Legal · DPA
Data Processing Addendum
TradesKit — Field Service Management Software
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Cascade Software Solutions LLC ("Processor," "we," "us," or "our") and the customer identified in the order ("Controller," "you," or "your") for the provision of the TradesKit field service management service (the "Service"). This DPA applies whenever we process personal information on your behalf and to the extent the processing is subject to applicable data protection law.
In the event of conflict between the Agreement and this DPA on the subject of personal-information processing, this DPA controls.
1. Definitions
Unless otherwise defined here, terms have the meaning given in the Agreement.
- "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means beneficial ownership of more than fifty percent (50%) of voting interests.
- "Applicable Data Protection Laws" means all laws and regulations governing the processing of Personal Information that apply to a party, including the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act (TDPSA), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec Law 25, and, where the Controller is established in or processes data of residents of those jurisdictions, the General Data Protection Regulation 2016/679 (EU GDPR) and the UK GDPR.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Sub-processor" have the meanings given in Applicable Data Protection Laws. "Personal Information," "Business," "Service Provider," "Sensitive Personal Information," and analogous CCPA/CPRA terms are construed consistently.
- "Personal Information" means any Personal Data we Process on your behalf in connection with the Service.
- "Security Incident" means any accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Information.
- "Sub-processor" means a third party we engage to Process Personal Information on your behalf in connection with the Service.
2. Roles and Scope
2.1 Roles
- For Personal Information about you and your Authorized Users that we collect for our own purposes (such as Account administration, billing, and Service operation), we act as a Controller and our Privacy Policy applies.
- For Personal Information that you upload to or generate within the Service in connection with your End Customers, we act as a Processor / Service Provider on your behalf. You are the Controller of that Personal Information.
This DPA governs the second role. The first role is governed by our Privacy Policy.
2.2 Scope
We Process Personal Information only:
- To provide, operate, secure, and support the Service as described in the Agreement;
- On your documented instructions, including the configuration choices you make within the Service;
- As required by applicable law (with prior notice to you unless legally prohibited); and
- To comply with this DPA.
We will not Process Personal Information for any other purpose.
2.3 No "Sale," "Sharing," or Targeted Advertising
We do not "sell" or "share" Personal Information (as those terms are defined under Applicable Data Protection Laws), and we do not use Personal Information for cross-context behavioral advertising or for targeted advertising. We are a "Service Provider" under the CCPA/CPRA.
2.4 Your Obligations
You will:
- Comply with Applicable Data Protection Laws in your collection, use, and disclosure of Personal Information you upload to the Service;
- Provide all required notices to Data Subjects and obtain all required consents;
- Configure the Service consistently with Applicable Data Protection Laws;
- Not instruct us to Process Personal Information in violation of Applicable Data Protection Laws.
3. Processing Requirements
We will:
- (a) Process Personal Information only as described in Section 2.2;
- (b) Not retain, use, or disclose Personal Information outside the direct business relationship between you and us or for any purpose other than performing the Service;
- (c) Comply with applicable restrictions under the CCPA/CPRA on combining Personal Information from multiple sources;
- (d) Ensure that personnel authorized to Process Personal Information are bound by appropriate confidentiality obligations;
- (e) Provide reasonable assistance to you in responding to Data Subject rights requests, taking into account the nature of the Processing and the information available to us;
- (f) Promptly notify you if we determine that we cannot meet our obligations under this DPA or Applicable Data Protection Laws, or if your instructions appear to us to violate Applicable Data Protection Laws (in which case we may decline to perform the instruction without being in breach).
4. Security
We implement and maintain appropriate technical and organizational measures designed to protect Personal Information against Security Incidents. These measures are described in Exhibit A and are reviewed periodically.
You acknowledge that the security measures provide protection commensurate with the nature of the Personal Information we Process and the risks to Data Subjects, subject to your obligation to configure and use the Service consistently with the measures (for example, by enabling two-factor authentication, applying role-based access controls, and not uploading Sensitive Personal Information into fields not designed for it).
5. Security Incidents
We will notify you of a Security Incident affecting your Personal Information without undue delay and in any event within seventy-two (72) hours after we become aware of it. The notification will include:
- A description of the nature of the Security Incident, including (where possible) the categories and approximate number of Data Subjects and records affected;
- The name and contact details of our designated security point of contact;
- A description of the likely consequences; and
- A description of the measures taken or proposed to address the Security Incident and mitigate possible adverse effects.
We will provide reasonable assistance to you in fulfilling your obligations to notify supervisory authorities and Data Subjects.
We will document Security Incidents and our response, and make those records available to you on reasonable request, subject to confidentiality and security-information sensitivities.
6. Sub-Processors
6.1 General Authorization
You authorize us to engage Sub-processors to Process Personal Information in connection with the Service. We require each Sub-processor to be bound by contractual obligations at least as protective as those in this DPA with respect to Personal Information they Process on your behalf.
6.2 List of Sub-Processors
A current list of Sub-processors (names and categories) is set out in Section 7 of our Privacy Policy; additional detail (purposes and processing locations) is available on request by emailing privacy@tradeskit.io. We will notify you of changes to that list as described in Section 6.3.
6.3 Notice of Changes
We will give you at least thirty (30) days' advance notice of any new Sub-processor or material change in the role of an existing Sub-processor that Processes Personal Information on your behalf.
6.4 Objection
You may object to a new Sub-processor on reasonable grounds relating to the protection of Personal Information by written notice to us within thirty (30) days of our notice. If you object, we will use commercially reasonable efforts to (a) propose an alternative arrangement that does not require the Sub-processor, or (b) replace the Sub-processor. If we cannot do either, you may terminate the affected portion of the Service and receive a pro-rated refund of any pre-paid unused fees for the affected portion.
7. Audits
7.1 Audit Information
On reasonable written request, we will provide you with information reasonably necessary to demonstrate compliance with this DPA, including (where available) our most recent SOC 2 Type II report or equivalent third-party audit report, our published Information Security Program summary, and our subprocessor list.
7.2 Customer Audits
If the information we provide under Section 7.1 is not reasonably sufficient to demonstrate compliance, you may, no more than once in any twelve (12) month period (unless additional audits are required by Applicable Data Protection Laws or follow a Security Incident), conduct an audit through a qualified independent third-party auditor under reasonable terms (including reasonable notice of at least thirty (30) days, scope limited to compliance with this DPA, confidentiality obligations consistent with this DPA, and reasonable cooperation by both parties).
You will pay the costs of the audit. We will reasonably cooperate. You will not have access to data of other customers, information protected by confidentiality obligations to third parties, information that would compromise security, or our trade secrets and proprietary information.
8. Data Subject Rights
We will provide reasonable assistance to you in responding to Data Subject rights requests under Applicable Data Protection Laws, including requests for access, correction, deletion, portability, and opt-out. Where a Data Subject contacts us directly about Personal Information we Process on your behalf, we will refer the Data Subject to you (the Controller) and reasonably notify you of the request.
The Service includes tools that allow you to perform certain Data Subject rights operations directly. To the extent you can fulfill a request through Service tools, that is the expected mechanism; otherwise, contact us and we will provide reasonable assistance.
9. Return or Destruction of Personal Information
On termination or expiration of the Agreement, we will, at your written election (a) return Personal Information to you in a portable format (such as CSV or other agreed format) within a reasonable time, or (b) securely destroy Personal Information, in each case subject to:
- The sixty (60) day post-termination retention window described in the Terms of Service;
- Backups retained per our normal retention schedule, which will be Processed only for backup/disaster-recovery purposes and securely destroyed when overwritten in the ordinary course; and
- Personal Information we are required to retain by Applicable Data Protection Laws or by a legal hold.
If you do not make an election within the sixty (60) day window, we may securely destroy Personal Information in the ordinary course of business.
10. De-Identified and Aggregated Data
We may generate de-identified and aggregated data derived from Personal Information and from your use of the Service, and we may use that de-identified and aggregated data to operate, secure, improve, and develop the Service, provided that we (a) take reasonable steps to ensure the data cannot be reasonably linked to a Data Subject, (b) publicly commit to maintain and use the data in de-identified form, and (c) contractually prohibit recipients from re-identifying it.
11. International Transfers
To the extent we Process Personal Information of Data Subjects located in the European Economic Area, the United Kingdom, or Switzerland and that Processing involves a transfer to a country that has not received an adequacy decision, the parties incorporate by reference the European Commission Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (the "SCCs") and the UK Addendum issued by the UK Information Commissioner's Office, with:
- Module 2 (Controller-to-Processor) applying to processing where you are a Controller and we are a Processor;
- Module 3 (Processor-to-Processor) applying to processing where you are a Processor and we are a Sub-processor of your Controller;
- Clause 7 (docking clause) included;
- Clause 9(a) Option 2 (general written authorization) with the 30-day notice period in Section 6.3 above;
- Clause 11 (independent dispute resolution) not selected unless required by law;
- Clause 17 (governing law) — Ireland for EU SCCs; UK Addendum governing law as set out in the Addendum;
- Clause 18 (forum and jurisdiction) — Ireland for EU SCCs;
- Annex I.A and I.B (parties and processing description) populated by reference to the Agreement, the Privacy Policy, and this DPA;
- Annex II (technical and organizational measures) populated by Exhibit A to this DPA;
- Annex III (sub-processors) populated by reference to the sub-processor list.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. Claims under this DPA may be brought only between the contracting entities.
13. Conflicts and Survival
In the event of conflict between the Agreement and this DPA on the subject of personal-information processing, this DPA controls. Provisions of this DPA that by their nature should survive (including return/destruction, audits, security incident, and survival of confidentiality obligations) will survive termination of the Agreement.
14. Governing Law
This DPA is governed by the governing law of the Agreement, except that to the extent Applicable Data Protection Laws or the SCCs require otherwise, those laws govern the relevant Personal Information processing.
15. Contact
For DPA-related matters (including Sub-processor objections, audit requests, Security Incident notifications):
Cascade Software Solutions LLC, Attn: Privacy / DPA, 5441 S Macadam Ave, Ste N, Portland, OR 97239, USA, Email: privacy@tradeskit.io
Exhibit A — Technical and Organizational Measures
We maintain an information-security program designed to protect Personal Information. The program includes the measures below, which we may update from time to time provided that the level of protection is not materially reduced.
A.1 Governance
- Written information security policies, standards, and procedures
- Periodic review and update of policies
- Designated security responsibility
A.2 Physical Security
- Production systems hosted with reputable cloud providers (currently Supabase and Vercel; see the sub-processor list in Section 7 of our Privacy Policy) operating data centers with industry-standard physical access controls
- Restricted physical access to office locations storing Personal Information
A.3 Access Controls
- Role-based access controls
- Multi-factor authentication for administrative and production-environment access
- Periodic access reviews and de-provisioning on termination
- Principle of least privilege
A.4 Network and System Security
- Encryption of Personal Information in transit (TLS 1.2+ or equivalent)
- Encryption of sensitive Personal Information at rest
- Network segmentation between production, staging, and development environments
- Vulnerability management program (patching, scanning, remediation)
- Anti-malware controls on systems handling Personal Information
A.5 Application Security
- Secure development practices (code review, dependency scanning, security testing)
- Production change management
- Logging and monitoring for security-relevant events
A.6 Personnel
- Confidentiality obligations for personnel with access to Personal Information
- Security awareness training
- Background checks where permitted by law and proportionate to role
A.7 Vendor Management
- Diligence on Sub-processors before engagement
- Contractual obligations on Sub-processors at least as protective as this DPA
- Periodic review of Sub-processor security posture
A.8 Incident Response
- Documented incident-response plan
- Periodic tabletop exercises
- Post-incident reviews and corrective actions
A.9 Business Continuity and Disaster Recovery
- Documented business-continuity and disaster-recovery plans
- Periodic backups of Personal Information
- Testing of recovery procedures
This DPA forms part of the Agreement and is effective on the same date as the Agreement.