Data Processing Agreement

Operated by First Light Holdings LLC (Focal)

Last Revised: July 22, 2026


1. Introduction

First Light Holdings LLC ("First Light Holdings", "Focal", "we", "us", or "our") is committed to protecting personal data and to processing it lawfully, fairly, and transparently. In connection with the Services we provide, First Light Holdings abides by the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), where applicable, and by the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"). This Data Processing Agreement ("DPA") describes how personal data is processed in the course of delivering the Services and sets out the respective responsibilities of First Light Holdings and of the Client with respect to that data.

2. Data Processing Overview

This DPA forms part of, and is incorporated by reference into, the Focal Terms of Service (the "Terms"). It is entered into between First Light Holdings LLC, a North Carolina limited liability company having a mailing address at 4030 Wake Forest Rd, Ste 349, Raleigh, NC 27609, USA ("Focal"), and the client or customer that subscribes to the Services (the "Client", "Customer", or "you").

This DPA applies to the processing of Customer Personal Data by Focal:

  • as a Data Processor acting on behalf of the Client (who is the Data Controller) with respect to the end-customer data that flows through the websites Focal builds, hosts, and runs on the Client's behalf — including contact-form and booking submissions and the Client's customer list; and
  • as a Data Controller with respect to the account data that Focal collects directly from the Client in order to establish and administer the Client's Focal account (for example, the business owner's name, email address, telephone number, business details, and billing information).

In the event of any conflict between this DPA and the Terms with respect to the processing of Customer Personal Data, this DPA shall prevail.

3. Definitions

Capitalized terms used but not defined in this DPA have the meanings given to them in the Terms. For the purposes of this DPA:

  • "The Services" means the done-for-you online-presence service that Focal provides to local and small businesses, including designing, building, hosting, maintaining, and running the Client's business website; connecting online booking and scheduling and the Client's chosen third-party payment processor; and setting up and managing the Client's Google Business Profile and local search presence, together with related onboarding, support, and account-administration services.

  • "Data Controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data. With respect to the end-customer data described in Section 2, the Client is the Data Controller.

  • "Data Processor" means a natural or legal person which processes personal data on behalf of, and under the instructions of, the Data Controller. With respect to the end-customer data described in Section 2, Focal is the Data Processor.

  • "Directive" means Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, as superseded by the GDPR.

  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing the Directive.

  • "Customer Personal Data" means any personal data (as defined under the GDPR and CCPA/CPRA) that Focal processes on behalf of the Client in the course of providing the Services — including without limitation the data submitted by the Client's website visitors and customers through contact forms and booking/scheduling flows, and the Client's customer list. Customer Personal Data does not include the Client's own account data, for which Focal acts as a Data Controller.

4. Compliance and Use

Each party shall comply with its respective obligations under all applicable data protection laws, including the GDPR (where applicable) and CCPA/CPRA, in connection with the processing of Customer Personal Data. Focal shall process Customer Personal Data only in accordance with this DPA, the Terms, and the Client's documented lawful instructions, and shall not use, sell, retain, or disclose Customer Personal Data for any purpose other than the specific purpose of delivering the Services, except as required by applicable law. Nothing in this DPA authorizes Focal to process Customer Personal Data for its own independent commercial purposes.

5. Processing

The Client has sole responsibility for the lawfulness, accuracy, and adequacy of the Customer Personal Data — that is, its end-customers' data — that it collects through the Focal-built site or that it directs Focal to process, and for establishing and maintaining a valid legal basis and, where required, the consent of Data Subjects for that processing. The Client alone determines the nature and purpose of the processing and the categories of Data Subjects whose data is processed.

Focal shall process Customer Personal Data only:

(a) as reasonably necessary to deliver the Services on the Client's behalf — including to host and run the Client's website, to receive and deliver contact-form and booking submissions, to maintain the Client's customer list, and to provide support to the Client;

(b) for maintenance, security, troubleshooting, and improvement of the Services, and then only in aggregated or anonymized form that does not identify any Data Subject; and

(c) as otherwise required by applicable law, in which case Focal shall, to the extent legally permitted, inform the Client of that legal requirement before processing.

Focal shall not be responsible for the content of, the basis for collecting, or the accuracy of any Customer Personal Data that the Client or its end-users submit to or through the Services.

6. Data Access, Modification and Deletion

The Client may access and modify its own account data and, where the functionality is provided, the Customer Personal Data held on its behalf through its Focal account dashboard. The Client may also exercise, or request assistance with, data-access, modification, and deletion matters by contacting Focal at privacy@focuswithfocal.com.

Upon termination or expiry of the Services, and at the Client's option and where technically feasible, Focal will return or enable the export of the Client's content and its end-customer data. Any such return, export, or deletion is subject to a reasonable wind-down period and to Focal's standard backup, retention, and archival cycles, and to any retention that Focal is required to observe under applicable law. Focal will delete or anonymize Customer Personal Data remaining in its live systems following the wind-down period, except to the extent retention is legally required.

7. Cooperation and Data Subjects' Rights

Taking into account the nature of the processing, Focal shall provide reasonable assistance to the Client, by appropriate technical and organizational measures and insofar as this is possible, to enable the Client to respond to requests from Data Subjects seeking to exercise their rights under applicable data protection law — including rights of access, rectification (correction), erasure, restriction, and data portability.

If Focal receives any request, complaint, or communication directly from a Data Subject relating to Customer Personal Data, Focal shall not respond to that request itself (other than to acknowledge receipt where appropriate) but shall promptly forward the request to the Client so that the Client, as Data Controller, may respond, unless Focal is otherwise required to respond by applicable law.

8. Data Protection Impact Assessment

Taking into account the nature of the processing and the information available to Focal, Focal shall provide the Client with reasonable assistance and information in connection with any data protection impact assessment ("DPIA") and any prior consultation with a supervisory authority that the Client is required to carry out under the GDPR or other applicable data protection law, where such assessment or consultation relates to the processing of Customer Personal Data under this DPA.

9. Confidentiality

Focal shall treat all Customer Personal Data as confidential and shall ensure that any personnel, contractors, or agents authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are made aware of the confidential nature of the data. Access to Customer Personal Data is limited to those personnel who require access in order to perform their duties in connection with the Services. These confidentiality obligations survive the termination of this DPA.

10. Security

Focal shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. These measures include, as appropriate:

  • Access controls that restrict access to Customer Personal Data to authorized personnel on a need-to-know basis, including passwordless magic-link authentication for account access (no passwords are stored);
  • Encryption in transit using industry-standard Transport Layer Security (TLS) for data transmitted between Data Subjects, the Client, and Focal's systems;
  • measures designed to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; and
  • processes for regularly testing, assessing, and evaluating the effectiveness of these technical and organizational measures.

The Services are hosted on infrastructure operated by reputable providers — including application hosting on Vercel and the managed database on Neon — that maintain their own recognized security and compliance programs. Focal relies on and configures these providers' security capabilities as part of its overall security posture.

11. Security Incidents (Personal Data Breaches)

If Focal becomes aware of a Personal Data Breach affecting Customer Personal Data, Focal shall notify the Client without undue delay after becoming aware of it. Such notification shall include the information then available to Focal regarding the nature of the breach, the categories and approximate number of Data Subjects and records concerned (where known), the likely consequences, and the measures taken or proposed to address it. Focal shall provide the Client with reasonable further information as it becomes available.

As Data Controller, the Client is responsible for determining whether the breach triggers, and for discharging, its own notification obligations to supervisory authorities and to affected Data Subjects under applicable data protection law. The Client shall indemnify and hold Focal harmless from and against any claims, losses, fines, or liabilities arising out of a Personal Data Breach to the extent it is caused by the Client's non-compliance with this DPA, the Terms, or applicable data protection law.

12. Sub-processors

The Client authorizes Focal to engage sub-processors to process Customer Personal Data in connection with the Services. Focal currently engages the following sub-processors:

Sub-processorPurpose
VercelWebsite and application hosting and content delivery (CDN)
NeonManaged PostgreSQL database hosting
DigitalOceanDNS management
Authorize.netPayment processing of Focal's own fees charged to the Client
TaxJarSales-tax calculation at checkout
PostmarkTransactional email delivery
GoogleAnalytics (GA4) and Google Business Profile / local search management on the Client's behalf
AnthropicAI-assisted text polishing during the onboarding interview

Focal shall impose data-protection obligations on each sub-processor that are, in substance, no less protective than those set out in this DPA, and shall remain responsible to the Client for the performance of each sub-processor's obligations. The Client consents to Focal's use of the sub-processors listed above. Focal will give the Client notice of any intended material change to its sub-processors (whether by addition or replacement) so that the Client has an opportunity to object on reasonable data-protection grounds.

Note on payment processors. The third-party payment processor that the Client chooses and connects for its own sales (for example, Stripe, PayPal, Klarna, Authorize.net, or Square) is the Client's own vendor, not a sub-processor of Focal. The Client's end-customers' payments flow directly to the Client through the Client's own processor; Focal does not process, hold, touch, or have access to those funds and makes no representation or warranty regarding the availability, holds, fees, or terms of any such processor.

13. Other Obligations of the Client

The Client represents and warrants that it has, and will maintain throughout the term of the Services, all necessary rights, permissions, consents, notices, and lawful bases required under applicable data protection law to provide the Customer Personal Data to Focal and to have Focal process it as contemplated by this DPA and the Terms — including the Customer Personal Data that the Client collects through the Focal-built website. The Client shall not provide to Focal, or collect through the Services, any personal data in a manner that violates applicable data protection law, and shall ensure that appropriate privacy notices are given to its Data Subjects. The Client's instructions to Focal regarding the processing of Customer Personal Data shall comply with applicable data protection law.

14. Audits and Inspections

Focal shall make available to the Client, on reasonable prior written request and no more than once per calendar year (except where required more frequently by a supervisory authority or following a Personal Data Breach), such information as is reasonably necessary to demonstrate Focal's compliance with its obligations under this DPA. Any audit or inspection shall be conducted during normal business hours, with reasonable advance notice, subject to appropriate confidentiality obligations, and in a manner that does not unreasonably disrupt Focal's business operations or compromise the confidentiality or security of the data of Focal's other clients. Where available, Focal may satisfy an audit request by providing relevant third-party certifications, attestations, or reports of its sub-processors.

15. Agreement Summary

This DPA governs how First Light Holdings LLC processes personal data in connection with the Focal Services. Focal acts as a Data Processor for the end-customer data that flows through the websites it builds, hosts, and runs on the Client's behalf — the Client is the Data Controller of that data — and as a Data Controller for the account data it collects directly from the Client. Focal processes Customer Personal Data only to deliver the Services, on the Client's instructions, and in accordance with applicable data protection law, including the GDPR (where applicable) and CCPA/CPRA. Focal engages the sub-processors listed in Section 12 under appropriate data-protection terms and remains responsible for their performance. The Client is responsible for the lawfulness and accuracy of the Customer Personal Data it provides or collects and for meeting its own obligations as Data Controller.

Questions about this DPA or about data processing generally may be directed to Focal's privacy contact at privacy@focuswithfocal.com.