Data Processing Addendum
Last updated: June 13, 2026
This Data Processing Addendum ("DPA") forms part of, and is governed by, the Terms & Conditions between you ("Customer") and CrewShot ("CrewShot," "we," "us"). It applies when we process personal information about your End Customers on your behalf in providing the Service. Capitalized terms not defined here have the meaning given in the Terms. If there is a conflict between this DPA and the Terms regarding the processing of End Customer personal information, this DPA controls.
1. Roles of the Parties
For personal information about your End Customers that you submit to or create in the Service ("Customer Personal Data"), you are the controller/business and CrewShot is the processor/service provider acting on your documented instructions. For your own account, billing, and usage information, CrewShot acts as a controller/business as described in our Privacy Policy. You are responsible for establishing the legal basis for, and obtaining any consents required for, the Customer Personal Data you provide.
2. Details of Processing
- Subject matter & nature: hosting, storing, organizing, displaying, transmitting, and otherwise processing Customer Personal Data to provide the Service (photo documentation, project and customer management, reports, estimates, payment requests, and client portals).
- Purpose: to provide, maintain, secure, and improve the Service for you, and as otherwise permitted by the Terms.
- Duration: for the term of your subscription and until deletion as described in Section 7.
- Categories of data subjects: your End Customers (such as homeowners and property contacts).
- Categories of data: names, email addresses, phone numbers, property/job addresses, photos and their metadata (including GPS and timestamps), messages, estimates, payment-request details, and notes you enter.
3. Our Obligations
We will:
- process Customer Personal Data only to provide the Service and on your instructions (including as given through your use of the Service and the Terms), unless required by law;
- ensure personnel authorized to process Customer Personal Data are bound by confidentiality;
- implement and maintain reasonable administrative, technical, and organizational security measures appropriate to the risk, including encryption in transit and access controls (see our Privacy Policy, Security);
- make available information reasonably necessary to demonstrate compliance with this DPA; and
- not sell or share Customer Personal Data, and not retain, use, or disclose it for any purpose other than providing the Service or as permitted by applicable law. We certify that we understand and will comply with these restrictions.
4. Subprocessors
You authorize us to engage subprocessors to help provide the Service. Our current subprocessors are listed in our Privacy Policy (Subprocessors). We impose data-protection obligations on each subprocessor that are substantially similar to those in this DPA, and we remain responsible for their performance. We will update the list before adding a new subprocessor; if you reasonably object to a new subprocessor on data-protection grounds, you may stop using the affected feature or cancel as described in the Terms.
5. Assisting You
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from data subjects to access, correct, delete, or port their personal information, and to meet your security, breach-notification, and assessment obligations. If we receive a request directly from one of your End Customers, we will, where permitted, direct them to you.
6. Personal Data Breach
We will notify you without undue delay after becoming aware of a confirmed breach of security leading to the unauthorized disclosure of, or access to, Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations.
7. Deletion & Return
On termination of the Service, or on your valid deletion request, we will delete Customer Personal Data in accordance with the retention practices described in our Privacy Policy, except for limited information we are required or permitted to retain by law (such as financial records) and copies in routine backups that expire on our normal cycle. You should export any content you wish to keep before your account closes.
8. International Transfers
The Service is intended for US-based businesses and is operated in the United States. We do not rely on cross-border transfer mechanisms for offering the Service outside the United States. Information may be processed in the United States or other countries where our subprocessors operate.
9. Liability & Term
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA takes effect when you accept the Terms and remains in effect for as long as we process Customer Personal Data on your behalf.
10. Contact
Questions about this DPA? Contact us at support@crewshot.net.