Skip to content
Trust & legal

Data processing agreement

How Soffyt processes personal information for your organization, including instructions, security, service providers, privacy requests, and deletion.

1. Agreement, version, and scope

Version: September 23, 2026. This Data Processing Agreement (DPA) is between Soffyt LLC, doing business as Soffyt, and the Customer identified in the parties’ accepted subscription agreement or order (Service Agreement). It takes effect when both parties accept it by signature or expressly incorporate this version into an accepted order or written amendment. Reading this page does not execute a DPA. This DPA governs personal information Soffyt processes on Customer’s behalf through the purchased service (Customer Personal Data).

  • Applicable Data Protection Law means privacy, data-protection, and data-security law that applies to the parties’ processing of Customer Personal Data. Personal information, controller, processor, business, service provider, contractor, sale, and sharing have the meanings given by that law where applicable.
  • This DPA, including the processing description and security commitments below, controls conflicts concerning Customer Personal Data. Other terms of the Service Agreement continue to apply, including its liability provisions to the extent permitted by law. No contractual limit reduces a person’s statutory rights or a regulator’s authority.
  • The DPA remains in effect while Soffyt or its subprocessors retain Customer Personal Data. Material amendments require the parties’ written agreement, including electronic acceptance; changing this webpage alone does not amend an executed DPA.
Read the Terms of Service

2. The parties’ roles

Customer determines the purposes and means of processing its organization’s personal information. Soffyt processes Customer Personal Data on Customer’s behalf as a processor, service provider, or contractor, as applicable. If Customer itself acts for another controller, Customer must have that controller’s authority to appoint Soffyt and give the instructions in this DPA. The parties’ roles depend on their actual activities and applicable law, not solely on the labels used here.

  • Customer is responsible for the lawfulness of its collection, notices, instructions, sharing choices, and any required consent. Customer must limit data to what its supported workflow requires, control authorized users, and communicate relevant restrictions to Soffyt.
  • Soffyt’s own account administration, subscription billing, website inquiries, and other activities for which it independently determines the purposes are addressed by the privacy policy and applicable law. Soffyt will not reclassify Customer’s workspace content as its own business data to avoid this DPA’s restrictions.
Read the privacy policy

3. Documented instructions and permitted purposes

Customer instructs Soffyt to process Customer Personal Data for the specific purposes described in Section 12, using the features and integrations Customer authorizes. The Service Agreement, this DPA, authorized configuration choices, and verified written requests constitute documented instructions. Soffyt will process only on those instructions unless law requires otherwise. Where legally permitted, Soffyt will inform Customer of such a legal requirement before processing outside the instructions.

  • Soffyt will promptly inform Customer if it believes an instruction violates Applicable Data Protection Law and may pause the affected instruction while the parties resolve the issue. Customer must not instruct Soffyt to circumvent another person’s rights or an integration provider’s restrictions.
  • An instruction for a new type of processing or specialized data must be agreed in writing before it is carried out. An ordinary support request does not authorize an undisclosed new purpose or unlimited access to workspace information.

4. Restrictions on use and disclosure

Soffyt will not sell Customer Personal Data, share it for cross-context behavioral advertising or targeted advertising, use it to build advertising profiles, or use Customer content to train AI or machine-learning models. Soffyt will not retain, use, or disclose Customer Personal Data outside the direct business relationship or for purposes other than the specific purposes in this DPA, except as expressly permitted by Applicable Data Protection Law and consistent with the additional restrictions in this section.

  • Where the CCPA applies, Soffyt will comply with the applicable CCPA and implementing regulations and provide the same level of privacy protection required of the business. Soffyt will not combine Customer Personal Data with personal information received from another customer or person, or collected through Soffyt’s own interactions with individuals, except as expressly permitted by the CCPA and its regulations. Soffyt certifies that it understands and will comply with these restrictions.
  • Customer provides the information only for the limited, specified purposes in Section 12. Permission to secure or maintain the service does not authorize unrelated commercial use of Customer Personal Data.
  • Google API data remains subject to the Google API Services User Data Policy and Google Workspace user-data policy, including Limited Use. Broader language in this DPA does not expand authorized scopes, permit prohibited transfers or human access, or override those restrictions. The additional Google commitments in the privacy policy continue to apply.
  • If Soffyt determines it can no longer meet its data-protection obligations, it will notify Customer without undue delay. Upon notice, Customer may take reasonable and appropriate steps, with Soffyt’s cooperation, to stop and remediate unauthorized processing, including requiring evidence of correction or deletion.

5. Confidentiality and security

Soffyt will ensure that personnel permitted to process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty. Access will be limited to authorized people with a need to perform the agreed processing. Soffyt will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data and risks, including the commitments in Section 13.

  • Soffyt will assess and maintain safeguards as the service and risks change. Changes will not materially reduce the overall protection of Customer Personal Data during the Service Agreement.
  • Customer must configure access, secure its accounts and devices, and review external sharing. These responsibilities do not relieve Soffyt of its own security obligations.

6. Subprocessors and authorized integrations

A subprocessor is a provider engaged by Soffyt to process Customer Personal Data on Customer’s behalf. Before processing under this DPA begins, Soffyt will give Customer a written subprocessor schedule identifying each provider, its service purpose, the categories of data it processes, and processing locations, including relevant remote-access locations. Customer authorizes the subprocessors identified in that schedule when accepting it with this DPA. The public provider overview supplies context; it does not replace the customer-specific schedule.

  • Soffyt will assess each subprocessor and enter a written agreement imposing data-protection duties appropriate to its processing and no less protective than this DPA’s applicable duties. Soffyt remains responsible to Customer for the subprocessor’s performance of those duties.
  • Soffyt will give Customer at least 30 days’ written notice before a new or replacement subprocessor processes its data, identifying the provider, purpose, data categories, and locations. Customer may object during that period on reasonable data-protection grounds. Silence after the notice period constitutes authorization unless the accepted schedule or applicable law requires express consent.
  • If Customer objects, the parties will work in good faith to resolve the concern before the new processing starts. If they cannot resolve it, Soffyt will avoid using that provider for Customer’s data or either party may terminate the affected service, with a prorated refund of prepaid fees for the unused portion. Soffyt will not start the disputed processing while the objection is unresolved.
  • Customer may separately instruct a transfer to an integration or recipient it chooses. A provider’s independent processing of its own account, payment, or other service information follows that provider’s terms. A provider is still a subprocessor for any activity in which it actually processes on Soffyt’s behalf; an integration label does not remove this section’s protections.
Review service providers and connected services

7. Assistance with requests and assessments

Taking account of the processing and information available to it, Soffyt will assist Customer with its duties under Applicable Data Protection Law, including requests to access, correct, copy, delete, restrict, or opt out of processing; applicable appeals; security duties; and required privacy risk assessments, audits, and consultations. Customer should send instructions to privacy@soffyt.com with the relevant organization, scope, and applicable deadline. Soffyt will provide assistance without undue delay and in time to support applicable legal deadlines.

  • If Soffyt receives a request about Customer-controlled records directly, it will promptly refer or forward it to Customer as appropriate and will not make a substantive decision on Customer’s behalf without instructions, unless legally required. Soffyt may acknowledge the request and explain the appropriate contact route.
  • Customer is responsible for verifying requests and deciding its response unless the parties agree that Soffyt will assist with verification. Soffyt will verify the authority of anyone requesting access to organization data before releasing it.
  • Soffyt will provide relevant information in its possession or control for required assessments and audits. Any fee for additional work beyond included assistance must be agreed in advance and may not obstruct an obligation or assistance that must be provided under applicable law.
Send a processing instruction or request

8. Personal-data incidents

A Personal Data Incident is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Soffyt or its subprocessors. Soffyt will notify Customer without undue delay after becoming aware of an incident, and immediately where applicable law requires immediate notice. Notification will not wait for a completed investigation. Soffyt will use Customer’s designated privacy or security contact, or its account contact if no separate contact is recorded.

  • As information becomes available, Soffyt will describe the nature and timing of the incident, affected data and individuals or records, likely consequences, containment and remediation steps, and a contact for follow-up. Information may be supplied in stages with timely updates.
  • Soffyt will investigate, take reasonable steps to contain and remediate the incident, preserve relevant evidence, and cooperate with Customer’s response and required notices. Customer determines notices concerning its controlled records unless law requires Soffyt to notify directly. The parties will coordinate where lawful; neither party may delay a notice required by law.
  • Unsuccessful attempts that do not compromise Customer Personal Data are not Personal Data Incidents under this definition. Notification is not by itself an admission of fault, and the definition does not narrow a notification duty imposed by applicable law.

9. Information, audits, and remediation

Soffyt will make available information reasonably necessary to demonstrate compliance with this DPA and allow and contribute to reasonable assessments and audits by Customer or an independent assessor bound by confidentiality. The parties will ordinarily begin with relevant documentation and available assessment reports. Customer may seek further inspection or testing when reasonably necessary to verify compliance, address a credible concern, or satisfy applicable law or a regulator.

  • The parties will coordinate reasonable notice, scope, timing, and safeguards to protect service availability, confidential information, and other customers’ data. Those arrangements may not frustrate meaningful verification, urgent investigation, or a statutory or regulatory right of access.
  • Customer may take reasonable and appropriate steps to confirm that Soffyt uses Customer Personal Data consistently with Customer’s applicable legal obligations. Soffyt will address substantiated deficiencies and provide information about the corrective measures.
  • A questionnaire or a description of controls is not a certification. Soffyt will identify the scope and date of any report it supplies rather than imply an audit or certification that has not occurred.

10. Return, deletion, and retained copies

At Customer’s choice and on its verified instructions, Soffyt will return or delete Customer Personal Data when the processing service ends and delete remaining copies unless applicable law requires retention. Soffyt will carry out the instruction without undue delay, coordinate the available return format and timetable with Customer, and explain any specific legal or technical limitation. Customer should request needed copies before closure; this DPA does not promise a self-service export tool or continued application access after termination.

  • Deletion instructions apply to eligible data held by subprocessors as well as Soffyt. On request, Soffyt will confirm completion and identify any data still retained, its justification, and applicable retention criteria. Retention must be limited to what the specific obligation requires.
  • Residual backups remain protected and isolated from ordinary processing until overwritten or expired under the applicable documented backup lifecycle. Soffyt will disclose the applicable lifecycle to Customer on request. If a backup is restored, applicable deletion instructions will be reapplied. Backup timing does not extend a legal deadline for responding to a request or authorize continued ordinary use.
  • Disconnecting an integration, archiving a record, removing a user, cancelling billing, and deleting an organization are distinct actions. Source records retained independently by Customer’s integration provider or message recipients are outside Soffyt’s deletion control. Soffyt will explain which copies its response covers.

11. Processing locations and legal demands

A U.S. customer relationship does not itself mean all processing or provider support occurs within the United States. The accepted subprocessor schedule and any written residency commitment identify the permitted locations. Before making a transfer subject to additional legal safeguards, the parties will establish the required lawful transfer mechanism and any supplemental measures. This DPA alone is not an executed international transfer mechanism or a commitment to a particular data-residency region.

  • Customer must identify any required geographic or regulated-processing restriction before the affected use begins. Soffyt will not carry out processing that requires an additional agreement or safeguard until it is in place.
  • If Soffyt receives a legally binding demand for Customer Personal Data, it will assess the demand, disclose only what it is legally required to disclose, and notify Customer where legally permitted. Soffyt will consider reasonable grounds to challenge an unlawful or disproportionate demand and cooperate with lawful efforts to protect the data.

12. Processing description

The subject matter is delivery of Customer’s purchased contractor-management service. Processing occurs on an ongoing basis during authorized use and afterward only as necessary to complete return or deletion and meet specific lawful retention duties. The scope is limited to enabled features, Customer’s instructions, and the data actually supplied. A description here does not make an unavailable feature part of Customer’s subscription.

  • People: Customer’s users, employees, contractors, applicants where lawfully included, prospects, customers, property contacts, suppliers, signers, portal visitors, and people corresponding with authorized connected accounts.
  • Customer relationships and jobs: names, business/contact details, property and billing addresses, leads, appointments, assignments, project and service records, notes, and correspondence. Purposes: organize customer relationships, plan and deliver work, and provide Customer’s service history.
  • Documents and field records: quotes, contracts, invoices, templates, signatures and acceptance evidence, photographs, attachments, comments, and associated metadata. Purposes: prepare, store, retrieve, share, and document Customer’s work and transactions.
  • Connected communications: authorized account identities, access credentials, participants, message content and attachments, timestamps, and supported message state. Purposes: operate the authorized visible communication and document-template functions and associate records as instructed. Access remains limited by provider authorization and policy.
  • Commercial records: invoice amounts, balances, payment status, transaction references, connected payment-account identifiers, refunds, and disputes. Purposes: reconcile Customer’s invoices and administer enabled payment workflows. Full card numbers and security codes must use the designated payment provider’s flow rather than ordinary workspace fields.
  • Dispatch and work time: precise phone coordinates, accuracy, available speed and heading, observation/receipt timestamps, user/organization/shift associations, sharing-session start/end records, shift punches, visit timers, and attributed corrections. Purposes: provide technician-enabled live location during active shifts, coordinate field work, and review recorded time. Background updates require device permission. The live feed replaces the latest point rather than building a route history and removes it when the server processes the end of sharing or the shift; undelivered stops and backup handling require separate lifecycle controls. Customer must provide required worker notices and establish an appropriate lawful basis; device permission alone does not establish it.
  • Fleet records: vehicle details, VIN, driver assignments, entered odometer readings, maintenance templates and schedules, and dated service records with providers, costs, and notes. Purposes: manage Customer’s vehicles and maintenance history. Mileage is entered by authorized users rather than inferred from GPS.
  • Workspace access and technical records: user roles, memberships, authentication/access events, network and device identifiers, error records, and portal/document activity. Purposes: authenticate and authorize use, maintain attribution, troubleshoot, prevent misuse, and secure Customer’s service.
  • Operations: collection, recording, organization, storage, retrieval, authorized modification and sharing, transmission to approved providers or instructed recipients, restriction, return, and deletion. Human access is limited by Section 5 and any stricter provider restrictions.
  • Sensitive information: precise location is processed only for the enabled dispatch purposes and safeguards described above. Ordinary notes, email, and files are not intended for passwords, government identification numbers, health records, or other specialized regulated data. If Customer’s content nevertheless contains sensitive information, it remains protected by this DPA; its presence does not expand the permitted purpose. Any supported specialized processing must be agreed before use, including the necessary restrictions and safeguards.

13. Security commitments

The following measures form part of Soffyt’s obligations under this DPA. They describe the required protection of Customer Personal Data, rather than a certification or a guarantee that incidents cannot occur. Specific additional commitments, including a recovery target or dedicated region, require a written agreement.

  • Access: enforce authenticated access, organization-based permissions and least-privilege administration; review privileged access and remove it when no longer needed. Personnel access must remain subject to confidentiality and authorized purposes.
  • Transport and credentials: use encrypted network connections for service access and data transfers; protect authorization credentials from public access, logs, and unauthorized users; revoke or remove stored integration credentials when the authorized connection is ended.
  • Files and organization boundaries: restrict private file access, apply organization scope to storage and record access, and limit shared links and downloads to intended authorized access. Configure any scanning provider under the subprocessor requirements.
  • Operations: maintain relevant security and access logs, address vulnerabilities according to risk, control production changes, and maintain procedures for investigating and responding to incidents. Limit personal information in diagnostic records to what is needed.
  • Recovery and lifecycle: maintain protected backup and recovery procedures appropriate to the service, periodically check restoration procedures, document retention and deletion handling, and reapply deletion restrictions following restoration.
  • Providers and people: assess providers’ relevant protections, bind them to appropriate written duties, and make personnel aware of their confidentiality, access, and incident-reporting responsibilities.

14. Contacts and execution

For a DPA, processing instructions, provider information, or privacy requests, contact privacy@soffyt.com. Identify your legal business name, Soffyt organization, authorized representative, and any required processing restrictions. Soffyt and Customer will identify the Service Agreement, this DPA version, applicable subprocessor schedule, privacy/security contacts, and any agreed supplemental terms in the acceptance record. A representative accepting for a party must have authority to bind it.

  • Soffyt LLC, doing business as Soffyt. 7 Sherburne Hills Rd, Danville, CA 94526, United States. Privacy contact: privacy@soffyt.com. Contractual questions: hello@soffyt.com.
  • Customer’s identity and authorized contact details are those recorded in its accepted order or DPA acceptance record. Customer must keep incident and privacy contacts current.
Arrange a DPA for your organization
People behind the platform

Let’s get you to the right place.

Questions about Soffyt? We’re here to help.

Contact support