Data Processing Addendum
1. Introduction and Scope
This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the FieldVault Terms of Service (the "Terms") between the Customer and Next313, a registered d/b/a of Dignetix Ltd, a Michigan corporation ("FieldVault," "we," "us"). It applies where, in providing the Service, we process Personal Data on the Customer's behalf.
If there is a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA controls. Capitalized terms not defined here have the meanings given in the Terms.
2. Definitions
- "Applicable Data Protection Laws" — all privacy and data‑protection laws applicable to the processing, including the EU GDPR, the UK GDPR, and the CCPA, each as amended.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" — have the meanings in the GDPR, with the corresponding CCPA terms applying where the CCPA governs.
- "Customer Personal Data" — Personal Data within Customer Content that we process on the Customer's behalf.
- "Sub‑processor" — a third party engaged by us to process Customer Personal Data.
- "Standard Contractual Clauses (SCCs)" — the contractual clauses approved for transfers of Personal Data to countries without an adequacy decision.
3. Roles of the Parties
For Customer Personal Data, the Customer is the Controller and we act as Processor and, where the CCPA applies, as a Service Provider. The subject matter and details of processing are described in Annex 1.
4. Processing Instructions
We process Customer Personal Data only on the Customer's documented instructions — including as set out in the Terms, this DPA, and through the Customer's configuration and use of the Service — unless required by law, in which case we will inform the Customer unless legally prohibited.
5. Confidentiality
We ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.
6. Security
We implement and maintain appropriate technical and organizational measures (TOMs) designed to protect Customer Personal Data, as described in Annex 2, including encryption in transit and at rest, tenant isolation, and access controls.
7. Sub‑processors
The Customer provides general written authorization for us to engage Sub‑processors to process Customer Personal Data. Our current Sub‑processors are listed in Annex 3. We impose data‑protection obligations on each Sub‑processor no less protective than those in this DPA, and remain responsible for their performance. We will give the Customer notice of any intended addition or replacement of a Sub‑processor, and the Customer may object on reasonable data‑protection grounds within ten (10) days of notice. Notice may be given by email to the Customer's workspace administrators, by notice in the Service, or by publication on our website.
8. Data Subject Requests
We will assist the Customer by appropriate measures, insofar as reasonably possible, to respond to requests from Data Subjects exercising their rights. If we receive such a request directly, we will forward it to the Customer and will not respond except on the Customer's instructions or as legally required.
9. Personal Data Breach
We will notify the Customer without undue delay — and, where feasible, within seventy‑two (72) hours — after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations.
10. Data Protection Impact Assessments
We will provide reasonable assistance to the Customer with data protection impact assessments (DPIAs) and any required prior consultations with a supervisory authority.
11. International Transfers
Where the provision of the Service involves transfer of Customer Personal Data from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the applicable SCCs (together with the UK Addendum and Swiss amendments, as relevant) apply and are incorporated by reference.
12. CCPA Terms
To the extent the CCPA applies, we act as a Service Provider. We will not sell or share Customer Personal Data; will not retain, use, or disclose it except as necessary to perform the Service or as otherwise permitted by the CCPA; and will not combine it with other personal information except as the CCPA permits.
13. Audit and Compliance
We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and, where available, relevant third‑party audit reports of our infrastructure providers. On‑site audits may be conducted only where legally required or where such documentation is insufficient, subject to reasonable advance notice, confidentiality obligations, and limits on frequency (no more than once annually). Assistance under Sections 8, 10, and 13 that exceeds our standard service obligations may be subject to reasonable fees.
14. Return and Deletion of Customer Personal Data
Upon termination of the Service and at the Customer's choice, we will delete or return Customer Personal Data and delete existing copies, except where retention is required by law. Consistent with our Privacy Policy, the Customer may export its Customer Content during a 30‑day window after termination; the Customer is solely responsible for completing its export within that window. We delete workspace content within 90 days of account closure, and backups containing deleted data are purged within 30 days.
15. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Terms.
16. Term, Precedence, and Governing Law
This DPA takes effect when the Customer accepts the Terms and remains in effect while we process Customer Personal Data. This DPA is governed by the laws of the State of Michigan, USA, except that the SCCs are governed by the law they specify. As between this DPA and the Terms, this DPA prevails on matters of Personal Data processing.
17. Changes to This DPA
We may update this DPA from time to time, including to reflect changes in law, our Sub‑processors, or the Service. We will provide notice of material changes to the Customer's workspace administrators by email or in the Service at least thirty (30) days before they take effect (Sub‑processor changes follow the notice‑and‑objection process in Section 7). Continued use of the Service after a change takes effect constitutes acceptance of the updated DPA. If the Customer reasonably objects to a material change on data‑protection grounds and we cannot resolve the objection, the Customer may terminate the affected subscription and export its Customer Content as described in Section 14.
18. Contact
Privacy and data‑protection inquiries: hello@fieldvault.app. The Customer should provide a data‑protection contact in Annex 1.
Annex 1 — Details of Processing
Subject matter: provision of the FieldVault equipment and asset‑tracking Service.
Duration: the subscription term, plus the export, deletion, and backup‑purge periods described in Section 14.
Nature and purpose: hosting, storage, processing, transmission, display, backup, and support of Customer Content in order to provide the Service, including AI‑assisted equipment‑photo recognition where the Customer's plan includes it.
Categories of Data Subjects: the Customer's personnel and Users; and any individuals referenced within Customer Content (for example, incidentally captured in equipment photos).
Categories of Personal Data: account data such as names, email addresses, Microsoft Entra ID identifiers, workspace and role assignments, and notification preferences; and, within workspace content, gear/kit/job/site records, event history, warranty and stocktake records, uploaded photos and documents, and addresses entered for Sites/Jobs.
Special category data: none intended. The Customer should not submit special‑category Personal Data except where expressly agreed in writing.
Customer data‑protection contact: hello@fieldvault.app
Annex 2 — Technical and Organizational Measures
- Encryption of Customer Personal Data in transit (TLS) and at rest.
- Tenant isolation using PostgreSQL row‑level security with restrictive isolation policies.
- Role‑ and tenant‑based access controls and least‑privilege principles.
- Access‑controlled storage buckets for uploaded files.
- An immutable audit log of who changed what and when, across the Customer's workspace.
- Logging, monitoring, and incident‑response procedures.
- Backups with defined retention and purge schedules.
- Vendor risk management and reliance on audited infrastructure providers.
Annex 3 — Sub‑processors
As of the effective date, we engage the following Sub‑processors to process Customer Personal Data:
- Supabase — database, authentication, and file storage — United States.
- Microsoft Azure — application hosting (Static Web Apps) — United States.
- Microsoft 365 (Microsoft Graph) — delivery of transactional and notification email — United States.
- Anthropic — AI‑assisted equipment‑photo recognition, for plans that include it, and internal, staff‑facing triage of submitted feedback — United States.
- Google Maps Platform (Google LLC) — address autocomplete for Sites and Jobs; receives IP address and entered addresses when this feature is used — United States.
- Stripe — payment processing, for paid plans — United States.