Data Processing Addendum

Effective date: September 28, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between Wheeler Technologies, Inc., doing business as Sometime ("Sometime"), and the Customer. It applies whenever Sometime processes Customer Personal Data on the Customer's behalf, and takes effect when the Customer accepts the Terms. Customers who need a countersigned copy can request one at help@usesometime.com. Capitalized terms not defined here have the meanings given in the Terms.

1. Definitions

  • Data Protection Laws means all laws that apply to the processing of Customer Personal Data under the Terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act as amended ("CCPA") and similar US state laws.
  • Customer Personal Data means personal data in Customer Data that Sometime processes on the Customer's behalf in providing the Service.
  • Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • Subprocessor means a third party Sometime engages to process Customer Personal Data.
  • SCCs means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
  • "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR.

2. Roles and instructions

The Customer is the controller of Customer Personal Data, or a processor acting for its own clients, and Sometime is its processor (and, under the CCPA and similar laws, its service provider). The Customer is responsible for the lawfulness of the Customer Personal Data and of its instructions, including having a lawful basis for the processing and giving data subjects any required notices.

Sometime will process Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, and the Customer's configuration and use of the Service, unless the law requires otherwise, in which case Sometime will tell the Customer first unless the law prohibits it. Sometime will tell the Customer if it believes an instruction infringes Data Protection Laws. Annex I describes the processing.

3. Personnel

Sometime will ensure that everyone it authorizes to process Customer Personal Data is bound by confidentiality obligations and has access only as needed to provide the Service.

4. Security

Sometime will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, including at least the measures in Annex II. Sometime may update those measures if the update does not reduce the overall level of protection.

5. Security Incidents

Sometime will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, and Sometime will provide further information as it becomes available. Sometime will take reasonable steps to contain and remedy the incident. Notifying the Customer is not an acknowledgment of fault.

6. Subprocessors

The Customer gives Sometime general authorization to engage Subprocessors. The current list is at usesometime.com/subprocessors. Sometime will email the Customer's account administrators at least 30 days before a new Subprocessor begins processing Customer Personal Data. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected Service and receive a refund of prepaid Fees for the unused period.

Sometime will bind each Subprocessor by written terms that protect Customer Personal Data at least as strictly as this DPA, and remains responsible for its Subprocessors' performance.

7. Data subject requests and assistance

Taking into account the nature of the processing, Sometime will assist the Customer, through the Service or otherwise, in responding to requests from data subjects to exercise their rights. If Sometime receives such a request directly, it will pass it on to the Customer and will not respond itself except to direct the data subject to the Customer, unless the law requires otherwise.

Sometime will provide reasonable assistance with the Customer's data protection impact assessments and prior consultations with supervisory authorities, where they relate to the Service and the Customer cannot obtain the information otherwise.

8. Deletion and return

If the Customer asks within 30 days after the Terms end, Sometime will make Customer Personal Data available for export. Sometime will delete Customer Personal Data within 30 days after the Terms end, except where the law requires it to keep some, in which case it will protect that data under this DPA and process it only for that purpose. Backups are overwritten on their normal schedule.

9. Audits

Sometime will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including answers to a reasonable security questionnaire no more than once a year. Where Data Protection Laws require more, or after a Security Incident, the Customer may conduct an audit, itself or through an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, no more than once a year, at its own cost, and in a way that does not unreasonably disrupt Sometime's operations.

10. International transfers

Sometime processes Customer Personal Data in the United States. To the extent a transfer of Customer Personal Data to Sometime is a restricted transfer under Data Protection Laws:

  • From the EEA, the SCCs are incorporated into this DPA: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. Clause 7 (docking) applies; under Clause 9, option 2 (general written authorization) applies with the notice period in Section 6; the optional language in Clause 11 does not apply; under Clauses 17 and 18, the SCCs are governed by the laws of Ireland and disputes are resolved by the courts of Ireland. Annexes I and II of this DPA complete the SCCs' Annexes I and II, and the list at usesometime.com/subprocessors completes Annex III.
  • From the United Kingdom, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner, with the tables completed by the information in this DPA, and either party may end the Addendum as its Section 19 allows.
  • From Switzerland, the SCCs apply with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and "Member State" including Switzerland.

If the SCCs conflict with this DPA, the SCCs control.

11. US state privacy laws

As a service provider under the CCPA and similar US state laws, Sometime will not:

  • sell or share Customer Personal Data, as those terms are defined in the CCPA;
  • retain, use or disclose Customer Personal Data for any purpose other than providing the Service under the Terms, or outside the direct business relationship with the Customer;
  • combine Customer Personal Data with personal data it receives from or on behalf of another person, except as those laws permit a service provider to.

Sometime will comply with those laws and provide the same level of privacy protection they require, will tell the Customer if it can no longer meet its obligations, and will allow the Customer to take reasonable steps to stop and remedy unauthorized use. Sometime certifies that it understands and will comply with these restrictions.

12. Enrichment and usage data

To enrich a submission, Sometime sends the prospect's email address to its enrichment provider and receives the person's name, job title and employer. Sometime caches that result, keyed by email address, for up to 90 days and may use the cached result to answer a later lookup of the same address for any customer. The cache holds only information obtained from the provider, never Customer Data received from another customer. Company information comes from Sometime's own database of business information. As the Terms describe, Sometime may use data about the use and performance of the Service in aggregate or de-identified form that does not identify the Customer or any individual.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms, to the extent Data Protection Laws allow. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. This DPA ends when Sometime no longer processes Customer Personal Data.

Annex I · Description of the processing

A. Parties

  • Data exporter · the Customer, as identified in its account, acting as controller (or processor). Activities: use of the Service. Contact: the Customer's account administrator.
  • Data importer · Wheeler Technologies, Inc., doing business as Sometime, acting as processor. Activities: providing the Service. Contact: help@usesometime.com.

B. Description of the transfer

  • Data subjects · the Customer's prospects who submit its forms or booking pages, the Customer's users and sales reps, and the contacts and users in the Customer's connected CRM.
  • Categories of personal data · name, business email address, employer, job title and other form fields the Customer collects; answers to follow-up questions; meeting times and time zone; routing decisions; HubSpot and Google Analytics cookie identifiers; reps' account email, name, photo and calendar event times; CRM fields the Customer's routing rules use.
  • Sensitive data · none. The Customer will not use the Service to collect special categories of personal data.
  • Frequency · continuous, for as long as the Customer uses the Service.
  • Nature and purpose · hosting, storage, enrichment, qualification and routing, scheduling, and transmission to the Customer's connected services and email recipients, to provide the Service under the Terms.
  • Retention · for the term of the Terms and then as Section 8 describes. Enrichment results are cached for up to 90 days, calendar event times only within a rolling window of about four weeks.
  • Transfers to Subprocessors · as listed at usesometime.com/subprocessors, for the purposes listed there, for the duration above.

C. Competent supervisory authority

The supervisory authority determined under Clause 13 of the SCCs.

Annex II · Technical and organizational measures

  • Encryption in transit · every connection to the Service, and every call from the Service to an external provider's API, uses TLS.
  • Credential protection · OAuth tokens for connected Google and HubSpot accounts are encrypted with AES-256-GCM before storage. Sign-in tokens are stored hashed, are single-use, and expire after 15 minutes.
  • Access control · customer users sign in by emailed link, sessions are revocable server-side records, and state-changing requests require a per-session CSRF token. Access to production systems is limited to the personnel who need it.
  • Unguessable links · booking and connection links are signed with HMAC-SHA256 and verified before any data is read.
  • Data minimization · only the CRM fields routing needs are copied from connected CRMs, and only the start and end times of calendar events are requested from Google and stored.
  • Tenant isolation · every record is scoped to its Customer, and each Customer's pages are served only on that Customer's own hostnames or ours.
  • Availability and backups · a managed database with continuous backups and point-in-time recovery, and a static backup booking page that captures submissions during an outage.
  • Monitoring · automated alerts for failed jobs, revoked or failing connections, and processing delays.
  • Vendor management · Subprocessors are bound by written data protection terms (Section 6).

Annex III · Subprocessors

The list at usesometime.com/subprocessors.