DATA PROCESSING AGREEMENT

123 Whiting Marketing Company LLC

DATA PROCESSING AGREEMENT (DPA)

Effective Date: August 16, 2026

Business Entity: 123 Whiting Marketing Company LLC (sotryus.com)

This Data Processing Agreement ("DPA") is entered into by and between 123 Whiting Marketing Company LLC ("Processor", "we", "us", or "our") and any business client, agency partner, or user ("Controller" or "Client") utilizing the sotryus.com platform, reputation management tools, CRM workflows, and messaging services.

This DPA supplements the general Terms of Service and Privacy Policy and governs the processing of Personal Data in compliance with applicable United States state privacy laws (including the CCPA/CPRA, VCDPA, CPA, UCPA, and TDPSA), federal telecommunication standards (TCPA, 10DLC), and general commercial data protection practices.

1. Definitions

  • "Controller" means the Client who determines the purposes and means of processing Personal Data collected through the Platform.
  • "Processor" means 123 Whiting Marketing Company LLC, which processes Personal Data on behalf of the Controller in connection with providing reputation management, review aggregation, SMS/email marketing, and automation tools via sotryus.com.
  • "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.
  • "Standard Security Practices" means administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, destruction, loss, or alteration.

2. Roles of the Parties and Scope of Processing

  • Data Processing Roles: The parties acknowledge and agree that with regard to End-Customer Personal Data (such as customer names, phone numbers, and email addresses uploaded or collected via the Controller's campaigns), the Controller is the "Data Controller" (or Business) and 123 Whiting Marketing Company LLC is the "Data Processor" (or Service Provider).
  • Scope & Instructions: Processor shall process Personal Data only in accordance with the documented instructions of the Controller, including with respect to cross-border data transfers, and as necessary to provide the services under the Platform agreement (e.g., sending review requests, automated messaging, and reputation analytics).

3. Processor Obligations and Security Measures

  • Security Controls: Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
    • Encryption of Personal Data in transit using Secure Socket Layer (SSL) technology.
    • Encryption of Personal Data at rest utilizing robust encryption standards (such as AES-256).
    • Access controls limiting internal database access strictly to authorized personnel.
  • Confidentiality: Processor ensures that any personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Sub-processors: Controller provides general authorization for Processor to engage trusted third-party sub-processors (such as cloud hosting providers and telecommunication carriers like Twilio) to support the delivery of services. Processor remains fully liable for the performance of its sub-processors' obligations.

4. Consumer Rights, Compliance, and Regulatory Reporting

  • Assistance with Requests: Processor shall provide reasonable cooperation and assistance to help Controller respond to consumer rights requests (such as access, correction, or deletion requests) received under applicable U.S. state privacy laws.
  • Messaging & TCPA Compliance: For all SMS and email communication workflows facilitated through sotryus.com, Controller warrants that it has secured valid, express written consent from end-consumers prior to initiating campaigns.
  • Regulatory Dispute Notice: If an end-consumer or regulatory agency disputes messaging practices, both parties agree to cooperate in good faith to provide required records. End-consumers retain the right to file formal complaints regarding messaging rights with the Federal Communications Commission (FCC) at https://consumercomplaint.fcc.gov.

5. Data Incident and Breach Notification

In the event of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed by Processor, Processor shall:

  • Notify the Controller without undue delay after becoming aware of the security incident.
  • Take prompt and reasonable steps to mitigate the effects and minimize any damage resulting from the incident.

6. Data Return and Deletion

Upon termination or expiration of the primary service agreement with sotryus.com, Processor shall, at the choice of the Controller, delete or return all Controller Personal Data in its possession, unless storage is required by applicable United States federal or state laws.

7. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the State of Ohio, United States, without regard to its conflict of law principles, matching the governing law provisions of the primary platform agreements.

8. Contact Information

For inquiries, data protection compliance requests, or notices under this Data Processing Agreement, please contact:

123 Whiting Marketing Company LLC 

 Attn: Data Protection Officer / Legal Compliance 

 205 Louis Blvd, 

 Cortland, Ohio 44410 

 Email: dan@123wmc.xyz / support@123wmc.xyz