Data Processing Addendum

Effective Date: September 2, 2026 · Version 1.0

1. Parties

Data Controller / Business: The SERVNORA customer that determines the purposes and means of processing personal data (“Controller”).

Data Processor / Service Provider: SERVNORA (“Processor”), operating the SERVNORA customer experience intelligence platform.

The legal contracting entity providing the Services will be identified in the applicable order form, subscription record, or other commercial agreement between the parties.

2. Definitions

Applicable Data Protection Law means all laws and regulations applicable to the processing of personal data under this DPA, including (where applicable) the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”), the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”), and any successor legislation.

Personal Data means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller under this DPA.

Subprocessor means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

Security Incident means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

3. Scope and Duration

This DPA applies to all processing of Personal Data performed by the Processor on behalf of the Controller in connection with the SERVNORA service.

This DPA remains in effect for the duration of the Controller’s use of the SERVNORA service, plus any period during which the Processor retains Personal Data as described in Section 14 (Deletion and Return).

4. Nature and Purpose of Processing

The Processor processes Personal Data solely to provide the SERVNORA service as described in the Terms of Service. Processing activities include:

  • Sending configured customer communications (SMS and email) after completed service jobs
  • Collecting and processing customer feedback ratings and comments
  • Detecting customer sentiment and creating recovery cases for dissatisfied customers
  • Inviting customers to share their experience on Google and tracking review-link interactions
  • Providing analytics, technician performance insights, and operational reporting
  • Maintaining platform security, preventing abuse, and enforcing opt-out and compliance rules
  • Complying with applicable law, including TCPA, CTIA, and data-protection obligations

The Processor shall not process Personal Data for any purpose other than as necessary to provide the Service, unless required to do so by applicable law.

5. Categories of Personal Data

Processing may involve the following categories of Personal Data:

  • Customer identity: first name, last name, phone number, email address
  • Service information: service address, service type, job dates, invoice numbers, job status
  • Feedback data: ratings (1–5), written comments, feedback categories, sentiment classification
  • Communication records: SMS content, delivery status, opt-out status, consent records, inbound reply content
  • Technician data: technician name, employee identifier, assigned jobs, performance metrics derived from feedback
  • Recovery data: case notes, resolution outcomes, contact attempts, follow-up records
  • Account data: company name, user names, email addresses, roles, and API keys (hashed)

6. Categories of Data Subjects

Data subjects include:

  • The Controller’s customers and prospective customers whose phone numbers or email addresses are submitted to the Service
  • The Controller’s employees and technicians whose names and identifiers are submitted to the Service
  • The Controller’s own staff (office managers, dispatchers, administrators) who hold SERVNORA user accounts

7. Controller Obligations

The Controller represents and warrants that:

  • It has a valid legal basis for providing Personal Data to the Processor, including all necessary consents and authorizations required under Applicable Data Protection Law
  • Its collection and use of customer phone numbers complies with the Telephone Consumer Protection Act (TCPA), CTIA guidelines, and equivalent local laws
  • It has provided its customers with adequate notice that their data may be processed by SERVNORA as a subprocessor
  • It will not submit Personal Data to the Service in violation of Applicable Data Protection Law

8. Documented Instructions

The Processor shall process Personal Data only on documented instructions from the Controller, including with respect to transfers of Personal Data to third countries, unless required to do so by Applicable Data Protection Law. In such cases, the Processor shall inform the Controller of the legal requirement before processing, unless prohibited by law.

9. Confidentiality

The Processor shall ensure that all persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of the engagement.

10. Security Measures

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate:

  • Encryption: TLS for all data in transit; passwords and API keys hashed using scrypt (a secure key derivation function)
  • Access control: role-based access control, multi-tenant data isolation, and unique authentication for every user
  • Isolation: every customer workspace is fully isolated; cross-tenant data access is prevented by server-side enforcement on every query and API endpoint
  • Audit logging: comprehensive activity logging for data access, SMS sending, opt-out events, settings changes, and user management
  • Availability: automated testing and deployment; data persistence requires persistent storage configuration
  • Testing: regular automated test suites covering security-critical paths including tenant isolation, consent enforcement, and access control

The Processor regularly evaluates and updates its security measures in response to new threats, vulnerabilities, and changes in the processing environment.

11. Subprocessors

The Processor may engage Subprocessors to assist in providing the Service. The Processor shall:

  • Maintain a current list of Subprocessors at servnora.com/subprocessors
  • Notify the Controller of any material changes to Subprocessors at least 30 days before the change takes effect, unless a shorter period is required by urgent operational needs
  • Impose on each Subprocessor data-protection obligations that are no less protective than those set out in this DPA
  • Remain fully liable to the Controller for the performance of each Subprocessor’s obligations

If the Controller objects to a new Subprocessor on reasonable data-protection grounds, the parties shall discuss the objection in good faith. If the objection cannot be resolved, the Controller may terminate the affected Service without penalty.

12. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to data-subject requests under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection, taking into account the nature of the processing.

Where the Processor receives a request directly from a data subject, the Processor shall promptly notify the Controller (unless prohibited by law) and shall not respond without the Controller’s written authorization.

The Processor provides self-service data-export and deletion tools within the Service that the Controller may use to fulfill data-subject requests. The Processor shall respond to direct requests from the Controller within 30 calendar days.

13. Security Incident Notification

The Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of a Security Incident affecting the Controller’s Personal Data.

The notification shall include, to the extent reasonably available:

  • Nature of the Security Incident, including the categories and approximate number of data subjects and records affected
  • Name and contact details of the Processor’s data-protection point of contact
  • Likely consequences of the Security Incident
  • Measures taken or proposed to address the Security Incident, including mitigation and remediation steps

Where the Processor cannot provide complete information within the initial notification, it shall provide supplementary information in phases without further undue delay.

The Processor shall cooperate with the Controller and take such reasonable commercial steps as the Controller may direct to assist in the investigation, mitigation, and remediation of each Security Incident.

14. Deletion and Return of Data

Upon termination of the Service or upon the Controller’s written request, the Processor shall, at the Controller’s choice:

  • Return all Personal Data in a commonly used, machine-readable format; or
  • Delete all Personal Data and certify deletion in writing

The Processor shall complete deletion within 30 calendar days of the request, except where retention is required by Applicable Data Protection Law or a binding legal obligation.

Residual copies in system backups, where backups are configured, may persist for up to 90 days for disaster-recovery purposes and will be overwritten in the normal backup rotation cycle.

15. Audits and Compliance Demonstration

The Processor shall make available to the Controller, upon request, information reasonably necessary to demonstrate compliance with this DPA, including:

  • Written security policies and procedures
  • Documentation of security controls and access policies conducted within the prior 12 months
  • The current Subprocessor list and applicable contractual obligations
  • Audit logs demonstrating tenant isolation and access control

The Controller may conduct or commission an audit of the Processor’s compliance with this DPA no more than once per calendar year, upon 30 days’ prior written notice. The audit shall be conducted during normal business hours, shall not unreasonably interfere with the Processor’s operations, and the Controller shall bear its own costs. Where the Controller engages a third-party auditor, the auditor must be reasonably acceptable to the Processor and must be bound by confidentiality obligations.

16. International Data Transfers

The Processor currently processes and stores Personal Data in the United States. Where Personal Data is transferred from the EU/EEA or the United Kingdom to a country outside that area that has not been deemed to provide an adequate level of data protection, the parties shall ensure that an appropriate transfer mechanism is in place, such as:

  • Standard Contractual Clauses approved by the European Commission (or the UK International Data Transfer Agreement / Addendum)
  • Binding Corporate Rules, where applicable
  • Any other legally recognized transfer mechanism

The Processor shall cooperate with the Controller to execute the applicable transfer mechanism and shall assist with any required transfer-impact assessments.

Current Subprocessor locations are listed on the Subprocessor Disclosure page.

17. Liability

Each party’s liability under this DPA is subject to the limitations set forth in the Terms of Service, except where prohibited by Applicable Data Protection Law. Nothing in this DPA shall limit or exclude either party’s liability for:

  • Death or personal injury caused by negligence
  • Fraud or fraudulent misrepresentation
  • Any other liability that cannot be limited or excluded by law

18. Governing Law and Jurisdiction

Any governing-law and jurisdiction provisions applicable to a customer’s subscription will be specified in the applicable agreement or order form.

This DPA shall be governed by and construed in accordance with the laws of the jurisdiction specified in the applicable agreement, without regard to its conflict-of-laws provisions.

For data-protection matters arising under GDPR or UK GDPR, the parties acknowledge that the supervisory authority having jurisdiction over the Controller’s establishment shall have authority over disputes relating to this DPA.

19. Changes to this DPA

The Processor may update this DPA from time to time to reflect changes in the Service, subprocessors, or legal requirements. Material changes will be notified to the Controller at least 30 days before they take effect. The Controller’s continued use of the Service after the effective date constitutes acceptance of the updated DPA. If the Controller does not agree to the changes, it may terminate the Service without penalty before the effective date.

20. Severability

If any provision of this DPA is held to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the parties’ original intent.

This Data Processing Addendum is supplementary to and forms part of the SERVNORA Terms of Service. Defined terms used but not defined herein have the meaning given to them in the Terms of Service.

This document should be reviewed by qualified legal counsel before execution with customers.

Data Processing Addendum | SERVNORA