Data Processing Addendum
Last updated June 2026
Purpose
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and SiteControlHQ ("Processor") and applies where SiteControlHQ processes personal data on the customer's behalf. Where they conflict, this DPA controls for data-protection matters.
Roles of the parties
The Controller determines the purposes and means of processing personal data submitted to the service; SiteControlHQ acts as Processor and processes personal data only on the Controller's documented instructions, including via configuration of the service.
Scope & instructions
Processing covers the personal data of the Controller's staff, customers, and prospects contained in workspace content (contacts, jobs, quotes, schedule, photos, signatures) for the purpose of providing the service. Using the service constitutes the Controller's instructions; additional instructions must be agreed in writing.
Subprocessors
The Controller authorizes SiteControlHQ to engage subprocessors to deliver the service, including payment (Stripe), accounting sync you connect (QuickBooks Online, Xero), messaging (Resend, Twilio), cloud hosting, and AI providers. SiteControlHQ imposes data-protection obligations on each subprocessor and remains responsible for their performance. We will give notice of new subprocessors and allow reasonable objection.
Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and access data only as needed to provide the service.
Security measures
SiteControlHQ maintains technical and organizational measures appropriate to the risk, including encryption in transit, encryption of sensitive tokens at rest, role-based least-privilege access, checksummed US storage, malware scanning, and audit logging. See the Security page for details.
Data subject requests
Taking into account the nature of processing, SiteControlHQ will assist the Controller with appropriate measures to respond to data-subject requests (access, correction, deletion, portability, objection), including self-service tools in the application.
Personal data breach
SiteControlHQ will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably necessary for the Controller to meet its notification obligations.
International transfers
Where personal data is transferred out of the EEA/UK, the parties rely on an appropriate transfer mechanism such as the EU Standard Contractual Clauses and the UK Addendum, which are incorporated by reference where applicable.
Audits
SiteControlHQ will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an appointed auditor on reasonable notice and subject to confidentiality.
Return & deletion
On termination, SiteControlHQ will, at the Controller's choice, return or delete personal data within a reasonable period, subject to a 30-day soft-delete recovery window and any legal retention requirement.
Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
Execution
To countersign a copy for your records, email chris.suht@gmail.com and we will provide an executable version. Continued use of the service constitutes acceptance of this DPA.
