Data Processing Addendum
This Data Processing Addendum (the "DPA") is entered into between the Customer ("Controller") and LWR Technologies, Inc. d/b/a Kontracks ("Processor" or "Kontracks") and forms part of the Kontracks Terms of Service. It governs Kontracks' processing of Personal Data on Controller's behalf and applies to the extent the EU GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA, the Virginia VCDPA, the Colorado CPA, the Connecticut CTDPA, the Utah UCPA, the Texas TDPSA, or any other applicable data protection law ("Data Protection Laws") applies to the processing of such Personal Data.
By executing the Terms or otherwise accepting the Service, Controller is deemed to have signed this DPA. A countersigned copy is available on request to privacy@kontracks.com.
1. Definitions
Capitalized terms not defined here have the meanings given in the Terms. "Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Sub-processor", and "Supervisory Authority" have the meanings given in the GDPR. "Personal Information" has the meaning given in the CCPA/CPRA. "EU SCCs" means the standard contractual clauses approved by the European Commission's Implementing Decision (EU) 2021/914. "UK Addendum" means the UK International Data Transfer Addendum issued by the Information Commissioner's Office. "Restricted Transfer" means a transfer of Personal Data from a jurisdiction whose data protection law restricts onward transfers to a jurisdiction not recognized as providing adequate protection.
2. Roles & scope
The parties acknowledge that, for purposes of the GDPR and UK GDPR, Controller is the controller (or processor acting on behalf of an upstream controller) of Personal Data uploaded to the Service, and Kontracks is the processor. For purposes of the CCPA/CPRA, Kontracks is a "Service Provider" (and not a "third party") acting under the limited purposes described in this DPA. Kontracks will not (a) "sell" or "share" Personal Information as those terms are defined in the CCPA/CPRA, (b) retain, use, or disclose Personal Information outside of the direct business relationship with Controller, or (c) combine Personal Information received from Controller with Personal Information received from any other source, except as expressly permitted by the CCPA/CPRA for service-provider activities.
3. Details of processing
| Subject matter | Provision of the Kontracks SaaS platform — leads, proposals, jobs, measurements, photos, invoicing, payments, communications (email, SMS), and integrations including QuickBooks Online, Stripe, calendar/contacts/file sync, and materials suppliers — to Controller. |
|---|---|
| Duration | The Subscription Term, plus any Data Export Period and any period required to comply with legal hold or retention obligations under Section 11. |
| Nature & purpose | Hosting, storage, access, retrieval, organization, structuring, transmission, modification (for feature delivery and format conversion), display, deletion, and analysis of Personal Data for the purposes of operating the Service in accordance with Controller's documented instructions. |
| Categories of Data Subjects | Controller's End Customers (homeowners, property owners, decision-makers); Controller's employees, contractors, sales reps, crew members, and other Authorized Users. |
| Categories of Personal Data | Identity (name, postal address, email, mobile and landline phone numbers); property information; consent records and audit metadata; communications content (email, SMS, voice if enabled); employment-context data for Authorized Users; financial-context data necessary to render invoices and reconcile payments (excluding full card numbers, which are tokenized by Stripe). Special category data is not processed except where Controller voluntarily uploads it (e.g., photographs of a property that incidentally include a Data Subject). |
| Frequency | Continuous, throughout the Subscription Term. |
4. Processor obligations
Kontracks will:
- Process Personal Data only on the documented instructions of Controller, including with regard to transfers, unless required to do otherwise by EU, EEA, UK, Swiss, or U.S. federal or state law to which Kontracks is subject; in such case, Kontracks will inform Controller of that legal requirement before processing unless that law prohibits notification on important grounds of public interest. Controller's instructions are set out in (a) the Terms, (b) this DPA, (c) Order Forms, and (d) Controller's configuration of the Service.
- Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement and maintain the technical and organizational measures described in Annex II (Security Measures).
- Respect the conditions for engaging Sub-processors set out in Section 7.
- Taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, for the fulfilment of Controller's obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws (Section 6).
- Assist Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to Kontracks.
- At Controller's choice, delete or return all Personal Data to Controller after the end of the provision of services, and delete existing copies unless EU, EEA, UK, Swiss, or U.S. law requires storage of the Personal Data.
- Make available to Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR (Section 9).
- Notify Controller without undue delay if, in Kontracks' opinion, an instruction infringes the GDPR or other Data Protection Laws.
5. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Kontracks will implement and maintain the technical and organizational security measures described in Annex II to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Kontracks may update Annex II from time to time, provided the changes do not materially decrease the overall level of protection. The current version is published at /legal/security/.
6. Data Subject rights
Kontracks will assist Controller, through appropriate technical and organizational measures and to the extent possible, in fulfilling Controller's obligations to respond to Data Subject requests to exercise rights of access, rectification, erasure, restriction, portability, and objection. The Service provides Controller with self-service tools to view, export, modify, and delete Personal Data for each End Customer. For requests Controller cannot fulfill through the in-product tools, Kontracks will assist within the timeframes required by applicable Data Protection Laws upon written request to privacy@kontracks.com.
If Kontracks receives a request from a Data Subject directly, Kontracks will (a) inform the Data Subject to contact the relevant Controller, and (b) inform Controller of the request without undue delay. Kontracks will not respond to such a request on its own except to confirm Controller's identity or as required by law.
7. Sub-processors
Controller grants Kontracks a general written authorization to engage Sub-processors to process Personal Data, subject to the conditions in this Section. The current list of authorized Sub-processors, including their identity, location, and processing activity, is published at /legal/subprocessors/ (the "Sub-processor List").
Kontracks will:
- Notify Controller in advance of any intended changes concerning the addition or replacement of Sub-processors, by updating the Sub-processor List page and providing email notice to administrators on Controller's account at least fifteen (15) days before the change takes effect.
- Allow Controller to object to such changes by sending a reasoned written objection to privacy@kontracks.com within fifteen (15) days. If Controller objects on reasonable Data Protection grounds and the parties cannot resolve the objection within thirty (30) days, Controller may terminate the affected portion of the subscription and receive a refund of prepaid, unused fees for that portion.
- Enter into a written contract with each Sub-processor that imposes data protection obligations no less protective than those in this DPA, including the requirement to provide sufficient guarantees to implement appropriate technical and organizational measures.
- Remain fully liable to Controller for the performance of each Sub-processor's data protection obligations.
8. International transfers
Kontracks is established in the United States. Where Controller's processing of Personal Data is subject to the GDPR, the UK GDPR, or the Swiss FADP, and the processing involves a Restricted Transfer to Kontracks or its Sub-processors located outside the EEA, UK, or Switzerland in a jurisdiction not recognized as providing adequate protection, the EU SCCs (Module Two: Controller-to-Processor) are incorporated by reference into this DPA, with the following selections:
- Clause 7 (Docking clause): applicable.
- Clause 9(a) (Sub-processors): Option 2 (general written authorization), with a notice period of fifteen (15) days as set out in Section 7.
- Clause 11(a) (Redress): the optional language is not used.
- Clause 17 (Governing law): Irish law.
- Clause 18 (Choice of forum): Irish courts.
- Annex I.A: The data exporter is Controller; the data importer is LWR Technologies, Inc., 390 NE 191st St STE 32488, Miami, FL 33179, USA, contact privacy@kontracks.com.
- Annex I.B: Categories of Data Subjects, categories of Personal Data, frequency, and nature/purpose of processing as set out in Section 3.
- Annex I.C: The competent supervisory authority is the Irish Data Protection Commission.
- Annex II: Security measures as set out in Annex II to this DPA and the Trust & Security Overview.
- Annex III: Sub-processors as listed at /legal/subprocessors/.
For Restricted Transfers from the United Kingdom, the UK Addendum is incorporated, completed by reference to the EU SCCs above. For Restricted Transfers from Switzerland, the EU SCCs apply with the references to the GDPR construed as references to the Swiss FADP and to the competent supervisory authority being the Swiss Federal Data Protection and Information Commissioner.
9. Audits
Kontracks will make available to Controller, on request to privacy@kontracks.com and subject to confidentiality obligations, (a) the most recent third-party audit reports applicable to the Service (e.g., the SOC 2 Type II reports of our hosting providers), (b) responses to Controller's reasonable security questionnaires (limited to once per twelve-month period absent a Personal Data Breach), and (c) other information reasonably necessary to demonstrate compliance with this DPA.
Where the foregoing is insufficient to satisfy a documented audit obligation under Data Protection Laws, Controller may, on at least thirty (30) days' prior written notice and not more than once in any twelve-month period (except following a Personal Data Breach), conduct an audit of Kontracks' processing of Personal Data. The audit will be performed during regular business hours, in a manner that does not unreasonably interfere with Kontracks' operations, by Controller or a mutually agreed independent third-party auditor bound by appropriate confidentiality obligations and subject to a written audit plan agreed in advance. Each party will bear its own costs of the audit. The auditor will not have access to systems or data of other Customers.
10. Personal Data Breach
Kontracks will notify Controller without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a Personal Data Breach affecting Controller's Personal Data. The notification will include, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate adverse effects. Kontracks will provide further information as it becomes available and will assist Controller, at Controller's reasonable request and expense, with regulatory notifications and Data Subject communications.
11. Return or deletion
At Controller's choice and on Controller's written request, Kontracks will delete or return all Personal Data to Controller after the end of the provision of services. Following the Data Export Period set out in the Terms, Kontracks will delete the Personal Data unless EU, EEA, UK, Swiss, U.S. federal, or U.S. state law requires storage. Where deletion is not technically feasible (e.g., immutable backup snapshots), Kontracks will isolate the Personal Data from active processing and ensure it is permanently deleted in accordance with the backup-rotation schedule (currently ninety (90) days).
12. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under applicable law.
13. Order of precedence
If there is any conflict between this DPA and the Terms, this DPA prevails to the extent of the conflict with respect to the processing of Personal Data. If the EU SCCs apply and conflict with this DPA, the EU SCCs prevail to the extent of the conflict.
14. Updates
Kontracks may update this DPA to reflect changes in law, regulatory guidance, or operational practice. Material changes will be notified to Controller at least thirty (30) days in advance. Controller's continued use of the Service constitutes acceptance.
Annex II — Security Measures
The current technical and organizational measures Kontracks implements to protect Personal Data include:
- Encryption in transit: TLS 1.2 or higher for all client-server connections and all sub-processor API calls.
- Encryption at rest: Database storage encrypted using AES-256. Backups encrypted at rest. Column-level AES-256-GCM encryption for sensitive credentials including OAuth refresh tokens, payment processor keys, and Third-Party Service API keys.
- Access control: Role-based access control for Authorized Users; least-privilege access for Kontracks personnel; mandatory password complexity and rotation; SSO integration available; multi-factor authentication available on every Customer account.
- Tenant isolation: Logical isolation by tenant identifier on every record. Every database query is scoped to the requesting tenant at the application layer. Cross-tenant access requires elevated operator authorization and is logged.
- Audit logging: Authentication events, administrative actions, financial-record changes, and access to sensitive integrations are logged with user attribution and timestamp. Logs are retained for at least one year.
- Network controls: Web Application Firewall, DDoS mitigation, rate limiting, and bot protection at the edge.
- Vulnerability management: Continuous dependency scanning; regular penetration testing by independent third parties; documented patch management.
- Incident response: Documented runbook with defined roles, escalation paths, and communications templates; tabletop exercises performed at least annually.
- Personnel: Background checks for personnel with production access; annual security training; written confidentiality agreements.
- Vendor management: Sub-processors selected for SOC 2 or equivalent assurance posture; written data processing agreements with each Sub-processor.
- Business continuity: Geographically distributed database replicas; automated backups; documented recovery objectives (RTO ≤ 4 hours, RPO ≤ 1 hour for Tier-1 data).
Contact
Privacy questions: privacy@kontracks.com.
Legal: legal@kontracks.com.
Mailing address: LWR Technologies, Inc. · 390 NE 191st St STE 32488 · Miami, FL 33179 · United States.
KONTRACKS