Data Processing Agreement

Last updated: 8/25/2026

Draft placeholder — replace with counsel-reviewed terms before offering this as a signed agreement.

1. Roles

You ("Customer") are the data controller for the personal data you put into the Service. CloudGlobal360 ("Processor") processes it only on your behalf, only to provide the Service, and only under your documented instructions as given through your use of the Service.

2. What we process

Your customers' and team members' personal data as entered into the Service: names, contact details, addresses, quotes, invoices, payment records, and — only with explicit opt-in — field-staff location during job hours. See the Privacy Policy for the full list.

3. Sub-processors

We use the following sub-processors to run the Service: Stripe (payments), Intuit/QuickBooks (accounting sync, only if you connect it), Twilio (SMS), Resend (email), Meta/Facebook (lead ads, only if you connect it), cal.com (scheduling, only if you connect it), and Supabase (database, auth, file storage) hosted on infrastructure in the United States. Each is bound by its own data protection terms. We will not add a sub-processor that materially changes this list without notice to you. We do not sell Customer Data, or data obtained through any connected integration, to any third party, sub-processor or otherwise.

4. Connecting your own third-party accounts

Some integrations (QuickBooks, Facebook Lead Ads, Stripe, cal.com) run through your own account with that provider, not ours. You authorize the connection directly with the provider using your own login credentials; we never see or store that password. We hold only the resulting access token, scoped to the actions the integration needs, until you disconnect it from Settings → Integrations. We are a conduit for that connection, not a party to your agreement with the provider.

5. Security measures

Row-level tenant isolation enforced in the database on every tenant-scoped table, encryption in transit (TLS) and at rest via our infrastructure providers, and access to production data restricted to what the Service requires to operate.

6. Breach notification

We will notify you without undue delay after becoming aware of a breach affecting your data, with what we know at the time and how we're responding.

7. Deletion on termination

On request, or automatically per your organization's retention setting after account closure, we delete or anonymize your data, except where we're required to keep it (e.g., tax records).

8. Your own records

This Agreement describes how we protect the data you give us - it does not replace your own obligation to keep independent copies of records critical to your business. See the Terms of Service §5 for the current scope of what you can export yourself.

9. Contact

Questions: admin@cloudglobal360.com