Back to home

Data Processing Addendum

Effective August 12, 2026 · Last updated August 12, 2026 · v1.0

1. Introduction and Scope

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the FieldVault Terms of Service (the "Terms") between the Customer and Next313, a registered d/b/a of Dignetix Ltd, a Michigan corporation ("FieldVault," "we," "us"). It applies where, in providing the Service, we process Personal Data on the Customer's behalf.

If there is a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA controls. Capitalized terms not defined here have the meanings given in the Terms.

2. Definitions

3. Roles of the Parties

For Customer Personal Data, the Customer is the Controller and we act as Processor and, where the CCPA applies, as a Service Provider. The subject matter and details of processing are described in Annex 1.

4. Processing Instructions

We process Customer Personal Data only on the Customer's documented instructions — including as set out in the Terms, this DPA, and through the Customer's configuration and use of the Service — unless required by law, in which case we will inform the Customer unless legally prohibited.

5. Confidentiality

We ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.

6. Security

We implement and maintain appropriate technical and organizational measures (TOMs) designed to protect Customer Personal Data, as described in Annex 2, including encryption in transit and at rest, tenant isolation, and access controls.

7. Sub‑processors

The Customer provides general written authorization for us to engage Sub‑processors to process Customer Personal Data. Our current Sub‑processors are listed in Annex 3. We impose data‑protection obligations on each Sub‑processor no less protective than those in this DPA, and remain responsible for their performance. We will give the Customer notice of any intended addition or replacement of a Sub‑processor, and the Customer may object on reasonable data‑protection grounds within ten (10) days of notice. Notice may be given by email to the Customer's workspace administrators, by notice in the Service, or by publication on our website.

8. Data Subject Requests

We will assist the Customer by appropriate measures, insofar as reasonably possible, to respond to requests from Data Subjects exercising their rights. If we receive such a request directly, we will forward it to the Customer and will not respond except on the Customer's instructions or as legally required.

9. Personal Data Breach

We will notify the Customer without undue delay — and, where feasible, within seventy‑two (72) hours — after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations.

10. Data Protection Impact Assessments

We will provide reasonable assistance to the Customer with data protection impact assessments (DPIAs) and any required prior consultations with a supervisory authority.

11. International Transfers

Where the provision of the Service involves transfer of Customer Personal Data from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the applicable SCCs (together with the UK Addendum and Swiss amendments, as relevant) apply and are incorporated by reference.

12. CCPA Terms

To the extent the CCPA applies, we act as a Service Provider. We will not sell or share Customer Personal Data; will not retain, use, or disclose it except as necessary to perform the Service or as otherwise permitted by the CCPA; and will not combine it with other personal information except as the CCPA permits.

13. Audit and Compliance

We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and, where available, relevant third‑party audit reports of our infrastructure providers. On‑site audits may be conducted only where legally required or where such documentation is insufficient, subject to reasonable advance notice, confidentiality obligations, and limits on frequency (no more than once annually). Assistance under Sections 8, 10, and 13 that exceeds our standard service obligations may be subject to reasonable fees.

14. Return and Deletion of Customer Personal Data

Upon termination of the Service and at the Customer's choice, we will delete or return Customer Personal Data and delete existing copies, except where retention is required by law. Consistent with our Privacy Policy, the Customer may export its Customer Content during a 30‑day window after termination; the Customer is solely responsible for completing its export within that window. We delete workspace content within 90 days of account closure, and backups containing deleted data are purged within 30 days.

15. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Terms.

16. Term, Precedence, and Governing Law

This DPA takes effect when the Customer accepts the Terms and remains in effect while we process Customer Personal Data. This DPA is governed by the laws of the State of Michigan, USA, except that the SCCs are governed by the law they specify. As between this DPA and the Terms, this DPA prevails on matters of Personal Data processing.

17. Changes to This DPA

We may update this DPA from time to time, including to reflect changes in law, our Sub‑processors, or the Service. We will provide notice of material changes to the Customer's workspace administrators by email or in the Service at least thirty (30) days before they take effect (Sub‑processor changes follow the notice‑and‑objection process in Section 7). Continued use of the Service after a change takes effect constitutes acceptance of the updated DPA. If the Customer reasonably objects to a material change on data‑protection grounds and we cannot resolve the objection, the Customer may terminate the affected subscription and export its Customer Content as described in Section 14.

18. Contact

Privacy and data‑protection inquiries: hello@fieldvault.app. The Customer should provide a data‑protection contact in Annex 1.

Annex 1 — Details of Processing

Subject matter: provision of the FieldVault equipment and asset‑tracking Service.

Duration: the subscription term, plus the export, deletion, and backup‑purge periods described in Section 14.

Nature and purpose: hosting, storage, processing, transmission, display, backup, and support of Customer Content in order to provide the Service, including AI‑assisted equipment‑photo recognition where the Customer's plan includes it.

Categories of Data Subjects: the Customer's personnel and Users; and any individuals referenced within Customer Content (for example, incidentally captured in equipment photos).

Categories of Personal Data: account data such as names, email addresses, Microsoft Entra ID identifiers, workspace and role assignments, and notification preferences; and, within workspace content, gear/kit/job/site records, event history, warranty and stocktake records, uploaded photos and documents, and addresses entered for Sites/Jobs.

Special category data: none intended. The Customer should not submit special‑category Personal Data except where expressly agreed in writing.

Customer data‑protection contact: hello@fieldvault.app

Annex 2 — Technical and Organizational Measures

Annex 3 — Sub‑processors

As of the effective date, we engage the following Sub‑processors to process Customer Personal Data: