Data Processing Add-on

Effective: September 20, 2026 · Version 2.0


About this add-on

This Data Processing Add-on ("Add-on") is part of the Precision IT Management Customer Terms (the "Terms") between Precision IT Management, LLC ("PIM," "we") and the customer in the accepted proposal ("you").

When it applies. This Add-on applies when you ask for it in writing (including in your proposal), or automatically when a Product collects personal information from members of the public who buy from you, such as an InkPortal store or a PlateCash ordering site. It then covers all Customer Personal Data we process for you.

How it fits with the Terms. Words defined in the Terms mean the same here. If this Add-on and the Terms conflict about personal data, this Add-on wins; on everything else, including the limits of liability, which apply to this Add-on, the Terms win.

1. Key words

Terms such as "business," "controller," "service provider," "processor," "sell," "share" and "de-identified" have the meanings the Privacy Laws give them.

2. Roles

You are the business (controller) for Customer Personal Data. We are your service provider (processor) and process it only on your behalf.

Your responsibilities. You are responsible for the accuracy and legality of Customer Personal Data and how you collected it; for giving any required privacy notice and getting any required consent, including consent to the texts and emails we send for you; and for answering people who ask about their data, with our help under Section 9. Your instructions to us must comply with the law.

3. Your instructions

We process Customer Personal Data only:

These are your complete instructions. New instructions need our written agreement and may carry a quoted fee. We will tell you if we believe an instruction breaks the law.

4. What we will not do with your data (US state law terms)

As your service provider, we will not:

Your disclosure of Customer Personal Data to us is for these limited business purposes and is not a sale or a share.

Permitted internal uses. As the Privacy Laws allow, we may use Customer Personal Data to fix security problems, fraud and errors, and to maintain and improve the Products we provide you. We will never use one customer's identifiable data to build or improve features for another customer. Any product improvement that benefits anyone other than you uses only aggregated or de-identified data.

De-identified data. If we create de-identified or aggregated data, we will take reasonable steps so it cannot be linked to an individual or to you. We will publicly commit not to re-identify it, and we will require anyone we give it to do the same.

Certification. We understand these restrictions and will comply with them. We will tell you if we can no longer meet our obligations under the Privacy Laws; you may then take reasonable steps to stop and fix any unauthorized use, after written notice and a reasonable chance for us to fix it.

5. Our people

Everyone we allow to access Customer Personal Data must keep it confidential, and only people who need access to run the Products get it.

6. Security

We use reasonable technical and organizational measures suited to our size and to the data involved. They include:

We may update these measures without materially reducing protection. No system is perfectly secure; these measures are not a guarantee.

You are responsible for securing your own logins and devices, choosing appropriate user roles, and removing users who leave. We are not responsible for incidents caused by your users, devices or credentials.

7. Subprocessors

You authorize us to use Subprocessors. Our current Subprocessors are:

Subprocessor Purpose Location
Google Cloud / Firebase Hosting, database, file storage, user login United States
Cloudflare Website hosting, content delivery, security United States
Stripe Payment processing United States
Twilio Text messages United States
Resend Email delivery United States
Anthropic AI features United States

Stripe's role. When you take payments through a Product, you are the merchant and Stripe processes cardholder and bank data under its own agreement with you. We do not store full card or bank account numbers.

Our commitments. Each Subprocessor is bound by a written contract with data protection terms at least as protective as this Add-on, including the service-provider restrictions in Section 4, where the Privacy Laws require them. We remain responsible for our Subprocessors' work, subject to the limits of liability in the Terms.

Changes. We will email you at least 30 days before a new Subprocessor starts processing Customer Personal Data. If you have a reasonable data protection objection, tell us in writing within those 30 days and we will try in good faith to resolve it. If we cannot, you may cancel the affected Product before the change, with a refund of any prepaid fees for the period after cancellation. In an emergency (security, legal or continuity), we may give shorter notice.

8. Security incidents

If we confirm a Security Incident affecting your Customer Personal Data, we will notify you without undue delay, with a target of 72 hours after confirmation. We will investigate promptly and not delay confirmation to put off notice. Our notice will say what we know then: what happened, the kinds of data and approximate number of people affected, and what we are doing about it, with updates as we learn more.

We will reasonably cooperate with you. You decide whether to notify affected people or regulators, and you make those notices. Our notice is not an admission of fault.

9. Help with privacy requests

The Products include tools to find, export, correct and delete records. We will give you reasonable help, using those tools and other reasonable measures, to respond to requests from individuals exercising their rights under the Privacy Laws. That includes requests to access, correct, delete or get a copy of their data.

If an individual contacts us directly, we will send the request to you or tell them to contact you, and will not respond on the merits unless you instruct us to. Help beyond the Products' normal tools may carry a reasonable fee agreed in advance.

10. Deletion and return

During the subscription. You can export your data at any time.

After cancellation. We keep Customer Personal Data available for export for 60 days after your subscription ends. We then delete it. Copies in our backups are deleted within 90 more days as backups roll off, and remain protected by this Add-on until then. You can ask us to delete sooner in writing.

Exceptions. We may keep information the law requires us to keep or that we reasonably need for a legal claim, protected and used only for that reason. De-identified and aggregated data is not covered.

On written request, we will confirm in writing that deletion is complete.

11. Audits

Once a year on request, or after a Security Incident affecting your data, we will give you a written summary of our security practices (or answer a reasonable security questionnaire). This is our confidential information. If the Privacy Laws give you a right to more, we will cooperate with a reasonable review at your cost, on 30 days' notice, limited to your data, and without penetration testing or access to other customers' data.

12. Requests from government or others

If we receive a subpoena or similar legal demand for Customer Personal Data, we will tell you promptly unless the law forbids it, and disclose only what the law requires.

13. Location, term and general

Location. We and our Subprocessors process Customer Personal Data in the United States. Do not put data about people in the European Union, the United Kingdom or Switzerland into a Product without our written agreement.

Term. This Add-on lasts as long as we process Customer Personal Data for you, including the export and deletion periods in Section 10.

Everything else. Governing law, venue, notices and changes follow the Terms. Nothing in this Add-on limits any individual's rights under a privacy law that cannot be waived.


Details of processing

Item Details
Purpose Providing, supporting and securing the Products you subscribe to
Nature Hosting, storing, organizing, displaying, sending (email and text), backing up and deleting data
Duration Your subscription, plus the export and deletion periods in Section 10
People whose data is involved Your crew, drivers, employees and contractors; your own customers, clients and buyers; your authorized users
Types of data Names and contact details; job, schedule, time-card, payroll and billing records; order, appointment and delivery details; photos and documents you upload; device location when you turn on location features; limited payment details (card brand, last four digits, status); message logs
Sensitive data Only what a Product supports and you choose to enter (such as payroll tax IDs or precise location); you handle any extra notice or consent. No health or biometric data.