Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Depot Terms of Service or other written agreement between Depot Holdings Group, Inc. (“Depot”) and the customer organization identified in that agreement (“Customer”) (the “Agreement”).
This DPA applies automatically to Customer’s use of the Depot Asset Intelligence Platform and related services (the “Service”) whenever Depot Processes Personal Data on Customer’s behalf. No separate signature is required for it to take effect. A separately executable version containing identical terms is available on request at [email protected].
1. Definitions
“Controller” means the entity that determines the purposes and means of Processing Personal Data. For Customer Personal Data, Customer is the Controller.
“Customer Personal Data” means Personal Data contained in Customer Data that Depot Processes on Customer’s behalf in providing the Service.
“Data Protection Laws” means all laws applicable to the Processing of Customer Personal Data under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), other US state privacy laws, and Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation.
“Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.
“Personal Data” means information relating to an identified or identifiable natural person, and includes “personal information” as defined under the CCPA and PIPEDA.
“Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion. “Process” and “Processed” are construed accordingly.
“Processor” means the entity that Processes Personal Data on behalf of the Controller. For Customer Personal Data, Depot is the Processor.
“Security Incident” means a breach of Depot’s security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data Processed by Depot. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial-of-service attacks, or similar events.
“Sub-processor” means a third party engaged by Depot to Process Customer Personal Data.
Capitalized terms not defined here have the meaning given in the Agreement.
2. Roles and scope
2.1 Roles. For Customer Personal Data, Customer is the Controller and Depot is the Processor. Depot Processes Customer Personal Data only on Customer’s behalf and as described in this DPA.
2.2 Depot as Controller. Depot is an independent Controller for a limited set of data it collects for its own purposes, including account administration, billing, diagnostics necessary to operate and improve the Service, security and abuse prevention, and the evaluation set described in Section 2.5. Depot’s handling of that data is governed by Depot’s published Privacy Policy, not by this DPA.
2.3 Customer’s responsibilities. Customer is responsible for: (a) the accuracy and legality of Customer Personal Data; (b) having a lawful basis, and where required obtaining consent or providing notice, for Processing Customer Personal Data and for making it available to Depot; and (c) its own compliance with Data Protection Laws as Controller.
2.4 Processing details. The subject matter, duration, nature and purpose of Processing, the categories of Data Subjects, and the types of Personal Data are set out in Annex A.
2.5 Artificial-intelligence features. Where the Service uses artificial intelligence to interpret text, images, or audio a user submits — for example to suggest a component, failure type, or severity from a technician’s note, photograph, or voice memo — Depot: (a) Processes that content as Processor, using the model providers identified under Section 5.2, in order to produce the suggestion and, for content considered for the evaluation set, to perform the screening described in Section 8.3(c); and (b) retains a bounded evaluation set, described in Section 8.3(c), consisting of selected submitted content together with the suggestion produced and any correction a user made to it, in order to measure whether these features are accurate, and to develop and improve them — including by deriving the reference data and prompt patterns described in Section 2.6(b) and by the adaptation described in Section 2.6(a). For (b) Depot acts as an independent Controller.
2.6 How Depot may use the evaluation set. Within the limits in Section 8.3(c) and subject to Section 2.8, Depot may use the evaluation set to: (a) fine-tune or otherwise adapt models it uses to interpret submitted content; and (b) derive aggregated reference data and prompt patterns — for example component and failure-mode vocabularies, or the shape of an effective instruction to a model. Material derived under (b) contains no Customer content and no information identifying Customer, its personnel, its sites, or its assets, and may be used across Depot’s customers. Depot exercises these rights only for the purposes stated in Section 2.5(b).
2.7 What Depot does not do with Customer Data. Depot’s model providers are engaged on commercial terms under which content submitted through their interfaces is not used to train their models. Depot does not use one Customer’s content, or any excerpt of it, to produce output for another Customer — only the derived material described in Section 2.6(b), which carries neither. Depot does not sell Customer Data, use it for advertising, or disclose it to a third party for that third party’s own purposes. If Depot ever intends to act outside Sections 2.5 to 2.7, it will amend this DPA and give notice under Section 5.3 before doing so.
2.8 Exclusion from the evaluation set. Customer may exclude its Customer Data from the evaluation set described in Section 2.5(b), and therefore from the uses in Section 2.6, by written notice to Depot. Exclusion takes effect prospectively and, on request, Depot will delete Customer’s previously selected content from that set. Exclusion does not reverse an adaptation already performed under Section 2.6(a): a model that has already been fine-tuned on content cannot be made to un-learn it, and Depot does not represent otherwise. Material derived under Section 2.6(b) is unaffected by exclusion, because it contains no Customer content or identifying information.
3. Depot’s processing obligations
3.1 Documented instructions. Depot Processes Customer Personal Data only on Customer’s documented instructions, which comprise this DPA, the Agreement, and Customer’s use and configuration of the Service. Depot does not Process Customer Personal Data for any other purpose.
3.2 Additional instructions. Instructions beyond those described in Section 3.1 require written agreement, and may be subject to additional fees where they require material effort.
3.3 Unlawful instructions. If Depot reasonably believes an instruction violates Data Protection Laws, Depot will inform Customer without undue delay. Depot may suspend performance of that instruction until it is confirmed, withdrawn, or modified.
3.4 Required disclosure. If Depot is legally compelled to disclose Customer Personal Data, Depot will notify Customer before disclosing, unless legally prohibited, and will disclose only what is legally required.
3.5 Confidentiality of personnel. Depot ensures that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations and receive access only as needed to operate and support the Service.
3.6 No sale or sharing. Depot does not sell or share Customer Personal Data, does not use it for cross-context behavioural advertising, does not use it to build advertising profiles, and does not use it to train generative artificial-intelligence models.
4. Security
4.1 Measures. Depot implements and maintains the technical and organizational measures set out in Annex B, designed to protect Customer Personal Data against a Security Incident.
4.2 Changes. Depot may update its security measures from time to time provided the updates do not materially reduce the overall level of protection.
4.3 Customer responsibilities. Customer is responsible for its own use of the Service, including administering user accounts and permissions, configuring organization and branch access scoping, and protecting the email accounts used for authentication.
5. Sub-processors
5.1 General authorization. Customer grants Depot general authorization to engage Sub-processors to Process Customer Personal Data.
5.2 Current list. Depot maintains a current list of Sub-processors at thedepot.io/subprocessors and, on request, will provide it by email. The Sub-processors in use as of the date of this DPA are identified in Annex C.
5.3 New Sub-processors. Depot will give Customer at least thirty (30) days’ advance notice before a new Sub-processor begins Processing Customer Personal Data, by updating the list at the URL in Section 5.2 and sending notice by email to each of Customer’s organization administrators. Updating the list alone is not notice, and does not start the objection period in Section 5.4. Customer is responsible for keeping its administrator contact details current in the Service.
5.4 Objection. Customer may object to a new Sub-processor on reasonable data-protection grounds by written notice within thirty (30) days of the email notice under Section 5.3. If Customer does not object within that period, the new Sub-processor is deemed approved. The parties will discuss any objection in good faith. If Depot cannot reasonably accommodate the objection, Customer may terminate the affected subscription without penalty, and Depot will refund any prepaid fees for the unused portion of the term. For a Term Plan, termination under this Section is not an early termination for the purposes of the Agreement and no accelerated fees are due.
5.5 Depot’s responsibility. Depot imposes data protection obligations on each Sub-processor no less protective than those in this DPA and remains responsible to Customer for each Sub-processor’s performance.
6. Data subject requests
6.1 Assistance. Taking into account the nature of the Processing, Depot will assist Customer by appropriate technical and organizational measures, so far as reasonably possible, in fulfilling Customer’s obligation to respond to requests to exercise Data Subject rights.
6.2 Self-service. Customer may access, correct, export, and delete Customer Personal Data directly through the Service. Where the Service provides that capability, it constitutes Depot’s assistance.
6.3 Requests received by Depot. If Depot receives a request from a Data Subject relating to Customer Personal Data, Depot will not respond substantively except to confirm receipt and direct the Data Subject to Customer, and will notify Customer without undue delay unless legally prohibited.
7. Security incidents
7.1 Notification. Depot will notify Customer of a Security Incident affecting Customer Personal Data without undue delay, and in any event within seventy-two (72) hours after Depot confirms the Security Incident.
7.2 Content. The notification will describe, to the extent known: the nature of the Security Incident, the categories and approximate volume of Customer Personal Data affected, the likely consequences, and the measures taken or proposed. Depot will provide further information as it becomes available.
7.3 Cooperation. Depot will take reasonable steps to contain and remediate the Security Incident and will reasonably cooperate with Customer’s investigation and with any notification Customer is required to make.
7.4 No admission. Notification of a Security Incident is not an acknowledgment of fault or liability.
8. Deletion and return
8.1 During the term. Customer may export Customer Data through the Service at any time during the subscription term.
8.2 After termination. On termination or expiry of the Agreement, Depot will retain Customer Data for twelve (12) months so that Customer can still retrieve it — for its own records or to migrate to another provider — and will make it available for export on request during that period. At the end of that period Depot will delete Customer Personal Data, except as set out in Section 8.3. Customer may opt out of this retention at any time, before or after termination, by written notice; on receiving that notice Depot will delete Customer Personal Data within thirty (30) days, except as set out in Section 8.3. Customer may also require deletion at any point during the twelve-month period on the same basis. Depot will notify Customer’s organization administrators at termination that Customer Data is being retained under this Section, for how long, and how to opt out.
8.3 Retained copies. Depot may retain Customer Personal Data: (a) in routine, automated backups, which are deleted on Depot’s standard backup cycle; (b) to the extent required by applicable law; and (c) in the evaluation set described in Section 2.5(b), which is limited to no more than fifty thousand (50,000) records at any time, and is retained for no longer than five (5) years from selection. Depot screens every image considered for selection for human faces and vehicle registration plates, and does not knowingly retain in the evaluation set any image showing a face, a registration plate, or other information identifying a natural person or third-party property; on discovering such an image in the set, Depot deletes it. Screening is itself Processing under Section 2.5(a) and precedes the selection decision. Personal Data retained under (a) or (b) remains subject to this DPA for as long as it is retained; Personal Data retained under (c) is held by Depot as Controller under Section 2.2 and is governed by Depot’s Privacy Policy. The evaluation set is a bounded sample rather than a copy of Customer Data, and it is held longer than the period in Section 8.2 because measuring whether a change improves accuracy requires a set that stays stable across successive versions of the feature.
8.4 Certification. On request, Depot will certify in writing the deletion carried out under Section 8.2. The certificate will identify any categories of Customer Personal Data still retained under Section 8.3, including whether any of Customer’s content remains in the evaluation set described in Section 8.3(c) and the date on which it will be deleted, so that Customer may exercise the exclusion right in Section 2.8 if it wishes. Depot will not issue an unqualified statement that all Customer Personal Data has been deleted while any is retained under Section 8.3.
9. Audits and assessments
9.1 Documentation. Depot will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire not more than once in any twelve-month period.
9.2 Independent audit reports. Depot does not currently hold a SOC 2 report. Depot is in the process of pursuing SOC 2 attestation and will make the report available to Customer under confidentiality once issued. Until then, Section 9.1 governs.
9.3 On-site audit. Where Customer is required by Data Protection Laws to conduct an audit that cannot be satisfied under Sections 9.1 or 9.2, Customer may audit Depot’s compliance at Customer’s cost, on at least sixty (60) days’ written notice, not more than once in any twelve-month period, during business hours, subject to confidentiality, and in a manner that does not disrupt the Service or compromise the security or confidentiality of other customers’ data. Audits do not extend to Depot’s Sub-processors’ facilities or to other customers’ environments.
10. International and cross-border transfers
10.1 Locations. Depot Processes Customer Personal Data primarily in the United States. One Sub-processor, Capgo (Digital Solutions AG), operates from Switzerland and Processes limited device and application-version information for mobile update delivery.
10.2 Canadian Customers. Where Customer or Data Subjects are in Canada, Customer acknowledges that Customer Personal Data is stored and Processed outside Canada, including in the United States, and is therefore subject to the laws of those jurisdictions and accessible to their courts and law enforcement under those laws. Depot remains accountable for Customer Personal Data transferred to a Sub-processor and requires each Sub-processor by contract to provide a comparable level of protection, consistent with PIPEDA’s accountability principle.
10.3 No EEA or UK transfers. Depot does not offer the Service to customers established in the European Economic Area or the United Kingdom, and this DPA does not include EU Standard Contractual Clauses. If Customer requires them, contact Depot before Processing any Personal Data of Data Subjects in those territories.
11. United States state privacy laws
11.1 Service provider status. With respect to Personal Data subject to the CCPA, the parties agree that Customer is a “business” and Depot is a “service provider.” Depot Processes Personal Data solely on Customer’s behalf and pursuant to the Agreement.
11.2 Depot’s CCPA undertakings. Depot:
- (a) will not sell or share Personal Data as those terms are defined in the CCPA;
- (b) will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including retaining, using, or disclosing it for a commercial purpose other than providing the Service, or outside the direct business relationship with Customer — except for the internal use permitted to a service provider to build or improve the quality of its services, which is limited to the screening and evaluation described in Sections 2.5 and 8.3(c) and does not include building or modifying a profile about any consumer or household;
- (c) will not combine Personal Data received from Customer with Personal Data received from or on behalf of any other person, or collected from its own interaction with a Data Subject, except as permitted by the CCPA;
- (d) certifies that it understands the restrictions in this Section 11.2 and will comply with them;
- (e) will notify Customer promptly if it determines it can no longer meet its obligations under the CCPA; and
- (f) grants Customer the right to take reasonable and appropriate steps to help ensure Depot uses Personal Data in a manner consistent with Customer’s CCPA obligations, and to stop and remediate unauthorized use of Personal Data.
11.3 Other state laws. Where other US state privacy laws apply, Depot acts as a “processor,” “service provider,” or equivalent, and the obligations in this DPA apply correspondingly.
12. Liability, term, and precedence
12.1 Liability. Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement.
12.2 Term. This DPA takes effect when Customer accepts the Agreement and continues until Depot has deleted or returned all Customer Personal Data in accordance with Section 8.2.
12.3 Precedence. In the event of any conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and a separately negotiated and executed data processing agreement signed by both parties, that executed agreement controls.
12.4 Changes to this DPA. Depot may update this DPA to reflect changes in Data Protection Laws, the Service, or its Sub-processors, provided that no update will materially reduce the protections afforded to Customer Personal Data. Depot will give Customer at least thirty (30) days’ notice of a material update. Depot’s right under the Agreement to amend the Agreement unilaterally does not apply to this DPA.
12.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force.
12.6 Governing law. This DPA is governed by the law and subject to the venue specified in the Agreement.
Annex A — Details of processing
Subject matter. Depot’s provision of the Depot Asset Intelligence Platform to Customer.
Duration. For the term of the Agreement, plus the retention and deletion periods in Section 8.
Nature and purpose. Hosting, storage, and Processing of Customer Data to provide asset management, preventive maintenance scheduling, guided inspections, work order generation, asset history, and reporting; user authentication; transactional email; diagnostics necessary to operate and improve the Service; interpretation of submitted text, images, and audio by artificial-intelligence features; screening of images considered for the evaluation set as described in Section 8.3(c); and the bounded evaluation and the uses described in Sections 2.5(b) and 2.6; and customer support.
Categories of Data Subjects. Customer’s employees, contractors, operators, technicians, and other personnel authorized by Customer to use the Service, and individuals identified in records Customer creates in the Service.
Types of Personal Data.
- Account information — name, work email address, role, organization, branch.
- Authentication data — email address and one-time sign-in codes.
- User-generated content — equipment records, inspections, work orders, maintenance schedules, and documents, including photographs attached as inspection evidence and voice memos recorded on failed inspection items, to the extent these identify or relate to an individual.
- Device identifiers — push notification tokens associated with a user, used to deliver notifications to that user’s device.
- Diagnostic data — crash reports, device model, operating-system version, associated with a user ID.
Special categories. Depot does not require, and the Service is not designed to receive, special-category or sensitive Personal Data, government identifiers, payment card numbers, or health information. Customer shall not submit such data to the Service without Depot’s prior written agreement.
Annex B — Technical and organizational measures
- Encryption in transit — all data transmitted to and from the Service is encrypted using TLS. Plaintext HTTP connections are redirected to HTTPS and are not served.
- Encryption at rest — Customer Data is encrypted at rest using AES-256. Encryption keys are generated per project and protected by keys held in FIPS 140-2 compliant hardware security modules. Backups are encrypted both in transit and at rest.
- Tenant isolation — enforced in the database, not in application code. Every organization’s records are separated by PostgreSQL row-level security policies evaluated on each query against the authenticated user’s organization and, for branch-scoped roles, their branch. Tables holding account and membership records are additionally unreachable by the public API roles, which hold no privileges on them at all; the anonymous role holds no privileges on any application table. Cross-organization and cross-branch isolation is asserted by automated tests that run on every build, and a failure blocks the change from merging.
- Authentication — Customer accounts use passwordless authentication with one-time codes delivered to the user’s registered email address. No passwords are stored for Customer accounts. Customer accounts are created by Customer’s administrator or by an authorized representative of Customer subscribing directly.
- Access control — Depot staff access to Customer Data is limited to what operating and supporting the Service requires, and is granted on a least-privilege basis.
- Change control — changes to the Service are reviewed and must pass an automated verification suite, including the isolation tests above, before they can be merged. Deployment to production requires a separate, explicitly authorized promotion of a specific build that has already been deployed and verified in a staging environment.
- Personnel — personnel with access to Customer Personal Data are bound by written confidentiality obligations.
- Sub-processor management — Sub-processors are contractually bound to data protection obligations no less protective than this DPA.
- Backups — Customer Data is backed up automatically on a daily schedule by Depot’s infrastructure provider, and backups are encrypted in transit and at rest.
- Logging — edge and application request logging for security, abuse prevention, and reliability, and an append-only audit record of changes to business-critical data.
- Incident response — documented process for identifying, containing, investigating, and notifying Security Incidents, consistent with Section 7.
- Evaluation set — the set described in Section 2.5(b) sits outside the per-organization isolation above, because Depot holds it as Controller under Section 2.2 rather than on any one Customer’s behalf. The measures specific to it are: a hard ceiling of fifty thousand (50,000) records enforced in the system that writes it; deletion no later than five (5) years from selection; access limited to the Depot personnel who develop and measure the artificial-intelligence features; and honouring an exclusion under Section 2.8 by removing that Customer’s selected content; and screening of every image considered for selection for human faces and vehicle registration plates, with removal of any image later found to show a face, a plate, or other information identifying a natural person or third-party property. Reference data derived under Section 2.6(b) carries no Customer content or identifying information and is not subject to those limits.
- Independent assurance — SOC 2 attestation is in progress and has not yet been obtained. Depot will make the report available under confidentiality once issued.
Annex C — Sub-processors
The current list is maintained at thedepot.io/subprocessors, which is the authoritative version. Depot will give at least thirty (30) days’ notice before a new Sub-processor begins Processing Customer Personal Data, in accordance with Section 5.3.
Execution
This DPA applies automatically under the Agreement and does not require signature. A separately executable version containing identical terms is available on request at [email protected] for Customers whose procurement process requires an executed document.
Contact
Questions about this DPA: [email protected].