← Back

Data Processing Addendum

Version 2.2 · Effective August 25, 2026

A few terms are still being finalised. They are marked Not settled yet below. Where a decision has not been made we say so, rather than state a number we would not stand behind. If one of them matters to you, email johnsontechstudio@gmail.com and we will tell you where it stands, in writing, before you rely on it.

This document has not been reviewed by a lawyer yet. It is a first publication, drafted from an attorney-review package, and several of its sections depend on facts about our providers that we have not finished verifying — those are marked below rather than asserted. If a section matters to a decision you are making, email johnsontechstudio@gmail.com and we will tell you where it stands, in writing, before you rely on it.

This Addendum is part of your Terms of Service with Johnson Tech Studio LLC dba gig33 (“Johnson Tech Studio,” “we,” “us”). It covers the personal information of your own customers — the people who ring your phone, chat on your website, or fill in your form — which passes through our system because you asked us to answer your phone and capture your leads.

Those people never signed up with us. They rang you. That is what this document is about, and if it disagrees with the Terms of Service on anything to do with their information, this document wins.

1. Who decides what, and who does what

2. What we process, for whom, and for how long

3. What you are responsible for

4. Security

We maintain safeguards appropriate to this kind of information. These are the ones we can point at:

Not settled yetwe have not had an outside security assessment, we hold no security certification, and we are not claiming one. Ask about a specific control and we will tell you honestly whether it exists.

No system is completely secure, and we will not tell you otherwise.

5. The companies we use to do this

We use other companies to run parts of the service. Our Privacy Policy names every one of them and says what each receives — the database and file storage, the telephone and voice provider, the AI providers, the host, the email delivery service, the registrar, and the payment processor.

Not settled yetwe have not finished verifying, for each provider, its exact legal entity, the region it stores data in, its own data-processing terms, its retention periods, and who it passes data to in turn. We are not going to present those as verified facts before we have checked them. Ask about a specific provider and we will tell you what we know and what we do not.

Not finalhow you can object to a new provider, and what happens if you do, has not been settled with our lawyer. Until it is, tell us your objection and we will work it out with you rather than point at a clause.

6. Requests from the people whose information it is

If one of your customers asks to see, correct, delete, or get a copy of their information, or asks to be left alone:

Not settled yetwe have not committed to a response deadline, and we have not built a formal appeal route. If a law that applies to you gives your customers a deadline or an appeal, it applies whether or not it is written here.

7. Deleting and getting your data back

What is actually true about deletion today. There is a routine that runs every night to remove the contents of old transcripts. It deletes nothing: it is set to rehearse, counting what it would remove and stopping. Two separate deliberate acts by a person are needed to arm it, and neither has been done. Not settled yetso there is no automatic deletion schedule in force, and this document is not going to promise one. Deletion happens because you ask for it, which you can do at any time and which we do act on. The periods that routine is aimed at are listed in our Privacy Policy, described as targets rather than commitments.

If you connect a Google Business Profile, Google’s own rules may require us to hold content from it for a shorter time than anything above. Where they do, Google’s rules win for that content.

8. If there is a security incident

If we confirm a security incident affecting your customers’ personal information, we will tell you without undue delay, and we will keep telling you as we learn more — early information is usually incomplete, and waiting until the picture is whole is worse than telling you what we know. We will work with you on containing it, fixing it, and any notice that has to go out.

Not settled yetwe have not fixed a notification deadline in hours or days, because the deadlines that actually apply differ by state and we would rather meet the real one than a number we invented. We also do not yet maintain a written incident-response plan, and we are telling you that rather than implying one exists.

9. Helping you with your own obligations

If you have to carry out a privacy assessment or demonstrate that you are meeting your obligations, ask us and we will give you the information we reasonably have about how the service handles data. Whether what you are doing with the service is lawful in the first place — your marketing, your calling, your recording, your industry’s rules — remains yours to judge.

Once a year, on reasonable written notice, you can ask us for the information reasonably needed to show we are meeting this Addendum. If a law that applies to you requires an actual audit and that information is not enough, we will agree a narrow one that does not expose other customers’ data. You cover your own costs unless the audit finds a material failure on our side.

10. State privacy laws

This Addendum is written to support the processor and service-provider obligations that United States state privacy laws impose — including in Texas, Virginia, Colorado, and California — where they apply to us.

Not finalwhich of those laws actually applies to us, and the specific wording each one requires, has not been confirmed by our lawyer. Several turn on revenue and volume thresholds we have not measured. This document states no certification and claims no determination; if a law applies, it applies, and nothing here reduces what it gives your customers.

11. Outside the United States

This is written for United States operations. We do not have the transfer arrangements that European, United Kingdom, or Swiss data-protection law requires, and we are not going to pretend we do. If your business needs them, ask us before you send us data that falls under those rules — the honest answer today is that this is not the right product for it.

12. How this fits with the rest

The liability limits, third-party claim provisions, disputes wording, and governing law in the Terms of Service apply here too, except where a privacy law says they cannot. Where this Addendum and the Terms disagree about your customers’ personal information, this Addendum wins.

13. Contact

Anything about this Addendum, including a request about a specific person’s information: johnsontechstudio@gmail.com, or by post at Johnson Tech Studio LLC, 4319 Country Brook Dr, Dallas, TX 75287, United States.

Data protection questions: johnsontechstudio@gmail.com

See also our Terms of Service, Privacy Policy, Refund Policy, and Acceptable Use Policy.