Skip to content

Wisconsin-Based31 Five-Star Reviews

Data Processing Addendum

Effective July 2026 · Version 2026-07

This document is provided for general information and is being finalized pending review by legal counsel. It is not legal advice. Project-specific terms are governed by your signed Order Form and Client Services Agreement, which control in the event of any conflict.

1. Scope and roles

This Data Processing Addendum ("DPA") supplements the Client Services Agreement and applies where Tech Turtle LLC ("Tech Turtle," "we," "us," or "our") processes personal data on behalf of Client in providing the services. Where Client determines the purposes and means of processing personal data it provides, Client acts as the controller (or business) and we act as the processor (or service provider); each party complies with the privacy laws that apply to it.

For our own website visitors and prospects, we act as controller under our Privacy Policy. This DPA governs only data we process on Client's behalf under the engagement.

2. Processing details

Subject matter and duration: for the term of the engagement and any wind-down period. Nature and purpose: hosting, maintaining, and operating the Client's website and related services described in the Order Form. Types of data and data subjects: as determined by the Client's website and submissions (for example, the Client's own customers, leads, and contacts). We process personal data only on Client's documented instructions, which include the Order Form and this DPA, unless law requires otherwise.

3. Confidentiality and security

We restrict access to personal data to personnel who need it to provide the services and are bound by confidentiality. We maintain commercially reasonable technical and organizational measures appropriate to the risk, as summarized in our Security & Data-Retention Summary. We do not represent that any specific certification or audit standard applies unless expressly stated in writing.

4. Subprocessors

Client authorizes us to engage the subprocessors listed in our Subprocessor List to process personal data in connection with the services. We remain responsible for their performance of the applicable obligations. We will make available the current Subprocessor List and, where feasible, provide notice of a material change so Client may raise a reasonable objection.

5. Assistance and data subject requests

Taking into account the nature of the processing, we will provide reasonable assistance to help Client respond to verified requests from individuals to access, correct, or delete their personal data, and to meet Client's security-incident and impact-assessment obligations. Where an individual contacts us directly about Client data, we will refer them to Client unless law requires otherwise.

6. Security incidents

We will notify Client without undue delay after becoming aware of a confirmed personal-data breach affecting Client data, and will provide the information reasonably available to help Client meet its own notification obligations. Our notification is not an acknowledgment of fault or liability.

7. Return or deletion

On termination of the engagement, and on Client's written request, we will return or delete Client personal data in our control within a commercially reasonable period, except for copies we must retain for legal, tax, or recordkeeping purposes or that exist in routine backups, which we continue to protect until deleted in the ordinary course.

8. International transfers and order of precedence

Where personal data is processed outside its country of origin, the parties will rely on a lawful transfer mechanism as applicable. This DPA does not by itself commit either party to a particular processing region; storage regions are configured per the services and confirmed with Client where relevant.

If this DPA conflicts with the Client Services Agreement regarding the processing of personal data, this DPA controls to the extent of the conflict.