Skip to content
On Site & Ready

Data Processing Agreement

Last updated: 2026-07-27

This is a template, not legal advice.

This document is drafted to reflect how this specific platform actually works, but it has not been reviewed by a lawyer and is not a substitute for one. Have it reviewed and adjusted by a qualified attorney in your jurisdiction — including the liability, indemnity, arbitration, and data-transfer terms — before relying on it.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between [LEGAL ENTITY NAME] ("Processor", "we") and the Business that has registered for On Site & Ready ("Controller", "you"), and applies whenever we process personal data on your behalf as described in Section 6 ("End-Customer Data") of our Terms of Service. It reflects the requirements of Article 28 of the EU/UK GDPR and is intended to apply, to the extent relevant, to similar obligations under other data protection laws.

1. Purpose & Scope

You (the Business) are the controller of the personal data of your own Team Members and End Customers that is submitted to or generated within the Service ("Customer Personal Data"). We are the processor, and we process Customer Personal Data solely on your documented instructions — as set out in the Terms and this DPA, or as otherwise agreed in writing — and as necessary to provide the Service, except where otherwise required by law applicable to us.

2. Duration

This DPA remains in effect for as long as we process Customer Personal Data on your behalf, which generally corresponds to the term of your Business Account plus any post-termination retention/export period described in our Privacy Policy.

3. Categories of Data Subjects

  • Your Team Members (owners, managers, office staff, and technicians)
  • Your End Customers (customers, prospective customers, and property occupants)

4. Categories of Personal Data & Processing Activities

Depending on how you configure and use the Service, Customer Personal Data may include: names, email addresses, phone numbers, property/service addresses, appointment and job history, notes, photographs, e-signatures, invoice and payment-reference details, chat messages and file attachments, and — where you enable the relevant features — GPS location data for Team Members. This data is processed by storing it, making it available to your authorized Team Members through the Service, transmitting it as needed to deliver notifications (push/email) and process payments, and backing it up, all for the purpose of providing the Service to you.

5. Processor Obligations

  • Process Customer Personal Data only on your documented instructions;
  • Ensure persons authorized to process Customer Personal Data are subject to confidentiality obligations;
  • Implement appropriate technical and organizational security measures (see Section 8);
  • Engage sub-processors only as disclosed in Section 7, and impose data protection obligations on them that are no less protective than those in this DPA;
  • Assist you, to the extent reasonably possible, in responding to requests from data subjects seeking to exercise their rights;
  • Assist you in meeting obligations relating to security, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of processing and information available to us;
  • At your election, delete or return all Customer Personal Data at the end of the relationship, except to the extent we are required to retain copies by law; and
  • Make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits as described in Section 11.

6. Your Obligations as Controller

You are responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it was collected; for ensuring you have a valid legal basis to instruct us to process it; for providing required privacy notices to your Team Members and End Customers; and for responding to data subject requests directed at you, using the Service's tools and our reasonable assistance where needed.

7. Sub-processors

You authorize us to engage the following sub-processors to provide the Service. We will update this list as our infrastructure changes and, on request, will provide advance notice of a new sub-processor so you may object on reasonable data-protection grounds.

Sub-processorPurposeProcessing location
Supabase, Inc.Database hosting, authentication, and file/object storage[Region — TO BE CONFIRMED based on selected Supabase project region]
Stripe, Inc.Payment processing for platform subscriptions, and (via each Business's own connected Stripe account) for End Customer invoice paymentsUnited States / global
Email delivery (SMTP) providerTransactional email delivery. Where a Business configures its own SMTP server, its mail is delivered through that server instead[Provider and region — TO BE CONFIRMED once an SMTP provider is selected]
Google LLC (Google Maps Platform, including Routes and Distance Matrix APIs)Address geocoding, route optimization for technician dispatch, and travel-time/distance estimatesUnited States / global
SMS delivery providerDelivery of SMS/text message notifications, where a Business enables the optional SMS add-on[Provider and region — TO BE CONFIRMED once an SMS provider is selected]
Xero (Xero Limited) / QuickBooks Online (Intuit Inc.)Where a Business connects one of these optional accounting integrations, synchronization of its accounting records into its own connected account — on demand or on a daily/weekly schedule chosen by the Business. Covers customer contact details, invoices, payments, credit notes, estimates and expenses, and (QuickBooks only) team members' recorded working hoursNew Zealand / United States, respectively
Web push notification infrastructure (browser vendors, e.g. Google/Mozilla/Apple push services)Delivery of browser push notifications to subscribed devicesDepends on end-user's browser/device vendor

8. Security Measures

We maintain technical and organizational measures designed to protect Customer Personal Data, including: encryption of data in transit; database-level access controls and row-level security scoped to each Business Account; hashed storage of authentication credentials; role-based permissions within the Service; and restricted internal access to production data on a need-to-know basis. [A fuller security overview / SOC 2 or similar certification status, if applicable, should be added here once available — TO BE CONFIRMED.]

9. International Transfers

Where we or our sub-processors transfer Customer Personal Data originating in the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, such transfers are made subject to appropriate safeguards, such as the European Commission's Standard Contractual Clauses (including, where applicable, the UK International Data Transfer Addendum), incorporated by reference into this DPA.

10. Personal Data Breach Notification

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet any notification obligations you may have under applicable law.

11. Audits & Return or Deletion of Data

On reasonable written request, and no more than once per year (except following a confirmed security incident), we will provide information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of relevant audit reports or responses to a reasonable security questionnaire, in lieu of an on-site audit unless required by applicable law. Upon termination of the Service, you may export Customer Personal Data using the Service's built-in export tools during the retention window described in our Privacy Policy, after which it will be deleted or anonymized in accordance with that Policy.

12. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Customer Personal Data, this DPA controls.

13. Contact / Executing a Countersigned DPA

Some Businesses may require a bilaterally signed copy of this DPA (for example, incorporating Standard Contractual Clauses as a formal annex) for their own compliance records. To request one, contact us at [SUPPORT EMAIL], attention [CONTACT NAME].