Legal

Data Processing Addendum

Version 1.0 · Effective August 7, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between [COMPANY LEGAL NAME — e.g. Trash Tools LLC] ("Processor") and the hauler customer ("Controller") and applies where we process personal data contained in Customer Data on the Controller's behalf.

1. Scope and roles

The Controller determines the purposes and means of processing personal data of its own customers and personnel entered into the Service; the Processor processes such data only to provide the Service per the Terms and the Controller's documented instructions expressed through use of the Service.

2. Categories of data and subjects

Data subjects: the Controller's customers, prospects, and staff. Data categories: contact details (name, email, phone, service address), service and billing records, message content, and location data incidental to service delivery. No special categories of data are intended to be processed.

3. Confidentiality and personnel

The Processor limits access to personnel who need it to operate the Service and binds them to confidentiality obligations.

4. Security measures

The Processor implements appropriate technical and organizational measures, including: encryption in transit and at rest; application-layer encryption of connected payment credentials; tenant isolation enforced in application code on every query; role-based access; httpOnly session tokens; audit and error logging; and routine dependency updates.

5. Subprocessors

The Controller provides general authorization for the subprocessors listed at trash-tools.com/subprocessors. The Processor will update that list before adding subprocessors and remains responsible for their performance.

6. Data subject requests

Taking into account the nature of processing, the Processor assists the Controller in responding to data subject requests, primarily through the Service's built-in export, correction, and deletion capabilities.

7. Breach notification

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, with information reasonably available to help the Controller meet its obligations.

8. Deletion and return

Upon termination, the Controller may export Customer Data from the Service. Following the 60-day wind-down period described in the Privacy Policy, the Processor deletes Customer Data, except where retention is required by law.

9. International transfers

Processing occurs in the United States. If the Controller is subject to laws requiring transfer mechanisms for international transfers, the parties will cooperate to put appropriate safeguards in place.