Data Processing Addendum
Last Updated: August 27, 2026Processing terms for Customer Personal Data that EquipmentFlow handles on behalf of a business customer.
1. Definitions
- “Customer” means the EquipmentFlow customer identified in the applicable account or order.
- “Customer Personal Data” means Personal Data submitted to the Service by or for Customer.
- “Data Protection Law” means applicable privacy and data-protection law, including the GDPR, UK GDPR, and applicable United States state privacy laws.
- “Data Subject” means an identified or identifiable individual.
- “Processing,” “Controller,” “Processor,” and “Subprocessor” have the meanings assigned by applicable Data Protection Law.
2. Roles and Scope
For Customer Personal Data entered into EquipmentFlow for the Customer’s operational purposes, the Customer is the Controller or equivalent business and EquipmentFlow is the Processor or equivalent service provider. EquipmentFlow will process Customer Personal Data only to provide, secure, support, maintain, and improve the Service, comply with documented Customer instructions, and comply with law.
This DPA does not apply to information EquipmentFlow processes as an independent controller for account administration, security, billing, legal compliance, product communications, or relationship management. That processing is described in the Privacy Policy.
3. Processing Details
Subject matter: hosting and operating equipment, fleet, maintenance, inspection, JSA, repair, workforce, document, notification, audit, and account workflows.
Duration: the term of the Customer’s Service account plus the deletion or return period described below.
Data Subjects: Customer users, employees, contractors, mechanics, drivers, safety personnel, customers, vendors, visitors, and other individuals whose information the Customer submits.
Data categories: names, contact information, roles, identifiers, signatures, photos, device and activity information, job-site information, assignments, inspection and maintenance records, and other information selected by Customer.
4. Customer Instructions and Responsibilities
Customer is responsible for the legality, accuracy, security, retention, and instructions associated with Customer Personal Data. Customer must provide required notices, obtain required permissions, establish a lawful basis, respond to Data Subject requests, and ensure its instructions comply with Data Protection Law. EquipmentFlow may suspend an instruction that it reasonably believes violates law or creates a security risk.
5. Confidentiality and Security
EquipmentFlow will restrict access to Customer Personal Data to personnel and providers who need it to perform authorized duties and who are subject to confidentiality obligations. We maintain safeguards appropriate to the risk, including company-scoped authorization, access controls, authentication, encrypted transmission, protected storage, logging, backups, and incident-response procedures. No security program eliminates all risk.
6. Subprocessors
Customer authorizes EquipmentFlow to use subprocessors needed to provide the Service, including Clerk for identity, Resend for transactional email, and Replit for hosting, database, and object storage. EquipmentFlow remains responsible for its subprocessors’ performance of processing obligations to the extent required by Data Protection Law. We will provide notice of material subprocessor changes where required and allow a reasonable objection process.
7. Data Subject Requests and Assistance
EquipmentFlow will reasonably assist Customer with Data Subject requests using available Service capabilities and information reasonably available to us. If assistance requires substantial custom work, we may charge reasonable costs after discussing the scope. Customer remains responsible for verifying the requestor, determining the response, and communicating with the Data Subject.
8. Personal Data Incidents
EquipmentFlow will notify Customer without undue delay after confirming a Personal Data incident affecting Customer Personal Data and will provide information reasonably available to support Customer’s response. Customer is responsible for legal assessments, regulator notices, and Data Subject notices unless applicable law requires otherwise. Notifications may be staged as information becomes available.
9. International Transfers
Customer authorizes processing in the United States and other locations used by EquipmentFlow and its subprocessors. Where a transfer mechanism is legally required, the parties will use an applicable lawful mechanism, such as an adequacy decision, Standard Contractual Clauses, or another recognized safeguard.
10. Return and Deletion
At Customer’s written request after termination, EquipmentFlow will make Customer Personal Data available through available export features or delete it in accordance with the Service’s retention process, except for copies retained in backups, legal records, security records, accepted agreement records, or other records required by law. Backup copies will be isolated and deleted through normal rotation.
11. Audit and Compliance Information
EquipmentFlow may provide reasonable information about its security and processing practices. Any audit must be proportionate, protect confidentiality, avoid disruption, and occur no more than once annually unless a confirmed incident requires otherwise. Audit logs assist with recordkeeping but are not the exclusive or definitive legal record; synchronization delays, user actions, connectivity issues, and system failures may affect audit history.
12. Liability and Order of Precedence
The liability exclusions, cap, indemnification obligations, force majeure terms, severability, and dispute terms in the Terms of Service apply to this DPA unless Data Protection Law requires otherwise. If this DPA conflicts with the Terms on processing of Customer Personal Data, this DPA controls for that conflict.
13. Contact and Effective Date
Questions about this document or a request for legal/privacy support may be sent to support@equipmentflowco.com. Security reports should be submitted through the security report form.