Version 2.2 · August 21, 2026
This DPA applies when IronDispatch Processes Personal Data in Customer Data to provide the Service. Customer is the controller/business or responsible organization, and IronDispatch is the processor/service provider/contractor, except where law assigns different roles for limited activities such as account administration, billing, fraud prevention, or legal compliance.
Customer determines the purposes and means of its workforce and client data Processing, including whether and why employee location tracking is enabled. IronDispatch will Process Personal Data only on Customer’s documented instructions in the Agreement, Order Form, Service configuration, and support requests, unless law requires otherwise.
| Topic | Description |
|---|---|
| Subject matter | Hosting and operating field-operations, rental, fuel, service, workforce, billing, customer, and reporting software |
| Duration | Subscription term plus approved export, retention, deletion, and backup periods |
| Nature | Collection, storage, organization, retrieval, transmission, display, synchronization, calculation, support, security, export, deletion |
| Purposes | Provide and secure purchased Service functions; support Customer; comply with documented instructions and law |
| Data subjects | Customer personnel, contractors, drivers, applicants or qualification-file subjects where entered, Customer clients and contacts, vendors, and other individuals represented in Customer Data |
| Data categories | Names, contact details, role/title, account identifiers, work assignments, time and break records, location/routes, device/session basics, photos, signatures, qualifications, licenses/certificates, inspections, tickets, fuel/service/rental records, client communications, billing documents, and support information |
| Sensitive/high-risk data | Precise location, employee-monitoring records, identification/qualification documents, signatures, and any sensitive content visible in uploaded photos/documents |
Customer will not submit payment-card data, bank credentials, Social Security numbers, protected health information, biometric identifiers used for identification, or other specially regulated data unless expressly supported and covered by a signed addendum.
IronDispatch will:
Customer will:
IronDispatch will provide reasonable self-service capabilities and assistance for access, correction, export, restriction, or deletion requests. If IronDispatch receives a request relating primarily to Customer Data, it may direct the requester to Customer and notify Customer where appropriate. Customer is responsible for deciding the response; IronDispatch will execute lawful documented instructions unless prohibited by law.
The current product permits an individual to initiate an account or personal-data deletion request in the app or by contacting the published privacy address. The Parties will coordinate because Customer may need to retain legitimate business records while deleting unnecessary personal details and location breadcrumbs.
IronDispatch will maintain measures appropriate to risk, including:
IronDispatch will notify Customer without undue delay after confirming a Security Incident (as defined in the MSA) affecting Customer Personal Data, and in any event within seventy-two (72) hours after confirmation where a notice period is legally or contractually applicable. Notice will include available information about nature, affected data, likely consequences, mitigation, and a contact for follow-up. IronDispatch may provide information in phases and may delay details where law enforcement or legal restriction requires.
Notification is not an admission of fault. Customer is responsible for notices to individuals, regulators, employees, clients, or others, except where law directly requires IronDispatch to notify.
Customer generally authorizes IronDispatch to use subprocessors to provide the Service. IronDispatch will impose data-protection obligations appropriate to their functions and remain responsible for its obligations under this DPA.
| Provider | Function | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | Account and Customer Data |
| Vercel | Web hosting and delivery | Requests, technical logs, limited transmitted data |
| Resend | Transactional email | Email addresses and message content selected by Customer |
| Mapbox | Maps and geospatial display | Map requests and location coordinates |
| Intuit / QuickBooks | Customer-selected accounting synchronization | Customers, invoices, time entries, payment status |
| Stripe | IronDispatch subscription billing, where activated | Customer billing contact and payment metadata; no card data is stored in IronDispatch |
| AI model provider | Dispatch Copilot, where enabled | Prompts, selected Customer records, retrieved document excerpts, outputs |
| Error monitoring provider | Reliability and security monitoring, where activated | Technical events and minimized context |
| Telematics and GPS providers | Customer-selected vehicle and location integrations | Vehicle, device, and location data |
A current subprocessor list, including legal entity and processing region for each provider, is maintained at https://irondispatch.app/legal/subprocessors and is available to Customer on request.
IronDispatch will maintain a current list and give thirty (30) days’ prior notice of a new material subprocessor where practicable. Customer may object on reasonable data-protection grounds. The Parties will work in good faith; if no reasonable alternative exists, Customer may terminate the materially affected Service and receive a prorated refund of prepaid unused fees.
If Personal Data is transferred across jurisdictions requiring a transfer mechanism, the Parties will use an applicable lawful transfer mechanism, including approved standard contractual clauses together with any required transfer assessment and supplementary measures. The applicable mechanism and the hosting regions for Customer Data are identified in the Order Form or in the current subprocessor list.
IronDispatch will provide information reasonably necessary to demonstrate compliance, subject to confidentiality and security restrictions. No more than once annually, unless a Security Incident or regulator requires otherwise, Customer may request a reasonable audit. The Parties should first use current third-party reports, questionnaires, and documentation. On-site audits require reasonable notice, must avoid disruption and other customers’ data, and are at Customer’s expense unless they identify a material breach.
At Customer’s request or account end, IronDispatch will make standard exports available and delete Customer Data according to the Agreement and retention schedule, except where law requires retention. Deleted active data may persist temporarily in protected backups until overwritten through the normal cycle.
Customer Data will remain available for standard export for 18 months after the paid subscription ends. Quenchifying will then delete or irreversibly de-identify it from active systems within 90 days, subject to verified early-deletion requests, binding preservation duties, lawful retention exceptions, and the backup-expiration process in the MSA. Location breadcrumbs should follow the separately documented rolling period rather than the general business-record period unless Customer lawfully configures otherwise.
Section 16 of the MSA, including the super-cap in Section 16.3(f), governs each Party’s liability arising out of or relating to this DPA, except where applicable data-protection law does not permit that limitation. This Section 12 does not create a separate or additional limitation of liability, and the order-of-precedence rule in MSA Section 1.3 does not operate to displace MSA Section 16.
For a conflict concerning the Processing of Personal Data — meaning the purposes, means, instructions, security measures, subprocessing, data-subject rights, transfers, retention, or deletion of Personal Data — this DPA controls.
Quenchifying LLC, an Oregon limited liability company, dba Iron Dispatch · 82595 Green Valley Street, Creswell, OR 97426 · legal@irondispatch.app