Data Processing and Security Addendum
Last updated July 2026
Version 1.0 · Effective July 17, 2026 ·
Bundle 2026-07-clearvin-v1
Lkota LLC, Level 17, 444 West Lake Street, Suite 1700, Chicago, Illinois 60606
This Data Processing and Security Addendum, the “DPA,” forms part of the Agreement between Lkota and Customer.
1. Definitions
“Customer Personal Data” means personal information submitted by or for Customer and processed by Lkota to provide the Services.
“Security Incident” means confirmed unauthorized access to, acquisition of, use of, alteration of, or disclosure of Customer Personal Data under Lkota’s control.
“Subprocessor” means a third party engaged by Lkota to process Customer Personal Data in connection with the Services.
ClearVin Licensed Materials and third-party proprietary vehicle data are not Customer Personal Data merely because they are displayed through Customer’s account.
2. Roles
To the extent Lkota processes Customer Personal Data solely on Customer’s documented instructions:
- Customer acts as the business, controller, or equivalent responsible party; and
- Lkota acts as the service provider, processor, or equivalent processing party.
Lkota may act independently for account administration, billing, fraud prevention, security, legal compliance, service analytics, and enforcement of agreements.
3. Customer instructions
Customer instructs Lkota to process Customer Personal Data as necessary to:
- provide the Services;
- process VIN requests;
- verify information;
- store transaction records;
- generate documents;
- obtain signatures;
- provide support;
- prevent fraud;
- maintain security; and
- comply with law.
Lkota is not required to follow an instruction that Lkota reasonably believes is unlawful, insecure, or inconsistent with provider restrictions.
4. Customer obligations
Customer represents that:
- it has provided all required notices;
- it has obtained all required consents and authorizations;
- it has a lawful basis for the processing;
- its instructions comply with law;
- it will not submit unnecessary sensitive information;
- it will restrict access to authorized personnel;
- it will configure user permissions appropriately; and
- it will not direct Lkota to violate ClearVin restrictions.
5. Confidentiality
Lkota will restrict Customer Personal Data to personnel and contractors with a legitimate need to access it.
Such persons will be subject to confidentiality obligations appropriate to their roles.
Customer must treat Lkota software, ClearVin Licensed Materials, API information, provider documentation, reports, and proprietary system information as confidential.
6. Security measures
Lkota will maintain commercially reasonable administrative, technical, and physical safeguards, which may include:
- unique user accounts;
- password protection;
- role-based access;
- tenant isolation;
- encryption in transit;
- encryption at rest where appropriate;
- logging and monitoring;
- backup procedures;
- rate limiting;
- session controls;
- vulnerability management;
- incident-response procedures;
- employee access restrictions;
- secure software-development practices; and
- secure deletion processes.
ClearVin’s agreement requires security safeguards that are no less rigorous than those used by Lkota for its own information and, in all events, commercially reasonable safeguards, including password-protected access.
7. Subprocessors
Customer authorizes Lkota to use Subprocessors, including providers supporting:
- vehicle data;
- ClearVin services;
- hosting;
- storage;
- backups;
- OCR;
- document generation;
- electronic signatures;
- email;
- messaging;
- payments;
- analytics;
- fraud prevention; and
- customer support.
Lkota will require Subprocessors that process Customer Personal Data to maintain appropriate confidentiality and security obligations.
8. ClearVin data
Customer acknowledges that:
- ClearVin remains the owner or licensor of ClearVin Licensed Materials;
- ClearVin data is subject to separate proprietary restrictions;
- Customer has no independent sublicensing right;
- Customer may not use ClearVin information outside the Lkota Services;
- Customer may not create a derivative vehicle or valuation database;
- Lkota may disclose limited usage information to ClearVin for compliance, billing, support, security, and audit purposes; and
- Lkota may modify, suspend, or delete access to ClearVin data when required by ClearVin or applicable law.
9. Security incidents
After confirming a Security Incident affecting Customer Personal Data, Lkota will notify Customer without undue delay where notification is legally or contractually required.
The notice may include, as information becomes reasonably available:
- the nature of the incident;
- affected information;
- affected systems;
- mitigation measures;
- recommended Customer actions; and
- a contact for follow-up.
Notification does not constitute an admission of fault or liability.
Customer is responsible for notifications resulting from Customer’s systems, users, credential misuse, downloaded files, or instructions unless applicable law requires otherwise.
10. Cooperation with requests
Taking into account the nature of the Services, Lkota will provide reasonable assistance with legally valid requests concerning Customer Personal Data.
Customer is responsible for determining whether and how to respond.
Lkota may charge reasonable fees for requests requiring substantial manual work, unless prohibited by law.
11. Government and legal requests
Lkota may disclose information where required by subpoena, court order, legal process, law, or government request.
Where legally permitted, Lkota may provide Customer notice before disclosure.
Lkota may disclose only the information reasonably necessary to comply with the applicable request.
12. Return and deletion
Following termination, Lkota will delete or return eligible Customer Personal Data according to:
- the Data Retention and Deletion Policy;
- Customer’s plan;
- legal obligations;
- provider restrictions;
- backup cycles;
- claims;
- disputes;
- audits; and
- legal holds.
13. Compliance information and audits
Upon reasonable written request, Lkota may provide information reasonably necessary to demonstrate compliance with this DPA.
Customer audits must:
- occur no more than once annually unless required after a confirmed incident;
- be scheduled with reasonable notice;
- occur during normal business hours;
- avoid access to other customers’ information;
- avoid source code, penetration testing, or production-system access;
- be performed by an independent auditor under confidentiality obligations; and
- be paid for by Customer.
Lkota may satisfy an audit request using policies, summaries, questionnaires, certifications, or third-party audit reports where reasonably sufficient.
14. Liability
The disclaimers, exclusions, indemnities, and liability limits in the Terms of Service apply to this DPA.
This DPA does not create greater liability than the Agreement unless applicable law expressly prohibits the relevant limitation.