This Data Processing Addendum (the "DPA") forms part of the Agreement between the Customer identified in an Order Form ("Customer") and Thirtysix Solutions, LLC ("Provider") for FieldScroll. It applies when Provider processes Customer Personal Data on Customer's behalf.
1. Definitions and roles
"Applicable Data Protection Law" means privacy, data-protection, and breach-notification law that applies to the processing described in the Order Form. "Customer Personal Data" means personal data or personal information contained in Customer Data that Provider processes on Customer's behalf. "Data Subject," "Controller," "Processor," "Business," "Service Provider," and "Process" have the meanings given by Applicable Data Protection Law.
Customer is the Controller or Business and Provider is the Processor or Service Provider unless Applicable Data Protection Law assigns a different role. Each party is independently responsible for its own compliance duties.
2. Documented instructions
Provider will process Customer Personal Data only on Customer's documented instructions in the Agreement, Order Form, configured workflows, and authorized support requests, unless law requires other processing. Provider will notify Customer before legally required processing unless law prohibits notice.
Provider will promptly inform Customer if an instruction appears to violate Applicable Data Protection Law. Provider may suspend the affected processing while the parties resolve the instruction.
Customer will ensure that its instructions are lawful and that it has provided required notices and obtained required rights, consents, or legal bases. Customer will not submit Restricted Data unless the Order Form expressly identifies it and Provider accepts it in writing.
3. Personnel and confidentiality
Provider will limit access to personnel and approved subprocessors who need access to perform the Agreement, ensure they are bound by confidentiality obligations, and provide appropriate privacy and security instructions.
4. Security
Provider will implement and maintain the technical and organizational measures in Attachment 3, taking into account the state of the art, implementation cost, nature and purposes of processing, and risks to individuals. Customer is responsible for configuring roles, users, retention, integrations, devices, and available security features appropriately.
No system can eliminate all risk. The measures are not a warranty that a Security Incident will never occur. Provider may update measures if the overall level of protection is not materially reduced during an active paid Order Term.
5. Security Incidents
"Security Incident" means confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Customer Personal Data in Provider's possession or control. It excludes unsuccessful attempts, events affecting only Customer-controlled systems or credentials, and activity that does not compromise Customer Personal Data.
Provider will notify Customer without unreasonable delay after confirming a Security Incident and, where feasible, within 72 hours after confirmation. Notice will include reasonably available information about the nature, affected data and individuals, likely consequences, containment, and a contact. Provider may provide information in phases and will take commercially reasonable containment and remediation steps.
Customer is responsible for determining whether notices to individuals, regulators, customers, employees, insurers, or others are required, except to the extent law assigns a duty directly to Provider. Provider will reasonably assist at Customer's expense unless the Security Incident resulted from Provider's breach of this DPA.
6. Subprocessors
Customer gives general authorization for Provider to use subprocessors listed in Attachment 2. Provider will contractually require a subprocessor that processes Customer Personal Data to protect it consistently with this DPA. Provider remains responsible for the subprocessor's performance of those obligations to the extent required by law.
Provider will give at least 15 days' advance notice of a new subprocessor during an active paid Order Term when reasonably practicable. Customer may object on reasonable documented data-protection grounds within 10 days. The parties will work in good faith on an alternative; if none is commercially reasonable, either party may terminate the affected processing without penalty, and Customer's sole refund is prepaid unused fees for the terminated portion.
For a no-fee pilot, Customer's remedy for an unresolved subprocessor objection is to stop the affected feature or terminate the pilot.
7. Data-subject requests
Taking into account the nature of processing, Provider will reasonably assist Customer with access, correction, deletion, restriction, portability, and objection requests to the extent Customer cannot fulfill them through available controls. Provider may refer a requester to Customer unless law requires a direct response.
Customer is responsible for verifying the requester, determining whether a right applies, and providing lawful instructions. Provider may charge reasonable fees for assistance that is disproportionate, repetitive, or outside standard Service functionality unless the need resulted from Provider's breach.
8. Assessments, consultations, and audits
Provider will provide information reasonably necessary for Customer's data-protection assessment or regulator consultation regarding the Service. Provider will make available then-current security and privacy documentation reasonably sufficient to demonstrate compliance with this DPA.
No more than once per 12 months, unless a Security Incident or regulator requires more, Customer may request a remote audit of Provider's relevant controls on at least 30 days' notice. The parties will first use questionnaires, policies, summaries, and independent reports. Onsite review requires a genuine unmet need, confidentiality, scope limits, no access to other customers' data or Provider secrets, no disruption, and Customer payment of reasonable costs. Customer may not conduct penetration testing without written permission.
9. Return, deletion, and retention
During the Order Term, Customer may retrieve records through the Service's API and configured integrations, and may request an export at any time. On request, and for 30 days after the Agreement ends (or a longer export window stated in the Order Form), Provider will deliver submitted records in CSV or JSON format and attached media as a per-organization archive within ten business days.
After the export window, Provider will delete Customer Personal Data from active systems and from Provider-managed media backups within 30 days, unless law requires retention, following Provider's documented organization-deletion procedure. Copies in the provider-managed database backups expire on the seven-day backup cycle stated in Attachment 3, remain protected, and will not be restored except for disaster recovery or legal necessity. Provider does not delete Customer Data automatically during the Order Term.
Submitted operational records may be retained or de-identified under Customer's lawful instructions when Customer is required to preserve them. Provider will not promise deletion that would conflict with Customer's documented retention obligation; the parties will agree on de-identification or access restriction.
10. International transfers
Provider processes Customer Personal Data in the United States: database, authentication, and file storage in Supabase's US East region; document rendering and managed connectors in Fly.io's Ashburn, Virginia region; web application hosting on Vercel in the United States. Customer will not submit personal data subject to an international transfer restriction unless the Order Form identifies the jurisdiction and the parties implement a lawful transfer mechanism before processing. If required, the parties will execute applicable standard contractual clauses and supplementary measures.
11. U.S. state privacy terms
To the extent Provider is a Service Provider, Contractor, or Processor under applicable U.S. state privacy law, Provider will not sell or share Customer Personal Data, retain/use/disclose it outside the direct business relationship or permitted business purposes, combine it with personal data from another source except as permitted by law, or use it for targeted advertising. Provider will notify Customer if it can no longer meet these obligations and allow reasonable steps to stop and remediate unauthorized use.
12. Liability and conflict
This DPA is subject to the exclusions and liability caps in the FieldScroll Terms of Service or a specifically identified master services agreement. If this DPA conflicts with another Agreement document on processing Customer Personal Data, this DPA controls. The rest of the Agreement remains unchanged.
Attachment 1 - Processing details
| Item | Detail |
|---|---|
| Subject matter | Hosting and operating the FieldScroll pilot and the selected capture, review, document, export, and routing workflow. |
| Duration | The Order Term, the 30-day export window, the 30-day deletion period, and the seven-day database backup cycle. |
| Nature and purpose | Account administration; mobile/web capture; offline synchronization; review and approval; document and export generation; routing/integrations; support; security; and service operations. |
| Data subjects | Authorized Customer users; Customer employees or contractors; and other people appearing in pilot records only as approved in the Order Form. |
| Data categories | Business contact and account data (name, email, hashed password, roles); workflow records and text responses; photos and files; signatures; timestamps; device metadata attached to every mobile submission (device model, operating system and version, application version) and delivered with the record to Customer-configured integrations; sign-in and request metadata (IP address, user agent) in security and audit logs; and location coordinates with accuracy, altitude, heading, and speed only where a Customer-designed form includes a location field and the user captures it. |
| Restricted Data | None unless specifically listed and accepted in the Order Form. Do not sign with an ambiguous Restricted Data field. |
| Customer instructions | Agreement documents, configured workflows, administrator actions, and authorized written support requests. |
Attachment 2 - Subprocessor schedule
Verified against the production environment on 2026-08-24. The same schedule is published at https://www.fieldscroll.com/legal/subprocessors and is updated under Section 6.
| Subprocessor | Location | Purpose | Data processed | Processing region | Terms |
|---|---|---|---|---|---|
| Supabase Pte. Ltd. | 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | Database, authentication, file storage, serverless functions, secrets vault | All Customer Data and account data | AWS US East | https://supabase.com/legal/dpa |
| Vercel Inc. | Delaware; 440 N Barranca Ave #4133, Covina, CA 91723 | Web dashboard and API hosting | All dashboard and API traffic including record content, IP addresses | United States | https://vercel.com/legal/dpa |
| Fly.io, Inc. | 2261 Market Street #4990, San Francisco, CA 94114 | Document rendering (PDF/HTML from records) and managed data connectors | Full record content and images for rendering; record payloads and destination credentials for connectors | Ashburn, Virginia | https://fly.io/legal/data-privacy-framework/ |
| Anthropic, PBC | San Francisco, CA | AI assistant for form, report, and integration authoring (off unless enabled in the Order Form) | User messages, form and report definitions, user-attached images; not used for training; deleted within 30 days | United States | https://www.anthropic.com/legal/data-processing-addendum |
| Sinch Email (Mailgun), a business unit of Sinch AB | Lindhagensgatan 74, 112 18 Stockholm, Sweden | Transactional email (sign-in, invitations, report deliveries) and website contact form | Email addresses, invitation content, rendered report attachments containing record content | United States sending region | https://www.mailgun.com/legal/dpa/ |
| Plus Five Five, Inc. (Resend) | 2261 Market Street #5039, San Francisco, CA 94114 | Alternate transactional email transport (not the default) | Same as above when selected | United States | https://resend.com/legal/dpa |
| Functional Software, Inc. (Sentry) | 45 Fremont Street, 8th Floor, San Francisco, CA 94105 | Error monitoring for the web application and server functions (not the mobile application) | Stack traces, request identifiers, organization identifiers; incidental payload fragments in error messages | United States | https://sentry.io/legal/dpa/ |
| Better Stack, Inc. | United States | Log management, uptime monitoring, and alerting for web, mobile, server functions, and database | Structured logs: user and organization identifiers, routes, error text, mobile device platform and app version | United States | https://betterstack.com/dpa |
| PostHog, Inc. | 2261 Market St. #4008, San Francisco, CA 94114 | Product analytics for web, website, and mobile application (session replay disabled) | Event names with user, organization, form, and record identifiers; IP address; device and browser metadata; no record contents | United States | https://posthog.com/dpa |
| Mapbox, Inc. | San Francisco, CA | Map display for location fields in the mobile application | Device IP address and map viewport when a location field renders a map | United States | https://www.mapbox.com/legal/dpa |
| Cloudflare, Inc. | 101 Townsend Street, San Francisco, CA 94107 | Bot protection on the website contact form | Visitor IP address and challenge token; no Customer Data | United States | https://www.cloudflare.com/cloudflare-customer-dpa/ |
| Apple Inc. / Google LLC | Cupertino, CA / Mountain View, CA | Mobile application distribution | Store account data and operating-system crash reports; no Customer Data from Provider | United States | Apple Developer Program License Agreement; Google Play Developer Distribution Agreement |
Not subprocessors (Customer-configured destinations): Salesforce, Customer databases, webhook endpoints, and email recipients of report deliveries. Build-time only, no Customer Data: 650 Industries, Inc. (Expo/EAS) and GitHub, Inc.
Attachment 3 - Technical and organizational measures
Access control: unique accounts; five defined organization roles plus an instance-owner role; least-privilege form access resolved through direct, team, and collection grants; administrator actions on organizations, memberships, roles, and form publication are audit-logged. Multi-factor authentication is not currently offered. Passwords require a minimum of 10 characters with mixed character classes.
Encryption: TLS for all data in transit. Provider-managed encryption at rest for the database, file storage, and backups. Data cached on mobile devices relies on device operating-system storage encryption; the application does not apply separate encryption to its local database.
Tenant separation: shared environment. Each customer organization is isolated by database row-level security policies bound to organization membership; media storage is private by default with time-limited signed URLs (one hour). A deactivated organization denies every member and ends their signed-in sessions.
Secure development: source control with branch protection, code review on pull requests, automated tests (database, web, mobile) on every change, staged promotion (staging to production), and dependency advisory review.
Logging and monitoring: security-relevant application logs shipped to Better Stack from the web tier, mobile application, server functions, and database; error monitoring with Sentry on the web tier and server functions; uptime checks and alert routing to Provider personnel. Audit logs (including IP address and user agent) are retained for 365 days; upload diagnostics for 90 days; integration delivery history for 90 days after delivery or failure; operational metrics for 30 to 90 days.
Incident response: documented intake, triage, containment, investigation, customer communication, recovery, and post-incident review process.
Backup and recovery: database — provider-managed daily backups retained seven days; no point-in-time recovery. Media — daily copy of the media bucket to a same-region backup bucket with automated verification of completeness (size and checksum); backup copies are deleted with the organization, not rotated. Restore procedures for a single organization and for the full bucket are documented and operator-run; recovery point objective 24 hours.
Deletion: tested user account-deletion procedure that removes the account and reassigns record provenance to a system placeholder while preserving organization records; organization-deletion procedure that removes records, media, media backups, rendered documents, integration payload history, and AI usage rows on Customer's written election after the export window.
Vendor management: subprocessors selected and reviewed based on service, data access, security, contractual protection, and change risk.
Personnel: confidentiality obligations, access limited by need, and timely access removal.