TerraVex Data Processing Addendum (DPA)
Effective date: on acceptance · Last updated: October 7, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (https://app.terravexos.com/legal/terms) and applies where TerraVex processes Customer Personal Data on behalf of the Customer in providing the Service and where such processing is subject to Data Protection Laws (U.S. state privacy laws such as the CCPA/CPRA and, to the extent they apply, other data-protection laws).
1. Definitions
Terms such as "controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings in the applicable Data Protection Laws. "Customer Personal Data" means personal data within Customer Data. "Subprocessor" means a third party engaged by TerraVex to process Customer Personal Data. "De-identified data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual.
2. Roles
The Customer is the controller (or a processor acting for a third-party controller) of Customer Personal Data, and TerraVex is the processor (or subprocessor). For CCPA/CPRA, TerraVex acts as a service provider. Each party will comply with its obligations under Data Protection Laws. The Customer alone is responsible for records, reports and disclosures that pesticide laws require of it, including any that contain personal data, and TerraVex processes them only as the Customer's processor.
3. Scope & instructions
3.1 TerraVex will process Customer Personal Data only (a) to provide, secure, and support the Service; (b) per the Customer's documented lawful instructions (including the Terms, this DPA, and configuration of the Service); and (c) as required by law (in which case TerraVex will inform the Customer unless legally prohibited). 3.2 TerraVex will notify the Customer if it believes an instruction violates Data Protection Laws (without obligation to provide legal advice). 3.3 The Customer is responsible for the accuracy and lawfulness of Customer Personal Data and for having a valid legal basis and required notices/consents. 3.4 Support access. The Customer instructs TerraVex that authorized TerraVex personnel may access the Customer's workspace, including by operating it with administrator permissions, where reasonably necessary to provide support the Customer has requested (for example, loading data the Customer has sent for import), to investigate and resolve a problem, or to respond to a security or abuse concern. Such access is limited to the purpose, is restricted to personnel bound by confidentiality obligations, and is recorded in an audit log available to the Customer's administrators. The Customer may narrow this instruction in writing, subject to TerraVex's ability to provide the affected support and security services.
4. Confidentiality
TerraVex ensures that personnel authorized to process Customer Personal Data are bound by confidentiality and process it only as needed.
5. Security
TerraVex will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art and the risk. These measures are summarized in Annex II and include role-based access control, database row-level security enforcing tenant isolation, field-level restrictions on sensitive data, encryption of data at rest and in transit, authenticated APIs, logging/audit trails, and access minimization.
6. Subprocessors
6.1 The Customer provides general authorization for TerraVex to engage Subprocessors to process Customer Personal Data. The current list is in Annex III, the Subprocessors list at https://app.terravexos.com/legal/subprocessors. 6.2 TerraVex will impose data-protection obligations on each Subprocessor that are substantially the same as those in this DPA and remains responsible for its Subprocessors' performance. 6.3 TerraVex will give notice of intended additions or replacements of Subprocessors by email to the Customer's admin address and by a dated entry in the change log on the Subprocessors list at least 30 days before the change, and the Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve the objection; if unresolved, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees for it.
7. Data-subject requests
Taking into account the nature of processing, TerraVex will provide reasonable assistance (including appropriate technical and organizational measures, and self-service tools in the Service) to help the Customer respond to data-subject requests. If TerraVex receives a request directly, it will (unless legally required to act) refer the data subject to the Customer.
8. Assistance
TerraVex will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security obligations under Data Protection Laws, taking into account the information available to TerraVex and the nature of processing.
9. Personal data breach
TerraVex will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations. Notification is not an acknowledgment of fault.
10. Deletion & return
On termination or expiry of the Service, and at the Customer's choice, TerraVex will delete or return Customer Personal Data (and delete existing copies) within 30 days after the later of termination or restoration of the Customer's export access, except to the extent retention is required by law or for permitted backup cycles, during which the data remains protected by this DPA. If the Customer's only owner deletes their own account in the Service, that is the Customer's instruction to delete all Customer Personal Data and uploaded files at once, without an export period; TerraVex deletes them immediately, subject to the same legal-retention and backup-cycle exceptions. Retention periods that pesticide laws impose on the Customer (for example for application records) are the Customer's to meet by exporting its records; they do not extend TerraVex's retention.
11. Audits
TerraVex will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, security, frequency, and cost conditions; TerraVex may satisfy audit requests by providing third-party certifications or reports where available.
12. Location of processing
The Service is offered to businesses in the United States and Customer Personal Data is processed in the United States, except as noted on the Subprocessors list. TerraVex does not intend to process personal data subject to the EU or UK GDPR. If the parties agree in writing to processing that requires a cross-border transfer mechanism under those laws, they will execute the appropriate standard contractual clauses before that processing begins.
13. CCPA/CPRA (service-provider terms)
TerraVex will process personal information only to perform the Service under the Terms (the "business purpose"), and will not (a) sell or share it, (b) retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purpose, or (c) combine it with other personal information except as permitted by CCPA/CPRA. TerraVex may create and use De-identified data as CCPA/CPRA permits; TerraVex will not attempt to re-identify such data, will maintain it in de-identified form, and will contractually obligate any recipient to the same. TerraVex certifies it understands and will comply with these restrictions.
14. Liability & precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In a conflict between this DPA and the Terms regarding personal-data processing, this DPA controls.
Annex I: Processing details
- Controller: the Customer (and its Authorized Users). Processor: TerraVex LLC.
- Subject matter & duration: provision of the Service for the subscription term and any wind-down period.
- Nature & purpose: hosting, storage, transmission, display, and processing of Customer Personal Data to operate the pest control operations platform (property plans and measurements, inspections and findings, estimating, treatment plans, scheduling and routing, technician management, service and application records, invoicing/payments facilitation, client portal, recurring service plans, reporting, training, time-clock, team onboarding, company policy distribution and acknowledgement, electronic signatures, and optional integrations and AI features).
- Categories of data subjects: the Customer's staff/Authorized Users, including technicians and applicators; new hires and other Team Members who use an onboarding or signing link without a login; emergency contacts named by Team Members; the Customer's clients and their contacts, including commercial facility contacts; Portal End Users; property occupants and neighbors referenced in job data or notification records; candidates the Customer screens.
- Categories of personal data: identity and contact details; role and account data; property addresses, geolocation, and access details (for example access codes, key location) as entered by the Customer; property plans and measurements, including device and bait station locations; inspection photos, findings and reports (including WDO reports); treatment and application records (products, EPA registration numbers, amounts, target pests, sites, dates, and the applicator's name and license or certification number); notification and posting records; job/estimate/invoice/scheduling records; time-clock records and precise location stamps taken at clock-in/check-in; pay type and pay rate; emergency contacts; Team Member home addresses; applicator license and certification details; uploaded documents (certificates of insurance, licenses and certifications, signed company documents); electronic signature records (typed name, signature image, time, IP address, browser, document hash); policy and notice acknowledgement records (version, statements, time, IP address, device); onboarding progress; background-screening and drug-screening status; texts exchanged with clients and text consent records; photos/reference images, including photos of checks and receipts; walkthrough video frames and voice notes and their AI transcriptions; records of each user's permission for AI processing; usage, log and diagnostic data; payment-related metadata (card data handled by Stripe).
- Special categories: not intended to be processed, except the drug-screening status (for example clear or needs review) that the Customer's own Checkr account returns when the Customer orders a screening; the full results stay with Checkr. The Service is not designed to hold Social Security or taxpayer identification numbers, government ID numbers or images, immigration status, or payment card or bank account numbers, and the Customer agrees not to upload them. The Customer must not submit other special-category data (for example a client's medical sensitivity to pesticides) except where lawful and necessary, such as a notification registry the law requires, and remains responsible for any it submits. Voice inputs are transcribed to text and are not used to create voiceprints or to identify speakers.
- Frequency: continuous, for the duration of the Service.
Annex II: Technical & organizational security measures (summary)
Access control and least-privilege roles; a separate private storage bucket for team member documents uploaded through onboarding links, with no public address, opened only through signed links that expire after one minute and are issued only to the Customer's owner and office roles; row-level security enforcing per-tenant isolation; field-level read/write restrictions on sensitive fields (for example property access codes and integration secrets); server-side re-verification of tenant ownership in privileged operations; authenticated APIs and webhook signature verification for payment events; encryption of data at rest and in transit; audit logging of security-relevant actions, including personnel support access to a Customer workspace; environment secret management; daily backups and recovery; personnel confidentiality; and vulnerability management.
Annex III: Subprocessors
The Subprocessors list at https://app.terravexos.com/legal/subprocessors is incorporated into this DPA.