Legal

Data Processing Agreement

Effective date: August 26, 2026

This Data Processing Agreement ("DPA") supplements and is incorporated into our Terms of Service and any Statement of Work, order form, or Enterprise agreement (together, the "Agreement") between RD TechBridge, LLC ("RD TechBridge," "we," "us," or "our") and a business using our platform to operate its own website, bookings, e-commerce, or customer communications ("Tenant," "you"). This DPA applies whenever RD TechBridge processes personal data on your behalf as part of delivering the Services — for example, your customers' booking details, leads, or order information. It does not cover RD TechBridge's own collection of data directly from you or from visitors to our marketing site, which is addressed in our Privacy Policy.

1. Roles of the Parties

As between RD TechBridge and Tenant, Tenant is the "Business" (or, where applicable under other privacy laws, the "Controller") and RD TechBridge is the "Service Provider" (or "Processor") with respect to any personal data of Tenant's own customers, leads, or end users ("Tenant Customer Data") that RD TechBridge processes while providing the Services. Tenant determines the purposes for which its customers' personal data is collected and used; RD TechBridge processes Tenant Customer Data only to deliver, support, and secure the Services.

2. Scope of Processing

Depending on which features of the platform you use, Tenant Customer Data processed on your behalf may include:

  • Names, email addresses, and phone numbers of your leads and customers
  • Booking, appointment, and scheduling details
  • E-commerce order information (payment card data itself is tokenized and handled directly by our payment processor — see Section 6)
  • Content your customers submit through forms, chat, or AI agents you have configured on your site
  • Communications sent or logged through the platform on your behalf

RD TechBridge processes Tenant Customer Data only as necessary to provide the Services, in accordance with your configuration of the platform and your documented instructions, and as otherwise required by law.

3. Confidentiality

RD TechBridge restricts access to Tenant Customer Data to personnel and contractors who need it to provide the Services, and requires those personnel to be bound by confidentiality obligations at least as protective as those in our Terms of Service.

4. Security Measures

RD TechBridge maintains technical and organizational measures designed to protect Tenant Customer Data, including HTTPS encryption in transit, role-based access controls on our AWS infrastructure, and limiting production data access to personnel who need it. No method of transmission or storage is completely secure, and RD TechBridge cannot guarantee absolute security.

5. Sub-processors

Tenant authorizes RD TechBridge to engage the following sub-processors to deliver the Services:

  • Amazon Web Services (AWS) — application hosting (EC2) and file/asset storage (S3)
  • Vercel — hosting for the client-facing website and admin dashboard
  • Stripe — payment processing and, where applicable, Stripe Connect for tenant payouts
  • Resend — transactional and outreach email delivery
  • OpenAI — AI-generated content, lead parsing, and AI agent features you enable
  • Google — Google Business Profile, Calendar, Maps/Places, and related integrations you connect

Each sub-processor is contractually bound to data protection obligations consistent with this DPA. If we engage a new sub-processor with access to Tenant Customer Data, we will update this list and notify active Tenants by email at least 15 days in advance, giving you an opportunity to raise concerns before the change takes effect.

6. Payment Data

Payment card data is collected and processed directly by Stripe and does not pass through or get stored on RD TechBridge servers. RD TechBridge receives only tokenized payment references and transaction metadata (amount, status, timestamps) necessary to display order and billing information within the platform.

7. Assistance with Data Subject Requests

If one of your customers contacts RD TechBridge directly to exercise a privacy right (such as access, correction, or deletion) regarding data you control, we will refer the request to you. We will provide reasonable assistance, through the platform's existing tools or otherwise, to help you respond to such requests within the time required by applicable law.

8. Data Breach Notification

If RD TechBridge becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Tenant Customer Data, we will notify you without undue delay, and in no event later than 72 hours after becoming aware of the breach, with information reasonably available to us at the time regarding the nature of the breach and any remediation steps taken or planned.

9. Data Retention and Deletion

RD TechBridge retains Tenant Customer Data for as long as your account is active. Upon termination of your Agreement, RD TechBridge will delete or anonymize Tenant Customer Data within 30 days, except to the extent retention is required by law or necessary to resolve disputes or enforce our agreements. You are responsible for exporting any data you wish to keep before termination takes effect.

10. Audits

On reasonable written request, no more than once per 12-month period, RD TechBridge will provide a written summary of its security practices and complete a reasonable, standard-form security questionnaire. RD TechBridge does not commit to unlimited on-demand audits or on-site inspections; alternative audit arrangements may be negotiated as part of an Enterprise agreement.

11. CCPA Service Provider Terms

To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), applies to Tenant Customer Data, RD TechBridge is a "Service Provider" as defined under that law and certifies that it will: (a) not sell or share Tenant Customer Data; (b) not retain, use, or disclose Tenant Customer Data for any purpose other than performing the Services, including any commercial purpose outside the direct business relationship between RD TechBridge and Tenant; and (c) not combine Tenant Customer Data with personal data received from another source, except as permitted under the CCPA/CPRA.

12. International Scope

This DPA is written for Tenants and Tenant customers located in the United States. If you or your customers are located outside the United States (including the EU/UK), contact us before onboarding — additional terms, such as Standard Contractual Clauses, may be required and are not included in this version of the DPA.

13. Relationship to Other Agreements

This DPA works together with our Terms of Service, our Privacy Policy, and any signed SOW, order form, or Enterprise agreement. If there is a conflict between this DPA and a signed Enterprise agreement specifically addressing data processing, the signed agreement controls.

14. Governing Law

This DPA is governed by the laws of the State of California, consistent with the governing law provision in our Terms of Service.

15. Changes to This DPA

We may update this DPA from time to time, including to reflect a change in sub-processors as described in Section 5. Material changes will be communicated to active Tenants by email.

16. Contact

Questions about this DPA can be sent to:

RD TechBridge, LLC
Email: rctechconsulting1@gmail.com
Phone: (626) 922-0091
Location: California, United States

Terms of Service →Privacy Policy →Subscription Terms →Help Center →