Version 1.0-draft · 2026-08-24

Data Processing Addendum

Controller-processor terms for Customer Personal Data processed by FieldScroll.

This Data Processing Addendum (the "DPA") forms part of the Agreement between the Customer identified in an Order Form ("Customer") and Thirtysix Solutions, LLC ("Provider") for FieldScroll. It applies when Provider processes Customer Personal Data on Customer's behalf.

1. Definitions and roles

"Applicable Data Protection Law" means privacy, data-protection, and breach-notification law that applies to the processing described in the Order Form. "Customer Personal Data" means personal data or personal information contained in Customer Data that Provider processes on Customer's behalf. "Data Subject," "Controller," "Processor," "Business," "Service Provider," and "Process" have the meanings given by Applicable Data Protection Law.

Customer is the Controller or Business and Provider is the Processor or Service Provider unless Applicable Data Protection Law assigns a different role. Each party is independently responsible for its own compliance duties.

2. Documented instructions

Provider will process Customer Personal Data only on Customer's documented instructions in the Agreement, Order Form, configured workflows, and authorized support requests, unless law requires other processing. Provider will notify Customer before legally required processing unless law prohibits notice.

Provider will promptly inform Customer if an instruction appears to violate Applicable Data Protection Law. Provider may suspend the affected processing while the parties resolve the instruction.

Customer will ensure that its instructions are lawful and that it has provided required notices and obtained required rights, consents, or legal bases. Customer will not submit Restricted Data unless the Order Form expressly identifies it and Provider accepts it in writing.

3. Personnel and confidentiality

Provider will limit access to personnel and approved subprocessors who need access to perform the Agreement, ensure they are bound by confidentiality obligations, and provide appropriate privacy and security instructions.

4. Security

Provider will implement and maintain the technical and organizational measures in Attachment 3, taking into account the state of the art, implementation cost, nature and purposes of processing, and risks to individuals. Customer is responsible for configuring roles, users, retention, integrations, devices, and available security features appropriately.

No system can eliminate all risk. The measures are not a warranty that a Security Incident will never occur. Provider may update measures if the overall level of protection is not materially reduced during an active paid Order Term.

5. Security Incidents

"Security Incident" means confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Customer Personal Data in Provider's possession or control. It excludes unsuccessful attempts, events affecting only Customer-controlled systems or credentials, and activity that does not compromise Customer Personal Data.

Provider will notify Customer without unreasonable delay after confirming a Security Incident and, where feasible, within 72 hours after confirmation. Notice will include reasonably available information about the nature, affected data and individuals, likely consequences, containment, and a contact. Provider may provide information in phases and will take commercially reasonable containment and remediation steps.

Customer is responsible for determining whether notices to individuals, regulators, customers, employees, insurers, or others are required, except to the extent law assigns a duty directly to Provider. Provider will reasonably assist at Customer's expense unless the Security Incident resulted from Provider's breach of this DPA.

6. Subprocessors

Customer gives general authorization for Provider to use subprocessors listed in Attachment 2. Provider will contractually require a subprocessor that processes Customer Personal Data to protect it consistently with this DPA. Provider remains responsible for the subprocessor's performance of those obligations to the extent required by law.

Provider will give at least 15 days' advance notice of a new subprocessor during an active paid Order Term when reasonably practicable. Customer may object on reasonable documented data-protection grounds within 10 days. The parties will work in good faith on an alternative; if none is commercially reasonable, either party may terminate the affected processing without penalty, and Customer's sole refund is prepaid unused fees for the terminated portion.

For a no-fee pilot, Customer's remedy for an unresolved subprocessor objection is to stop the affected feature or terminate the pilot.

7. Data-subject requests

Taking into account the nature of processing, Provider will reasonably assist Customer with access, correction, deletion, restriction, portability, and objection requests to the extent Customer cannot fulfill them through available controls. Provider may refer a requester to Customer unless law requires a direct response.

Customer is responsible for verifying the requester, determining whether a right applies, and providing lawful instructions. Provider may charge reasonable fees for assistance that is disproportionate, repetitive, or outside standard Service functionality unless the need resulted from Provider's breach.

8. Assessments, consultations, and audits

Provider will provide information reasonably necessary for Customer's data-protection assessment or regulator consultation regarding the Service. Provider will make available then-current security and privacy documentation reasonably sufficient to demonstrate compliance with this DPA.

No more than once per 12 months, unless a Security Incident or regulator requires more, Customer may request a remote audit of Provider's relevant controls on at least 30 days' notice. The parties will first use questionnaires, policies, summaries, and independent reports. Onsite review requires a genuine unmet need, confidentiality, scope limits, no access to other customers' data or Provider secrets, no disruption, and Customer payment of reasonable costs. Customer may not conduct penetration testing without written permission.

9. Return, deletion, and retention

During the Order Term, Customer may retrieve records through the Service's API and configured integrations, and may request an export at any time. On request, and for 30 days after the Agreement ends (or a longer export window stated in the Order Form), Provider will deliver submitted records in CSV or JSON format and attached media as a per-organization archive within ten business days.

After the export window, Provider will delete Customer Personal Data from active systems and from Provider-managed media backups within 30 days, unless law requires retention, following Provider's documented organization-deletion procedure. Copies in the provider-managed database backups expire on the seven-day backup cycle stated in Attachment 3, remain protected, and will not be restored except for disaster recovery or legal necessity. Provider does not delete Customer Data automatically during the Order Term.

Submitted operational records may be retained or de-identified under Customer's lawful instructions when Customer is required to preserve them. Provider will not promise deletion that would conflict with Customer's documented retention obligation; the parties will agree on de-identification or access restriction.

10. International transfers

Provider processes Customer Personal Data in the United States: database, authentication, and file storage in Supabase's US East region; document rendering and managed connectors in Fly.io's Ashburn, Virginia region; web application hosting on Vercel in the United States. Customer will not submit personal data subject to an international transfer restriction unless the Order Form identifies the jurisdiction and the parties implement a lawful transfer mechanism before processing. If required, the parties will execute applicable standard contractual clauses and supplementary measures.

11. U.S. state privacy terms

To the extent Provider is a Service Provider, Contractor, or Processor under applicable U.S. state privacy law, Provider will not sell or share Customer Personal Data, retain/use/disclose it outside the direct business relationship or permitted business purposes, combine it with personal data from another source except as permitted by law, or use it for targeted advertising. Provider will notify Customer if it can no longer meet these obligations and allow reasonable steps to stop and remediate unauthorized use.

12. Liability and conflict

This DPA is subject to the exclusions and liability caps in the FieldScroll Terms of Service or a specifically identified master services agreement. If this DPA conflicts with another Agreement document on processing Customer Personal Data, this DPA controls. The rest of the Agreement remains unchanged.

Attachment 1 - Processing details

ItemDetail
Subject matterHosting and operating the FieldScroll pilot and the selected capture, review, document, export, and routing workflow.
DurationThe Order Term, the 30-day export window, the 30-day deletion period, and the seven-day database backup cycle.
Nature and purposeAccount administration; mobile/web capture; offline synchronization; review and approval; document and export generation; routing/integrations; support; security; and service operations.
Data subjectsAuthorized Customer users; Customer employees or contractors; and other people appearing in pilot records only as approved in the Order Form.
Data categoriesBusiness contact and account data (name, email, hashed password, roles); workflow records and text responses; photos and files; signatures; timestamps; device metadata attached to every mobile submission (device model, operating system and version, application version) and delivered with the record to Customer-configured integrations; sign-in and request metadata (IP address, user agent) in security and audit logs; and location coordinates with accuracy, altitude, heading, and speed only where a Customer-designed form includes a location field and the user captures it.
Restricted DataNone unless specifically listed and accepted in the Order Form. Do not sign with an ambiguous Restricted Data field.
Customer instructionsAgreement documents, configured workflows, administrator actions, and authorized written support requests.

Attachment 2 - Subprocessor schedule

Verified against the production environment on 2026-08-24. The same schedule is published at https://www.fieldscroll.com/legal/subprocessors and is updated under Section 6.

SubprocessorLocationPurposeData processedProcessing regionTerms
Supabase Pte. Ltd.65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513Database, authentication, file storage, serverless functions, secrets vaultAll Customer Data and account dataAWS US Easthttps://supabase.com/legal/dpa
Vercel Inc.Delaware; 440 N Barranca Ave #4133, Covina, CA 91723Web dashboard and API hostingAll dashboard and API traffic including record content, IP addressesUnited Stateshttps://vercel.com/legal/dpa
Fly.io, Inc.2261 Market Street #4990, San Francisco, CA 94114Document rendering (PDF/HTML from records) and managed data connectorsFull record content and images for rendering; record payloads and destination credentials for connectorsAshburn, Virginiahttps://fly.io/legal/data-privacy-framework/
Anthropic, PBCSan Francisco, CAAI assistant for form, report, and integration authoring (off unless enabled in the Order Form)User messages, form and report definitions, user-attached images; not used for training; deleted within 30 daysUnited Stateshttps://www.anthropic.com/legal/data-processing-addendum
Sinch Email (Mailgun), a business unit of Sinch ABLindhagensgatan 74, 112 18 Stockholm, SwedenTransactional email (sign-in, invitations, report deliveries) and website contact formEmail addresses, invitation content, rendered report attachments containing record contentUnited States sending regionhttps://www.mailgun.com/legal/dpa/
Plus Five Five, Inc. (Resend)2261 Market Street #5039, San Francisco, CA 94114Alternate transactional email transport (not the default)Same as above when selectedUnited Stateshttps://resend.com/legal/dpa
Functional Software, Inc. (Sentry)45 Fremont Street, 8th Floor, San Francisco, CA 94105Error monitoring for the web application and server functions (not the mobile application)Stack traces, request identifiers, organization identifiers; incidental payload fragments in error messagesUnited Stateshttps://sentry.io/legal/dpa/
Better Stack, Inc.United StatesLog management, uptime monitoring, and alerting for web, mobile, server functions, and databaseStructured logs: user and organization identifiers, routes, error text, mobile device platform and app versionUnited Stateshttps://betterstack.com/dpa
PostHog, Inc.2261 Market St. #4008, San Francisco, CA 94114Product analytics for web, website, and mobile application (session replay disabled)Event names with user, organization, form, and record identifiers; IP address; device and browser metadata; no record contentsUnited Stateshttps://posthog.com/dpa
Mapbox, Inc.San Francisco, CAMap display for location fields in the mobile applicationDevice IP address and map viewport when a location field renders a mapUnited Stateshttps://www.mapbox.com/legal/dpa
Cloudflare, Inc.101 Townsend Street, San Francisco, CA 94107Bot protection on the website contact formVisitor IP address and challenge token; no Customer DataUnited Stateshttps://www.cloudflare.com/cloudflare-customer-dpa/
Apple Inc. / Google LLCCupertino, CA / Mountain View, CAMobile application distributionStore account data and operating-system crash reports; no Customer Data from ProviderUnited StatesApple Developer Program License Agreement; Google Play Developer Distribution Agreement

Not subprocessors (Customer-configured destinations): Salesforce, Customer databases, webhook endpoints, and email recipients of report deliveries. Build-time only, no Customer Data: 650 Industries, Inc. (Expo/EAS) and GitHub, Inc.

Attachment 3 - Technical and organizational measures

Access control: unique accounts; five defined organization roles plus an instance-owner role; least-privilege form access resolved through direct, team, and collection grants; administrator actions on organizations, memberships, roles, and form publication are audit-logged. Multi-factor authentication is not currently offered. Passwords require a minimum of 10 characters with mixed character classes.

Encryption: TLS for all data in transit. Provider-managed encryption at rest for the database, file storage, and backups. Data cached on mobile devices relies on device operating-system storage encryption; the application does not apply separate encryption to its local database.

Tenant separation: shared environment. Each customer organization is isolated by database row-level security policies bound to organization membership; media storage is private by default with time-limited signed URLs (one hour). A deactivated organization denies every member and ends their signed-in sessions.

Secure development: source control with branch protection, code review on pull requests, automated tests (database, web, mobile) on every change, staged promotion (staging to production), and dependency advisory review.

Logging and monitoring: security-relevant application logs shipped to Better Stack from the web tier, mobile application, server functions, and database; error monitoring with Sentry on the web tier and server functions; uptime checks and alert routing to Provider personnel. Audit logs (including IP address and user agent) are retained for 365 days; upload diagnostics for 90 days; integration delivery history for 90 days after delivery or failure; operational metrics for 30 to 90 days.

Incident response: documented intake, triage, containment, investigation, customer communication, recovery, and post-incident review process.

Backup and recovery: database — provider-managed daily backups retained seven days; no point-in-time recovery. Media — daily copy of the media bucket to a same-region backup bucket with automated verification of completeness (size and checksum); backup copies are deleted with the organization, not rotated. Restore procedures for a single organization and for the full bucket are documented and operator-run; recovery point objective 24 hours.

Deletion: tested user account-deletion procedure that removes the account and reassigns record provenance to a system placeholder while preserving organization records; organization-deletion procedure that removes records, media, media backups, rendered documents, integration payload history, and AI usage rows on Customer's written election after the export window.

Vendor management: subprocessors selected and reviewed based on service, data access, security, contractual protection, and change risk.

Personnel: confidentiality obligations, access limited by need, and timely access removal.

Related documents