Data Processing Addendum
Last updated: June 2026 · draft
This addendum describes how ServiceProof processes personal information on behalf of a customer organization. It supplements the Terms of Service.
Roles
For personal information collected through your use of the service (for example, technicians’ self-attested details in service records, and the emails of colleagues you invite), your organization is the controller and ServiceProof is the processor, acting on your instructions. Billing-contact information we collect to run your subscription is handled as described in our Privacy Policy.
Scope of processing
- Categories of data: technician self-attested name, company, notes, and optional photos in service records; member and invitee email addresses; building/equipment records.
- Purpose: to provide the maintenance-logging and compliance features you use, as instructed by your organization.
- Duration: for the term of your account, subject to the retention practice below.
Sub-processors
We use the following sub-processors. We will keep this list current and give notice of material changes:
- Supabase (Canada) — hosting, database, file storage, authentication. Data is stored in the ca-central-1 region.
- Stripe, Inc. (United States) — subscription billing.
- Resend, Inc. (United States) — transactional email delivery.
- Anthropic (United States) — automated extraction of uploaded maintenance contracts (used only when you upload one).
International transfers
Data is stored in Canada at rest. Certain sub-processors above are located in the United States; personal information shared with them is subject to U.S. law. We disclose these transfers in our Privacy Policy and at the point of collection where applicable.
Security
We protect personal information with measures appropriate to its sensitivity, including authenticated access, organization-level data isolation, private storage for uploaded photos with short-lived access links, and signed-request verification on payment webhooks.
Retention & deletion
Service records are retained for a rolling 36-month window, after which identifying details are redacted while a de-identified proof skeleton (equipment, date, checklist) is kept as a maintenance-compliance record. Redaction can also be performed by our staff, at our discretion for validated requests (audited). After your account ends, personal information continues to be handled under this redaction practice; the de-identified skeleton may be retained as a compliance record. Contact us to discuss deletion of any remaining personal information we hold as processor.
Assistance
We will reasonably assist your organization in responding to individuals exercising their rights under applicable privacy law, and in meeting your own obligations as controller.