Data Processing Addendum
Last updated: 17 August 2026
This Data Processing Addendum ("DPA") forms part of the ActionKeeper Terms of Service or other written agreement between LeaderPath, LLC, a Texas limited liability company doing business as ActionKeeper ("ActionKeeper"), and the provider, customer, or organization using the ActionKeeper service ("Customer"). It applies when ActionKeeper Processes Customer Personal Data on Customer's behalf.
If Customer has entered into a separate written master services agreement, subscription agreement, or order form with ActionKeeper, references in this DPA to the "Agreement" mean that agreement together with the ActionKeeper Terms of Service, as applicable.
1. Scope and Order of Precedence
1.1 This DPA governs ActionKeeper's Processing of Customer Personal Data in connection with the Services. It does not apply to Personal Data for which ActionKeeper determines the purposes and means of Processing independently, such as limited provider account administration, billing administration, security, fraud prevention, legal compliance, and business records, which are handled as described in the Privacy Policy.
1.2 If this DPA conflicts with the Agreement regarding the Processing of Customer Personal Data, this DPA controls. If applicable Standard Contractual Clauses or other mandatory data-transfer terms conflict with this DPA, those mandatory terms control to the extent of the conflict.
2. Definitions
For purposes of this DPA:
- "Applicable Data Protection Law" means any privacy, data protection, or data security law that applies to the Processing covered by this DPA, including, where applicable, U.S. state comprehensive privacy laws, the EU GDPR, the UK GDPR, and implementing legislation.
- "Customer Personal Data" means Personal Data Processed by ActionKeeper on behalf of Customer through the Services, including Personal Data relating to participants and Personal Data contained in Customer-uploaded program materials.
- "Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates.
- "Personal Data" has the meaning given to "personal data," "personal information," or similar terms under Applicable Data Protection Law.
- "Process" or "Processing" means any operation performed on Personal Data, whether automated or not, including collection, storage, use, retrieval, transmission, deletion, or disclosure.
- "Processor," "Controller," "Business," "Service Provider," "Contractor," "Subprocessor," and similar terms have the meanings given under Applicable Data Protection Law.
- "Security Incident" means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Unsuccessful attempts or activities that do not compromise Customer Personal Data are not Security Incidents.
- "Services" means the ActionKeeper platform and related features provided under the Agreement.
3. Roles of the Parties
3.1 For Customer Personal Data, Customer acts as the Controller, Business, or equivalent party that determines the purposes and means of Processing, and ActionKeeper acts as the Processor, Service Provider, Contractor, or equivalent party Processing Personal Data on Customer's behalf.
3.2 Customer is responsible for determining whether and how to use the Services, selecting participants, determining the lawful basis for Processing, providing required notices, obtaining required permissions or consents, and ensuring that Customer's instructions comply with Applicable Data Protection Law.
3.3 ActionKeeper will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's configuration and use of the Services, and other written instructions accepted by ActionKeeper, unless Applicable Data Protection Law requires otherwise. If law requires Processing outside Customer's instructions, ActionKeeper will notify Customer before Processing unless legally prohibited from doing so.
3.4 If ActionKeeper reasonably believes an instruction violates Applicable Data Protection Law, ActionKeeper may suspend the affected Processing and notify Customer, unless prohibited by law, while the parties work in good faith to resolve the issue.
4. Details and Purpose of Processing
The subject matter, nature, purpose, duration, categories of Personal Data, and categories of Data Subjects are described in Exhibit A. Customer instructs ActionKeeper to Process Customer Personal Data as reasonably necessary to provide, maintain, secure, support, and administer the Services in accordance with the Agreement.
5. Customer Obligations
Customer represents and warrants that:
- it has all rights, notices, permissions, consents, and lawful bases necessary for ActionKeeper to Process Customer Personal Data as contemplated by the Agreement and this DPA;
- its instructions to ActionKeeper comply with Applicable Data Protection Law;
- it will not intentionally use the Services to collect or Process Personal Data from anyone under 18 years old;
- it will not instruct ActionKeeper to Process sensitive, special-category, biometric, precise geolocation, health, clinical, financial-account, or similarly regulated data unless such Processing is expressly supported by the Services and agreed in writing by ActionKeeper; and
- it will not use ActionKeeper's AI coach to make or determine employment, eligibility, medical, legal, financial, safety-critical, or other high-impact decisions.
6. ActionKeeper Processor Obligations
6.1 Confidentiality
ActionKeeper will ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and are permitted to access Customer Personal Data only as necessary to perform their duties.
6.2 Security
ActionKeeper will implement and maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, alteration, or disclosure. The current safeguards are summarized in Exhibit B.
Customer acknowledges that no system can guarantee absolute security and that security measures may evolve as technology, threats, and the Services change, provided ActionKeeper does not materially reduce the overall level of protection during an active subscription without a legitimate reason.
6.3 Data Subject Requests
Taking into account the nature of the Processing, ActionKeeper will provide commercially reasonable assistance to Customer in responding to verified requests by Data Subjects to exercise rights under Applicable Data Protection Law. Where a participant submits a request directly to ActionKeeper concerning Customer-controlled program data, ActionKeeper may refer the participant to Customer or notify Customer and act on Customer's documented instructions, unless law requires ActionKeeper to respond directly.
6.4 Regulatory and Compliance Assistance
Taking into account the nature of the Processing and information available to ActionKeeper, ActionKeeper will provide commercially reasonable assistance with Customer's obligations relating to security, breach notification, data protection impact assessments, prior consultations with regulators, and similar obligations required by Applicable Data Protection Law.
6.5 Security Incidents
ActionKeeper will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to ActionKeeper regarding the nature of the incident, affected data, likely consequences, and mitigation measures. ActionKeeper's notification or response to a Security Incident is not an admission of fault or liability.
ActionKeeper will take reasonable steps to contain, investigate, and mitigate a Security Incident and will reasonably cooperate with Customer's legally required response. Customer is responsible for determining whether notification to Data Subjects, regulators, or other parties is legally required unless Applicable Data Protection Law places that obligation directly on ActionKeeper.
6.6 Demonstrating Compliance; Audits
ActionKeeper will make available information reasonably necessary to demonstrate compliance with its obligations as a Processor under Applicable Data Protection Law. Where legally required, Customer may request a reasonable audit or assessment no more than once in any 12-month period, except following a material Security Incident or where a regulator requires otherwise.
Audits must be conducted during normal business hours, on reasonable advance notice, in a manner that does not unreasonably interfere with ActionKeeper's operations or compromise the confidentiality, security, or data of other customers. ActionKeeper may satisfy an audit request by providing available security documentation, questionnaires, independent reports, or other evidence before permitting an onsite review. Customer will bear its own audit costs and reimburse ActionKeeper for reasonable costs of extraordinary audit assistance unless Applicable Data Protection Law requires otherwise.
7. Subprocessors
7.1 Customer provides general authorization for ActionKeeper to engage Subprocessors to Process Customer Personal Data as necessary to provide the Services. The current Subprocessors are listed in Exhibit C.
7.2 ActionKeeper will enter into written terms with each Subprocessor that impose data protection obligations appropriate to the services provided and no less protective in material respects than the obligations applicable to ActionKeeper under this DPA, to the extent required by Applicable Data Protection Law. ActionKeeper remains responsible for its Subprocessors' performance of their delegated Processing obligations to the extent required by law.
7.3 ActionKeeper may add or replace Subprocessors. Where Applicable Data Protection Law requires prior notice, ActionKeeper will provide notice before a new Subprocessor begins materially Processing Customer Personal Data. Customer may object on reasonable, documented data-protection grounds within 15 days after notice. The parties will work in good faith to address the objection. If no reasonable alternative is available, ActionKeeper may permit Customer to discontinue the affected feature or terminate the affected Services without penalty for the unused prepaid portion attributable to the affected Services.
8. Restrictions Under U.S. State Privacy Laws
To the extent ActionKeeper acts as a Service Provider, Contractor, or Processor under applicable U.S. state privacy law, ActionKeeper will not sell Customer Personal Data or share it for cross-context behavioral advertising, targeted advertising, or other purposes prohibited for a service provider or processor; will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by law; and will Process such data only for the limited and specified purposes described in the Agreement, this DPA, and Customer's documented instructions.
ActionKeeper will not combine Customer Personal Data received from or on behalf of Customer with Personal Data received from another person or collected from ActionKeeper's own interaction with a Data Subject except where permitted by Applicable Data Protection Law and reasonably necessary to provide the Services.
9. International Transfers
9.1 Customer acknowledges that ActionKeeper and its Subprocessors may Process Customer Personal Data in the United States and other countries identified in the Privacy Policy or applicable Subprocessor documentation.
9.2 If Customer Personal Data subject to the EU GDPR is transferred to ActionKeeper in a country that does not benefit from an applicable adequacy decision and a transfer mechanism is legally required, the parties incorporate the European Commission's 2021 Standard Contractual Clauses for transfers from controllers to processors (Module Two), as amended or replaced from time to time, subject to Exhibit D.
9.3 If Customer Personal Data subject to the UK GDPR is transferred to ActionKeeper and a transfer mechanism is legally required, the applicable UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or any successor mechanism recognized by the UK Information Commissioner's Office, will apply as described in Exhibit D.
9.4 The parties will reasonably cooperate with legally required transfer impact assessments and supplementary measures. Nothing in this section requires ActionKeeper to provide information that would compromise the security, confidentiality, or rights of other customers.
10. Return and Deletion of Customer Personal Data
10.1 During the subscription, Customer may access or export program data using available Service functionality.
10.2 Following termination or expiration of the Agreement, ActionKeeper will retain Customer Personal Data in the active service for up to 30 days to permit export or account reactivation, unless a different period is required by law or agreed in writing. After that period, ActionKeeper will delete or render inaccessible Customer Personal Data from active systems in accordance with its standard deletion procedures.
10.3 Residual copies may remain temporarily in backups, security logs, or disaster-recovery systems until overwritten or deleted under ordinary retention schedules. During that period, the data remains protected by this DPA and will not be restored for ordinary business use except as necessary for disaster recovery, security, legal compliance, or system integrity.
10.4 If Applicable Data Protection Law requires Customer to choose between return and deletion, ActionKeeper will honor Customer's documented choice to the extent technically feasible and legally required. ActionKeeper may retain Personal Data where required by law, provided it remains protected and is not Processed for other purposes.
11. Legal Requests
If ActionKeeper receives a legally binding request from a public authority for Customer Personal Data, ActionKeeper will, to the extent legally permitted, notify Customer and will disclose only the information it is legally required to provide. ActionKeeper will not voluntarily provide Customer Personal Data to a public authority for purposes unrelated to the Services except where required by law or necessary to protect rights, safety, or security.
12. Liability
The exclusions and limitations of liability in the Agreement apply to this DPA and all claims arising from it, except to the extent such limitations are prohibited by Applicable Data Protection Law. Nothing in this DPA expands either party's liability beyond the liability allocated under the Agreement unless mandatory law requires otherwise.
13. Term and Survival
This DPA takes effect when the Agreement takes effect or when ActionKeeper first Processes Customer Personal Data on Customer's behalf, whichever occurs first, and remains in effect for as long as ActionKeeper Processes Customer Personal Data. Sections that by their nature should survive termination, including confidentiality, deletion, audit, transfer, and liability obligations, will survive as necessary to give them effect.
14. Changes to this DPA
ActionKeeper may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, Subprocessors, security measures, or the Services. Material changes that reduce Customer's data protection rights or materially expand Processing will be notified in accordance with the Agreement. Changes required by law may take effect as required to maintain compliance.
15. Contact
Privacy and DPA inquiries may be sent to:
LeaderPath, LLC / ActionKeeper
3526 Lakeview Pkwy, Ste. B-104, Rowlett, TX 75088
Exhibit A — Details of Processing
| Item | Details |
|---|---|
| Subject matter | Processing of Customer Personal Data to provide the ActionKeeper learning-reinforcement, participant check-in, accountability, reporting, email, and AI-coaching features. |
| Duration | For the term of the Agreement, plus the limited post-termination retention and backup periods described in this DPA and the Privacy Policy. |
| Nature of Processing | Collection, receipt, organization, storage, hosting, retrieval, indexing, transmission, display, analysis, generation of program reports and aggregate themes, AI-assisted response generation, email delivery, security monitoring, support, export, and deletion. |
| Purposes | To provide and administer Customer's programs; authenticate users; deliver participant communications; support commitments, check-ins, reflections, and action planning; provide bounded AI coaching; generate permitted program reporting; secure and support the Services; and comply with documented Customer instructions and applicable law. |
| Data Subjects | Participants enrolled by Customer; Customer personnel, team members, facilitators, coaches, trainers, speakers, or administrators whose Personal Data is included in Customer-controlled program data or uploaded materials. |
| Personal Data Categories | Names; email addresses; program and cohort identifiers; commitments and action steps; weekly check-in answers and reflections; self-rated scores; AI-coach messages; email delivery events; completion/activity status; and Personal Data that Customer elects to include in uploaded source materials. |
| Sensitive data | The Services are not designed to solicit special-category, sensitive, biometric, precise-geolocation, health, clinical, or similarly regulated Personal Data. Participants may nevertheless voluntarily enter sensitive information in free-text fields. Customer must not intentionally configure programs to solicit such data unless expressly supported and agreed in writing. |
| Frequency | Continuous or recurring during active programs and as initiated by Customer or participants. |
Exhibit B — Technical and Organizational Measures
ActionKeeper currently uses safeguards designed to include the following, as applicable to the Services:
- Encrypted network connections for data in transit.
- Email-link authentication rather than reusable account passwords for ordinary user access.
- Multi-factor authentication available to providers and required for ActionKeeper platform administrators.
- Database-level access controls designed to separate provider accounts and their associated program data.
- Role-based and least-privilege access practices for administrative access.
- Rate limiting and controls for sign-in, verification, registration, and other abuse-sensitive functions.
- Support access to customer content limited to authorized personnel for a stated support or operational reason, with access logging and time-limited access where technically implemented.
- Security and audit logging appropriate to the Services.
- Regular backups and disaster-recovery capabilities provided through infrastructure vendors, subject to vendor retention schedules.
- Use of established infrastructure, hosting, email, payment, AI, and indexing providers subject to contractual and security review appropriate to the service provided.
- Incident-response procedures for investigating, containing, mitigating, and communicating confirmed Security Incidents.
- Logical separation of provider data and restrictions designed to prevent cross-customer retrieval in AI-coaching workflows.
- AI safety and operational controls, including bounded coaching interactions, usage controls, and safeguards intended to reduce prohibited or high-risk outputs.
ActionKeeper has not represented that it currently holds SOC 2 certification or an equivalent independent security certification. Security measures may be updated over time, provided the overall level of protection is not materially reduced without a legitimate reason.
Exhibit C — Current Subprocessors
| Subprocessor | Purpose | Data / Processing |
|---|---|---|
| Supabase | Database, authentication, storage | Account identifiers, participant/program data, uploaded content, security metadata |
| Vercel | Hosting and delivery | Application requests and technical data necessary to host and deliver the Services |
| Resend | Transactional email | Names, email addresses, message content or program-related email content, and delivery events |
| Anthropic | AI inference | Participant input, relevant retrieved provider passages, program context, and instructions needed to generate a response |
| Voyage AI | Indexing / embeddings | Provider-uploaded text or passages required to create and query searchable indexes |
Stripe processes provider payment information in connection with subscription billing. To the extent Stripe determines its own purposes and means for payment processing, it acts as an independent controller or equivalent party rather than a Subprocessor under this DPA. Current vendor and location information is also described in the Privacy Policy.
Exhibit D — International Transfer Terms
This Exhibit applies only when Customer Personal Data is subject to the EU GDPR or UK GDPR and a legally recognized international transfer mechanism is required.
D.1 EU Standard Contractual Clauses
The European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference. Module Two (Controller to Processor) applies where Customer is a Controller and ActionKeeper is a Processor. For purposes of the Clauses: (a) the optional docking clause applies; (b) general written authorization for Subprocessors applies, with the notice process stated in Section 7 of this DPA; (c) the competent supervisory authority and governing law will be determined under the Clauses based on the exporter and applicable law; and (d) Exhibit A, Exhibit B, and Exhibit C of this DPA provide the processing, security, and Subprocessor information required by the applicable annexes to the Clauses, supplemented as reasonably necessary.
D.2 United Kingdom
For Restricted Transfers subject to the UK GDPR, the then-current UK International Data Transfer Addendum to the EU Standard Contractual Clauses issued or approved by the UK Information Commissioner's Office is incorporated by reference and applies to the extent required by law. Information in this DPA and its Exhibits will populate the corresponding tables of the UK Addendum to the extent applicable.
D.3 Supplementary Measures
ActionKeeper will use the technical and organizational measures described in Exhibit B and will reasonably cooperate with Customer regarding legally required transfer assessments. If a mandatory transfer mechanism is invalidated or replaced, the parties will use a lawful successor mechanism where reasonably available.
