Data Processing Addendum
Last updated: June 12, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between WebWork CRM LLC ("WebWork", "we", "Processor") and the customer that accepts the Terms ("Customer", "Controller"). It applies whenever we process personal data contained in Customer Data on the Customer's behalf. It is accepted electronically by creating an account or using the Service — no signature is required, though we will countersign a copy on request.
1. Roles & scope
- The Customer is the controller of the personal data it and its team enter into the Service (its own customers' names, addresses, contact details, service history, photos, notes, and payment records — "Customer Personal Data").
- WebWork is the processor and processes Customer Personal Data only to provide, secure, and support the Service, per the Customer's documented instructions (the Terms, settings the Customer configures, and use of Service features), and as required by law.
- WebWork acts as an independent controller for its own business records (the Customer's account, billing, and support history), as described in the Privacy Policy.
2. Details of processing
- Subject matter & duration: operation of the WebWork field-service platform for the term of the subscription, plus the post-termination export window.
- Nature & purpose: hosting, storage, transmission, display, backup, and related technical processing needed to run scheduling, routing, invoicing, communications, and the customer portal.
- Categories of data subjects: the Customer's customers and prospects, staff users, and technicians.
- Categories of personal data: contact details, service addresses, service and billing history, communications content (email/SMS the Customer sends), photos and documents, and technician activity (e.g., visit check-ins and location while on the clock, where the Customer enables those features).
- Special categories: the Service is not designed for special-category data; the Customer agrees not to store it.
3. Our obligations
- Instructions. Process Customer Personal Data only as described above; if we believe an instruction violates data-protection law, we will tell you.
- Confidentiality. Personnel with access are bound by confidentiality obligations and access only what their role requires.
- Security. Maintain the technical and organizational measures in Annex A. We will not materially reduce them during your subscription.
- Breach notice. Notify you without undue delay (and within 72 hours of confirmation) of a personal-data breach affecting Customer Personal Data, with the information reasonably needed for your own notifications.
- Assistance. Provide reasonable help with data-subject requests (access, correction, deletion, export), security assessments, and regulator inquiries. The Service's export and deletion tools are the first line for fulfilling requests.
- Deletion & return. Customer Data remains exportable (CSV) during your subscription and for at least 30 days after termination, after which it is deleted from production systems; backups expire on a rolling schedule.
- Audit. On written request (no more than annually, absent a breach), we will provide documentation of our security practices reasonably sufficient to demonstrate compliance with this DPA.
4. Subprocessors
You authorize the subprocessors listed at /subprocessors. We remain responsible for their performance, bind them to data-protection obligations no less protective than this DPA, and will give you advance notice before adding or replacing a core subprocessor so you can object on reasonable data-protection grounds.
5. International transfers
The Service is hosted in the United States. If you are subject to laws restricting international transfers (e.g., GDPR/UK GDPR), contact us at support@webworkcrm.com before storing in-scope personal data, and we will discuss appropriate transfer mechanisms.
6. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. The Customer is responsible for the accuracy and lawfulness of Customer Personal Data, including any consents needed to contact its customers.
Annex A — Technical & organizational measures
- TLS encryption for all data in transit.
- Strict multi-tenant isolation: every query is scoped to the owning company at the database layer, with automated enforcement.
- Passwords hashed with Argon2id; password-reset and session tokens stored only as hashes; integration credentials encrypted at rest.
- Role-based access control for staff users; customer-portal users see only their own records.
- Audit logging of security-relevant events; rate limiting and account-lockout protection on authentication.
- Managed database with automated backups; documented schema-migration safety procedures.
- Card data handled exclusively by Stripe (PCI DSS Level 1); it never touches WebWork servers.
- Error monitoring scrubbed of credentials and secrets.
Contact
Privacy and data-processing questions: support@webworkcrm.com. We will countersign a mutually executed copy of this DPA on request.