Live Agent Pro Data Processing Addendum
Effective Date: July 22, 2026 Last Updated: July 22, 2026
1. Background and Scope
This Data Processing Addendum ("DPA") supplements and forms part of the Live Agent Pro Terms of Service (the "Agreement") between Pelton Solutions LLC d/b/a Live Agent Pro ("Live Agent Pro," "we") and the talent agency that has accepted the Agreement (the "Agency," "you"). It applies where Live Agent Pro Processes Agency Personal Data (defined below) on your behalf in providing the Service.
This DPA governs Live Agent Pro's Processing of the personal data of your Hosts (the live-streaming creators and talent you manage), Applicants (people who submit your public application forms), and Message Correspondents (people who send or receive messages through the Service, including third parties who email or message a Host or an Agency address) — in each case, personal data that you upload to the Service or that is generated through your use of the Service. For that data, you are the Business / Controller (under Brazilian law, the controlador) and Live Agent Pro is the Service Provider / Processor (under Brazilian law, the operador).
This DPA does not apply to personal data for which Live Agent Pro is itself the business/controller — your Agency account, staff-user, and billing data — which is governed by the Live Agent Pro Privacy Policy. In addition, because Hosts sign in directly to the Pelton-operated host portal and mobile app, Live Agent Pro has a narrow direct relationship with Hosts as end users — limited to their portal/app account credentials, session data, device identifiers, and push notification tokens. That narrow end-user data is addressed in the Privacy Policy and the Host Privacy Notice, not this DPA. Everything else about a Host that you put into, or generate through, the Service is Agency Personal Data under this DPA.
If you accept the Agreement and use the Service to Process Agency Personal Data, this DPA is incorporated into the Agreement. Where a separate signed DPA is required, the signature block in Section 16 applies.
2. Definitions
Capitalized terms not defined here have the meaning given in the Agreement.
- "Applicable Privacy Laws" means the privacy and data protection laws applicable to the Processing under this DPA, including (a) U.S. State Privacy Laws — the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with similar laws, as each is in effect and applicable; and (b) Brazil's Lei Geral de Proteção de Dados Pessoais, Law No. 13,709/2018 ("LGPD"), together with applicable regulations and resolutions of the Autoridade Nacional de Proteção de Dados ("ANPD").
- "Business," "Controller," "Service Provider," "Processor," "Consumer," "Sell," "Share," "Personal Information," and "Process" have the meanings given under Applicable Privacy Laws. "Business," "Controller," and "controlador" are used interchangeably for the Agency; "Service Provider," "Processor," and "operador" are used interchangeably for Live Agent Pro. "Personal Information" and "personal data" (dados pessoais) are used interchangeably.
- "Agency Personal Data" means Personal Information of Hosts, Applicants, and Message Correspondents that Live Agent Pro Processes on your behalf in providing the Service — data that you upload to the Service or that is generated through your use of the Service — as described in Annex 1. Agency Personal Data does not include your Agency account, staff-user, or billing data, or the narrow Host end-user data (credentials, sessions, push tokens) described in Section 1, for which Live Agent Pro is the controller under the Privacy Policy.
- "Host" means a live-streaming creator or other talent whose records you manage in the Service, including as a data subject of your account and (separately) as an end user of the host portal and mobile app.
- "Applicant" means a person who submits information through a public application form you publish through the Service.
- "Message Correspondent" means a person who sends or receives a WhatsApp message or email through the Service, including a third party who was never a user of the Service.
- "Sub-Processor" means a third party engaged by Live Agent Pro to Process Agency Personal Data. The current Sub-Processors are listed in the Live Agent Pro Sub-Processor List.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Agency Personal Data Processed by Live Agent Pro, including a security incident that may create risk or relevant damage to data subjects within the meaning of LGPD Article 48.
3. Roles and Instructions
3.1 As between the parties, you are the Business/Controller (controlador) and determine the purposes and means of Processing Agency Personal Data, and Live Agent Pro is the Service Provider/Processor (operador) acting on your behalf.
3.2 Live Agent Pro will Process Agency Personal Data only (a) to provide, maintain, secure, and support the Service in accordance with the Agreement; (b) in accordance with your documented lawful instructions (which include the Agreement, this DPA, and your configuration and use of the Service — for example, the message campaigns you schedule, the automations you enable, the custom fields you define, and the credentials you connect); and (c) as otherwise required by applicable law, in which case Live Agent Pro will inform you of that requirement unless legally prohibited. Live Agent Pro will notify you if, in its opinion, an instruction infringes Applicable Privacy Laws, though it is not obligated to review your instructions for legal compliance.
3.3 You are responsible for the lawfulness of Agency Personal Data and of your collection of it, including: establishing a valid legal basis under Applicable Privacy Laws for each Processing activity you direct; providing any required privacy notice to, and obtaining any required consent from, Hosts, Applicants, and Message Correspondents (including messaging consent as required by the Acceptable Use Policy); and ensuring you have the right to transfer Agency Personal Data to Live Agent Pro for Processing under this DPA, including the international transfer described in Section 6.
3.4 You warrant that every Host you onboard to the Service is at least 18 years of age, so that Agency Personal Data does not include the personal data of children or adolescents within the meaning of LGPD Article 14 or children's data under U.S. State Privacy Laws.
4. U.S. State Privacy Laws — Service Provider Certifications
Live Agent Pro certifies that it understands and will comply with the restrictions in this Section. With respect to Agency Personal Data, Live Agent Pro will:
- (a) Process it only on your behalf and for the limited and specified purpose of providing the Service (the "Business Purpose"), and not for any other purpose;
- (b) not Sell and not Share Agency Personal Data;
- (c) not retain, use, or disclose Agency Personal Data for any purpose other than the Business Purpose, including not for any commercial purpose other than providing the Service, except as permitted by Applicable Privacy Laws;
- (d) not retain, use, or disclose Agency Personal Data outside the direct business relationship between you and Live Agent Pro;
- (e) not combine Agency Personal Data with personal information it receives from, or on behalf of, another person, or collects from its own interactions with the Consumer, except as permitted by Applicable Privacy Laws to perform the Service;
- (f) provide the same level of privacy protection as is required of businesses under Applicable Privacy Laws;
- (g) notify you promptly if it makes a determination that it can no longer meet its obligations under Applicable Privacy Laws; and
- (h) comply with applicable obligations under Applicable Privacy Laws and provide reasonable assistance to enable your compliance, as further described below.
You may take reasonable and appropriate steps to help ensure that Live Agent Pro uses Agency Personal Data in a manner consistent with your obligations under Applicable Privacy Laws, and to stop and remediate any unauthorized use, as described in Section 12 (Audits).
5. Brazil — LGPD Processing Terms
Where the LGPD applies to the Processing of Agency Personal Data (for example, because Agency Personal Data relates to Hosts, Applicants, or Message Correspondents located in Brazil, or was collected in Brazil), the following additional terms apply:
5.1 Roles. You are the controlador and Live Agent Pro is the operador with respect to Agency Personal Data. Live Agent Pro will carry out the Processing in accordance with your documented instructions as set out in Section 3, and you remain responsible for verifying that your instructions comply with the LGPD (LGPD Articles 39 and 42).
5.2 Security (LGPD Art. 46). Live Agent Pro will adopt the security, technical, and administrative measures described in Section 8 and Annex 2, which are designed to protect Agency Personal Data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication, or dissemination, consistent with LGPD Articles 46–49.
5.3 Incident notification (LGPD Art. 48). Live Agent Pro will notify you as described in Section 11 of any Security Incident that may create risk or relevant damage to data subjects, with the information reasonably available to it (including, where known, the nature of the affected data, the data subjects involved, the measures taken, and the risks associated with the incident), so that you can assess and, where required, make your own communication to the ANPD and to affected data subjects within the time frames the LGPD and ANPD regulations impose on you as controlador. As between the parties, you are responsible for notifications to the ANPD and to data subjects in respect of Agency Personal Data.
5.4 Data subject rights (LGPD Art. 18). Live Agent Pro will assist you as described in Section 10 in responding to requests by data subjects to exercise their LGPD Article 18 rights — including confirmation of Processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, and information about the consequences of denying consent — taking into account the nature of the Processing and the information available to Live Agent Pro.
5.5 Records and cooperation. Live Agent Pro maintains records of its Processing operations as operador (LGPD Article 37) and will reasonably cooperate with you, including in any dealings you have with the ANPD concerning the Processing under this DPA, at your reasonable request and expense.
5.6 Data protection contact (encarregado). Live Agent Pro's data protection contact for matters arising under this DPA is legal@peltonsolutions.com.
6. International Data Transfers
6.1 Processing location. Agency Personal Data is Processed in the United States, on Amazon Web Services infrastructure, in a primary region plus a separate region used for inbound email receiving (see the Sub-Processor List). By entering into this DPA and using the Service, you instruct and authorize this transfer.
6.2 LGPD transfer mechanism. Where the LGPD applies, the transfer of Agency Personal Data to Live Agent Pro in the United States is an international transfer of personal data under LGPD Articles 33–36. Live Agent Pro relies on contractual safeguards — this DPA and the specific contractual clauses regime contemplated by LGPD Article 33 — and, where required for the transfer to be valid, the standard contractual clauses approved by the ANPD (as annexed to ANPD Resolution CD/ANPD No. 19/2024, or any successor version) are hereby incorporated into this DPA by reference, with you as the exporting controlador and Live Agent Pro as the importing operador. In the event of a conflict between the ANPD standard contractual clauses and the rest of this DPA, the ANPD standard contractual clauses control to the extent of the conflict for the transfers they govern. Executed copies are available on request to legal@peltonsolutions.com.
6.3 No EEA/UK/Swiss offering. The Service is not offered to customers established in the European Economic Area, the United Kingdom, or Switzerland, and this DPA does not include GDPR terms or EU standard contractual clauses.
7. Confidentiality
Live Agent Pro will ensure that personnel authorized to Process Agency Personal Data are subject to a duty of confidentiality and Process the data only as necessary to provide the Service. Access by Pelton Solutions support staff to tenant data is on a least-access basis and limited to support, maintenance, security, and legal-compliance purposes. Each such access is written to an append-only support-access log recording the staff member, the time, the Agency whose data was reached, and the request made; on reasonable written request we will tell you whether and when your Agency's data was accessed in this way.
8. Security
Live Agent Pro will implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect Agency Personal Data, as described in Annex 2 and in the Privacy Policy (Security), consistent with LGPD Article 46 and the reasonable-security requirements of U.S. State Privacy Laws. Live Agent Pro may update its security measures from time to time provided that the updates do not materially reduce the overall level of protection.
9. Sub-Processors
9.1 You authorize Live Agent Pro to engage the Sub-Processors listed in the Live Agent Pro Sub-Processor List to Process Agency Personal Data in connection with the Service.
9.2 Live Agent Pro will impose on each Sub-Processor data-protection obligations that are substantially consistent with those in this DPA, to the extent applicable to the nature of the Sub-Processor's services, and Live Agent Pro remains responsible to you for each Sub-Processor's performance of its obligations.
9.3 Live Agent Pro will maintain the Sub-Processor List and will provide notice (by updating the list and/or by email or in-product notice) before adding a new Sub-Processor that Processes Agency Personal Data. If you reasonably object to a new Sub-Processor on data-protection grounds, you may notify Live Agent Pro within the notice period stated on the list (or, if none is stated, within fourteen (14) days); the parties will work in good faith to address the objection, and if they cannot, your sole remedy is to stop using the affected feature or to terminate the affected Service.
9.4 Agency-directed services are not Sub-Processors. Third-party services you connect using your own credentials or accounts — your Meta WhatsApp Business account, per-Host TikTok connections, and your own email provider (Postmark, Resend, or your SMTP server) — are engaged by you, act on your instructions under your own agreements with those providers, and are not Sub-Processors of Live Agent Pro. You are responsible for those providers and for your compliance with their terms, as described in the Agreement (BYO Credentials and Messaging).
10. Assistance — Data Subject and Consumer Requests
10.1 Rights requests. Taking into account the nature of the Processing, Live Agent Pro will provide reasonable assistance through appropriate technical and organizational measures (including the self-service features of the Service, such as record editing, contact deletion, data export, and message suppression tools) to help you respond to verifiable requests from Hosts, Applicants, and Message Correspondents to exercise their rights under Applicable Privacy Laws — including access, deletion, correction, portability, and opt-out rights under U.S. State Privacy Laws and the rights listed in LGPD Article 18.
10.2 Host requests route through you. Because you are the Controller of Agency Personal Data, a Host who wants to exercise rights over the records you keep about them should contact you first, as stated in the Host Privacy Notice. If Live Agent Pro receives such a request directly from a Host, Applicant, or Message Correspondent relating to data Processed on your behalf, Live Agent Pro will, where lawful, forward it to you or instruct the individual to contact you, and will not respond on your behalf except on your instruction or as legally required. (Requests concerning the narrow Host end-user data for which Live Agent Pro is controller — portal/app credentials, sessions, push tokens — are handled by Live Agent Pro under the Privacy Policy.)
10.3 Other assistance. Live Agent Pro will provide you with reasonable information and assistance necessary for you to meet your obligations under Applicable Privacy Laws in relation to the Processing, including with respect to security of Processing, Security Incident notification, and any required risk or impact assessments (including an LGPD relatório de impacto à proteção de dados pessoais, if you are required to prepare one), taking into account the information available to Live Agent Pro.
11. Security Incidents
Live Agent Pro will notify you without undue delay after becoming aware of a Security Incident affecting Agency Personal Data, and will provide information reasonably available to it to help you assess the incident and meet any notification obligations you may have under Applicable Privacy Laws — including your obligation as controlador under LGPD Article 48 to communicate qualifying incidents to the ANPD and to affected data subjects, and your obligations under U.S. state breach-notification laws. Live Agent Pro will take reasonable steps to mitigate and, where possible, remediate the Security Incident. Live Agent Pro's notification is not an acknowledgment of fault or liability.
12. Audits
Live Agent Pro will make available to you information reasonably necessary to demonstrate its compliance with this DPA. No more than once per twelve (12) months (unless required by a regulator, including the ANPD, or following a Security Incident), and subject to reasonable advance notice, confidentiality obligations, and Live Agent Pro's security and operational requirements, Live Agent Pro will respond to a reasonable written assessment questionnaire and, where genuinely necessary, allow a remote review of relevant documentation. Audits must not unreasonably disrupt Live Agent Pro's business or compromise the security or confidentiality of other agencies' data.
13. Deletion and Return
13.1 Export. You can export your Agency Personal Data during the term of the Agreement, and a contacts CSV export remains available even after your subscription lapses — a lapsed Agency can sign in, export its contacts, and leave without reactivating (see Terms of Service, Termination and Data Export). The contacts export covers Host identity and contact fields; a fuller export of other record types is available on written request to hello@liveagentpro.com.
13.2 Deletion on termination. Upon termination or expiration of the Agreement, and as described in the Terms of Service and the Privacy Policy (Data Retention): access to the Service ends, you have an approximately 30-day period to export your data, and Live Agent Pro then permanently deletes Agency Personal Data from active systems, with residual backup copies aging out on the normal rotation cycle, except where retention is required by law (for example, billing and tax records).
13.3 Deletion on request. Verified deletion requests you submit during the term (for example, to give effect to a Host's erasure request under LGPD Article 18 or a Consumer deletion request) are honored within forty-five (45) days, with one 45-day extension where Applicable Privacy Laws allow. While your account is active, correcting or deleting a record does not scrub prior values from your account's change-history audit trail, which is kept for integrity, security, and fraud-prevention purposes; the audit trail is deleted along with the account.
13.4 Anonymization of a single Host; retained financial records. Erasing one Host while your account remains open is performed as an anonymization: the Service removes or irreversibly redacts that Host's identity and contact data (name, email, phone, date of birth, gender, social handles, CPF, PIX key and key type, payout address, staff notes, custom-field values, message content, and photos), and retains the financial and transaction records in de-identified form — monthly statements, calculated payout amounts, payout methods and dates, recruiter commission, and points-ledger entries — linked to a non-identifying reference. This is done because you, as controlador / Business, have your own tax, accounting, and audit record-keeping obligations for amounts you paid or owe, which both LGPD Article 16, I–II and the legal-obligation exceptions in U.S. State Privacy Laws permit you to satisfy notwithstanding an erasure request. The retained records are limited to what those obligations require and are deleted in full when your account is deleted under Section 13.2. As controlador you remain responsible for determining that the retention period is the one your law requires, and for telling the Host that these records are kept.
14. Liability and Conflict
14.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service, Limitation of Liability).
14.2 In the event of a conflict between this DPA and the Agreement with respect to the Processing of Agency Personal Data, this DPA controls (subject to Section 6.2 regarding the ANPD standard contractual clauses). In all other respects, the Agreement remains in full force and effect.
15. Term and Governing Law
This DPA takes effect on the Effective Date (or on execution, if signed) and continues for as long as Live Agent Pro Processes Agency Personal Data on your behalf. This DPA is governed by the laws of the State of Michigan, consistent with the Agreement, without regard to conflict-of-laws principles, except that mandatory provisions of the LGPD apply to the Processing they govern. This DPA is drafted in English; translations may be provided for convenience, but the English version governs.
16. Signatures (if executed as a standalone document)
By signing below, or by accepting the Agreement and using the Service to Process Agency Personal Data, the parties agree to this DPA.
Most Agencies do not need to sign anything: accepting the Terms of Service and using the Service to Process Agency Personal Data brings this DPA into effect. A countersigned copy for your records is available on request to legal@peltonsolutions.com.
Agency (Business / Controller / Controlador)
Name: ______________________________
Title: ______________________________
Entity: ______________________________
Date: ______________________________
Pelton Solutions LLC d/b/a Live Agent Pro (Service Provider / Processor / Operador)
Name: Nathanael Pelton
Title: Owner
Date: ______________________________
Annex 1 — Details of Processing
- Subject matter: Provision of the Live Agent Pro talent-agency CRM Service — host and talent records, recruiting and applications, messaging (WhatsApp and email), performance statistics and compensation statements, points and rewards record-keeping, and the host portal and mobile app.
- Duration: For the term of the Agreement and until deletion in accordance with Section 13.
- Nature and purpose: Storing and organizing Host records on your behalf; sending and receiving WhatsApp messages and email at your direction; receiving public application-form submissions; importing and computing platform performance statistics and monthly compensation statements; keeping points/rewards ledgers you administer; generating branded profile photos and hosting uploaded files; and related support and security.
- Categories of data subjects: Hosts and talent you manage; Applicants who submit your public application forms; Message Correspondents, including third parties who never signed up but who email or message a Host or an Agency address through the Service.
- Categories of Agency Personal Data:
- Host identity and contact data — name, email address, phone number, date of birth, gender, Instagram handle, preferred contact method, locale, and timezone; CPF (Brazilian national taxpayer ID), PIX key and key type (which may itself be a CPF, phone number, or email), and free-text payout address.
- Platform records — streaming-platform usernames and platform IDs, status and start/end dates, recruiter attribution, commission percentages, and free-text notes.
- Earnings and performance data — per-Host follower/following/likes/video/live counts, live views, peak viewers, diamonds earned, and derived monthly compensation statements (tier, payout amount, payout method, paid date, recruiter commission). This is earnings and productivity data about individuals and is treated with corresponding care.
- Communications content — the full body of every WhatsApp message and email sent or received through the Service, in both directions, including inbound messages from third parties; threading and participant data; blocked numbers and email suppressions with reasons.
- Application submissions — name, email, phone, date of birth, and answers to whatever custom questions you configure, submitted by members of the public; rejected applications are retained with their rejection reason.
- Notes, tasks, and onboarding records — free-text staff notes about Hosts (which may contain subjective opinions and are still personal data), tasks, targets, onboarding checklists, and event attendance.
- Photos and files — uploaded images and documents, and profile photos the Service generates by compositing Host images onto your branded templates. Generated and published assets intended for sharing are publicly accessible by URL.
- Points and rewards records — points ledgers, expiry dates, reward redemptions, and the deciding staff member.
- Custom-field values — values in fields you define, an open-ended container whose contents you control.
- Sensitive data: The CPF is a government identifier and is handled with heightened care. You must not put special categories of personal data (dados pessoais sensíveis under LGPD Article 5, or sensitive personal information under U.S. State Privacy Laws — health, biometric, religious, and similar data) into custom fields, notes, or other free-text areas (see the Acceptable Use Policy, Section 2.6 — data-hygiene rules for contact records and custom fields). Live Agent Pro is not a HIPAA-compliant platform and will not sign a Business Associate Agreement (BAA); you must not use the Service to Process Protected Health Information (PHI) subject to HIPAA. All Hosts must be at least 18 years old (Section 3.4), so Agency Personal Data must not include children's data.
- Frequency: Continuous, as you and your Hosts use the Service and as messages and application submissions arrive.
Annex 2 — Security Measures
Live Agent Pro maintains safeguards including, as described in the Privacy Policy (Security):
- HTTPS/TLS encryption in transit, terminated at the load balancer with certificates managed through AWS Certificate Manager; DKIM/SPF/DMARC authentication on outbound email.
- Application servers, cache, and database in private network subnets, not directly reachable from the internet; database credentials and application secrets held in AWS Secrets Manager, never in configuration files.
- Encryption at rest for the database and for the object storage holding uploaded files and media — excluding assets published deliberately for sharing (generated profile photos), which are public by design.
- Continuous database backups with point-in-time restore, an approximately 30-day retention window (recovery point objective on the order of minutes), and an automatic-failover standby instance in a second availability zone (recovery time on the order of a minute for an instance or availability-zone failure); backups are encrypted at rest. This describes Live Agent Pro's disaster-recovery posture and is not a service-level commitment.
- An append-only support-access log of every request Pelton Solutions staff make against tenant data (Section 7).
- Agency-supplied WhatsApp access tokens, email provider API keys, and per-Host TikTok OAuth tokens stored encrypted at the application layer.
- Logical tenant isolation: every record is scoped to your Agency within shared infrastructure, enforced at the application layer on every query.
- Multi-factor authentication (TOTP with recovery codes) and passkeys available for Agency staff accounts; short-lived, automatically pruned API tokens for the mobile app.
- An append-only change-history audit trail of record modifications, supporting integrity review and rollback.
- Deployments authenticated via short-lived OIDC credentials rather than long-lived static keys; access controls, logging, monitoring, and regular security review.
Annex 3 — Sub-Processors
The current Sub-Processors authorized to Process Agency Personal Data are listed in the Live Agent Pro Sub-Processor List, which is incorporated into this DPA by reference and includes Amazon Web Services (infrastructure, storage, and email, in a primary U.S. region plus a separate U.S. region for inbound email receiving), Stripe (billing — limited to Agency billing data, not Agency Personal Data), Meta Platforms (WhatsApp Cloud API), TikTok (Open API, per-Host authorization), Google (reCAPTCHA and sign-in), Sentry (error diagnostics), and Expo and/or Firebase Cloud Messaging (mobile push delivery). Agency-directed email providers (Postmark, Resend, or your own SMTP) are engaged by you and are noted on the list but are not Sub-Processors (see Section 9.4).