1Overview
First Light Holdings LLC abides by relevant data privacy laws and makes efforts to comply with applicable aspects of regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
This Data Processing Agreement (the “DPA”) forms part of the overall Terms of Service (the “Terms”) governing your use of Focal Campaign (the “Platform” or the “Services”) at focalcampaign.com. It is made and entered into by and between First Light Holdings LLC, a North Carolina limited liability company, on behalf of itself and its subsidiaries (“First Light Holdings”, “we”, “us”, “our”), and the client using the Services (the “Customer”, “Client”, “you”, “your”).
Focal Campaign is a marketing-automation platform. The Client uses it to store contacts, build campaigns and automations, and send the Client’s own text messages and email to the Client’s audience. This DPA sets out how personal data is handled under two distinct roles:
- Focal Campaign as Data Processor. For the personal data that the Client uploads, collects, or stores in the Platform about the Client’s own contacts, leads, and subscribers (the “Customer Personal Data”), we act as a Data Processor and process that data on the Client’s behalf, solely to provide the Services. The Client is the Data Controller of that data and is solely responsible for its lawful basis, accuracy, quality, and the consent of the individuals concerned.
- Focal Campaign as Data Controller. For the account data we collect directly from the Client and its authorized users — such as name, business details, email address, login credentials, plan, credit and billing metadata, and product usage — we act as a Data Controller, as described in our Privacy Policy.
2Definitions
- “The Services” means the Focal Campaign marketing-automation platform provided through focalcampaign.com, including contact storage, campaign and automation building, SMS and MMS message delivery, email delivery, phone-number intelligence, and the preparation and submission of carrier brand and campaign registrations on the Client’s behalf.
- “Customer Personal Data” means the personal data relating to the Client’s own contacts, leads, subscribers, and customers that the Client uploads to or collects and stores within the Services, and which we process on the Client’s behalf.
- “Data Controller” means the party that determines the purposes and means of processing personal data. The Client is the Data Controller of the Customer Personal Data. We are the Data Controller of the account data we collect directly from the Client.
- “Data Processor” means the party that processes personal data on behalf of the Data Controller. We are the Data Processor of the Customer Personal Data.
- “Subprocessor” means a third party engaged by us to process Customer Personal Data in connection with the Services.
- “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended or superseded, together with other applicable data protection and privacy laws (collectively, “Data Protection Requirements” or “Privacy Laws”).
3Nature and purpose of processing
The subject matter of the processing is the operation of a marketing-automation platform on the Client’s behalf: storing the Client’s contacts, building the Client’s campaigns and automations, transmitting the Client’s text messages and email to the recipients the Client selects, recording delivery outcomes and replies, honouring opt-outs, and reporting results back to the Client.
- Categories of data subjects: the Client’s own contacts, leads, subscribers, and customers.
- Categories of Customer Personal Data: telephone numbers, email addresses, names, custom fields and tags, message content and media, delivery status and carrier failure reasons, inbound replies, consent and opt-out events, and — where the Client uses those features — the carrier, line type, and country returned by a phone-number lookup.
- Duration: for the term of the Client’s account, then as set out in the Privacy Policy — with consent and opt-out events retained longer, because those records are the evidence that a message was permitted or that an objection was honoured.
- No special categories. We do not require, and the Client should not upload, special-category (sensitive) personal data — including health information, financial account details, precise geolocation, biometric data, or government identifiers — in contact fields or message content. The Services are not designed for it, and doing so may attract obligations neither party has agreed to.
Because these Services send text messages, Customer Personal Data necessarily includes telephone numbers. A telephone number carries obligations that an email address does not, and the Client’s warranties in this DPA should be read with that in mind.
4Compliance and use
The Client and First Light Holdings shall each comply with their respective Data Protection Requirements, including, to the extent applicable, the GDPR, the CCPA, and other applicable Privacy Laws. In the course of using the Services, the Client will upload or otherwise provide us with Customer Personal Data as required by the nature of the Services. The Client warrants that it has all necessary rights, consents, and legal bases to collect, process, and transfer Customer Personal Data to us for processing in accordance with this DPA and the Services, and that its contact lists were lawfully collected with the consent required by applicable law — including, for telephone numbers used for marketing messages, prior express written consent under the Telephone Consumer Protection Act where that standard applies.
5Processing
The Client shall have sole responsibility for the lawfulness, accuracy, quality, and secure collection of the Customer Personal Data it provides to us. We shall not access, use, or process Customer Personal Data except as necessary to:
- provide the Services (for example, storing the Client’s contacts and sending the messages the Client composes or schedules);
- provide technical support related to the Services;
- maintain, secure, and improve the Services, including in an anonymized and aggregated form;
- respond to a carrier, the messaging registry, or a regulator investigating a complaint about traffic sent from the Client’s account, which may require us to produce the record of a specific message or of a consent or opt-out event;
in each case in accordance with the Client’s documented instructions (including through use of the Platform’s features and its API), unless otherwise required by applicable law or by the carrier obligations described above. The Client, as Data Controller, determines the nature and purpose of the Customer Personal Data and the categories of data subjects. We do not sell Customer Personal Data, do not use it to build independent profiles, and do not market to the Client’s contacts.
If we ever believe an instruction from the Client would infringe applicable Privacy Laws, we will inform the Client rather than carry it out quietly.
6Opt-outs: the instruction we honour directly
This section is specific to messaging and qualifies the general rule that we act only on the Controller’s instructions.
When a recipient replies STOP, END, QUIT, UNSUBSCRIBE, CANCEL, or an equivalent keyword to a message sent through the Platform, we record that opt-out immediately, remove the recipient from any automation, and refuse every subsequent message to that number from the Client’s account, on every path including the API and any connected integration. That enforcement is not subject to the Client’s instruction and cannot be disabled, overridden, or cleared by re-importing the contact.
We do this because carrier policy and applicable law require the opt-out to be honoured by whoever receives it, and because a suppression record is the evidence that the objection was respected. Opt-out records are therefore retained beyond the deletion timetable in Section 13, in suppression form, for the period stated in the Privacy Policy. All other requests from a data subject are referred to the Client as Controller under Section 8.
7Data access, modification, and deletion
While Customer Personal Data is processed by us, the Client may access, modify, export, or delete such data directly through the self-serve account dashboard on the Platform, where such features are available. Requests relating to data not manageable through the dashboard may be submitted by contacting us at privacy@focalcampaign.com. Upon termination or expiry of the Services and, where requested, upon written request by the Client, we will delete or return (at the Client’s option, where feasible) Customer Personal Data in our possession or control relating to that Client’s account, subject to the retention, suppression, and backup provisions of this DPA.
8Cooperation and data subjects’ rights
We shall provide reasonable and timely assistance to the Client (at the Client’s expense where such assistance requires significant effort beyond standard service provision) to enable the Client to respond to requests from data subjects exercising their rights under the GDPR or other applicable Privacy Laws — including rights of access, correction, objection, erasure, restriction of processing, and data portability — and to any correspondence, enquiry, or complaint received from a data subject, regulator, or other third party in connection with our processing of Customer Personal Data on the Client’s behalf.
If any such request is made directly to us regarding data for which the Client is the Data Controller, we shall, to the extent permitted by law, promptly inform the Client and shall not otherwise respond except on the Client’s documented instructions or as required by law. The sole exception is an opt-out, which we act on immediately under Section 6 and then report to the Client.
9Data protection impact assessments
Where required by Data Protection Requirements, we shall provide the Client with reasonable assistance and available information (at the Client’s expense for significant efforts) in support of any data protection impact assessment (DPIA) conducted by the Client, solely in relation to our processing of Customer Personal Data as a Data Processor under this DPA, and where the Client would not otherwise have access to the relevant information.
10Confidentiality
We shall ensure that our personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. These obligations shall survive the termination of their engagement with us.
11Security
We implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, as appropriate:
- access controls limiting who may reach systems that process Customer Personal Data, with access logged;
- encryption of data in transit (TLS for Platform and API access), encryption at rest, and encryption of secrets and credentials, which are never displayed again once set;
- tenant isolation enforced in the database itself, not only in application code, so that each account’s data is separated at the storage layer and an application error cannot expose one Client’s records to another;
- passkey (WebAuthn) and multi-factor authentication available on every account;
- regular encrypted backups;
- measures to maintain the ongoing confidentiality, integrity, availability, and resilience of processing systems; and
- procedures for regularly testing and evaluating the effectiveness of these measures.
We may change specific measures as technology and threats move, provided the overall level of protection is not reduced.
12Security incidents (personal data breaches)
If we become aware of a confirmed Personal Data Breach affecting Customer Personal Data for which the Client is the Data Controller and we are the Data Processor, we shall notify the Client without undue delay after becoming aware of the breach. Where possible, such notification shall include the information available to us regarding the nature of the breach, the categories and approximate number of data subjects and records concerned, and the measures taken or proposed to address the breach and mitigate its effects. We shall provide reasonable cooperation to the Client in investigating and remediating the breach. The Client is solely responsible for complying with its own breach-notification obligations under applicable Data Protection Requirements.
13Subprocessors
The Client authorizes us to engage subprocessors to process Customer Personal Data in connection with the Services. We impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain responsible for our subprocessors’ performance of those obligations. We currently engage subprocessors in the following categories:
- Message delivery — a supplier that connects to the mobile carriers and transmits SMS and MMS traffic. Delivering a text message necessarily discloses the recipient’s number and the message content to this supplier and onward to the recipient’s mobile carrier. This is inherent to text messaging and cannot be avoided while the Service is used for its purpose.
- The messaging registry and the mobile carriers — recipients of brand and campaign registration data, which concerns the Client’s business rather than its contacts.
- Phone-number intelligence — a provider that returns carrier, line type, country, and reputation attributes for a number submitted for lookup.
- Cloud hosting, database, and file storage.
- Transactional and marketing email delivery.
- Payment processing — account and billing data only; not Customer Personal Data.
- AI model provider — for AI-assisted drafting features, as described in the Privacy Policy.
- Error monitoring and operational alerting.
Certain of these suppliers are engaged under confidentiality terms that prevent public naming. The current list identifying each subprocessor by name, with its location and processing role, is available to any Client on request from privacy@focalcampaign.com, and forms part of this DPA when provided.
We will give the Client advance notice — not less than 30 days where practicable — of any intended addition or replacement of a subprocessor that processes Customer Personal Data. The Client may object to a new subprocessor on reasonable, data-protection-related grounds; if the parties cannot resolve the objection, the Client may terminate the affected Services in accordance with the Terms without penalty.
14International transfers
We and our subprocessors may process Customer Personal Data in the United States and other countries. Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy decision, such transfers are carried out under an appropriate transfer mechanism, including the European Commission’s Standard Contractual Clauses (SCCs) where applicable, together with any supplementary measures reasonably required. If you are outside the United States, your use of the Services instructs us to transfer Customer Personal Data there.
15Return and deletion of data on termination
Upon termination or expiry of the Services, we will, at the Client’s option and where feasible, return or delete the Customer Personal Data in our possession or control relating to that Client’s account. This obligation does not apply to the extent we are required by applicable law to retain some or all of the Customer Personal Data; to opt-out and consent records retained under Section 6 and the Privacy Policy, which are kept in suppression form as evidence; or to data retained in backup archives, which are protected from further processing until they are overwritten in the ordinary course or restored, at which point deletion can be applied.
16Other obligations of the Client
The Client, as Data Controller for the Customer Personal Data, warrants that it has all necessary rights, consents, and legal bases to collect, process, and transfer that data to us for processing under this DPA. The Client shall maintain a procedure for individuals to exercise their rights, process only data that has been lawfully and validly collected, ensure such data is relevant and proportionate to its use, honor unsubscribe and opt-out requests, and not upload purchased, rented, scraped, or harvested lists or send messages without the required consent.
The Client shall also ensure that its own privacy notice discloses that a service provider transmits messages on its behalf, and that the disclosures made at the point of consent collection — message purpose, frequency, and rate notices — meet the standards the carriers and applicable law require.
17Audits and inspections
Upon reasonable written request from the Client (not more than once annually, unless a confirmed security incident or a regulator necessitates more frequent review), we shall provide the Client with information reasonably necessary to demonstrate compliance with our obligations under this DPA, including any current third-party security report we hold. If such information is insufficient, the Client may request an audit, to be conducted at the Client’s expense by the Client or an independent, qualified third-party auditor mutually agreed by the parties, during normal business hours, on reasonable advance notice, and subject to confidentiality. Any such audit shall be limited in scope to our processing of Customer Personal Data on the Client’s behalf and its compliance with this DPA.
18Governing terms
We take precautions to safeguard data and abide by relevant privacy laws. Any customized Data Processing Agreement mutually agreed in writing between us and the Client will supersede this DPA with respect to the subject matter of that custom agreement. This DPA may be updated from time to time to reflect changes in regulations, standards, or the Services; we will provide notice of material changes as required by law or as set out in the Terms. This DPA forms part of the Terms and, where it conflicts with the Terms on the subject of personal data, this DPA governs. It is governed by the laws of the State of North Carolina, consistent with the main Terms.
If you require more details or have any questions concerning this Data Processing Agreement, please contact us at privacy@focalcampaign.com.