Legal
Data Processing Addendum
The contractual terms governing how Engramn processes personal data on your dealership's behalf — roles, security, subprocessors, and breach notification.
- Last updated
- 2026-08-07
- Effective
- 2026-08-07
Roles
This Addendum forms part of the customer agreement between Customer and WatchGrid Studio LLC, a Texas limited liability company doing business as Engramn. Customer is the controller / business. Engramn is the processor / service provider.
Scope
- Subject matter: Engramn's provision of the review-reply service to Customer.
- Duration: the term of the customer agreement, plus any post-termination retention described below.
- Nature and purpose: storing, organizing, and drafting replies to reviews on Customer's connected Google Business Profile locations.
- Types of personal data: reviewer display name and review text; dealership staff name, email, and role.
- Categories of data subjects: dealership personnel with an Engramn account, and consumers who posted a review.
Instructions
Engramn will process personal data only on Customer's documented instructions, which include the instructions embedded in the customer agreement and this DPA.
Confidentiality
Engramn personnel authorized to process personal data are bound by confidentiality obligations.
Security — Exhibit A
- Encryption in transit and at rest
- Database-level tenant isolation via row-level security
- Least-privilege access
- Secret management — no secrets shipped to the client bundle
- Signature-verified webhooks
- Logging of administrative access
This exhibit provides the contractual safeguards commitment that 16 CFR 314.4(f) requires Customer to obtain from its service providers. It does not discharge Customer's own obligations under that rule to select a service provider capable of maintaining appropriate safeguards and to periodically assess that provider based on the risk it presents — those two duties remain Customer's to perform.
Subprocessors
Customer generally authorizes Engramn to engage the subprocessors listed on our Subprocessors page, subject to 30 days' notice before a new one is added and a right to object. Engramn remains responsible for its subprocessors' acts and omissions as for its own.
Assistance
Engramn will provide reasonable assistance to Customer with data subject requests, security obligations, breach notification, and data protection impact assessments.
Breach notification
Engramn will notify Customer without undue delay, and no later than 48 hours, after becoming aware of a personal data breach — giving Customer headroom to meet its own 72-hour notification clocks.
Deletion and return
On termination, Customer's personal data remains available for export for 30 days, and Engramn will delete or return it at the end of that window, except for sent-reply audit records and any data we are legally required to retain.
Audit
Engramn will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports where available, and will permit an audit no more than annually on reasonable notice.
AI processing
Engramn's AI subprocessors are contractually prohibited from using Customer's personal data to train or improve their models. This restates, as a contractual obligation, the commitment described in our Privacy Policy.
Current and authorized AI subprocessors are named on our Subprocessors page.
International transfers
Engramn stores personal data in the United States. One subprocessor, Zernio, which provides the Google Business Profile connection, operates in the European Union; review and reply data passes through its systems in order to reach and return from Google. Each subprocessor's location is listed on our Subprocessors page. Standard Contractual Clauses are available on request for customers that need them.
Contact
Questions about this Addendum, requests for a countersigned copy, subprocessor objections, and data subject requests routed under it: legal@watchgridstudio.com.