Data Processing Addendum

If you require a signed version of the DPA, you can download it here.

Last Updated: 28th August 2026

This Data Processing Addendum ("Addendum") is entered into between the Female Entrepreneur Association, operating the FEA Create platform ("FEA," "we," "us"), and the customer accepting the FEA Create Terms of Service ("Member," "you"), together the "Parties." This Addendum forms part of, and is incorporated by reference into, the FEA Create Terms of Service (the "Agreement") from the date you first process Personal Data through FEA Create (the "Effective Date"). Where any term of this Addendum conflicts with the Agreement, this Addendum prevails to the extent of that conflict.

FEA Create is built on white-label infrastructure provided by HighLevel, Inc. ("GoHighLevel"). GoHighLevel acts as FEA's Sub-processor for the underlying hosting, delivery, and platform infrastructure that powers FEA Create, as described in Section 3 and Section 5 below.

1. Definitions

“Account” means any account or workspace created by, or on behalf of, the Member within FEA Create.

“Applicable Data Protection Laws” means all data protection and privacy laws and regulations applicable to the Processing of Member Personal Data under this Addendum, including the UK and EU GDPR, and applicable US state privacy laws (each as amended or superseded from time to time).

“Member Personal Data” means Personal Data that the Member (or the Member's own end clients, leads, or customers) submits into, or generates through use of, FEA Create, and that FEA Processes on the Member's behalf. Member Personal Data does not include FEA's own Account or billing records relating to the Member.

“Sub-processor” means any third party engaged by FEA to Process Member Personal Data in connection with providing FEA Create, including GoHighLevel.

The terms “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Processing,” “Processor,” and “Supervisory Authority” have the meanings given to them under Applicable Data Protection Laws. Capitalized terms not defined here have the meaning given in the Agreement.

2. Scope

This Addendum applies to all Processing of Member Personal Data carried out by FEA in the course of providing FEA Create to the Member, regardless of where the Member or their end clients are located.

3. Roles of the Parties

As between FEA and the Member: the Member is the Controller of Member Personal Data, and FEA is the Processor. Where the Member itself acts as a Processor on behalf of its own end clients, FEA acts as a Sub-processor to the Member.

FEA, in turn, relies on GoHighLevel to provide the underlying platform infrastructure. GoHighLevel Processes Member Personal Data solely as FEA's Sub-processor, under the terms of GoHighLevel's own Data Processing Addendum with FEA, which imposes obligations at least as protective as those set out in this Addendum.

4. FEA's Obligations

FEA shall:

- Process Member Personal Data only on the Member's documented instructions, including as needed to provide, maintain, and improve FEA Create under the Agreement, unless otherwise required by law;

- Ensure that anyone authorized to Process Member Personal Data is bound by an obligation of confidentiality;

- Notify the Member promptly if, in FEA's reasonable opinion, an instruction from the Member would infringe Applicable Data Protection Laws;

- Implement the technical and organizational security measures described in Annex 2, taking into account the nature of the Processing and the risks involved; and Assist the Member, taking into account the nature of the Processing, in responding to requests from Data Subjects and in meeting the Member's own obligations under Applicable Data Protection Laws.

5. Sub-processors

The Member authorizes FEA to engage the Sub-processors listed in Annex 3, including GoHighLevel, as of the Effective Date. If FEA intends to appoint a new Sub-processor, FEA will give the Member reasonable advance notice. If the Member objects on reasonable data protection grounds within 14 days of that notice, the Parties will work together in good faith to find a resolution; if none is found, the Member may terminate the affected Service.

Where FEA engages a Sub-processor, FEA remains responsible to the Member for that Sub-processor's performance of its data protection obligations, and will ensure each Sub-processor is bound by a written agreement offering a level of data protection consistent with this Addendum.

6. Data Subject Rights

IIf FEA or GoHighLevel receives a request from a Data Subject relating to Member Personal Data, FEA will promptly notify the Member and will not respond to the request directly, except on the Member's instruction or as required by law. FEA will provide reasonable assistance to help the Member respond to such requests using the tools available within FEA Create.

7. Personal Data Breaches

If FEA becomes aware of a Personal Data Breach affecting Member Personal Data, FEA will notify the Member without undue delay, and in any event within 72 hours of becoming aware. That notice will describe, to the extent then known: the nature of the breach; the categories and approximate volume of Data Subjects and records affected; the likely consequences; and the measures taken or proposed to address it. FEA will keep the Member updated as more information becomes available and will take reasonable steps to investigate, contain, and remediate the breach.

Notification of, or response to, a Personal Data Breach under this Section is not an acknowledgment by FEA of fault or liability.

8. International Data Transfers

Where Member Personal Data originating in the UK, EEA, or Switzerland is transferred outside those regions (including to GoHighLevel's US-based infrastructure), the transfer is made subject to the appropriate safeguards that GoHighLevel maintains as FEA's Sub-processor, including Standard Contractual Clauses and GoHighLevel's certification to the EU-U.S., UK, and Swiss Data Privacy Framework, each as set out in GoHighLevel's Data Processing Addendum. FEA will provide a copy of the relevant safeguards to the Member on reasonable request.

9. Deletion or Return of Personal Data

The Member can export or delete Member Personal Data at any time using the tools available within FEA Create. On termination of the Agreement, and following any request from the Member, FEA will delete or return Member Personal Data within a commercially reasonable period, except where retention is required by law. This Section does not require deletion of data retained solely in secure backups, which FEA will isolate from further Processing until it is deleted in the ordinary course of FEA's backup cycle.

10. Audit Rights

On reasonable written request, and no more than once per year (unless required following a Personal Data Breach or by a Supervisory Authority), FEA will provide the Member with information reasonably necessary to demonstrate compliance with this Addendum, which may include a summary of relevant GoHighLevel audit or certification materials. FEA may satisfy this obligation by making available third-party audit reports, security certifications, or written responses to reasonable due-diligence questionnaires in place of an on-site audit.

11. Liability

Each Party's liability arising out of or in connection with this Addendum is subject to the limitations and exclusions of liability set out in the Agreement.

12. General Terms

- Order of precedence: this Addendum, then the Agreement, then any other document referenced by the Agreement, to the extent of any conflict regarding the Processing of Member Personal Data.

- Updates: FEA may update this Addendum from time to time to reflect changes in Applicable Data Protection Laws or in FEA Create's Sub-processors, and will give the Member reasonable notice of any material change.

- Severability: if any provision of this Addendum is found unenforceable, the remainder will continue in full force and effect.

- Governing law: this Addendum is governed by the same governing law and jurisdiction provisions set out in the Agreement.

Annex 1 — Details of Processing

Subject matter - Provision of the FEA Create platform (funnel, website, CRM, and marketing automation tooling) to the Member.

Duration - For as long as the Member maintains an active FEA Create Account, plus any post-termination retention period required by law.

Nature and purpose - Hosting, storage, and Processing of data the Member enters into, or collects through, FEA Create (e.g. funnels, forms, CRM records, email/SMS communications) in order to deliver the platform's core features.

Categories of Data Subjects - The Member's own team members, leads, customers, and other contacts that the Member enters into or collects through FEA Create.

Categories of Personal Data - Contact and identification details (e.g. name, email, phone number), CRM and funnel activity data, communications content, and any other Personal Data the Member chooses to input.

Special category data - Not anticipated. The Member should not submit special category data (e.g. health, biometric) into FEA Create unless it has first confirmed appropriate safeguards with FEA.

Sub-processors - See Annex 3.

Annex 2 — Technical and Organizational Security Measures

FEA maintains the following measures directly, and relies on corresponding measures maintained by GoHighLevel for the underlying platform infrastructure:

- Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256), as implemented at the infrastructure layer by GoHighLevel.

- Role-based access control, so that only team members who need access to a given Account can obtain it.

- Confidentiality obligations for all FEA team members and contractors with access to Member Personal Data.

- Reliance on GoHighLevel's managed cloud infrastructure (AWS / Google Cloud), including automated backups, endpoint protection, and regular third-party penetration testing, as described in GoHighLevel's own Data Processing Addendum.

- A documented process for responding to Personal Data Breaches, including the notification timelines set out in Section 7.

- Tools within FEA Create allowing Members to export or delete their own data on demand.

Annex 3 — Approved Sub-processors

HighLevel, Inc. (GoHighLevel) - Underlying white-label platform infrastructure, hosting, and delivery for FEA Create.

Signature

This Addendum has been executed on behalf of the Female Entrepreneur Association by its authorized signatory below. By accepting the FEA Create Terms of Service, the Member agrees to be bound by the terms of this Addendum without requiring a countersignature.

James Green

Authorized Signatory, Female Entrepreneur Association

Date: 28th August 2026

© Female Entrepreneur Association 2022. Inspiring female entrepreneurs from around the world!