Skip to content
Tessal
Features Templates Industries Pricing Sign in Start free

Legal

U.S. Data Processing Addendum

The commitments that apply when we process personal information on behalf of a business customer under United States state privacy laws.

Effective August 22, 2026Version 2026-08-22Information and policy notice

Service operator

Avatar Genie LLC d/b/a Tessal
LLC formed in Delaware
Contact: Tessal contact page

When this Addendum applies and what the words mean

This U.S. Data Processing Addendum (the “Addendum”) is part of the Terms of Service and applies whenever the Company processes personal information on a Customer’s behalf through the Service.

“Covered Information” means personal information the Company processes on the Customer’s behalf, including information Visitors submit through a Customer Site. “State Privacy Laws” means United States state privacy laws that apply to the processing, including the California Consumer Privacy Act as amended, and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other states as they take effect. “Subprocessor” means a provider engaged by the Company that processes Covered Information. “Security Incident” means a confirmed unauthorized acquisition of, or unauthorized access to, Covered Information in the Company’s possession that compromises its security or confidentiality.

The Customer is the business or controller for Covered Information. The Company is the service provider, contractor, or processor, as those roles are defined by the applicable State Privacy Law.

Details of the processing

Subject matter and purpose. The Company processes Covered Information to provide, secure, support, and improve the Service the Customer subscribes to.

Duration. Processing continues for the term of the Terms of Service and through the deletion and backup cycle described below.

Categories of individuals. Customer personnel and account users, and Visitors and customers of the Customer.

Categories of information. Contact and identification details, business records, form submissions, bookings, orders, requests, quotes, reviews, loyalty records, uploaded files, communications, and technical and analytics records described in the Privacy Policy.

The Customer determines what information it collects through the Service and what it instructs the Company to do with it.

Company obligations

The Company will:

  • process Covered Information only for the business purposes specified in this Addendum and the Terms, and only on the Customer’s documented instructions, which include use of the Service’s configurable features;
  • not sell Covered Information and not share it for cross-context behavioral advertising;
  • not retain, use, or disclose Covered Information for any purpose other than performing the services specified, or as otherwise permitted by State Privacy Laws;
  • not retain, use, or disclose Covered Information outside the direct business relationship between the parties;
  • not combine Covered Information with personal information received from another source, except as a service provider or processor is expressly permitted to do;
  • comply with the obligations that apply to it under State Privacy Laws and provide the same level of privacy protection those laws require of the Customer;
  • notify the Customer promptly if it determines it can no longer meet its obligations under applicable State Privacy Laws;
  • allow the Customer to take reasonable and appropriate steps to stop and remediate any unauthorized use of Covered Information;
  • ensure that personnel and providers with access are bound by appropriate confidentiality obligations and are trained for their role;
  • maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Covered Information; and
  • assist the Customer, taking account of the nature of the processing and the information available, with consumer requests, security obligations, and legally required assessments.

Customer obligations

The Customer will:

  • give only lawful instructions and ensure it has the right to transfer Covered Information to the Company for processing;
  • provide the notices and obtain the consents its own use of the Service requires, and publish its own privacy notice;
  • configure the consent, analytics, age-gate, retention, and access settings the Service provides to match its actual practices;
  • keep Covered Information accurate and limited to what it needs;
  • not submit information the Terms of Service list as restricted unless the Company has agreed in writing; and
  • respond to requests from its own Visitors and customers, using the Service’s tools where helpful.

Subprocessors

The Customer gives the Company general authorization to engage the Subprocessors described on the Subprocessors page, which the Company keeps current.

The Company will impose data-protection obligations on each Subprocessor that are substantially as protective as those in this Addendum, and remains responsible for a Subprocessor’s performance of those obligations.

The Company will update the Subprocessors page before a new Subprocessor begins processing Covered Information where that is practical. The Customer may object in writing within 30 days on reasonable data-protection grounds. The parties will discuss the concern in good faith, and if it cannot be resolved the Customer may stop using the affected feature or terminate the affected part of the subscription without further liability, other than fees already incurred.

Security and incidents

The Company maintains the safeguards described in the Privacy Policy and its security documentation, including access controls, tenant isolation, encryption in transit, hashed credentials and session tokens, private storage, rate limiting, audit logging, and monitoring. Safeguards may evolve, but the Company will not materially reduce the overall level of protection during the subscription.

The Company will notify the Customer without undue delay after confirming a Security Incident affecting the Customer’s Covered Information, and will provide the information reasonably available about what happened, what information was involved, and what steps are being taken. Notification is not an acknowledgment of fault or liability.

The Customer is responsible for notifying affected individuals and regulators where it is required to do so, and the Company will provide reasonable assistance.

Consumer requests and assessments

If the Company receives a request from a Visitor or other individual about Covered Information, it will not respond on the Customer’s behalf except to acknowledge the request and refer the person to the Customer, unless law requires otherwise or the Customer instructs it in writing.

The Company will provide reasonable assistance with consumer requests and with data-protection assessments the Customer is legally required to conduct, taking account of the nature of the processing.

On written request no more than once in any twelve-month period, the Company will provide a written summary of its relevant privacy and security practices sufficient to confirm compliance with this Addendum. If applicable law requires more, the Customer may arrange an assessment by an independent, qualified assessor bound by confidentiality, at the Customer’s expense, on at least 30 days’ written notice, during business hours, and in a way that does not disrupt the Service or expose another customer’s information.

Return and deletion

During the subscription, the Customer may retrieve supported data using the export tools in the dashboard.

After termination, or on the Customer’s written instruction, the Company will delete or de-identify Covered Information according to its normal deletion lifecycle, which includes the 30-day account-deletion recovery window and the rolling backup cycle described in the Privacy Policy.

The Company may retain Covered Information where law requires it, where it is needed for an established legal claim or investigation, or where it exists in backups that have not yet aged out. Retained information remains subject to this Addendum.

Liability, conflicts, and term

This Addendum is subject to the limitations of liability in the Terms of Service, and the parties’ aggregate liability under the Terms and this Addendum together is capped as stated there.

If this Addendum conflicts with the Terms of Service about the processing of Covered Information, this Addendum controls for that conflict. It does not create obligations beyond what applicable law requires, and it does not make the Service suitable for regulated information the Company has not approved in writing.

This Addendum takes effect when the Customer accepts the Terms of Service and continues until Covered Information has been deleted or returned in accordance with it.

Legal & trust Terms of ServicePrivacy PolicyAcceptable Use PolicyCookie & Tracking NoticeCopyright & DMCA PolicyU.S. Data Processing AddendumSubprocessors & Service ProvidersAccessibility Statement Report abuse
Tessal

A beautiful website and the practical tools behind it, finally in one calm place.

ProductFeaturesTemplatesIndustriesExamplesPricingCompare plansStart free
LegalTermsPrivacyAcceptable UseCookiesCopyrightData Processing
Company & trustAboutContactStatusService providersAccessibilityReport abuseSign in
© Tessal.