This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer (the "Customer" / "Controller") and Exterior Consigliere LLC (the "Provider" / "Processor") and governs Provider's processing of personal data on Customer's behalf. Where terms differ, this DPA controls for data-protection matters. By accepting the Terms, Customer accepts this DPA.
Customer is the controller (or, under U.S. laws, the "business") of the personal data it submits to the Service about its own customers and leads (homeowners). Provider is the processor / "service provider," processing that data only to provide the Service and on Customer's documented instructions (which include the Terms and Customer's use of the Service). Provider will not process the data for any other purpose.
| Subject matter | Provision of the Exterior Consigliere Service |
|---|---|
| Duration | The subscription term plus the post-termination retention window (Section 7) |
| Categories of data subjects | Customer's customers, prospects, and leads (homeowners); Customer's own staff users |
| Categories of personal data | Names, property/mailing addresses, phone numbers, emails, photos of properties, job/estimate notes, and similar data Customer chooses to store |
| Special categories | None requested or required; Customer should not submit sensitive data |
Customer authorizes Provider to engage the subprocessors listed in our Privacy Policy (the current list: Supabase, Vercel, Stripe, Google, Anthropic, Cloudflare, and an email/SMTP provider). Provider imposes data-protection obligations on each subprocessor substantially as protective as this DPA and remains responsible for their performance. Provider will give Customer reasonable prior notice of a new or replacement subprocessor; Customer may object on reasonable data-protection grounds, and if the parties cannot resolve it, Customer may terminate the affected Service.
Provider maintains the measures in Annex A, including encryption in transit, row-level access controls isolating each tenant's data, per-tenant isolation of stored files, and access restricted to authorized personnel.
Provider will notify Customer without undue delay (and in any event within 72 hours of confirmation) after becoming aware of a personal data breach affecting Customer's data, with the information reasonably available to help Customer meet its own notification obligations.
Customer may export its data during the subscription. On termination, data is retained during a hold period and then permanently deleted per the Terms (approximately a 60-day hold-then-delete window), except where retention is required by law or an active legal hold. On request during that window, Provider will provide an export or confirm deletion.
On reasonable written request (no more than annually, absent a breach or regulator requirement), Provider will make available information reasonably necessary to demonstrate compliance with this DPA.
The Service and its subprocessors are operated primarily in the United States. Where a transfer mechanism is legally required for data originating outside the U.S., the parties will implement an appropriate one (e.g., Standard Contractual Clauses) as applicable.