits and Compliance Information
Upon reasonable written request, Company will provide Customer with information reasonably necessary to demonstrate Company’s compliance with this DPA. Where required by applicable Data Protection Law and where the information provided is insufficient, Company will permit a reasonable audit or inspection subject to appropriate confidentiality, security, frequency, scope, and cost controls.
Audits must not unreasonably interfere with Company’s operations, expose information concerning other customers, compromise security, or require disclosure of privileged or highly sensitive security information except where legally required.
13. Return, Export, Archive, and Deletion
13.1 During Active Subscription.
Customer may use available Service functionality to access and export Customer Personal Data during an active subscription.
13.2 Before Cancellation Takes Effect.
Customer is responsible for exporting any Customer Personal Data it wishes to retain before its subscription access ends.
13.3 Archive.
Following the effective date of cancellation or termination, Company may archive Customer account data for up to ninety (90) days. If Customer reactivates within thirty (30) days, Company may restore the archived account without a restoration administration fee. If Customer reactivates after thirty (30) days but before permanent deletion, a restoration administration fee of $150 may apply in addition to applicable subscription fees.
13.4 Permanent Deletion.
After the ninety (90)-day archive period, Customer account data is scheduled for permanent deletion, subject to limited data Company may retain where reasonably necessary for legal, tax, accounting, insurance, fraud-prevention, dispute, chargeback, backup, security, or legal-claims purposes, or as otherwise required or permitted by law.
13.5 Purchased AI Credits.
Any unused purchased AI credits are unavailable once cancellation becomes effective and do not survive account termination, even if data remains temporarily archived.
13.6 Call Recordings.
Group call recordings and paid one-on-one call recordings made available through the Service may be stored and delivered using third-party media hosting and storage providers. Recordings remain available during Customer’s active subscription and, following cancellation or lapse, remain in the Customer’s archived account for up to ninety (90) days. After the archive period, recordings may be deleted from Customer-accessible storage. Company may retain copies for a longer period where reasonably necessary to establish, exercise, or defend legal claims; investigate or resolve disputes, payment disputes, or chargebacks; comply with legal, regulatory, tax, accounting, or insurance obligations; or protect the rights, property, or interests of Company or others. Any recording retained for such a purpose will be retained only for as long as reasonably necessary for that purpose and need not remain available to Customer through the Service after the applicable access or archive period.
14. International Data Transfers
Customer acknowledges that Company and its Subprocessors may process Personal Data in the United States and other countries where they operate. Each party will comply with applicable restrictions on international transfers of Personal Data.
Where a legally required transfer mechanism applies to a transfer of Customer Personal Data, the parties will cooperate in good faith to implement an appropriate mechanism, which may include applicable Standard Contractual Clauses, a UK transfer addendum or agreement, or another valid transfer mechanism.
15. Liability and Indemnification
The liability, indemnification, warranty, and limitation-of-liability provisions in the Agreement apply to this DPA except to the extent prohibited by applicable Data Protection Law or expressly modified in a signed order or addendum.
16. Term and Termination
This DPA becomes effective when Customer accepts the Agreement or otherwise enters into an arrangement under which Company processes Customer Personal Data on Customer’s behalf. It remains in effect for as long as Company processes Customer Personal Data subject to this DPA.
17. Governing Law
Except where applicable Data Protection Law requires otherwise, this DPA is governed by the laws of the State of Wyoming and by the governing-law and dispute-resolution provisions of the Agreement.
Annex A — Details of Processing
Subject matter: Processing Customer Personal Data as necessary to provide the Launch Navigation System and Customer-configured features.
Duration: For the Customer’s active subscription and applicable post-termination archive/deletion period, plus any legally required retention.
Nature of processing: Collection, receipt, storage, organization, hosting, retrieval, access, transmission, email delivery, AI processing at Customer direction, display, recording and recording storage, workflow execution, webhook/API transmission, support, security, backup where applicable, export, archive, and deletion.
Purposes: Providing and supporting LNS features selected or configured by Customer, including AI-assisted business tools, forms, funnels, quizzes, CRM/My Contacts, email marketing, courses, My Community, Support Desk, booking calendars, workflows and automations, webhooks/API integrations, media storage, embeddable widgets, Customer/Visitor Interaction Agents, payment integrations, analytics made available to Customer, account support, and Service security.
Data subjects: Customer’s leads, prospects, clients, customers, course students age 18+, Community Members age 18+, support requestors, website/funnel/quiz/form visitors, webinar registrants, appointment participants, and other individuals age 18 or older whose Personal Data Customer submits to or collects through the Service.
Personal Data categories: Names; email addresses; phone numbers; business/contact details; form and quiz responses; CRM notes, tags, status, and interaction records; course enrollment and access information; community membership, posts, messages, and activity; support tickets and attachments; scheduling and connected-calendar information; workflow and automation data; webhook/API event data; email engagement information; uploaded files and media; knowledge-base content; AI prompts and responses; order/transaction metadata; IP address, device/browser and technical usage data; and call recordings where applicable.
Sensitive data: LNS is not designed for Customer use involving regulated health data, government identifiers, financial account credentials, biometric identifiers, precise geolocation, Personal Data of individuals under age 18, or other sensitive/high-risk categories prohibited by the Agreement or Acceptable Use Policy. Customer must not intentionally configure the Service to collect such data unless Company has expressly approved the use case in writing and appropriate compliance controls are in place.
Customer Instructions by Feature:
- Forms and quizzes: process responses submitted to Customer-configured forms and quizzes and make them available to Customer.
- Funnels and public pages: host Customer-created pages and process visitor submissions, interactions, and related technical data.
- CRM / My Contacts: store and organize Customer-controlled contact records, tags, notes, activity, and related data.
- Email: use third-party email-delivery infrastructure to send Customer-directed transactional, broadcast, and automated email from Customer-connected domains or subdomains and maintain required suppression/unsubscribe functionality.
- AI features: transmit Customer-directed prompts, relevant context, knowledge-base content, and uploaded materials to approved AI model providers as necessary to generate requested outputs.
- Interaction Agents: process questions initiated by visitors or Customer end users and respond based on the Customer-provided knowledge base; where the system lacks sufficient information, direct the person to Customer support rather than independently taking action.
- Courses: create and authenticate student access for individuals age 18 or older, store enrollment/access data, and deliver Customer course content.
- Scheduling: process scheduling information for Customer 1:1 calls through third-party scheduling infrastructure; current scheduling fields may include name, email address, phone number, appointment information, and availability data.
- Calls: facilitate LNS-hosted group calls and paid one-on-one calls through third-party communications infrastructure and store automatic recordings through third-party media hosting and storage providers for access in authorized LNS accounts. Calls are not currently transcribed or analyzed by AI.
- Payments: facilitate Customer-connected Stripe payment functionality. Customer is the merchant of record for Customer sales processed as direct charges to Customer’s connected Stripe account.
- My Community: authenticate Community Members age 18 or older; host Customer-created channels, posts, events, and direct messages; and process related membership and activity data.
- Support Desk: process Customer-directed support tickets, communications, attachments, and related customer or account information submitted through Customer support portals.
- Booking calendars: process booking requests, availability, appointment details, and connected calendar data needed to provide Customer-configured scheduling features.
- Workflows and automations: process Customer Personal Data according to Customer-configured triggers and actions, including tags, purchases, opt-ins, course activity, and other supported events.
- Webhooks and API integrations: transmit or receive Customer-directed event and contact data to or from third-party systems and endpoints selected by Customer. Customer is responsible for the security, configuration, and lawful use of those third-party systems.
- Orders and products: store and organize Customer-created product/service information and related order and transaction metadata.
- Media storage and delivery: store and deliver Customer-uploaded images, files, documents, and video or other media through Company’s approved storage and content-delivery providers.
- Embeddable widgets: process data submitted through LNS forms, quizzes, and checkout or other supported widgets when embedded on Customer-controlled external websites.
- Customer-added code and tracking: where Customer enables custom scripts or third-party tracking, process or transmit data as directed by Customer. Customer is responsible for the third-party tools it selects, the data they collect, and required notices or consents.
Annex B — Security Measures
The following describes categories of administrative, technical, and organizational measures Company maintains or uses through its service providers to protect Customer Personal Data. The specific controls may evolve with the Service, provided the overall level of protection is not materially reduced during Customer’s active subscription.
- Access management: authentication and account-access controls designed to limit access to authorized users and personnel.
- Infrastructure controls: use managed cloud infrastructure and service providers for application hosting, database, authentication, storage, traffic delivery, content delivery, and security functions as applicable.
- Confidentiality: contractual or other confidentiality obligations for personnel and contractors authorized to access Personal Data.
- Transmission and storage protection: use of security protections provided by the applicable cloud and infrastructure vendors and production configuration.
- Logging and monitoring: technical logging, application monitoring, and security/traffic controls appropriate to the Service configuration.
- Availability and recovery: managed infrastructure, backups, redundancy, and recovery capabilities to the extent configured within LNS and its infrastructure providers.
- Incident response: internal procedures for investigating and responding to suspected security incidents and coordinating legally required notifications.
- Vendor management: reasonable review and contractual management of material vendors that process Customer Personal Data.
- Data minimization and retention: product rules and contractual restrictions designed to limit prohibited sensitive-data use and remove account data according to the documented retention schedule.
Annex C — Subprocessor Information
Company may engage material subprocessors to provide hosting, database, storage, artificial intelligence processing, communications, email delivery, scheduling, media hosting and delivery, analytics, security, payment processing, and other operational services. Company maintains current subprocessor information separately and may make that information available through its Legal or Compliance resources or upon reasonable request. This DPA intentionally describes subprocessors by function rather than disclosing Company’s internal technical architecture or vendor configuration.
| Provider Category | Purpose | Data Categories |
|---|---|---|
| Cloud and application infrastructure | Hosting, database, authentication, file/media storage, traffic delivery, content delivery, and security | Account data, Customer Personal Data, uploaded files, authentication data, technical/usage data, request and security metadata |
| Artificial intelligence providers | Process prompts, files, knowledge-base content, and relevant context to provide AI-enabled features | Customer prompts, relevant context, uploaded or knowledge-base content, and other data submitted to AI features as needed for requested output |
| Payment processor | Subscription billing and connected merchant-account payment processing | Billing, transaction, connected-account, payment, and fraud-prevention data |
| Email and communications providers | Transactional, broadcast, and automated email; video and call functionality | Email addresses, message content, delivery metadata, participant/session metadata, and audio/video streams as applicable |
| Scheduling providers | Appointment scheduling and availability management | Name, email address, phone number, appointment information, and availability data |
| Media hosting and delivery providers | Storage and delivery of call recordings and other media | Recorded audio/video and related storage/delivery metadata |
| Content-generation and document services | Generate requested presentations or other user-directed content outputs | Customer-provided or AI-generated content required to create the requested output |