RoofCaptain AI — Data Processing Addendum
DRAFT — NOT LEGAL ADVICE. Have an attorney review before use. CCPA/CPRA service-provider status depends on these contractual terms being correct.
Last updated: [DATE]
Effective: [DATE]
This Data Processing Addendum ("DPA") supplements the RoofCaptain AI Terms of Service (the "Agreement") between [LEGAL ENTITY NAME] ("RoofCaptain," "we," "Service Provider") and the customer agreeing to the Agreement ("Customer," "you," "Business"). It is incorporated into the Agreement by reference and applies whenever we process Personal Information on your behalf.
If the Agreement and this DPA conflict on data protection matters, this DPA controls.
1. Definitions
"Personal Information" has the meaning given under Applicable Privacy Law and, for this DPA, means personal information about homeowners and website visitors that we process on your behalf through the Service.
"Applicable Privacy Law" means the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and any other data protection law applicable to processing under the Agreement.
"Business," "Service Provider," "Sell," "Share," "Consumer," and "Processing" have the meanings given in the CCPA.
"Sub-processor" means a third party engaged by us to process Personal Information in providing the Service.
2. Roles of the Parties
2.1 With respect to Personal Information collected through your embedded widget or landing pages, you are the Business and we are the Service Provider. You determine the purposes and means of processing; we process only on your documented instructions.
2.2 The Agreement, this DPA, and your configuration of the Service constitute your documented instructions.
2.3 With respect to your own account and billing information, we act as a Business in our own right, as described in our Privacy Policy. This DPA does not apply to that data.
2.4 You are responsible for: providing any privacy notice required at the point of collection on your website; obtaining any consents required by law, including for marketing calls, texts, or emails to Leads; and ensuring you have a lawful basis to collect and use Lead data.
3. Scope of Processing
Subject matter: provision of the Service under the Agreement.
Duration: for the term of the Agreement, plus the retention period in Section 8.
Nature and purpose: generating roof measurements and estimates, delivering estimates and notifications by email, storing Leads for your access, and transmitting Leads to integrations you configure.
Categories of data subjects: homeowners and visitors who use your estimator widget or landing pages.
Categories of Personal Information:
- Identifiers: name, email address, telephone number
- Property information: address entered and approximate geographic coordinates
- Inquiry details: selected roof type, reported repair problem, free-text notes
- Internet activity: IP address, browser information, timestamps, referring page
Sensitive Personal Information: none is intentionally collected. You must not use the Service to collect Sensitive Personal Information as defined by the CCPA.
4. Service Provider Obligations
We will:
4.1 Not Sell or Share Personal Information, as those terms are defined by the CCPA.
4.2 Not retain, use, or disclose Personal Information for any purpose other than performing the Service specified in the Agreement, including not using it for our own commercial purposes, and not outside the direct business relationship between you and us, except as permitted by Applicable Privacy Law.
4.3 Not combine Personal Information received from you with personal information received from other sources, except as permitted by the CCPA (for example, to detect security incidents or prevent fraud).
4.4 Comply with the obligations applicable to a Service Provider under the CCPA and provide the same level of privacy protection the CCPA requires.
4.5 Notify you promptly if we determine we can no longer meet our obligations under Applicable Privacy Law.
4.6 Permit you to take reasonable steps to stop and remediate unauthorized use of Personal Information, and grant you the right, on reasonable notice, to take such steps.
4.7 Ensure personnel with access to Personal Information are bound by confidentiality obligations and receive appropriate access limitations.
5. Security
5.1 We will implement and maintain reasonable technical and organizational measures appropriate to the nature of the Personal Information, including:
- Encryption of data in transit
- Row-level access controls isolating each customer's data from other customers
- Hashed storage of authentication credentials
- Rate limiting and abuse controls on public endpoints
- Restricted internal administrative access
- Logging of system and security events
5.2 We may update these measures provided the overall level of protection is not materially reduced.
5.3 No system is perfectly secure. We do not warrant that Personal Information will never be subject to unauthorized access.
6. Security Incidents
6.1 We will notify you without undue delay after becoming aware of a Security Incident affecting Personal Information processed on your behalf.
6.2 Our notification will describe, to the extent known: the nature of the incident, the categories and approximate number of records affected, likely consequences, and measures taken or proposed.
6.3 We will reasonably cooperate with your investigation and with any notifications you are legally required to make. You are responsible for determining whether notice to Consumers or regulators is required and for making such notifications with respect to data you control.
6.4 Our notification is not an acknowledgment of fault or liability.
7. Consumer Rights Requests
7.1 Requests we receive directly from Consumers regarding data processed on your behalf will be forwarded to you without undue delay, and we will inform the Consumer that the request should be directed to you.
7.2 We will provide reasonable assistance, taking into account the nature of the processing, to help you respond to verified requests to know, access, correct, delete, or opt out — including by providing export and deletion functionality within the Service.
7.3 You are responsible for verifying Consumer identity and determining whether a request is valid.
8. Retention, Deletion, and Return
8.1 We retain Personal Information processed on your behalf for the term of the Agreement.
8.2 Following termination or cancellation, we retain it for ninety (90) days to allow export or account reactivation, after which we delete or de-identify it.
8.3 You may request deletion at any time, including before the end of that period, by contacting us. We will comply without undue delay.
8.4 You may export Lead data at any time while your account is active.
8.5 We may retain Personal Information beyond these periods only where required by law, or in backups that are deleted on a rolling schedule, and such retained copies remain subject to this DPA.
9. Sub-processors
9.1 You authorize us to engage Sub-processors to provide the Service. Current categories include:
| Category | Purpose |
|---|---|
| Cloud hosting and database infrastructure | Storing and serving application data |
| Mapping and satellite imagery providers | Geocoding addresses and generating roof measurements |
| Transactional email delivery | Sending estimate and notification emails |
| Payment processing | Billing (contractor data only; no Lead data) |
9.2 We will impose data protection obligations no less protective than those in this DPA on each Sub-processor, and remain responsible for their performance.
9.3 We will provide notice before adding a new Sub-processor category that materially changes how Personal Information is processed. If you reasonably object on data protection grounds, you may terminate the affected portion of the Service.
9.4 Integrations you configure — such as a CRM connection or webhook endpoint you enter into the Service — are not our Sub-processors. Data transmitted at your direction to a destination you choose becomes subject to that provider's terms, and we are not responsible for its handling there.
10. International Transfers
The Service is operated in the United States. Personal Information may be processed in the United States and in locations where our Sub-processors operate. If you are subject to a law requiring specific transfer mechanisms, contact us to discuss appropriate arrangements.
11. Audits and Assurance
11.1 On reasonable written request, no more than once per twelve (12) months, we will provide information reasonably necessary to demonstrate compliance with this DPA.
11.2 Any audit will be at your expense, during business hours, subject to reasonable confidentiality and security requirements, and must not unreasonably disrupt our operations.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
13. Term and Changes
13.1 This DPA takes effect when you accept the Agreement and continues until we cease processing Personal Information on your behalf.
13.2 We may update this DPA to reflect changes in law or our practices, provided the changes do not materially reduce the protections. Material changes will be communicated with reasonable notice.
14. Contact
Data protection inquiries: info@roofcaptainai.com
[LEGAL ENTITY NAME]
[MAILING ADDRESS]