Data Processing Addendum
Last updated: September 13, 2026
This Data Processing Addendum (DPA) forms part of the ServiceRunner Terms of Service between Isles Mechanical LLC (the Processor) and the Customer (the Controller). It applies automatically to all Customer Data containing personal data; no signature is required. Customers who need a countersigned copy, or the full text of the Standard Contractual Clauses with the Annexes completed, can request one from privacy@app.servicerunner.app.
1. Definitions and Roles
"Data Protection Laws" means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, Canada's PIPEDA and provincial equivalents including Quebec Law 25, the California Consumer Privacy Act as amended by the CPRA ("CCPA") and other U.S. state privacy laws. "Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR, and their CCPA equivalents ("business", "service provider", "consumer", "personal information") apply where the CCPA governs. "Customer Personal Data" means Personal Data contained in Customer Data that Isles Mechanical Processes on Customer's behalf. "Subprocessor" means a third party engaged by Isles Mechanical to Process Customer Personal Data. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the UK International Data Transfer Addendum to the SCCs issued by the Information Commissioner.
Customer is the Controller (or, where Customer acts on behalf of its own client, a Processor with that client as Controller, in which case Customer warrants that it has authority to engage Isles Mechanical as a sub-processor on these terms) and Isles Mechanical is the Processor of Customer Personal Data. Each party complies with the Data Protection Laws that apply to it in that role.
2. Details of Processing (Annex I)
| Subject matter | Provision of the ServiceRunner field-service, maintenance, dispatch, invoicing, customer payment and accounting-integration platform, including web and mobile applications, offline synchronization, storage, notifications and support. |
|---|---|
| Duration | The term of the Terms of Service, plus the export and deletion periods in Section 10. |
| Nature and purpose | Hosting, storage, synchronization, backup, display, transmission, optimization of photos, generation of reports, delivery of notifications (email, SMS, push), route calculation, Customer-directed invoice collection and QuickBooks Online accounting exchange where enabled, and related technical operations to provide the Service to Customer, its Authorized Users and its End Clients. |
| Categories of Data Subjects | Customer's employees, contractors and technicians; Customer's administrators and billing contacts; Customer's clients, tenants, property owners, occupants and site contacts; invoice payers and recurring-agreement signers; recipients of quotes, reports and notifications sent by Customer; other individuals whose data Customer records in the Service. |
| Categories of Personal Data | Identifiers and contact details (name, email, phone, address); role and organization; account credentials (hashed) and session data; device identifiers and push tokens; photographs and images (which may show persons, vehicles or premises); precise geolocation of technicians during shifts, where enabled; time and attendance entries; task, inspection, form and log records authored by or about individuals; chat messages; Customer invoices, accounting references, payment amounts and status, merchant and provider references, limited card details, agreement authorization wording, signer details and audit history; support correspondence. Full card numbers and card security codes are handled by Stripe, not stored in the Service. |
| Sensitive data | None intended. Precise geolocation is treated as sensitive where the law so provides. Customer must not submit special-category data (health, biometric, criminal, etc.) without a separate written agreement. |
| Frequency | Continuous, for the duration of the Service. |
| Competent Supervisory Authority (SCCs Clause 13) | The authority of the EU member state in which Customer (or its EU representative) is established; for UK data, the Information Commissioner's Office. |
3. Processor Obligations and Instructions
Isles Mechanical will:
- Process Customer Personal Data only on Customer's documented instructions, which consist of the Terms of Service, this DPA, Customer's use and configuration of the Service, and any further written instructions agreed by the parties, unless required to do otherwise by law, in which case Isles Mechanical will inform Customer of that requirement before Processing unless the law prohibits it;
- Immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws, without obligation to conduct a legal review;
- Not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than the business purpose of providing the Service, or combine it with Personal Data received from other sources except as the CCPA permits for service providers;
- Ensure that persons authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate training;
- Implement the technical and organizational measures in Section 4 and Annex II;
- Comply with the Subprocessor conditions in Section 5;
- Assist Customer as described in Sections 6 to 8;
- Delete or return Customer Personal Data as described in Section 10;
- Make available the information necessary to demonstrate compliance and allow for audits as described in Section 9; and
- Notify Customer if it determines that it can no longer meet its obligations under Data Protection Laws, in which case Customer may take reasonable steps to stop and remediate unauthorized Processing.
4. Security (Annex II)
Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing and the risks to Data Subjects, Isles Mechanical implements and maintains the following measures, which it may update provided the overall level of protection is not reduced:
| Measure | Description |
|---|---|
| Encryption | TLS 1.2+ for all data in transit; encryption at rest for databases, object storage and backups using provider-managed keys; passwords hashed with a memory-hard algorithm (argon2id) with transparent upgrade of legacy hashes. |
| Access control | Role-based access at organization and site level; least-privilege production access limited to named engineers with MFA; session tokens with expiry and revocation; optional two-factor authentication for users; signed, time-limited download links. |
| Confidentiality and integrity | Audit logging of create, update and delete operations with actor and timestamp; input validation; separation of tenants by organization identifier enforced in the application and query layer; rate limiting. |
| Availability and resilience | Managed database with automated daily backups and point-in-time recovery where supported; redundant object storage; health checks; documented restore procedures tested periodically. |
| Data minimization | Photo optimization strips non-essential embedded metadata; location captured only when the feature is enabled and the user is on shift; no third-party analytics SDKs. |
| Secure development | Code review, dependency vulnerability scanning, automated end-to-end tests, separate development, staging and production environments, secrets stored outside source control. |
| Incident management | Documented incident response process, security contact (security@app.servicerunner.app), breach register, post-incident review. |
| Personnel | Confidentiality obligations, security awareness training, prompt de-provisioning on departure. |
| Subprocessor assurance | Written contracts with equivalent obligations; review of security documentation (e.g., SOC 2 or ISO 27001 reports) before onboarding and periodically. |
| Physical security | Infrastructure hosted in data centers operated by the hosting Subprocessor with industry-standard physical controls; Isles Mechanical operates no data centers of its own. |
| Data portability and deletion | Self-service export in common formats; deletion workflows for organizations and users; backup expiry on a fixed schedule. |
5. Subprocessors
Customer gives Isles Mechanical general written authorization to engage the Subprocessors listed on the Subprocessors page, which forms Annex III to this DPA, and to engage additional or replacement Subprocessors subject to this Section.
- Notice. Isles Mechanical will update the Subprocessors page and notify Customer (by email to the Organization Owner and billing contacts, or by in-app notice) at least 30 days before a new Subprocessor begins Processing Customer Personal Data. Customers may subscribe to change notifications by emailing privacy@app.servicerunner.app.
- Objection. Customer may object on reasonable, data-protection-related grounds within that notice period by emailing privacy@app.servicerunner.app. The parties will discuss in good faith; if Isles Mechanical cannot reasonably accommodate the objection (for example by not using the Subprocessor for Customer's data), Customer may terminate the affected subscription on written notice and receive a pro-rata refund of prepaid Fees for the remainder of the term, as its sole remedy.
- Flow-down. Isles Mechanical will impose on each Subprocessor data protection obligations that are no less protective than those in this DPA, by written contract, and remains fully liable to Customer for the performance of each Subprocessor's obligations.
- Emergency replacement. Where a Subprocessor must be replaced urgently for security or continuity reasons, Isles Mechanical may do so with notice as soon as practicable, and Customer's objection right applies from that notice.
6. Data Subject Requests
The Service provides self-service tools that let Customer access, correct, export and delete Customer Personal Data. To the extent Customer cannot address a Data Subject request using those tools, Isles Mechanical will provide reasonable assistance on request, taking into account the nature of the Processing. If Isles Mechanical receives a request directly from a Data Subject relating to Customer Personal Data, it will (unless legally prohibited) inform the Data Subject that the request should be addressed to Customer, forward the request to Customer within 5 business days, and not respond substantively except on Customer's instruction or as required by law.
7. Personal Data Breach
Isles Mechanical will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point; information may be provided in phases as it becomes available. Isles Mechanical will take reasonable steps to contain, investigate and remediate the breach and will cooperate with Customer's own notifications to Supervisory Authorities and Data Subjects. Notification is not an acknowledgement of fault or liability.
8. Assistance with Impact Assessments and Consultations
Taking into account the nature of the Processing and the information available to it, Isles Mechanical will provide reasonable assistance to Customer in carrying out data protection impact assessments and prior consultations with Supervisory Authorities that relate to the Service (including privacy impact assessments required by Quebec Law 25 for cross-border communication), and in fulfilling Customer's obligation to maintain the security of Customer Personal Data. This DPA, the Privacy Policy, the Security section and the Subprocessors page are intended to supply the information most assessments need; assistance beyond that may be charged at Isles Mechanical's then-current professional services rates.
9. Audits
Isles Mechanical will make available to Customer, on written request no more than once per 12 months (or additionally after a Personal Data Breach affecting Customer or where required by a Supervisory Authority), the information reasonably necessary to demonstrate compliance with this DPA. This will normally consist of: this DPA and its Annexes; the current security documentation; completed security questionnaires; and, where Isles Mechanical holds third-party audit reports or certifications (such as SOC 2 Type II or ISO 27001), a copy or summary of those reports under confidentiality. Reports for hosting Subprocessors are provided by reference to those Subprocessors' published reports.
If the information provided is not reasonably sufficient to demonstrate compliance, Customer (or an independent auditor bound by confidentiality and approved by Isles Mechanical, not a competitor) may conduct an audit, limited to the matters in dispute, during business hours, on at least 30 days' written notice, no more than once in any 12-month period, at Customer's expense, in a manner that does not disrupt Isles Mechanical's business or compromise other customers' data. Audits are conducted remotely by document review and interviews unless an on-site visit is required by Data Protection Laws or a Supervisory Authority. Isles Mechanical will remediate material findings within a reasonable time. Audit rights under the SCCs are exercised in accordance with this Section to the extent permitted.
10. Return and Deletion
During the term, Customer may export Customer Personal Data at any time. After termination or expiry of the Service, Customer may export Customer Personal Data during the 30-day Export Window described in the Terms. Thereafter Isles Mechanical will delete Customer Personal Data from active systems within 90 days of termination and from backups within 6 months as backup media rotate, and will certify deletion in writing on request, unless retention is required by applicable law, in which case Isles Mechanical will continue to protect the retained data under this DPA and Process it only for the purpose of that legal requirement. Deletion of data on user devices (offline caches, queued photos and location points) is Customer's responsibility and is achieved by signing out or removing the app.
Customer invoice, card-payment, agreement-consent and QuickBooks sync evidence follows this account deletion process unless a separate legal retention requirement applies. We do not promise a seven-year archive of all Customer financial evidence. Disconnecting a provider does not delete data already held by that provider or immediately erase local reconciliation history; QuickBooks credential revocation can require retries or action in QuickBooks.
11. International Transfers
Customer authorizes Isles Mechanical and its Subprocessors to Process Customer Personal Data in the United States and in the other locations listed on the Subprocessors page, subject to the following safeguards:
- EEA transfers. Where Customer Personal Data protected by the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA and apply as follows: Module Two (controller to processor) applies where Customer is a Controller and Module Three (processor to processor) where Customer is a Processor; Clause 7 (docking) is included; under Clause 9 Option 2 (general authorization) applies with the notice period in Section 5; the optional language in Clause 11 is not included; under Clause 17 the SCCs are governed by the law of Ireland; under Clause 18 disputes are resolved by the courts of Ireland; Annex I is Section 2 of this DPA, Annex II is Section 4 and Annex III is the Subprocessors page. The parties will complete a transfer impact assessment on request.
- Swiss transfers. The SCCs apply as adapted for the Swiss FADP: references to the GDPR are read as references to the FADP, the Federal Data Protection and Information Commissioner is the competent authority, and Data Subjects in Switzerland may enforce their rights in Switzerland.
- UK transfers. The UK Addendum is incorporated, with Tables 1 to 3 completed by reference to the SCC selections above and this DPA, and Table 4 permitting either party to end the Addendum as set out in Section 19 of the Addendum.
- Canada. Isles Mechanical provides, by contract with each Subprocessor, a comparable level of protection to that required by PIPEDA and Quebec Law 25, and will assist Customer with the privacy impact assessment Law 25 requires before communicating Personal Data outside Quebec.
- Other frameworks. Where a recipient is certified under the EU-U.S., UK or Swiss-U.S. Data Privacy Framework, Isles Mechanical may rely on that certification in addition to the SCCs.
If the SCCs, UK Addendum or any successor mechanism is invalidated or replaced, the parties will cooperate in good faith to adopt a replacement mechanism promptly. In the event of conflict between this DPA and the SCCs, the SCCs prevail for the transfer they govern.
12. CCPA Service-Provider Terms
To the extent the CCPA applies, Customer discloses Customer Personal Data to Isles Mechanical only for the limited and specified business purpose of providing the Service, and Isles Mechanical certifies that it understands and will comply with the restrictions in Section 3, will comply with the CCPA and provide the same level of privacy protection the CCPA requires of businesses, will notify Customer if it can no longer meet its obligations, and grants Customer the right to take reasonable and appropriate steps to ensure that Isles Mechanical uses Customer Personal Data consistently with Customer's obligations and to stop and remediate unauthorized use. Isles Mechanical will cooperate with Customer in responding to verifiable consumer requests. The parties acknowledge that the disclosure of Customer Personal Data to Isles Mechanical is not a sale or sharing, and that no monetary or other valuable consideration is exchanged for it.
13. Liability and General
Each party's liability arising out of or relating to this DPA (including the SCCs, to the extent permitted by them) is subject to the exclusions and limitations of liability in the Terms of Service, and the aggregate liability of Isles Mechanical under the Terms and this DPA together will not exceed the cap stated in the Terms. Nothing in this Section limits the rights of Data Subjects under the SCCs or a party's liability that cannot be limited by Data Protection Laws. Where Isles Mechanical and Customer are jointly liable to a Data Subject, each is responsible for the part of the damage attributable to it.
This DPA prevails over the Terms of Service to the extent of any conflict regarding the Processing of Customer Personal Data. It is governed by the law and dispute-resolution provisions of the Terms, except that the SCCs are governed as stated in Section 11. It terminates automatically when Isles Mechanical has deleted or returned all Customer Personal Data. Customers who require a signed copy, or a version tailored to a specific regulatory regime, may request one from privacy@app.servicerunner.app.