Dear Alli
Dear Alli
Data Processing Agreement
Before you sign anything. These are Go To 11's standard processing terms, written to describe accurately what Dear Alli actually does with data. They have not been reviewed by a lawyer, and they are not legal advice to you or to us. If your organisation needs a signed DPA, send this to your counsel, or send us yours and we will work from it.

Between Go To 11 Communication Strategies ("the processor"), Toronto, Canada, and the customer who subscribes to Dear Alli ("the controller"). Effective from the date the subscription starts.

1. Roles

You decide what conversations to put into Dear Alli and why. That makes you the controller. We process what you send in order to provide the coaching, and nothing else. That makes us the processor.

2. What is processed

Subject matterCoaching a person on how to reply to a LinkedIn conversation.
DurationFor as long as the subscription is open, plus the thirty day deletion window in clause 8.
Categories of personYour team members who use Dear Alli, and the people they are messaging.
Categories of dataName, email address, and the content of the conversations submitted for coaching, which may name and describe third parties.
Special categoriesNone is requested or required. Dear Alli is a sales coaching tool. Anything sensitive present in a conversation you submit is there because you put it there.

3. Instructions

We process only on your documented instructions, which for ordinary use means the act of using the product. We do not sell data, do not share it outside the sub-processors in clause 5, and do not use it to train any model. Anthropic keeps what it receives for up to 30 days under its API terms, then deletes it, and does not train on it.

4. Confidentiality

Two people can access customer data. Kenny Solway at Go To 11, for support and to check coaching quality. Alli Rizacos of Authentic Results, who reads the private review channel where every conversation and draft is mirrored, to correct the drafts and train the coaching. No other staff and no contractor can. That access exists and we would rather say so than imply an isolation we do not have.

5. Sub-processors

You authorise these, each processing only what is described:

AnthropicWrites the coaching. Every submitted message reaches it. United States.
OpenAITranscribes voice notes. Reached only when audio is submitted. United States.
NotionStores profiles and conversation history. United States.
NetlifyRuns the application and short term storage. United States.
SlackThe private review channel where every draft is mirrored, and the legacy channel for the few coaches still on Slack. United States.
SupabaseThe function log: timings, status codes, token counts and cost, keyed to the coach id. No conversation text. United States.
Authentic ResultsAlli Rizacos of Authentic Results reads the review channel to correct drafts and train the coaching. Sees the conversation and the draft. Canada.
ResendAccount email. Name and address only, no conversation content. United States.
StripePayment. Card details go directly to Stripe and never reach us. United States.

We will tell you in writing before adding or replacing any of them, and you may object. This list is checked against the running code before every release: a new outbound connection fails the build until it is either added here or recorded as carrying no customer data.

6. Transfers

Data is processed in the United States. Go To 11 is in Canada. If you are in the UK or the EEA, transfers rely on the sub-processors' own standard contractual clauses, which each of them publishes. We are not in a position to offer regional hosting.

7. Security

The measures we actually take are listed in full at dearalli.goto11.ca/security, including the ones we do not: there is no SOC 2 report, no ISO 27001 certificate, and no third party penetration test. In summary: TLS on every connection, per person access codes that can be revoked in under a minute, signed server to server calls, separation between customers enforced in code and asserted by automated tests that block a release on failure, and logs that record who and what failed rather than what anyone wrote.

8. Deletion and return

Ask, at any time, and we delete everything: profiles, conversations, drafts and scoreboards, across every store that holds them. Records in Notion sit in its trash and are recoverable for thirty days, after which they are gone; everything elsewhere goes immediately, except Anthropic's copy, which runs out within 30 days under its API terms, and one other: drafts are mirrored to a private review channel that is not cleared by hand and instead ages out on its own within ninety days of writing. Ask for a copy first and you get one. At the end of the subscription we do the same within thirty days, whether or not you ask.

One stated exception. We keep an anonymised record of what kind of opening message tends to get a reply. It carries no name, no account, no recipient and none of your text. It cannot be traced back to a person. If you would rather it went too, say so and it goes.

9. Helping you meet your obligations

If one of your people, or someone they messaged, asks for access, correction or erasure, tell us and we will do it. If we become aware of a breach affecting your data we will contact you directly and without undue delay, and tell you what we know, including what we do not yet know.

10. Audit

We will answer questions in writing and point at the code or the running system where we can. We cannot host an on-site audit or complete a bespoke certification programme.

Version 1, 30 August 2026. Questions or a redline: kennysolway@goto11.ca.

Dear Alli home  ·  A Go To 11 Communication Strategies Build