JobCostingApp← Home

Data Processing Agreement

Effective date: September 1, 2026

This Data Processing Agreement (“DPA”) forms part of the JobCostingApp Terms of Service between Job Costing App LLC (“Processor”, “we”) and the customer identified in the account (“Controller”, “you”). It applies automatically to every customer; no signature is required, and we will countersign a copy on request — write to privacy@jobcostingapp.com.

This page describes how we handle the information you enter about other people — your workers, your customers, your subcontractors and suppliers. It does not cover information about you and your own account, which our Privacy Policy already explains.

1. Definitions

“Customer Personal Data” means personal information relating to an identified or identifiable individual that you or your users enter into, upload to, or generate within the Service — including information about your workers, your customers, subcontractors and suppliers. “Applicable Privacy Law” means any privacy or data protection law that applies to your use of the Service. “Subprocessor” means a third party engaged by us to process Customer Personal Data.

2. Roles

As to Customer Personal Data, you are the controller (and, in California, the “business”) and we are the processor (and, in California, a “service provider”). As to account, billing and usage information about you and your users, we are the controller and our Privacy Policy applies.

3. Our instructions

We process Customer Personal Data only (a) to provide, maintain, secure and support the Service; (b) as otherwise instructed by you in writing; and (c) as required by law, in which case we will tell you first unless the law forbids it. We will notify you if, in our opinion, an instruction breaches Applicable Privacy Law.

4. Service provider certifications

We certify that we: (a) will not sell or share Customer Personal Data; (b) will not retain, use or disclose it for any purpose other than the business purposes specified in this DPA and the Terms, including not for our own commercial purposes, and not outside the direct business relationship between you and us; (c) will not combine it with personal information received from another source, except as permitted by Applicable Privacy Law; and (d) will not use it to train, fine-tune or improve any machine learning or artificial intelligence model, whether ours or a third party’s. We will notify you if we determine we can no longer meet our obligations under Applicable Privacy Law.

5. Confidentiality

We limit access to Customer Personal Data to personnel who need it to perform their duties, and those persons are bound by confidentiality obligations. Today that means the owner of Job Costing App LLC and any support staff we bring on later under the same obligation.

6. Security

We implement and maintain the technical and organizational measures set out in Annex II, and will not materially reduce them during the term.

7. Subprocessors

You authorize the Subprocessors listed at jobcostingapp.com/subprocessors and in Annex III. We will give at least 30 days’ notice before adding or replacing a Subprocessor, by email to your account address and on that page. If you object on reasonable data protection grounds within that period, we will work with you in good faith to find a solution; if we cannot, you may terminate the affected part of the Service and receive a pro-rated refund of prepaid fees. We impose data protection obligations on each Subprocessor no less protective than those in this DPA and remain responsible for their performance.

8. Assisting you

Taking into account the nature of the processing, we will assist you, at your cost where the assistance is substantial: (a) in responding to requests from individuals to access, correct, delete, port or restrict their information — the Service provides self-service tools for most of these and you should use them first; (b) with security, breach notification, and any data protection impact assessment or consultation you are required to carry out. If we receive a request directly from one of your workers, customers or subcontractors, we will not respond substantively; we will tell them to contact you, and tell you they asked, within 5 business days.

9. Security incidents

We will notify you without undue delay, and in any event within 72 hours, after we determine that a security incident has resulted in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data. The notice will describe what we know, the categories and approximate number of records affected, the likely consequences, and what we are doing. We will provide further information as the investigation develops. Notifying you is not an admission of fault.

10. Deletion and return

On termination we delete Customer Personal Data in accordance with the retention periods published in our Privacy Policy, except that (a) you may export your data at any time before deletion, (b) signed documents and their signature records are retained on the separate schedule stated there, and (c) copies in backups are deleted when those backups expire on their normal rotation. We will confirm deletion in writing on request.

11. Audits

On written request, no more than once in any 12 months, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of our security measures and answers to a reasonable security questionnaire. Where a third-party audit report or certification for a Subprocessor is available, we will provide it in place of our own audit. Any on-site audit requires 30 days’ notice, must be at your cost, must not disrupt the Service, and is subject to confidentiality.

12. Location and transfers

Customer Personal Data is stored and processed in the United States — our servers in Arizona and our backups in Boston, Massachusetts. Our providers may process data in other locations, as shown on our subprocessors page. Where a transfer of personal data is subject to a law requiring a transfer mechanism, the parties will put an appropriate mechanism in place, and this DPA incorporates the applicable standard contractual clauses by reference where required.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits liability that cannot be limited under Applicable Privacy Law.

14. Term and precedence

This DPA applies for as long as we process Customer Personal Data. If this DPA conflicts with the Terms of Service, this DPA governs as to the processing of Customer Personal Data.

Annex I — Details of processing

Subject matter: provision of the JobCostingApp job costing, invoicing, labor tracking, document generation and subcontractor management service.
Duration: the term of your subscription, plus the retention periods published in our Privacy Policy.
Nature and purpose: hosting, storage, organization, retrieval, calculation, document generation, text extraction from uploaded documents, transmission of notifications, and backup.
Categories of individuals: your personnel and workers; your customers, including homeowners; your subcontractors and their personnel; your suppliers’ personnel.
Categories of personal data: names; business and personal contact details; job titles and roles; hours worked and pay rates; property addresses; project details; signatures and signature records including IP address, timestamp and device information; content of uploaded documents, photographs and receipts.
Special categories: none intended, and prohibited by the Terms of Service.

Annex II — Security measures

Annex III — Subprocessors

Maintained at jobcostingapp.com/subprocessors, which lists each Subprocessor, what it does, what it receives, and where.