Data Processing Addendum
Data-protection terms between Piripro, Inc. (processor) and each customer (controller), incorporated by reference into the Terms and each signed order form.
1. Roles and scope
This DPA applies where Piripro, Inc. ("Piri", "Processor") processes personal data on behalf of a customer ("Customer", "Controller") in providing the Service under the Terms. Customer is the controller of the personal data it submits ("Customer Personal Data") — including data about Customer's own end customers, properties, and jobs — and Piri is the processor. This DPA prevails over the Terms for data-protection matters.
2. Definitions
"Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given under applicable data protection law (including, as applicable, the GDPR/UK GDPR and U.S. state privacy laws). "Subprocessor" means a third party engaged by Piri to process Customer Personal Data.
3. Processing details
Piri processes Customer Personal Data only to provide and support the Service and only on Customer's documented instructions (the Terms, this DPA, and Customer's use of the Service being such instructions), unless required by law. The subject matter, duration, nature and purpose of processing, categories of data subjects, and types of personal data are described in Annex I.
4. Piri's obligations
- Process Customer Personal Data only on Customer's instructions, and inform Customer if an instruction appears to violate applicable law.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement the technical and organizational security measures in Annex II.
- Not sell Customer Personal Data and not process it for any purpose other than providing the Service.
- Assist Customer, taking into account the nature of processing, in meeting its obligations for security, breach notification, data protection impact assessments, and responding to data subject requests.
5. Subprocessors
Customer authorizes Piri to engage the subprocessors listed in Annex III. Piri imposes data-protection terms on each subprocessor no less protective than this DPA and remains responsible for their performance. Piri will give Customer at least 30 days' notice of any intended addition or replacement of a subprocessor, by updating Annex III and notifying account admins. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected subscription without penalty and receive a pro-rata refund of any prepaid fees for the unused remainder of the term.
6. Data subject requests
Piri will, to the extent legally permitted, promptly notify Customer if it receives a request from a data subject regarding Customer Personal Data, and will not respond directly except on Customer's instructions. Taking into account the nature of processing, Piri will provide reasonable assistance (including through the Service's own tools) to help Customer respond to data subject requests.
7. Personal data breach
Piri will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.
8. Audit
Piri will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates. To minimize disruption, Piri may satisfy audit rights by providing third-party audit reports or security documentation where available. Audits are limited to once in any 12-month period, on at least 30 days' written notice, during business hours, and at Customer's cost — except where a supervisory authority requires otherwise or an audit follows a confirmed personal data breach.
9. International transfers
Piri processes Customer Personal Data in the United States. Where Customer Personal Data originates from a jurisdiction that restricts transfers (e.g. the EEA/UK), the parties will implement an appropriate transfer mechanism (e.g. the EU Standard Contractual Clauses / UK Addendum), which will be incorporated by reference.
10. Deletion or return
On termination or expiration of the Service, Piri will, at Customer's choice, return or delete Customer Personal Data within a reasonable period (subject to the export window in the Terms), except where retention is required by law. Backups are deleted in the ordinary course.
Annex I — Details of processing
- Subject matter: provision of the Piri field service management platform.
- Duration: the term of the subscription plus any post-termination export/deletion window.
- Nature and purpose: hosting, storage, and processing of Customer Personal Data to operate the Service (customer/job management, scheduling and dispatch, routing, invoicing).
- Categories of data subjects: Customer's Authorized Users (its staff), and Customer's own end customers and their contacts.
- Types of personal data: names, contact details (email, phone), service and property addresses, unit/maintenance details, job and scheduling history, and billing-related information. The Service is not intended for, and Customer must not submit, special categories of personal data (as defined under applicable data protection law).
Annex II — Security measures
Current measures include: encryption of data in transit (TLS); authentication and access control via Auth0, with role-based permissions in-product; hosting on AWS with provider-managed physical and network security; network protection via Cloudflare; least-privilege access to production systems; and payment data handled by Stripe (PCI-DSS) rather than stored by Piri.
Annex III — Approved subprocessors
| Subprocessor | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and storage | United States |
| Auth0 (Okta) | Authentication and identity | United States |
| Stripe | Payments, quotes, invoices | United States |
| Cloudflare | DNS / CDN / network security | Global edge |
| QuickBooks (Intuit) | Accounting sync — only where Customer enables it | United States |
Piri keeps this list current; see Section 5 for the change-notification process.