How AutoKnerd processes a dealership's Customer Data on its behalf, as a processor / service provider.
LAST UPDATED: SEPTEMBER 2026
This Data Processing Agreement (“DPA”) is between the customer (“Customer,” the controller) and AutoKnerd LLC (“AutoKnerd,” the processor / service provider). It is incorporated into the Terms of Service.
This DPA governs AutoKnerd's processing of personal information contained in Customer Data on Customer's behalf when Customer uses the Service. Customer is the controller / business; AutoKnerd is the processor / service provider.
“Personal Information,” “Customer Data,” “Sub-processor,” “Security Incident,” and “Process” have the meanings given here and in applicable US privacy laws, including the CCPA/CPRA and other state consumer-privacy laws.
AutoKnerd will:
Customer authorizes AutoKnerd to use the sub-processors listed on our Sub-processors page to provide the Service. AutoKnerd will (a) impose data-protection obligations on each sub-processor no less protective than this DPA, (b) remain responsible for their performance, and (c) give Customer [30 days'] notice of any new sub-processor, with a right to object on reasonable data-protection grounds.
AutoKnerd will maintain reasonable and appropriate administrative, technical, and physical safeguards, including: encryption of Customer Data in transit and at rest; role-based access control and least-privilege access; logical tenant isolation between customers; authentication with server-side session verification; default-deny data-store rules; and secure software-development and access practices. Details are in the Security Overview.
AutoKnerd will notify Customer without undue delay (and in any event within [72 hours]) after becoming aware of a Security Incident affecting Customer Data, will provide information reasonably available to Customer, and will take reasonable steps to mitigate and remediate. [Attorney/ops to confirm the exact window.]
If AutoKnerd receives a request from a data subject regarding Customer Data, it will, to the extent legally permitted, direct them to Customer and assist Customer in responding.
On termination, or on Customer's request, AutoKnerd will delete or return Customer Data within [30 days] and delete existing copies, except as required by law. [Confirm mechanism and timeline; product deletion tooling is being added.]
AutoKnerd will make available information necessary to demonstrate compliance and will allow for and contribute to audits conducted by Customer or its auditor, subject to reasonable notice, confidentiality, and frequency limits. [Attorney to scope.]
Customer Data is processed in the United States. AutoKnerd does not transfer Customer Data outside the US.
In the event of a conflict, this DPA controls over the Terms of Service with respect to the processing of Customer Data.
[Signature blocks — Customer and AutoKnerd LLC.]