Legal & trust
Data Processing Addendum
This Data Processing Addendum is the default U.S.-focused agreement for personal data WashRoute Pro processes on behalf of a business customer. It supplements the Terms of Service.
This DPA becomes part of the Terms when the customer uses the Service to process covered personal data and no separately signed DPA controls.
1. Scope and order of precedence
This Data Processing Addendum (“DPA”) applies when WashRoute Pro processes Personal Data for Customer in providing the Service. It forms part of the Terms of Service or another written agreement governing the Service (the “Agreement”). If this DPA conflicts with the Agreement on processing Personal Data, this DPA controls.
2. Definitions
“Applicable Data Protection Law” means a privacy or data-protection law that applies to the processing. “Controller” includes a business or similar entity that determines purposes and means. “Processor” includes a service provider, contractor, or similar entity processing for a Controller. “Personal Data” means information covered by Applicable Data Protection Law. “Security Incident” means unauthorized access to or acquisition, destruction, loss, alteration, or disclosure of Customer Personal Data, excluding unsuccessful attempts that do not compromise it. “Subprocessor” means a third party engaged to process Customer Personal Data for the Service.
3. Roles and instructions
Customer is the Controller and WashRoute Pro is the Processor for Customer Personal Data, except where law assigns a different role. Customer instructs us to process the data to provide, secure, support, and improve the Service; comply with Customer’s documented use and configuration; and meet legal obligations.
Customer is responsible for lawful instructions, notices, consents, and authority. We will notify Customer if we believe an instruction violates Applicable Data Protection Law unless law prohibits notice. We may process data as law requires and will inform Customer when legally permitted.
4. Processing details
Subject and duration
Field-service business management and customer communication for the subscription term, plus the limited retention period described in the Agreement and Privacy Policy.
Nature and purpose
Collection, organization, hosting, storage, retrieval, display, transmission, calculation, support, security, export, deletion, and other processing needed for the Service and Customer instructions.
People
- Customer users and personnel.
- Crews, representatives, contractors, and subcontractors.
- Prospects, homeowners, property contacts, commercial contacts, reviewers, and referral participants.
- Other people whose information Customer lawfully submits.
Data categories
- Identifiers and contact details.
- Account, role, and authentication records.
- Customer, property, location, lead, quote, job, route, schedule, and commercial-site records.
- Photos, documents, notes, communications, consent, opt-out, payment status, support, device, and audit information.
- Sensitive data only when Customer chooses to submit it and the Service supports that purpose; the Service is not designed for Social Security numbers, government identifiers, health records, or full card credentials.
5. Processing restrictions
We will not sell Customer Personal Data, retain, use, or disclose it outside the business purposes in the Agreement, combine it with personal data from unrelated sources except as legally permitted to provide the Service, or use it for targeted advertising. We will not attempt to re-identify data Customer has lawfully de-identified, except to test whether de-identification works when law allows.
6. Confidentiality and access
We limit access to personnel and service providers who need Customer Personal Data for the Service and who are subject to confidentiality duties. We maintain role and tenant controls designed to prevent unauthorized account access. Customer controls user roles and must remove unnecessary access.
7. Security measures
Taking account of processing risks, we maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data. Current product controls are described on the Security & Trust page. Measures may evolve without materially reducing the overall protection of the Service.
8. Subprocessors
Customer gives general authorization for the Subprocessors listed on the Subprocessors page and for replacements needed to provide the Service. We require a Subprocessor to protect Customer Personal Data through written terms appropriate to its role. We remain responsible for our obligations under this DPA to the extent required by law and the Agreement.
We will update the public list before or within a reasonable period after a material new Subprocessor begins processing. Customer may object on reasonable data-protection grounds by contacting the legal email promptly. The parties will work in good faith on a commercially reasonable solution; if none exists, Customer may stop the affected feature or terminate it as the parties agree.
9. Individual rights
Taking account of the nature of processing, we will provide reasonable assistance for Customer to respond to verified access, correction, deletion, portability, opt-out, or appeal requests. If we receive a request about Customer-controlled data, we may direct the person to Customer and notify Customer where appropriate. Customer remains responsible for the response and legal decision.
10. Security incidents
We will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will include information reasonably available about the nature, affected data, likely consequences, measures taken or proposed, and a contact point. We may provide updates as the investigation continues.
Notice is not an admission of fault or liability. Customer is responsible for notices to individuals or authorities unless law assigns that duty to us. The parties will cooperate reasonably and avoid public statements naming the other without prior consultation unless law requires them.
11. Compliance assistance
We will provide information reasonably needed for Customer’s data-protection assessments, consultations, and processing records, considering the Service and information available to us. Additional bespoke assistance may require agreed fees if it materially exceeds ordinary support.
12. Audit information
On reasonable written request no more than once per year, unless a Security Incident or regulator requires more, we will provide available information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient, the parties may agree to a scoped remote or on-site review during normal business hours, subject to confidentiality, security, non-disruption, and reasonable cost allocation. This clause does not claim an existing independent certification or audit report.
13. Return and deletion
During the subscription, Customer may use available export tools. After termination and on Customer’s lawful instruction, we will delete or return Customer Personal Data unless law permits or requires retention. Consent, opt-out, financial, security, audit, legal-hold, and backup records may remain for their lawful purpose and will remain protected and isolated from ordinary product use.
14. International transfers
The Service is U.S.-focused and providers may process data in the United States or other places where they operate. If Applicable Data Protection Law requires a transfer mechanism, the parties will use a legally recognized mechanism appropriate to the transfer. This DPA does not represent that standard contractual clauses or a certification are already executed when they are not.
15. Term and contact
This DPA remains in effect while we process Customer Personal Data. Submit questions, objections, and requests using the Legal and contracts option on our Contact page. Include the Customer account name and enough detail to route the request safely, then keep the tracking reference.