Iron Dispatch · Legal

Data Processing Addendum

Version 2.2 · August 21, 2026

1. Scope and Roles

This DPA applies when IronDispatch Processes Personal Data in Customer Data to provide the Service. Customer is the controller/business or responsible organization, and IronDispatch is the processor/service provider/contractor, except where law assigns different roles for limited activities such as account administration, billing, fraud prevention, or legal compliance.

Customer determines the purposes and means of its workforce and client data Processing, including whether and why employee location tracking is enabled. IronDispatch will Process Personal Data only on Customer’s documented instructions in the Agreement, Order Form, Service configuration, and support requests, unless law requires otherwise.

2. Processing Details

TopicDescription
Subject matterHosting and operating field-operations, rental, fuel, service, workforce, billing, customer, and reporting software
DurationSubscription term plus approved export, retention, deletion, and backup periods
NatureCollection, storage, organization, retrieval, transmission, display, synchronization, calculation, support, security, export, deletion
PurposesProvide and secure purchased Service functions; support Customer; comply with documented instructions and law
Data subjectsCustomer personnel, contractors, drivers, applicants or qualification-file subjects where entered, Customer clients and contacts, vendors, and other individuals represented in Customer Data
Data categoriesNames, contact details, role/title, account identifiers, work assignments, time and break records, location/routes, device/session basics, photos, signatures, qualifications, licenses/certificates, inspections, tickets, fuel/service/rental records, client communications, billing documents, and support information
Sensitive/high-risk dataPrecise location, employee-monitoring records, identification/qualification documents, signatures, and any sensitive content visible in uploaded photos/documents

Customer will not submit payment-card data, bank credentials, Social Security numbers, protected health information, biometric identifiers used for identification, or other specially regulated data unless expressly supported and covered by a signed addendum.

3. Processing Commitments

IronDispatch will:

  1. Process Personal Data only to provide, secure, support, and improve the Service under documented instructions.
  2. Ensure personnel authorized to Process Personal Data are bound by confidentiality.
  3. Maintain the security measures in Section 6.
  4. Assist Customer, considering the nature of Processing, with reasonable data-subject requests and compliance obligations.
  5. Notify Customer if an instruction appears to violate applicable data-protection law, without providing legal advice.
  6. Not sell Personal Data, share it for cross-context behavioral advertising, or use it for targeted advertising.
  7. Not combine Personal Data with unrelated data except as permitted by applicable law and necessary to provide or secure the Service.

4. Customer Instructions and Responsibilities

Customer will:

  • Provide lawful instructions and an appropriate legal basis.
  • Give required privacy and workforce-monitoring notices and obtain required consent.
  • Limit access by role and promptly deactivate users.
  • Configure location collection, visibility, and retention appropriately.
  • Respond as controller to individuals and determine whether deletion exceptions apply to business, payroll, tax, safety, or legal records.
  • Avoid uploading unsupported specially regulated data.
  • Keep downloaded exports and connected third-party systems secure.

5. Data-Subject Requests

IronDispatch will provide reasonable self-service capabilities and assistance for access, correction, export, restriction, or deletion requests. If IronDispatch receives a request relating primarily to Customer Data, it may direct the requester to Customer and notify Customer where appropriate. Customer is responsible for deciding the response; IronDispatch will execute lawful documented instructions unless prohibited by law.

The current product permits an individual to initiate an account or personal-data deletion request in the app or by contacting the published privacy address. The Parties will coordinate because Customer may need to retain legitimate business records while deleting unnecessary personal details and location breadcrumbs.

6. Security Measures

IronDispatch will maintain measures appropriate to risk, including:

  • Encryption in transit using current industry-standard transport protection.
  • Logical tenant isolation and database authorization controls.
  • Private file storage and time-limited access where supported.
  • Role-based access and least-privilege administrative practices.
  • Protected production credentials and signing keys.
  • Dependency, code, and release checks appropriate to the Service.
  • Logging and monitoring designed to detect operational and security events without unnecessarily exposing Customer Data.
  • Backups and restoration procedures as described in the SLA.
  • Incident response, vulnerability handling, access revocation, and change management.
  • Reasonable personnel confidentiality and access controls.

7. Security Incidents

IronDispatch will notify Customer without undue delay after confirming a Security Incident (as defined in the MSA) affecting Customer Personal Data, and in any event within seventy-two (72) hours after confirmation where a notice period is legally or contractually applicable. Notice will include available information about nature, affected data, likely consequences, mitigation, and a contact for follow-up. IronDispatch may provide information in phases and may delay details where law enforcement or legal restriction requires.

Notification is not an admission of fault. Customer is responsible for notices to individuals, regulators, employees, clients, or others, except where law directly requires IronDispatch to notify.

8. Subprocessors

Customer generally authorizes IronDispatch to use subprocessors to provide the Service. IronDispatch will impose data-protection obligations appropriate to their functions and remain responsible for its obligations under this DPA.

Subprocessor schedule

ProviderFunctionData involved
SupabaseDatabase, authentication, file storageAccount and Customer Data
VercelWeb hosting and deliveryRequests, technical logs, limited transmitted data
ResendTransactional emailEmail addresses and message content selected by Customer
MapboxMaps and geospatial displayMap requests and location coordinates
Intuit / QuickBooksCustomer-selected accounting synchronizationCustomers, invoices, time entries, payment status
StripeIronDispatch subscription billing, where activatedCustomer billing contact and payment metadata; no card data is stored in IronDispatch
AI model providerDispatch Copilot, where enabledPrompts, selected Customer records, retrieved document excerpts, outputs
Error monitoring providerReliability and security monitoring, where activatedTechnical events and minimized context
Telematics and GPS providersCustomer-selected vehicle and location integrationsVehicle, device, and location data

A current subprocessor list, including legal entity and processing region for each provider, is maintained at https://irondispatch.app/legal/subprocessors and is available to Customer on request.

IronDispatch will maintain a current list and give thirty (30) days’ prior notice of a new material subprocessor where practicable. Customer may object on reasonable data-protection grounds. The Parties will work in good faith; if no reasonable alternative exists, Customer may terminate the materially affected Service and receive a prorated refund of prepaid unused fees.

9. International Transfers

If Personal Data is transferred across jurisdictions requiring a transfer mechanism, the Parties will use an applicable lawful transfer mechanism, including approved standard contractual clauses together with any required transfer assessment and supplementary measures. The applicable mechanism and the hosting regions for Customer Data are identified in the Order Form or in the current subprocessor list.

10. Audits and Information

IronDispatch will provide information reasonably necessary to demonstrate compliance, subject to confidentiality and security restrictions. No more than once annually, unless a Security Incident or regulator requires otherwise, Customer may request a reasonable audit. The Parties should first use current third-party reports, questionnaires, and documentation. On-site audits require reasonable notice, must avoid disruption and other customers’ data, and are at Customer’s expense unless they identify a material breach.

11. Return, Retention, and Deletion

At Customer’s request or account end, IronDispatch will make standard exports available and delete Customer Data according to the Agreement and retention schedule, except where law requires retention. Deleted active data may persist temporarily in protected backups until overwritten through the normal cycle.

Customer Data will remain available for standard export for 18 months after the paid subscription ends. Quenchifying will then delete or irreversibly de-identify it from active systems within 90 days, subject to verified early-deletion requests, binding preservation duties, lawful retention exceptions, and the backup-expiration process in the MSA. Location breadcrumbs should follow the separately documented rolling period rather than the general business-record period unless Customer lawfully configures otherwise.

12. Liability and Conflict

Section 16 of the MSA, including the super-cap in Section 16.3(f), governs each Party’s liability arising out of or relating to this DPA, except where applicable data-protection law does not permit that limitation. This Section 12 does not create a separate or additional limitation of liability, and the order-of-precedence rule in MSA Section 1.3 does not operate to displace MSA Section 16.

For a conflict concerning the Processing of Personal Data — meaning the purposes, means, instructions, security measures, subprocessing, data-subject rights, transfers, retention, or deletion of Personal Data — this DPA controls.

Quenchifying LLC, an Oregon limited liability company, dba Iron Dispatch · 82595 Green Valley Street, Creswell, OR 97426 · legal@irondispatch.app