Data Processing Add-on
Effective: September 20, 2026 · Version 2.0
About this add-on
This Data Processing Add-on ("Add-on") is part of the Precision IT Management Customer Terms (the "Terms") between Precision IT Management, LLC ("PIM," "we") and the customer in the accepted proposal ("you").
When it applies. This Add-on applies when you ask for it in writing (including in your proposal), or automatically when a Product collects personal information from members of the public who buy from you, such as an InkPortal store or a PlateCash ordering site. It then covers all Customer Personal Data we process for you.
How it fits with the Terms. Words defined in the Terms mean the same here. If this Add-on and the Terms conflict about personal data, this Add-on wins; on everything else, including the limits of liability, which apply to this Add-on, the Terms win.
1. Key words
- "Customer Personal Data" means personal information about any individual that you or your users put into a Product, or that a Product collects for you. Examples include your crew, drivers and employees, and your own customers and buyers. It does not include information we handle for our own purposes under our Privacy Policy, such as your billing contacts or our security logs.
- "Privacy Laws" means the US federal and state privacy laws that apply to the processing, such as the California Consumer Privacy Act.
- "Security Incident" means a confirmed breach of our security that leads to accidental or unlawful loss, alteration, disclosure of, or access to Customer Personal Data. Failed attempts, such as blocked logins or port scans, are not.
- "Subprocessor" means a third party we use to process Customer Personal Data for you.
Terms such as "business," "controller," "service provider," "processor," "sell," "share" and "de-identified" have the meanings the Privacy Laws give them.
2. Roles
You are the business (controller) for Customer Personal Data. We are your service provider (processor) and process it only on your behalf.
Your responsibilities. You are responsible for the accuracy and legality of Customer Personal Data and how you collected it; for giving any required privacy notice and getting any required consent, including consent to the texts and emails we send for you; and for answering people who ask about their data, with our help under Section 9. Your instructions to us must comply with the law.
3. Your instructions
We process Customer Personal Data only:
- to provide, support and secure the Products under the Terms;
- as you instruct us through the Terms, this Add-on, your proposal, and the settings you choose in the Products; and
- as the law requires. If the law requires other processing, we will tell you first unless the law forbids it.
These are your complete instructions. New instructions need our written agreement and may carry a quoted fee. We will tell you if we believe an instruction breaks the law.
4. What we will not do with your data (US state law terms)
As your service provider, we will not:
- sell or share Customer Personal Data (including for cross-context behavioral advertising);
- keep, use or disclose it for any purpose other than providing the Products to you, or for any commercial purpose other than that;
- keep, use or disclose it outside our direct business relationship with you; or
- combine it with personal information we receive from anyone else, including our other customers, or collect from our own dealings with the individual, except as the Privacy Laws allow.
Your disclosure of Customer Personal Data to us is for these limited business purposes and is not a sale or a share.
Permitted internal uses. As the Privacy Laws allow, we may use Customer Personal Data to fix security problems, fraud and errors, and to maintain and improve the Products we provide you. We will never use one customer's identifiable data to build or improve features for another customer. Any product improvement that benefits anyone other than you uses only aggregated or de-identified data.
De-identified data. If we create de-identified or aggregated data, we will take reasonable steps so it cannot be linked to an individual or to you. We will publicly commit not to re-identify it, and we will require anyone we give it to do the same.
Certification. We understand these restrictions and will comply with them. We will tell you if we can no longer meet our obligations under the Privacy Laws; you may then take reasonable steps to stop and fix any unauthorized use, after written notice and a reasonable chance for us to fix it.
5. Our people
Everyone we allow to access Customer Personal Data must keep it confidential, and only people who need access to run the Products get it.
6. Security
We use reasonable technical and organizational measures suited to our size and to the data involved. They include:
- encryption of data in transit, and at rest through our cloud providers;
- logical separation of each customer's data in our shared (multi-tenant) platform;
- role-based access controls, with PIM staff access to live systems limited and logged;
- hosting on established cloud providers (Google Cloud/Firebase and Cloudflare) with managed backups; and
- a process for detecting and responding to Security Incidents.
We may update these measures without materially reducing protection. No system is perfectly secure; these measures are not a guarantee.
You are responsible for securing your own logins and devices, choosing appropriate user roles, and removing users who leave. We are not responsible for incidents caused by your users, devices or credentials.
7. Subprocessors
You authorize us to use Subprocessors. Our current Subprocessors are:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, file storage, user login | United States |
| Cloudflare | Website hosting, content delivery, security | United States |
| Stripe | Payment processing | United States |
| Twilio | Text messages | United States |
| Resend | Email delivery | United States |
| Anthropic | AI features | United States |
Stripe's role. When you take payments through a Product, you are the merchant and Stripe processes cardholder and bank data under its own agreement with you. We do not store full card or bank account numbers.
Our commitments. Each Subprocessor is bound by a written contract with data protection terms at least as protective as this Add-on, including the service-provider restrictions in Section 4, where the Privacy Laws require them. We remain responsible for our Subprocessors' work, subject to the limits of liability in the Terms.
Changes. We will email you at least 30 days before a new Subprocessor starts processing Customer Personal Data. If you have a reasonable data protection objection, tell us in writing within those 30 days and we will try in good faith to resolve it. If we cannot, you may cancel the affected Product before the change, with a refund of any prepaid fees for the period after cancellation. In an emergency (security, legal or continuity), we may give shorter notice.
8. Security incidents
If we confirm a Security Incident affecting your Customer Personal Data, we will notify you without undue delay, with a target of 72 hours after confirmation. We will investigate promptly and not delay confirmation to put off notice. Our notice will say what we know then: what happened, the kinds of data and approximate number of people affected, and what we are doing about it, with updates as we learn more.
We will reasonably cooperate with you. You decide whether to notify affected people or regulators, and you make those notices. Our notice is not an admission of fault.
9. Help with privacy requests
The Products include tools to find, export, correct and delete records. We will give you reasonable help, using those tools and other reasonable measures, to respond to requests from individuals exercising their rights under the Privacy Laws. That includes requests to access, correct, delete or get a copy of their data.
If an individual contacts us directly, we will send the request to you or tell them to contact you, and will not respond on the merits unless you instruct us to. Help beyond the Products' normal tools may carry a reasonable fee agreed in advance.
10. Deletion and return
During the subscription. You can export your data at any time.
After cancellation. We keep Customer Personal Data available for export for 60 days after your subscription ends. We then delete it. Copies in our backups are deleted within 90 more days as backups roll off, and remain protected by this Add-on until then. You can ask us to delete sooner in writing.
Exceptions. We may keep information the law requires us to keep or that we reasonably need for a legal claim, protected and used only for that reason. De-identified and aggregated data is not covered.
On written request, we will confirm in writing that deletion is complete.
11. Audits
Once a year on request, or after a Security Incident affecting your data, we will give you a written summary of our security practices (or answer a reasonable security questionnaire). This is our confidential information. If the Privacy Laws give you a right to more, we will cooperate with a reasonable review at your cost, on 30 days' notice, limited to your data, and without penetration testing or access to other customers' data.
12. Requests from government or others
If we receive a subpoena or similar legal demand for Customer Personal Data, we will tell you promptly unless the law forbids it, and disclose only what the law requires.
13. Location, term and general
Location. We and our Subprocessors process Customer Personal Data in the United States. Do not put data about people in the European Union, the United Kingdom or Switzerland into a Product without our written agreement.
Term. This Add-on lasts as long as we process Customer Personal Data for you, including the export and deletion periods in Section 10.
Everything else. Governing law, venue, notices and changes follow the Terms. Nothing in this Add-on limits any individual's rights under a privacy law that cannot be waived.
Details of processing
| Item | Details |
|---|---|
| Purpose | Providing, supporting and securing the Products you subscribe to |
| Nature | Hosting, storing, organizing, displaying, sending (email and text), backing up and deleting data |
| Duration | Your subscription, plus the export and deletion periods in Section 10 |
| People whose data is involved | Your crew, drivers, employees and contractors; your own customers, clients and buyers; your authorized users |
| Types of data | Names and contact details; job, schedule, time-card, payroll and billing records; order, appointment and delivery details; photos and documents you upload; device location when you turn on location features; limited payment details (card brand, last four digits, status); message logs |
| Sensitive data | Only what a Product supports and you choose to enter (such as payroll tax IDs or precise location); you handle any extra notice or consent. No health or biometric data. |