Data Processing Addendum
The Integrity Shield: Protecting the Flow
1. Scope and Applicability
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Sovereign Terms of Service between LocalBoostApp LLC ("Architect") and the subscribing business ("Founder"). It applies to all processing of Personal Data conducted by the Architect on behalf of the Founder through the Sovereign Grid.
2. Roles and Instructions
Roles: Founder acts as the Data Controller (determining the purpose and means of processing) and the Architect acts as the Data Processor.
Instructions: The Architect shall process data only upon the documented instructions of the Founder, which include the provision of services outlined in the Terms of Service and any specific configuration of the Sovereign agents (Bear, Dragonfly, Cidela).
3. Data Categories and Purpose
Categories of Data: Includes contact information (names, emails, phones), business credentials, territory data, and any end-user data captured via Sovereign intake forms or CRM integrations.
Purpose of Processing: To provide forensic marketing intelligence, deploy hardened digital infrastructure, automate lead rotation, and maintain citational integrity within the 724/412 regional grid.
4. Technical and Organizational Measures
The Architect implements the Aletheia Framework for data security, which includes:
- Vault Isolation: Data is stored in siloed environments to prevent cross-tenant contamination.
- Encryption: Use of HMAC-SHA256 for signal verification and TLS 1.3 for data in transit.
- Access Control: Strict 4-digit PIN gates and multi-factor authentication for grid access.
- Integrity Checks: Continuous monitoring for signal desync and forensic anomalies.
5. Subprocessors
The Architect uses a curated list of subprocessors to provide grid infrastructure, including Google Cloud Platform (US-East1), Stripe (Payment Processing), and platform-native AI models. A full list of subprocessors is available upon request.
6. Data Rights and Cooperation
The Architect shall assist the Founder in responding to requests from individuals exercising their rights under applicable data protection laws (e.g., access, rectification, deletion). Requests should be routed to hello@localboostapp.com.
7. Confirmation Integrity
Mandatory Confirmation: Entry into the Sovereign Grid requires an explicit, mandatory confirmation of this DPA. This "Intake Valve" is a technical requirement to ensure all parties understand the integrity of the data flow before any processing begins.
8. Termination and Deletion
Upon termination of the Bond, the Architect shall delete or return all Personal Data in its possession within 30 days, unless required by law to retain specific records.
9. Contact Information
LocalBoostApp LLC
622 Central Ave, Unit A301, Johnstown, PA 15902
Email: hello@localboostapp.com
Legal Notice
This page is provided for transparency and should be reviewed with qualified counsel for your specific obligations. The Aletheia Framework is a technical security standard, not a replacement for legal advice.