TerraVex

TerraVex Data Processing Addendum (DPA)

Effective date: on acceptance · Last updated: October 7, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (https://app.terravexos.com/legal/terms) and applies where TerraVex processes Customer Personal Data on behalf of the Customer in providing the Service and where such processing is subject to Data Protection Laws (U.S. state privacy laws such as the CCPA/CPRA and, to the extent they apply, other data-protection laws).

1. Definitions

Terms such as "controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings in the applicable Data Protection Laws. "Customer Personal Data" means personal data within Customer Data. "Subprocessor" means a third party engaged by TerraVex to process Customer Personal Data. "De-identified data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual.

2. Roles

The Customer is the controller (or a processor acting for a third-party controller) of Customer Personal Data, and TerraVex is the processor (or subprocessor). For CCPA/CPRA, TerraVex acts as a service provider. Each party will comply with its obligations under Data Protection Laws. The Customer alone is responsible for records, reports and disclosures that pesticide laws require of it, including any that contain personal data, and TerraVex processes them only as the Customer's processor.

3. Scope & instructions

3.1 TerraVex will process Customer Personal Data only (a) to provide, secure, and support the Service; (b) per the Customer's documented lawful instructions (including the Terms, this DPA, and configuration of the Service); and (c) as required by law (in which case TerraVex will inform the Customer unless legally prohibited). 3.2 TerraVex will notify the Customer if it believes an instruction violates Data Protection Laws (without obligation to provide legal advice). 3.3 The Customer is responsible for the accuracy and lawfulness of Customer Personal Data and for having a valid legal basis and required notices/consents. 3.4 Support access. The Customer instructs TerraVex that authorized TerraVex personnel may access the Customer's workspace, including by operating it with administrator permissions, where reasonably necessary to provide support the Customer has requested (for example, loading data the Customer has sent for import), to investigate and resolve a problem, or to respond to a security or abuse concern. Such access is limited to the purpose, is restricted to personnel bound by confidentiality obligations, and is recorded in an audit log available to the Customer's administrators. The Customer may narrow this instruction in writing, subject to TerraVex's ability to provide the affected support and security services.

4. Confidentiality

TerraVex ensures that personnel authorized to process Customer Personal Data are bound by confidentiality and process it only as needed.

5. Security

TerraVex will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art and the risk. These measures are summarized in Annex II and include role-based access control, database row-level security enforcing tenant isolation, field-level restrictions on sensitive data, encryption of data at rest and in transit, authenticated APIs, logging/audit trails, and access minimization.

6. Subprocessors

6.1 The Customer provides general authorization for TerraVex to engage Subprocessors to process Customer Personal Data. The current list is in Annex III, the Subprocessors list at https://app.terravexos.com/legal/subprocessors. 6.2 TerraVex will impose data-protection obligations on each Subprocessor that are substantially the same as those in this DPA and remains responsible for its Subprocessors' performance. 6.3 TerraVex will give notice of intended additions or replacements of Subprocessors by email to the Customer's admin address and by a dated entry in the change log on the Subprocessors list at least 30 days before the change, and the Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve the objection; if unresolved, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees for it.

7. Data-subject requests

Taking into account the nature of processing, TerraVex will provide reasonable assistance (including appropriate technical and organizational measures, and self-service tools in the Service) to help the Customer respond to data-subject requests. If TerraVex receives a request directly, it will (unless legally required to act) refer the data subject to the Customer.

8. Assistance

TerraVex will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security obligations under Data Protection Laws, taking into account the information available to TerraVex and the nature of processing.

9. Personal data breach

TerraVex will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations. Notification is not an acknowledgment of fault.

10. Deletion & return

On termination or expiry of the Service, and at the Customer's choice, TerraVex will delete or return Customer Personal Data (and delete existing copies) within 30 days after the later of termination or restoration of the Customer's export access, except to the extent retention is required by law or for permitted backup cycles, during which the data remains protected by this DPA. If the Customer's only owner deletes their own account in the Service, that is the Customer's instruction to delete all Customer Personal Data and uploaded files at once, without an export period; TerraVex deletes them immediately, subject to the same legal-retention and backup-cycle exceptions. Retention periods that pesticide laws impose on the Customer (for example for application records) are the Customer's to meet by exporting its records; they do not extend TerraVex's retention.

11. Audits

TerraVex will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, security, frequency, and cost conditions; TerraVex may satisfy audit requests by providing third-party certifications or reports where available.

12. Location of processing

The Service is offered to businesses in the United States and Customer Personal Data is processed in the United States, except as noted on the Subprocessors list. TerraVex does not intend to process personal data subject to the EU or UK GDPR. If the parties agree in writing to processing that requires a cross-border transfer mechanism under those laws, they will execute the appropriate standard contractual clauses before that processing begins.

13. CCPA/CPRA (service-provider terms)

TerraVex will process personal information only to perform the Service under the Terms (the "business purpose"), and will not (a) sell or share it, (b) retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purpose, or (c) combine it with other personal information except as permitted by CCPA/CPRA. TerraVex may create and use De-identified data as CCPA/CPRA permits; TerraVex will not attempt to re-identify such data, will maintain it in de-identified form, and will contractually obligate any recipient to the same. TerraVex certifies it understands and will comply with these restrictions.

14. Liability & precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In a conflict between this DPA and the Terms regarding personal-data processing, this DPA controls.


Annex I: Processing details

Annex II: Technical & organizational security measures (summary)

Access control and least-privilege roles; a separate private storage bucket for team member documents uploaded through onboarding links, with no public address, opened only through signed links that expire after one minute and are issued only to the Customer's owner and office roles; row-level security enforcing per-tenant isolation; field-level read/write restrictions on sensitive fields (for example property access codes and integration secrets); server-side re-verification of tenant ownership in privileged operations; authenticated APIs and webhook signature verification for payment events; encryption of data at rest and in transit; audit logging of security-relevant actions, including personnel support access to a Customer workspace; environment secret management; daily backups and recovery; personnel confidentiality; and vulnerability management.

Annex III: Subprocessors

The Subprocessors list at https://app.terravexos.com/legal/subprocessors is incorporated into this DPA.