Last updated August 21, 2026
This Data Processing Agreement ("DPA") is entered into between Vendor Callout LLC, a Texas limited liability company ("Processor", "we"), and the customer identified in the Order ("Controller", "you").
It forms part of, and is governed by, the Terms of Use. It applies whenever we process Personal Data on your behalf in providing the Service. Where this DPA and the Terms conflict on data protection specifically, this DPA governs; on everything else, the Terms govern.
You are the Controller. You decide what goes into the Service, who may see it, how long it stays, and which vendors are notified. You are responsible for having a lawful basis for that processing, for the accuracy of what is entered, and for giving whatever notices your own people and your vendors' contacts are owed.
We are the Processor for that data, and act only on your instructions.
We act as a Controller in our own right for a narrow set of data: account administration, billing records, security and audit logs, and website traffic. That processing is described in our Privacy Policy and is not governed by this DPA.
Set out in the form a data protection authority or a security reviewer expects:
| Subject matter | Provision of the Vendor Callout compressor downtime and vendor callout service. |
|---|---|
| Duration | The term of your subscription, plus the deletion periods in Return & Deletion. |
| Nature and purpose | Recording compressor downtime and vendor callouts; calculating availability, downtime cost, lost production and contract credits; notifying your staff and your vendors; producing reports; storing photographs taken in the field. |
| Categories of Data Subject | Your employees and contractors who use the Service; the individual contacts at the compression vendors you nominate; individuals who contact us through the website. |
| Categories of Personal Data | Name, business email address, business telephone number, job role and access level, optional profile picture; sign-in and activity records; the identity of the person who logged or edited each callout; vendor contact names, telephone numbers and dispatch email addresses; free-text notes that may incidentally name individuals; photographs of equipment that may incidentally include individuals. |
| Special category data | None. The Service is not designed for, and must not be used to record, health, biometric, racial or ethnic, political, religious, trade union, genetic, or sexual orientation data. Do not enter it. |
| Children's data | None. The Service is industrial software sold to companies. |
Location data in the Service describes compressor units and leases. It is not used to track the position of any person or device.
Access to Personal Data is limited to those who need it to operate and support the Service. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement. Administrative access to your account is recorded in the audit log.
Every measure listed here is in place today. We do not list aspirations.
| Measure | Implementation |
|---|---|
| Encryption in transit | HTTPS throughout. The connection between our edge network and our origin server is authenticated as well as encrypted (TLS with origin certificate validation). |
| Encryption of backups | AES-256, applied before any archive leaves our server. The key is held only on the server and in offline safekeeping; the storage provider cannot read the archives. |
| Access control | Role-based, enforced server-side rather than hidden in the interface. Field users cannot reach rental rates, downtime cost, lost production value, credits, or billing. |
| Tenant isolation | Every database query is scoped to a single customer. One customer cannot reach another's records. |
| Authentication | Emailed single-use sign-in links, valid fifteen minutes, are the default. Where passwords are used they are stored only as salted bcrypt hashes. Sessions warn at ten minutes idle and end at twelve. |
| Third-party access | Vendor access is tokenised, limited to a single callout, and time-limited. Vendors have no account and never see financial information. |
| Integrity of the record | Vendor work notes are append-only. Consequential actions are written to an audit log that outlives the records it describes. |
| Availability & resilience | The whole system is archived hourly. Each archive is cryptographically signed and verified by restoring it into a scratch database and comparing record counts — an unverified backup is not treated as a backup. Copies are held off-site, encrypted. Automated health checks run every five minutes with independent external alerting. |
| Restoration testing | Restores are exercised, not assumed. Full-system restore has been performed and verified byte-for-byte against the source. |
| Payment data | None held. We do not collect, process or store payment card details. Invoices settle by ACH or wire, and we record only the reference number you provide. |
| Tracking | No analytics, advertising, session recording or third-party tracking anywhere in the product or in our emails. One essential session cookie. |
We may change these measures over time, but will not materially reduce the overall level of security during your subscription.
You give general written authorisation for the sub-processors below. Each is bound by written terms imposing data protection obligations no less protective than this DPA, and we remain responsible to you for their performance.
| Sub-processor | Purpose | Personal Data involved | Location |
|---|---|---|---|
| DigitalOcean | Server hosting | All Customer Data at rest and in processing | United States |
| Google Drive Workspace |
Off-site storage of encrypted backups | Encrypted archives only — unreadable without a key we do not share | Per Google Workspace configuration |
| Google Calendar | Calendar entries for presentations — only if enabled | Booking name, email and appointment time | United States |
| Brevo | Outbound email delivery | Recipient address, subject and body of notifications we send | EU / United States |
| Cloudflare | DNS, TLS termination, network protection | Request metadata in transit, including IP address | Global edge network |
| healthchecks.io | External availability monitoring | None — a periodic signal and technical failure reasons only | United States |
Content delivery networks (jsDelivr, unpkg), Google Fonts, and map tile providers (OpenStreetMap, Esri) receive a visitor's IP address and browser when a page loads, as any web resource does. They receive no Customer Data and are not sub-processors of it.
Changes. We will give you at least thirty days' notice before adding or replacing a sub-processor that processes Customer Data. If you object on reasonable data protection grounds within that period, we will work with you in good faith to find an alternative. If none is reasonably available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees; that is your sole remedy for the objection.
The Service is designed and sold for operators in the United States, and processing occurs primarily in the United States. Encrypted backup archives are stored in Google Workspace and may reside outside the United States depending on that account's configuration; those archives are encrypted before they leave our server and the storage provider cannot read them. Email delivery may route through infrastructure in the European Union.
Where a transfer of Personal Data is subject to a law requiring a specific transfer mechanism, the parties will put an appropriate mechanism in place, and this DPA will be read to incorporate it.
We will make available the information reasonably necessary to demonstrate compliance with this DPA. In practice that means, in this order:
Audits do not extend to our other customers' data, our sub-processors' premises, or information whose disclosure would compromise the security of the Service or another customer.
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Terms of Use, and any liability under this DPA counts toward — and does not increase — those limits. This DPA does not create a separate or additional cap.
Nothing in this DPA limits liability that cannot be limited under applicable law, including any direct statutory liability a processor owes to a Data Subject.
Where both parties are responsible for the same damage, each bears its share according to its responsibility for the circumstances giving rise to it.
This DPA takes effect when you accept the Terms of Use and continues while we process Personal Data on your behalf. Provisions that by their nature should survive — confidentiality, deletion, liability, governing law — survive termination.
This DPA applies automatically — no signature is needed for it to bind us.
If your procurement process requires a countersigned copy, or your own DPA template, contact us through the contact form with the document and we will review it. We would rather negotiate before you sign than discover a mismatch afterwards.
Vendor Callout LLC · a Texas limited liability company · vendorcallout.com