Legal

Data Processing Agreement

Last updated August 21, 2026

Parties & Scope

This Data Processing Agreement ("DPA") is entered into between Vendor Callout LLC, a Texas limited liability company ("Processor", "we"), and the customer identified in the Order ("Controller", "you").

It forms part of, and is governed by, the Terms of Use. It applies whenever we process Personal Data on your behalf in providing the Service. Where this DPA and the Terms conflict on data protection specifically, this DPA governs; on everything else, the Terms govern.

This document is published rather than kept behind a request form so your security reviewer can read it now. If your organisation requires a countersigned copy, see Signing This.

Definitions

  • Personal Data — information relating to an identified or identifiable individual that we process on your behalf through the Service.
  • Processing — any operation performed on Personal Data: collection, storage, transmission, display, deletion.
  • Data Subject — the individual the Personal Data relates to: your employees, and the vendor contacts you nominate.
  • Sub-processor — a third party we engage that processes Personal Data in delivering the Service.
  • Security Incident — a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data.
  • Terms defined in the Terms of Use carry the same meaning here.

Roles

You are the Controller. You decide what goes into the Service, who may see it, how long it stays, and which vendors are notified. You are responsible for having a lawful basis for that processing, for the accuracy of what is entered, and for giving whatever notices your own people and your vendors' contacts are owed.

We are the Processor for that data, and act only on your instructions.

We act as a Controller in our own right for a narrow set of data: account administration, billing records, security and audit logs, and website traffic. That processing is described in our Privacy Policy and is not governed by this DPA.

What We Process

Set out in the form a data protection authority or a security reviewer expects:

Subject matter Provision of the Vendor Callout compressor downtime and vendor callout service.
Duration The term of your subscription, plus the deletion periods in Return & Deletion.
Nature and purpose Recording compressor downtime and vendor callouts; calculating availability, downtime cost, lost production and contract credits; notifying your staff and your vendors; producing reports; storing photographs taken in the field.
Categories of Data Subject Your employees and contractors who use the Service; the individual contacts at the compression vendors you nominate; individuals who contact us through the website.
Categories of Personal Data Name, business email address, business telephone number, job role and access level, optional profile picture; sign-in and activity records; the identity of the person who logged or edited each callout; vendor contact names, telephone numbers and dispatch email addresses; free-text notes that may incidentally name individuals; photographs of equipment that may incidentally include individuals.
Special category data None. The Service is not designed for, and must not be used to record, health, biometric, racial or ethnic, political, religious, trade union, genetic, or sexual orientation data. Do not enter it.
Children's data None. The Service is industrial software sold to companies.

Location data in the Service describes compressor units and leases. It is not used to track the position of any person or device.

Instructions

  • We process Personal Data only on your documented instructions. The Terms, this DPA, your configuration of the Service, and your use of its features together constitute those instructions.
  • We will tell you if, in our opinion, an instruction infringes applicable data protection law, and may decline to act on it until resolved.
  • Where the law requires us to process Personal Data otherwise than on your instruction, we will tell you before doing so unless the law forbids us from telling you.
  • We do not sell Personal Data, share it for advertising, or use it to train machine-learning models — ours or anyone else's. We do not use one customer's data to serve another.

Our People

Access to Personal Data is limited to those who need it to operate and support the Service. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement. Administrative access to your account is recorded in the audit log.

Security Measures

Every measure listed here is in place today. We do not list aspirations.

MeasureImplementation
Encryption in transit HTTPS throughout. The connection between our edge network and our origin server is authenticated as well as encrypted (TLS with origin certificate validation).
Encryption of backups AES-256, applied before any archive leaves our server. The key is held only on the server and in offline safekeeping; the storage provider cannot read the archives.
Access control Role-based, enforced server-side rather than hidden in the interface. Field users cannot reach rental rates, downtime cost, lost production value, credits, or billing.
Tenant isolation Every database query is scoped to a single customer. One customer cannot reach another's records.
Authentication Emailed single-use sign-in links, valid fifteen minutes, are the default. Where passwords are used they are stored only as salted bcrypt hashes. Sessions warn at ten minutes idle and end at twelve.
Third-party access Vendor access is tokenised, limited to a single callout, and time-limited. Vendors have no account and never see financial information.
Integrity of the record Vendor work notes are append-only. Consequential actions are written to an audit log that outlives the records it describes.
Availability & resilience The whole system is archived hourly. Each archive is cryptographically signed and verified by restoring it into a scratch database and comparing record counts — an unverified backup is not treated as a backup. Copies are held off-site, encrypted. Automated health checks run every five minutes with independent external alerting.
Restoration testing Restores are exercised, not assumed. Full-system restore has been performed and verified byte-for-byte against the source.
Payment data None held. We do not collect, process or store payment card details. Invoices settle by ACH or wire, and we record only the reference number you provide.
Tracking No analytics, advertising, session recording or third-party tracking anywhere in the product or in our emails. One essential session cookie.

We may change these measures over time, but will not materially reduce the overall level of security during your subscription.

Sub-processors

You give general written authorisation for the sub-processors below. Each is bound by written terms imposing data protection obligations no less protective than this DPA, and we remain responsible to you for their performance.

Sub-processorPurposePersonal Data involvedLocation
DigitalOceanServer hosting All Customer Data at rest and in processingUnited States
Google Drive
Workspace
Off-site storage of encrypted backups Encrypted archives only — unreadable without a key we do not share Per Google Workspace configuration
Google CalendarCalendar entries for presentations — only if enabled Booking name, email and appointment timeUnited States
BrevoOutbound email delivery Recipient address, subject and body of notifications we sendEU / United States
CloudflareDNS, TLS termination, network protection Request metadata in transit, including IP addressGlobal edge network
healthchecks.ioExternal availability monitoring None — a periodic signal and technical failure reasons onlyUnited States

Content delivery networks (jsDelivr, unpkg), Google Fonts, and map tile providers (OpenStreetMap, Esri) receive a visitor's IP address and browser when a page loads, as any web resource does. They receive no Customer Data and are not sub-processors of it.

Changes. We will give you at least thirty days' notice before adding or replacing a sub-processor that processes Customer Data. If you object on reasonable data protection grounds within that period, we will work with you in good faith to find an alternative. If none is reasonably available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees; that is your sole remedy for the objection.

International Transfers

The Service is designed and sold for operators in the United States, and processing occurs primarily in the United States. Encrypted backup archives are stored in Google Workspace and may reside outside the United States depending on that account's configuration; those archives are encrypted before they leave our server and the storage provider cannot read them. Email delivery may route through infrastructure in the European Union.

Where a transfer of Personal Data is subject to a law requiring a specific transfer mechanism, the parties will put an appropriate mechanism in place, and this DPA will be read to incorporate it.

Assistance

  • Data subject requests. The Service is built so you can answer most requests yourself: your administrators can view, correct and delete records directly. For a complete export of the account — including callouts, credits, rate history and the audit log — ask us and we will produce it promptly. The first such export is free; subsequent exports carry the fee set out in the Terms of Use. Where you need further help, we will provide reasonable assistance, taking into account the nature of the processing and the information available to us.
  • If a Data Subject contacts us directly about data we process on your behalf, we will not respond substantively; we will refer them to you and tell you promptly.
  • Impact assessments. On request, we will provide reasonable assistance with data protection impact assessments and prior consultations, limited to information about our own processing that is not otherwise available to you.
  • Assistance beyond what is reasonably necessary, or requested repeatedly, may be charged at our then-current professional services rate, notified in advance.

Breach Notification

  • We will notify you of a Security Incident affecting your Personal Data without undue delay, and in any event within seventy-two (72) hours of becoming aware of it.
  • The notification will describe, to the extent known: the nature of the incident, the categories and approximate volume of data and Data Subjects affected, the likely consequences, and the measures taken or proposed. Where the full picture is not available at once, we will provide information in phases without further undue delay.
  • We will take reasonable steps to contain and remediate, and cooperate with you as you meet your own notification obligations. You are responsible for notifying regulators and Data Subjects where the law requires it; we will give you what you need to do so.
  • Notice is given to your account administrators. Keep those addresses current — it is the channel we will use.
  • Our notifying you is not an admission of fault or liability.

Audits

We will make available the information reasonably necessary to demonstrate compliance with this DPA. In practice that means, in this order:

  1. This document and our Privacy Policy, which describe our measures specifically rather than generically.
  2. A completed security questionnaire. We will answer yours, or provide our standard responses, once in any twelve-month period at no charge.
  3. An audit, where the above is genuinely insufficient and applicable law requires it. Audits are limited to once in any twelve-month period (unless a regulator directs otherwise or following a Security Incident affecting your data), require at least thirty days' written notice, must occur during business hours without unreasonably disrupting the Service, are subject to confidentiality obligations, and are at your cost. An auditor must not be a competitor of ours.

Audits do not extend to our other customers' data, our sub-processors' premises, or information whose disclosure would compromise the security of the Service or another customer.

Return & Deletion

  • You may request a full export of your account at any time during the subscription, and we will produce it promptly — the first free, subsequent exports at the fee set out in the Terms of Use. The export taken on termination is always free.
  • For thirty days after termination we retain your data and will provide an export on request.
  • After that period we delete Personal Data from live systems within ninety days, except where retention is required by law or for our own accounting records — invoices being the usual case.
  • Encrypted backups follow a separate clock, and we will not pretend otherwise. Archives are retained on a rolling schedule — hourly for a day, daily for a month, monthly for a year — so deleted Personal Data can persist in an encrypted archive for up to twelve months before the final copy expires. Those archives are not used to resurrect deleted records, remain subject to this DPA until they expire, and we will confirm the expiry date in writing on request.
  • On request we will certify deletion in writing.

Liability

Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Terms of Use, and any liability under this DPA counts toward — and does not increase — those limits. This DPA does not create a separate or additional cap.

Nothing in this DPA limits liability that cannot be limited under applicable law, including any direct statutory liability a processor owes to a Data Subject.

Where both parties are responsible for the same damage, each bears its share according to its responsibility for the circumstances giving rise to it.

Term

This DPA takes effect when you accept the Terms of Use and continues while we process Personal Data on your behalf. Provisions that by their nature should survive — confidentiality, deletion, liability, governing law — survive termination.

General

  • Governing law. This DPA is governed by the laws of the State of Texas, with venue as set out in the Terms of Use.
  • Precedence. A separately negotiated and signed data processing agreement prevails over this one. Otherwise this DPA governs data protection, and the Terms of Use govern everything else.
  • Changes. We may update this DPA to reflect changes in the Service or the law. For a change that materially reduces your protections, we will notify account administrators at least thirty days beforehand.
  • Severability. If a provision is unenforceable, the rest stands and that provision is narrowed to what is enforceable.

Signing This

This DPA applies automatically — no signature is needed for it to bind us.

If your procurement process requires a countersigned copy, or your own DPA template, contact us through the contact form with the document and we will review it. We would rather negotiate before you sign than discover a mismatch afterwards.

Vendor Callout LLC · a Texas limited liability company · vendorcallout.com