Skip to content
Updated September 16, 2026

Data Processing Agreement

Carver Sync LLC ("Carver Sync", "we", "us") builds custom software, AI systems, CRM builds, websites, voice agents and marketing infrastructure for other businesses. Doing that work means we hold personal data that belongs to your business and to the people your business deals with. This Data Processing Agreement (this "DPA") is the contract that governs that handling: what we may do with that data, what we must do to protect it, who else touches it, and what happens to it when we part ways.

This is the most technical of our four legal pages, because privacy law uses defined terms and those terms have to stay exact. We have kept the defined terms and the statutory references precise and written everything around them in plain English. It is still not legal advice, and Carver Sync is not a law firm: nothing here tells you what the law requires of your business. Where this page and a separately signed agreement between us conflict, the signed agreement wins.

When this DPA applies

This DPA applies whenever we process personal data on your behalf in the course of delivering a product or service: Horsie and Horsie Cloud, Total Analytics, GoCarve Trades, GoCarve Studio, GoCarve Creatives, GoCarve Voice, GoCarve Events, the AI Forge, Carver City, custom software, the CORE website and CRM package, marketing and media work, or anything else we build for you. It forms part of our Terms of Service and of any signed agreement that references it.

It takes effect on the earliest of these: you accept the Terms of Service, you sign an agreement that references this page, or we begin processing personal data for you. No separate signature is needed for it to bind us. If your procurement process needs a countersigned copy carrying your entity name, email info@carversync.com and we will sign one. A signed copy governs over this page where the two differ.

This DPA is about data we handle for you. Data we collect for our own purposes, such as visitors to carversync.com and people who book a call with us, is covered by the Privacy Policy. Affiliates are covered by the Affiliate Agreement.

Definitions

These terms carry the meanings given to them in the applicable law. They are repeated here so this page can be read on its own.

  • Applicable Data Protection Law.Every privacy and data protection law that applies to the processing under this DPA, including Regulation (EU) 2016/679 (the "GDPR"), the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 (the "UK GDPR") together with the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (the "FADP"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (together, the "CCPA"), and the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act and the Virginia Consumer Data Protection Act.
  • Personal Data.Any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1), and "personal information" as defined in Cal. Civ. Code section 1798.140.
  • Customer Personal Data. Personal Data that we process on your behalf and under your instructions in delivering the Services. It is the only data this DPA governs.
  • Processing.Any operation performed on Personal Data, as defined in GDPR Article 4(2): collection, recording, storage, retrieval, use, disclosure, transmission, erasure and everything in between. "Process" and "processed" follow from it.
  • Controller and Processor.As defined in GDPR Article 4(7) and Article 4(8). The Controller decides why and how Personal Data is processed. The Processor processes it on the Controller's behalf.
  • Data Subject.The identified or identifiable person the Personal Data is about, and "consumer" as defined in the CCPA and the other US state laws named above.
  • Personal Data Breach. A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, as defined in GDPR Article 4(12).
  • Subprocessor. Any third party we engage to process Customer Personal Data on our behalf, as contemplated by GDPR Article 28(2) and Article 28(4). The current list is in Annex C.
  • Business, Service Provider, Sell and Share. As defined in Cal. Civ. Code section 1798.140. In CCPA terms you are the Business and we are the Service Provider.
  • Standard Contractual Clauses ("SCCs"). The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
  • UK Addendum. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022.
  • Services. The Products and the Services as those terms are defined in the Terms of Service, taken together: every product, software system, build and service Carver Sync provides to you under the Terms of Service or a signed agreement. Where this DPA says Services it means all of that, and it is used in that sense throughout, so nothing we build for you falls outside this DPA on a definitional technicality.

Terms used in this DPA that are defined in the Terms of Service and not redefined here keep the meaning they have there.

Each of us complies with our own law

You comply with Applicable Data Protection Law as it applies to you, and we comply with it as it applies to us. Those are different jobs. Yours covers having a lawful basis for the processing, giving notice to the people whose data it is, collecting consent where consent is what the law requires, honoring opt outs, and deciding what data should be in the system at all. Ours covers processing that data only as you tell us to, keeping it secure, and everything else set out below. Neither of us is responsible for the other's half, and we cannot be your data protection officer or your compliance department.

Who is the controller and who is the processor

For Customer Personal Data you are the Controller and we are the Processor. You decide what goes into the systems we build, why it is there and how long it stays. We process it to deliver the Services and for nothing else.

Where you are yourself a Processor acting for someone else, for example an agency running systems for its own clients, we act as your Subprocessor and this DPA reads accordingly. You confirm in that case that your own controller has authorized the engagement of Carver Sync and of the Subprocessors in Annex C, and that your instructions to us match the instructions you were given.

There are two narrow places where we are a Controller rather than a Processor, and we would rather name them than blur them. First, our own business records: your billing contact, the emails between us, our calendar, our accounting. Second, operational telemetry we keep about the systems we run, such as error logs, request rates and abuse signals, which we use to keep the systems up and secure and not for any other purpose. Both are described in the Privacy Policy. We do not treat the contents of your CRM, your call recordings, your customer lists or your Forge answers as our own data, and we do not mine them to build our products.

Your instructions

We process Customer Personal Data only on your documented instructions, as required by GDPR Article 28(3)(a), including for transfers to a third country. Your instructions are: this DPA, the Terms of Service, any signed agreement or statement of work, the configuration you set in the products, the build briefs and Forge answers you submit, and anything else you ask us in writing (email counts as writing). Delivering the Services you have asked for is itself an instruction to process the data the Services need.

Two exceptions, both narrow. We may process Customer Personal Data where US law requires it of us, in which case we will tell you before we do unless the law forbids telling you. And if you give us an instruction we believe breaks Applicable Data Protection Law, we will tell you and we may pause that instruction until we have sorted it out with you, as the second subparagraph of GDPR Article 28(3) contemplates. Saying nothing and doing it anyway is not a service to either of us.

If an instruction falls outside the scope of what you are paying for, for example a bespoke export, a custom retention build, or a migration we did not quote, we will tell you what it takes and agree the cost with you before we start.

Your consents, your notices, and the indemnity that follows

You are responsible for the lawfulness of the data you put in front of us. That means you have the legal basis to collect it, you have given the people it belongs to the notice the law requires, you hold the consents the law requires, including consent for calling, texting, emailing and recording where that applies, and you have the right to hand that data to us and to the Subprocessors in Annex C for the purposes described in Annex A. The obligations in the Terms of Service about the TCPA, CAN-SPAM, do not call lists and recording consent sit with you as the business making the contact, and they are not restated here.

You will defend and indemnify Carver Sync against claims, fines and costs, including reasonable legal fees, that arise from Customer Personal Data you gave us without the basis, notice or consent the law required, or from an instruction of yours that broke Applicable Data Protection Law. This does not cover a claim caused by our own breach of this DPA, our gross negligence or our willful misconduct. It covers the decisions only you can make: whose data goes in, and what is done with it.

What we process, and why

The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subject are set out in Annex A, which is what GDPR Article 28(3) requires to be in writing. Annex A is written to cover the whole Carver Sync product line, so read it against the Services you actually bought. If your engagement processes something Annex A does not describe, tell us and we will put the specifics in your signed agreement.

Security

We implement appropriate technical and organizational measures to protect Customer Personal Data, as required by GDPR Article 32, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing as well as the risk to the people involved. Those measures are described, honestly and specifically, in Annex B.

Two things we will not do here. We will not claim a certification we do not hold: Annex B ends with a list of the certifications and frameworks Carver Sync is not certified under, because an earlier version of this document claimed certifications that belonged to another company. And we will not promise that measures never change. We may update them as the products and the threats change, provided the protection does not drop below what Annex B describes.

Our people keep it confidential

Access to Customer Personal Data is limited to the people who need it to do the work. Everyone with access, employees and contractors alike, is under a written obligation of confidentiality that survives the end of their engagement, which is what GDPR Article 28(3)(b) requires. Access is granted per engagement and removed when the engagement or the person's role ends. Carver Sync is a small team, and we would rather tell you that than describe a department we do not have.

Helping you answer people who ask about their data

People have rights over their own data: access, correction, deletion, portability, restriction and objection under GDPR Articles 12 to 23, and the equivalent rights under the CCPA and the other US state laws. Those requests go to you, because you are the Controller and only you know the context. We help you answer them, as GDPR Article 28(3)(e) requires.

In practice: where the product gives you the tools to find, export, correct or delete a record yourself, use them. Where it does not, ask us and we will do it, at no charge for ordinary volumes. If a request reaches us directly, we will not answer it on our own account. We will tell you within 5 business days, pass you what we have, and wait for your instruction, unless the law requires otherwise or the request concerns data we hold as a Controller.

Impact assessments and prior consultation

If you have to run a data protection impact assessment under GDPR Article 35, or consult a supervisory authority under GDPR Article 36, we will give you the information about our processing that you reasonably need to do it, which is what GDPR Article 28(3)(f) requires. That includes the details in Annex A, the measures in Annex B, the Subprocessor list in Annex C, and answers to a reasonable security questionnaire. We will not write your assessment for you, because the risk being assessed is the risk of your processing.

If there is a breach

GDPR Article 33(2) requires a Processor to notify the Controller of a Personal Data Breach without undue delay. We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 72 hours of becoming aware of it. Both halves of that run from the same event, our awareness, so the outer limit cannot be pushed back by how long we take to confirm what happened. Your own clock under GDPR Article 33(1) starts when you become aware, and it would be no use to you if ours started later. Notice goes to the account contact we have on file by email and, if we have your number, by phone, so keep that contact current.

The notice will describe what happened, the categories and approximate number of Data Subjects and records involved as far as we know them, the likely consequences, what we have done and what we are doing next, and a contact who can answer follow up questions. If we do not have all of that at first, you get what we have and the rest as we learn it, rather than silence while we assemble a complete report. We will help you meet your own obligations to notify a supervisory authority under GDPR Article 33 or affected people under GDPR Article 34, and under the US state breach laws that apply to you.

One honest note on scope. Several of the systems your data lives in belong to vendors, as Annex C sets out. If a breach happens inside a vendor's platform, our notice to you depends on their notice to us, and we will tell you when we learned it and from whom. Notifying you is not an admission that the breach was our fault.

Getting your data back, and getting it deleted

At any time during the engagement you can ask us for a copy of Customer Personal Data in a commonly used, machine readable format, and we will get you one. When the Services end, GDPR Article 28(3)(g) gives you the choice of deletion or return, and it is yours to make: tell us within 30 days of termination which you want. Absent an instruction we keep the data for 60 days after termination and then delete it, which is there so a hasty ending does not destroy your records.

The Terms of Service describe a 30 day window after an account closes in which you can ask for a copy of your data. Read the two together this way. You have 30 days to tell us whether you want deletion or return and to ask for your copy, we hold Customer Personal Data for 60 days after termination either way, and the deletion date for personal data we hold on your behalf is the one in this DPA, because data protection matters are where this DPA governs. If you need longer than 60 days, ask before the clock runs out and we will agree it in writing.

Deletion has real world edges and we would rather name them. Data inside a platform you own, such as your own CRM sub-account, stays with you and is yours to delete. Copies held by a Subprocessor are deleted on that vendor's cycle once we delete our own. Routine backups age out on their retention schedule rather than being surgically edited, and until they do, the data in them stays encrypted and is not used for anything. We may keep what US law requires us to keep, mainly accounting records, and we will tell you if that applies. On request we will confirm deletion in writing.

Audits, and what we will actually give you

GDPR Article 28(3)(h) requires us to make available the information needed to demonstrate compliance with Article 28 and to allow for and contribute to audits and inspections. Here is how that works with us, stated plainly so nobody is surprised.

  • First, documentation. Annexes A, B and C, our answers to a reasonable security questionnaire, and the security documentation our vendors publish. For most reviews this is the whole exercise, and it costs you nothing.
  • Then, if that is not enough, an audit. Once in any 12 month period, on 30 days written notice, during business hours, under a confidentiality agreement, scoped to the processing we do for you, and at your expense. More often than that only where a supervisory authority requires it or after a confirmed Personal Data Breach affecting your data.
  • Not a vendor's facilities. We cannot grant access to premises or systems that belong to the companies in Annex C, because they are not ours to open. For those we pass on what the vendor publishes.
  • Not other customers.An audit cannot reach another customer's data, systems or configuration, and yours is protected the same way.

Records of processing

We maintain a record of the categories of processing carried out on behalf of each customer, as GDPR Article 30(2) requires, covering our identity and contact details, the categories of processing, transfers to third countries, and a general description of the security measures in Annex B. We make it available to a supervisory authority on request, and to you where you reasonably need it for your own Article 30(1) record.

Sensitive data, health information and children

The Services are not built for special categories of personal data under GDPR Article 9, data about criminal convictions and offences under GDPR Article 10, protected health information under HIPAA, payment card numbers, or government identifiers. Do not load them into a system we run unless we have first agreed it in writing and put the extra safeguards in place. For protected health information that means a signed business associate agreement before any of it moves, and buying a subscription does not sign one. Card details are handled by Stripe on its own hosted page and never reach our systems.

The Services are not directed at children. Do not use them to process data about children under 16, or under 13 where US law sets that line, without telling us first so we can agree the terms that requires.

California: our service provider terms

For personal information subject to the CCPA, you are the Business and Carver Sync is a Service Provider. Cal. Civ. Code section 1798.100(d) requires certain terms in that contract, and these are ours.

  • We do not sell or share it. Carver Sync does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined in Cal. Civ. Code section 1798.140. No money and no other valuable consideration changes hands for your data. We do not load advertising pixels or third-party ad trackers on carversync.com.
  • We use it only for the business purpose. We retain, use and disclose personal information only to perform the Services specified in this DPA and the agreement between us, or as otherwise permitted by the CCPA. We do not use it for our own commercial purposes outside that.
  • We do not combine it. We do not combine personal information you give us with personal information we receive from anyone else, except where the CCPA permits a service provider to do so.
  • We certify that we understand it. Carver Sync understands the restrictions in this section and will comply with them, and imposes the same restrictions on the Subprocessors in Annex C.
  • We hold to the same standard you do. Carver Sync complies with the obligations the CCPA places on a service provider, and provides personal information the same level of privacy protection the CCPA requires of you. We impose that same obligation on the Subprocessors in Annex C. That is a broader promise than the bullets above, and it is meant to be: the standard is the statute, not just the list on this page.
  • You can check, and we will fix. You may take reasonable and appropriate steps to confirm we are using personal information consistently with your obligations under the CCPA, and to stop and remediate unauthorized use. The audit section above is how that gets done in practice.
  • We tell you if we cannot hold the line. If we determine that we can no longer meet our obligations under the CCPA, we will notify you promptly.
  • We help you honor requests. We assist you in responding to consumer requests to know, delete, correct, opt out and limit the use of sensitive personal information, as described above.

Other US state privacy laws

Where the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act or the Virginia Consumer Data Protection Act applies to your processing, we act as a processor under those laws and this DPA is the processor contract they require. The duties are close enough to the ones already written above that restating them separately would add length without adding protection: we follow your instructions, keep the data confidential, secure it, help with consumer requests and assessments, delete or return it at the end, engage subprocessors under the same terms, and make available the information those laws require. Where one of those laws imposes something stricter than this DPA, the stricter requirement applies to that processing.

Subprocessors

You give us general written authorization to engage Subprocessors, within the meaning of GDPR Article 28(2). The Subprocessors engaged as of September 16, 2026 are listed in Annex C, with what each one does and what data reaches it. We did not inherit that list from anyone: it is the set of companies Carver Sync actually depends on.

Before a new Subprocessor starts processing Customer Personal Data we will tell you at least 30 days in advance, by email to your account contact and by updating Annex C on this page. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will work with you to find a way to deliver the service without that vendor. If there is no reasonable way, either of us may terminate the affected service on written notice, and we will refund any prepaid fees for the part you have not received. Where the SCCs apply to the affected processing, that right to terminate on an unresolved objection is yours alone, as Clause 9 provides, because an SCC right you exercise should never become a reason we can exit. Staying silent for the 30 days is an approval.

Every Subprocessor is engaged under a written contract that imposes data protection obligations no less protective than this DPA, as GDPR Article 28(4) requires, and we remain fully liable to you for their performance of those obligations. That last part matters: subcontracting the work does not subcontract the responsibility.

Two categories that are not vendors but should be named anyway. Independent contractors who work on your build are not Subprocessors in their own right: they work under our direction and under written confidentiality obligations, with access granted per engagement. And where your service runs on a platform account you own, such as your own GoHighLevel sub-account, your telephone carrier, or a system we connect on your instruction, that provider is your vendor under your contract with them, not ours.

International transfers, and what we are not certified under

Carver Sync operates in the United States. Our team is in Arizona, and the applications and Postgres databases we run for you are hosted with Railway in the United States, so Customer Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to the United States when we process it.

Onward transfers happen as well, and we would rather say so than imply the data never moves again once it reaches us. Each vendor in Annex C processes under its own published terms and in the regions those terms allow, and several of them operate entities and infrastructure outside the United States: telephony routes through the carriers serving the number being contacted, a mailbox or tenant follows its own residency setting rather than our address, and some providers run regional capacity. Where a vendor processes Customer Personal Data outside the United States, that onward transfer runs on that vendor's own transfer mechanism, normally its own Standard Contractual Clauses, under our contract with it, and our contract with that vendor requires protection no less protective than this DPA either way. Ask us about a specific vendor's current regions and we will tell you what its terms say.

Carver Sync is not certified under the EU-U.S. Data Privacy Framework, the UK Extension to it, or the Swiss-U.S. Data Privacy Framework, and we have not certified anything to the US Department of Commerce. We do not rely on any of those frameworks as a transfer mechanism, and nothing we publish should be read as claiming we do.

For those transfers we rely on the Standard Contractual Clauses under GDPR Article 46(2)(c), which are incorporated into this DPA by reference and completed as follows.

  • Module selection. Module Two (controller to processor) applies where you are a Controller. Module Three (processor to processor) applies where you are a Processor acting for another controller.
  • Clause 7, the docking clause. Included, so another entity may accede to the SCCs by agreement of both parties.
  • Clause 9, subprocessors. Option 2, general written authorization, applies, with the 30 day notice period set out in the Subprocessors section above.
  • Clause 11, redress. The optional independent dispute resolution wording is not adopted.
  • Clause 17, governing law. Option 1 applies, and the SCCs are governed by the law of Ireland.
  • Clause 18(b), forum. Disputes arising from the SCCs are resolved by the courts of Ireland.
  • The annexes. Annex I of the SCCs is completed by Annex A below, Annex II by Annex B below, and Annex III by Annex C below.
  • United Kingdom. The UK Addendum applies to UK transfers. Table 1 is completed by Annex A, Tables 2 and 3 by the selections above and the annexes below, and in Table 4 neither party may end the Addendum as set out in Section 19.
  • Switzerland.For transfers subject to the FADP, the SCCs apply with these adjustments: references to the GDPR are read as references to the FADP, the competent supervisory authority is the Federal Data Protection and Information Commissioner, and "member state" includes Switzerland so that data subjects in Switzerland may enforce their rights there.

Where the SCCs and the rest of this DPA conflict on a transfer, the SCCs win. If a court or authority invalidates the SCCs, or a new transfer mechanism replaces them, we will adopt the replacement and update this page rather than carry on under a mechanism that no longer works.

One more honest limit. Carver Sync has no establishment in the European Union or the United Kingdom and has not appointed a representative under GDPR Article 27. If your engagement needs one, tell us and we will address it in your signed agreement.

Government and law enforcement requests

If a government body or law enforcement agency asks us for Customer Personal Data, we will tell you so you can respond, unless we are legally prohibited from telling you. If we are prohibited, we will use reasonable efforts to have the prohibition lifted and to tell you as much as we lawfully can, as soon as we lawfully can. We will challenge a request we believe is unlawful or overbroad, and we will disclose only the minimum the order actually compels. This mirrors the transparency obligations in Clause 15 of the SCCs, and it applies whether or not the SCCs are in play.

Liability

Each party's liability under this DPA is subject to the exclusions and the liability cap in the Terms of Service or in your signed agreement, and claims under this DPA and the agreement together count against that one cap rather than starting a second one. Nothing here limits a Data Subject's rights under the SCCs or under Applicable Data Protection Law, and nothing here limits liability that the law does not allow us to limit.

Term, changes, precedence and where disputes go

This DPA lasts as long as we process Customer Personal Data for you, and the obligations that are meant to outlive it, confidentiality, deletion and the transfer clauses, do.

We update this page when the law changes, when our vendors change, or when what we build changes, and the date at the top says when. For a change that materially reduces your protection or adds a Subprocessor, you get at least 30 days notice by email first. Editorial changes take effect when posted.

Order of precedence, highest first: the Standard Contractual Clauses for transfers they cover, then a signed agreement between us that addresses data protection, then this DPA, then the Terms of Service. If any part of this DPA is unenforceable, the rest stays in force.

Governing law and dispute resolution follow the Terms of Service in full, not only its venue sentence. Arizona law governs this DPA. Any dispute, claim or controversy arising out of or relating to this DPA, including a privacy, security or breach claim, is resolved by binding arbitration under the arbitration section of the Terms of Service and on exactly the terms written there: the American Arbitration Association Commercial Arbitration Rules, one arbitrator, seated in Phoenix, Arizona, the party that starts the arbitration advancing the filing, administrative and arbitrator fees, and the class and collective action waiver applying here just as it applies there. Nothing in this DPA carves privacy or breach claims out of that section.

Three things stay with the courts. Either of us may ask the state and federal courts located in Phoenix, Maricopa County, Arizona for provisional relief such as a temporary restraining order or a preliminary injunction. Any claim for which the class and collective action waiver is held unenforceable goes to those same courts, and only that claim. And disputes arising from the SCCs are the exception to all of it: Clause 17 places them under the law of Ireland and Clause 18(b) places them before the courts of Ireland, which is a right of the data subject and the exporter that we are not trying to route around.

How to reach us about data protection

Email info@carversync.com or call 602-560-5546. Postal mail reaches us at Carver Sync LLC, 14090 W Gray Fox Trail, Surprise, AZ 85387. Carver Sync has not appointed a data protection officer under GDPR Article 37, because none of the criteria in that article apply to us. Data protection questions go to the address above and reach a human who can answer them.

Annex A: details of the processing

This Annex completes GDPR Article 28(3) and Annex I of the Standard Contractual Clauses.

A1. The parties

  • Data exporter. The customer: the entity that accepted the Terms of Service or signed an agreement with Carver Sync. Its name, address and contact person are those on the account or in the signed agreement. Role: Controller, or Processor where the customer processes on behalf of its own clients. Activities relevant to the transfer: receiving the products and services described at carversync.com.
  • Data importer. Carver Sync LLC, an Arizona limited liability company, 14090 W Gray Fox Trail, Surprise, AZ 85387, United States. Contact for data protection: info@carversync.com, 602-560-5546. Role: Processor, or Subprocessor where the exporter is a Processor. Activities relevant to the transfer: designing, building, hosting, configuring, operating and supporting custom software, AI systems, CRM and website builds, voice agents, analytics and marketing infrastructure for the exporter.

A2. Categories of data subjects

  • Your customers and prospects. People in your CRM: leads, customers, past customers and anyone who filled in one of your forms.
  • People who contact you. Callers, texters, chat visitors and email correspondents handled by a system we built, including people a voice agent speaks to.
  • Your staff. Employees, contractors and agents of yours who use, administer or are named in the systems.
  • Visitors to sites we build for you. Including the people who book appointments or submit a questionnaire.
  • Your business contacts. Suppliers, vendors and partners whose contact records you store in the systems.

A3. Categories of personal data

  • Identity and contact data. Name, email address, phone number, postal address, company, job title.
  • Account data. Login email, password stored as a hash rather than as a password, two factor state, session and sign-in records for the consoles we build.
  • CRM and activity data. Records, tags, pipeline and opportunity stages, notes, custom fields and custom values, task and appointment history.
  • Communications content. The text of calls, SMS, email, chat and form submissions handled by the systems, and call recordings and transcripts where you switch them on.
  • Booking and scheduling data. Time slot, time zone, location, service requested and the brief assembled from the answers given.
  • Commercial data. Quotes, invoices, order and payment status. Card numbers are collected by Stripe on its own hosted page and are not stored by Carver Sync.
  • Technical and attribution data. IP address, browser and device information, page views, referrer and first touch or last touch attribution events where an analytics product is running.
  • Anything else you load. Content, files, lists and configuration you put into a system we run. You decide what that is, which is why the lawfulness of it sits with you.

A4. Sensitive data

None is requested and none is required by the Services. Special category data under GDPR Article 9, criminal offence data under GDPR Article 10, protected health information under HIPAA, payment card numbers and government identifiers are out of scope unless a separate signed agreement, and for health information a signed business associate agreement, is in place first and records the additional safeguards. Data about children is out of scope as described above.

A5. Frequency of the transfer

Continuous, for as long as the Services run.

A6. Nature and purpose of the processing

  • Hosting and storage. Running the databases and applications that hold your records, and backing them up.
  • Building and configuring. Designing schemas, automations, pipelines, agent configurations and integrations, including migrating data you ask us to move.
  • Delivering communications you configure. Placing and answering calls, sending SMS and email, running chat, and recording or transcribing where you have switched that on and hold the consent for it.
  • AI inference. Sending prompts and context to AI providers to generate replies, summaries, schema designs, scripts and synthesized speech. What goes into a prompt depends on what the product is doing for you.
  • Analytics and attribution. Producing the reporting you asked for, on your own data.
  • Support and troubleshooting. Investigating problems you report, which sometimes means looking at the record that broke.
  • Security and integrity. Rate limiting, abuse prevention, logging and access control for the systems we run.
  • Deletion and return. Exporting your data and deleting it when the engagement ends.

A7. Duration

For the term of the agreement between us, plus the deletion period described in the section about getting your data back, plus any period US law requires us to retain specific records.

A8. Processing by subprocessors

Subject matter and nature as set out per vendor in Annex C. Duration matches the term of the Services, or until we replace that vendor.

A9. Competent supervisory authority

Where the data exporter is established in an EEA member state, the supervisory authority of that member state. Where the exporter is not established in the EEA but falls within GDPR Article 3(2) and has appointed a representative under GDPR Article 27, the supervisory authority of the member state where that representative is established. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.

Annex B: technical and organizational measures

This Annex completes GDPR Article 32 and Annex II of the Standard Contractual Clauses. It describes what Carver Sync actually does. Where a control belongs to an infrastructure vendor rather than to us, it says so and names the vendor, because claiming someone else's control as your own is how a document like this stops being useful.

B1. Encryption in transit

Traffic to the sites and applications we run is served over HTTPS with TLS, and TLS certificates and termination are provided by Railway, our hosting vendor. Every response carries a Strict-Transport-Security header with a two year max-age covering subdomains, so a browser that has seen the site once will not talk to it over plain HTTP afterwards. Connections to our vendors' APIs are made over TLS.

B2. Encryption at rest

Application data sits in Postgres databases hosted on Railway, which provides the storage encryption for the underlying volumes. Data held inside a vendor platform, such as your CRM records in GoHighLevel or your call recordings with Twilio, is encrypted at rest by that vendor under its own terms. We do not operate our own disk level encryption on top of that, and we would rather tell you whose control it is than imply it is ours.

B3. Passwords, sessions and two factor

For the admin consoles we build, passwords are hashed with scrypt using a per-user random salt and compared in constant time, so a database copy does not hand anyone a password. A minimum password length is enforced. Two factor authentication is TOTP from a standard authenticator app, and single use recovery codes are stored only as SHA-256 hashes. Sessions are signed JSON Web Tokens in httpOnly cookies with a fixed expiry, and changing a password or changing two factor settings invalidates every existing session at once. The step between password and code carries no privileges other than the right to submit the code. Nothing in the authentication path logs a password, a TOTP secret or a recovery code.

B4. Access control and least privilege

Console accounts are named and individual, with roles that separate owner from admin. There are no shared logins for the systems we build. API tokens for vendor integrations are scoped to the specific integration and the specific account they serve, and are rotated when a person or an engagement ends. Access to a customer environment is granted for the engagement that needs it and removed when it ends. Where a vendor account offers two factor authentication, we turn it on.

B5. Secrets management

Credentials, API keys and signing secrets are held as environment variables in the hosting provider (Railway) and in local environment files that are excluded from source control. They are not committed to a repository, not embedded in client side code, and not sent over email or chat. A secret we believe has been exposed gets rotated rather than watched.

B6. Throttling and abuse controls

Sign-in is throttled twice over: per IP address, and per account in the database so that rotating a forwarded IP header cannot reset the counter. Public endpoints that accept submissions are rate limited by IP, request bodies are capped in size, and state changing requests are checked against the request origin. Unguessable random tokens, rather than sequential identifiers, address records that are reachable by link.

B7. Browser and network hardening

The sites we run ship a Content Security Policy that refuses scripts, frames and connections from origins that are not on a written allowlist, a frame-ancestors directive that blocks embedding by third parties, referrer and content type protections, and the HSTS header described above. We do not load Google Analytics, advertising pixels or third-party ad trackers on carversync.com. Where a third-party script is loaded at all, for example a CRM chat widget, it is named in the Privacy Policy and allowed explicitly by that policy.

B8. Payment data

Checkout runs on Stripe's own hosted page. Card numbers, CVCs and expiry dates go to Stripe and never reach our systems, so PCI scope for cardholder data stays with Stripe, which maintains its own compliance for it. We store the order and subscription status Stripe reports back, not the instrument.

B9. Data minimization

We ask for what the work needs and no more. Questionnaires and the links that reopen a saved questionnaire use a long random token instead of forcing an account, which means we hold fewer credentials, and we tell the person plainly that the link is a key and should not be forwarded. We do not copy customer records out of the systems they belong in for convenience.

B10. Change control and integrity

Code lives in private version control. Changes are reviewed before they are deployed, deployments are built from a known commit, and database schema changes are applied in migrations rather than by hand on a live database. Types are checked and the linter runs before a build ships. Application inputs are validated and capped at the boundary.

B11. Logging and monitoring

We keep application and deployment logs, which record errors, request outcomes, and administrative actions such as sign-ins, lockouts and account changes. Logs are retained on our hosting provider (Railway) and are used to run and secure the systems, not for any other purpose. Where a product we build includes an audit trail, our standard is an append-only record whose entries are hash chained so that tampering is detectable, and reads of sensitive records are logged as well as writes. We do not log secrets or credentials.

B12. Availability, backup and recovery

Hosting and managed Postgres are provided by Railway, which runs the automated backups of the managed database and the redundancy of the underlying platform. Our applications can be rebuilt and redeployed from source control at any time. We do not publish an uptime percentage, a recovery point objective or a recovery time objective, and a self-serve subscription does not carry a service level agreement. If you need a contractual availability commitment, it has to be negotiated into a signed agreement.

B13. Physical security

Carver Sync does not operate a data center and has no server room. Hosting is on Railway, which provides the physical security of the underlying facilities. Every other system that holds customer data is operated in the vendor's own facilities: GoHighLevel, Twilio, Stripe, Resend, Zoom, Microsoft 365, OpenAI, Anthropic and ElevenLabs each secure their own premises. For our own equipment, company laptops use full disk encryption, screen lock and a password manager, and customer data is not kept on removable media.

B14. People

Carver Sync is a small team. Everyone with access to customer data, employees and independent contractors alike, is under a written confidentiality obligation that survives the engagement, and access is granted per engagement rather than by default. New contractors are onboarded to a specific repository and a specific environment. When someone finishes, their accounts and tokens are revoked.

B15. Vendor selection and oversight

We choose infrastructure vendors that publish their own security documentation and accept data processing terms, we contract with them on terms no less protective than this DPA, and we pass through to them the restrictions in this document, including the CCPA service provider restrictions. Annex C names every one of them and says what data reaches each.

B16. Testing and review

We re-check security headers and dependency updates as part of our launch checks, and we fix what those turn up. What we do not do today is run a formal third-party penetration test program or a scheduled red team exercise. That is a real limit and this is the right place to say it rather than let a heading imply otherwise. Where an engagement requires that level of assurance, it can be scoped and paid for in a signed agreement.

B17. Incident response

Suspected incidents are triaged by the same small team that runs the systems: contain first, then work out what was reached and by whom, then notify. Reports go to info@carversync.com, and a security report from anyone, customer or not, gets looked at. Customer notification follows the breach section above.

B18. Deletion

Deletion on request and at the end of an engagement works as described in the section about getting your data back, including the honest edges about vendor copies and backup cycles.

B19. Certifications we do not hold

Carver Sync holds no security certification and claims none. We are not SOC 2 audited, not ISO 27001 certified, not PCI DSS attested in our own right, and we hold no HIPAA seal of compliance from any body. HIPAA has no certifying authority, so no vendor legitimately holds a HIPAA certificate. We are not certified under the EU-U.S. Data Privacy Framework or its UK Extension or the Swiss-U.S. Data Privacy Framework. Where a vendor in Annex C holds a certification, that certification is theirs and covers their platform, not ours.

Annex C: subprocessors

This Annex, together with the data processing terms each vendor publishes, completes Annex III of the Standard Contractual Clauses. It is the complete list of Subprocessors that may process Customer Personal Data as of September 16, 2026. Which of them touches your data depends on which Services you bought: a website build does not involve a voice vendor, and a voice agent does not involve a booking calendar.

Two notes on the fields below, because Annex III asks for more than a trade name. The entity named in each entry is the entity we contract with. Its registered address and the data protection contact it publishes are supplied in writing on request, and they also appear in that vendor's own data processing addendum, which we will send you with this page if your review needs the full package. If an entity named below ever differs from the entity on our signed agreement with that vendor, the signed agreement governs and we will correct this page.

The second note is location. Where a vendor processes is the vendor's decision under its own terms, not ours, so rather than claim a single country for all of them we say what we actually know per vendor, and any processing outside the United States is covered by that vendor's own transfer mechanism as described in the transfers section above.

HighLevel, Inc. (GoHighLevel / LeadConnector)

  • What it does. CRM platform, chat widget, marketing automation, and client sign-in at login.carversync.com.
  • Data it processes. Contact records and custom fields, conversation content across chat, SMS and email, pipeline and appointment data, and the account data of the people who sign in.
  • Entity and contact. HighLevel, Inc. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under HighLevel's own published terms rather than a region we select. Any processing outside the United States runs on that vendor's own transfer mechanism.

GoHighLevel / LeadConnector (HighLevel, Inc.)

  • What it does. The CRM platform underneath a large part of what we build: contact records, pipelines, conversations, calendars, the chat widget on our sites, the client sign-in at login.carversync.com, and the hosted checkout at go.carversync.com. Where an engagement is built inside GoHighLevel rather than alongside it or fully custom, this is where your data lives.
  • Data it processes. Contact records and the custom fields on them, conversation history across SMS, email and chat, appointments, opportunity and pipeline data, and, for engagements that use its checkout, order and payment status. In practice this is the broadest set of Customer Personal Data any subprocessor on this list touches.
  • Entity and contact. HighLevel, Inc., trading as GoHighLevel, with LeadConnector LLC as its communications entity. Its published address and data protection contact are set out in its own terms and data processing addendum, which govern its handling of the data.
  • Processing location.Under HighLevel's own published terms, which include processing and support outside the United States. We do not control its regions or its own subprocessor list. Where an engagement is built fully custom rather than inside GoHighLevel, this subprocessor is not in scope for that engagement at all.

Twilio

  • What it does. SMS and voice telephony for the systems we build, including the phone layer under GoCarve Voice.
  • Data it processes. Phone numbers, message content, call metadata, and call audio and transcripts where recording is switched on.
  • Entity and contact. Twilio Inc. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under Twilio's own published terms. Messages and calls necessarily reach the carriers serving the number being contacted, so telephony metadata and content can leave the United States in the ordinary course of delivering them, on Twilio's own transfer mechanism.

Stripe

  • What it does. Payment processing and subscription billing on its own hosted checkout page.
  • Data it processes. Billing name and email, payment card details collected directly by Stripe, and transaction and subscription status. Stripe is a Controller in its own right for payment processing, under its own terms.
  • Entity and contact. Stripe, Inc. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under Stripe's own published terms. Stripe is a controller for payment processing and processes in the regions its own terms set, on its own transfer mechanism.

Resend

  • What it does. Transactional email delivery: confirmations, calendar invites, reminders, questionnaire links and system notices.
  • Data it processes. Recipient name and email address, message subject and body, and delivery events.
  • Entity and contact. Resend, Inc. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under Resend's own published terms rather than a region we select. Any processing outside the United States runs on that vendor's own transfer mechanism.

Zoom

  • What it does. Hosting the video calls booked through our scheduling flows.
  • Data it processes. Attendee name and email, meeting time and join details, and anything shared on a call that is recorded.
  • Entity and contact. Zoom Communications, Inc. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under Zoom's own published terms. Meeting media can route through the regions enabled for the account, on Zoom's own transfer mechanism.

Microsoft 365

  • What it does.Carver Sync's own calendar and availability, read and written through Microsoft Graph so booked meetings land on the right calendar.
  • Data it processes. Meeting attendee name and email, meeting subject and notes, and scheduling metadata.
  • Entity and contact. Microsoft Corporation. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under Microsoft's own published terms. Data residency follows our tenant's own setting rather than the vendor's home country, on Microsoft's own transfer mechanism.

Railway

  • What it does. Application hosting, managed Postgres databases, TLS termination, backups and deployment logs.
  • Data it processes. Everything stored in the applications we run for you, which can include any of the categories in Annex A.
  • Entity and contact. Railway Corp. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.United States. The applications we run for you and the managed Postgres databases behind them are hosted in Railway's United States region.

OpenAI

  • What it does. AI inference through its API for features that generate or interpret language.
  • Data it processes.The prompt and context a feature sends, which may include customer records, conversation text or documents, and the output returned. We access these models through the API rather than the consumer products, and as of the date at the top of this page, under the API terms our account is on, content sent through the API is not used to train the provider's models. That is the vendor's policy on its own terms rather than a control we hold, so if it changes we will say so here.
  • Entity and contact. OpenAI, L.L.C. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under OpenAI's own published terms. Inference may be served from the regions those terms allow, on the vendor's own transfer mechanism.

Anthropic

  • What it does. AI inference through its API, used in the same way as above, including the engines behind Horsie.
  • Data it processes.The prompt and context a feature sends, which may include schema definitions, customer records or conversation text, and the output returned. Accessed through the API, and as of the date at the top of this page, under the API terms our account is on, content sent through the API is not used to train the provider's models, on the same footing described above.
  • Entity and contact. Anthropic, PBC. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under Anthropic's own published terms. Inference may be served from the regions those terms allow, on the vendor's own transfer mechanism.

ElevenLabs

  • What it does. Voice synthesis for AI voice agents and for spoken responses in our products.
  • Data it processes. The text the agent is about to speak, which can carry caller details, and the generated audio.
  • Entity and contact. ElevenLabs Inc. Its registered address and the data protection contact it publishes are supplied in writing on request and are set out in its own data processing addendum.
  • Processing location.Under ElevenLabs' own published terms. Synthesis may be served from the regions those terms allow, on the vendor's own transfer mechanism.

Not on this list, and deliberately so: there is no Carver Sync entity outside the United States, and no offshore development company processes your data. An earlier version of this document named an Indian entity and third-party staff email addresses as Carver Sync subprocessors. That text was copied from another company's legal pages and was never true of Carver Sync.

To be told when this list changes, email info@carversync.com and ask to be added to subprocessor change notices, and we will email your contact before a new vendor starts.