RouteHouse Data Processing Addendum (DPA)
Between: NextForge LLC ("NextForge," "Processor"), operator of the RouteHouse service, and the customer that agrees to the RouteHouse Terms of Service (the "Customer," "Controller").
Effective date: the date the Customer accepts the Terms of Service or this DPA, whichever is earlier.
1. Scope and relationship to the Terms
This DPA forms part of the RouteHouse Terms of Service between NextForge and the Customer (the "Agreement") and applies to NextForge's processing of Personal Data on the Customer's behalf in connection with the Service. If there is a conflict between this DPA and the Agreement regarding data protection, this DPA controls. Capitalized terms not defined here have the meaning given in the Agreement.
2. Definitions
- "Personal Data" means information relating to an identified or identifiable individual that is contained in Customer Data and processed by NextForge on the Customer's behalf.
- "Processing," "Controller," "Processor," and "Data Subject" have the meanings given under applicable Data Protection Laws.
- "Data Protection Laws" means the privacy and data-protection laws applicable to the processing of Personal Data under the Agreement, which may include U.S. federal and state privacy laws and, where applicable, the EU/UK GDPR.
- "Subprocessor" means a third party engaged by NextForge to process Personal Data.
3. Roles of the parties
As between the parties, the Customer is the Controller (or "business") and NextForge is the Processor (or "service provider") with respect to Personal Data contained in Customer Data. The Customer determines the purposes and means of processing; NextForge processes Personal Data only as described in this DPA. NextForge is an independent controller with respect to certain limited data described in the Privacy Policy (such as account and billing data and Service usage data), which is outside the scope of this DPA.
4. Processing instructions
NextForge will process Personal Data only:
- to provide, maintain, secure, and support the Service in accordance with the Agreement;
- in accordance with the Customer's documented lawful instructions (the Agreement and Customer's configuration and use of the Service constitute such instructions); and
- as required by applicable law, in which case NextForge will inform the Customer of the requirement unless legally prohibited.
NextForge will notify the Customer if, in its opinion, an instruction violates Data Protection Laws. NextForge will not "sell" or "share" Personal Data, and will not retain, use, or disclose it for any purpose other than performing the Service or as permitted by Data Protection Laws.
The subject matter, duration, nature and purpose of processing, categories of Personal Data, and categories of Data Subjects are described in Annex A.
5. Confidentiality
NextForge will ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and are trained on their responsibilities.
6. Security
NextForge will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art and the risks of processing. A description of current measures is set out in Annex B. NextForge may update its measures provided they do not materially reduce the overall level of protection.
7. Subprocessors
- The Customer authorizes NextForge to engage Subprocessors to process Personal Data in connection with the Service. Current Subprocessors include, for example, Stripe (subscription billing and, where enabled, customer-payment processing via Stripe Connect), Sent (Sent, Inc.) (messaging), Resend (email delivery), and Railway (hosting and infrastructure). A current list is available at https://www.getroutehouse.com/subprocessors.
- NextForge will impose data-protection obligations on each Subprocessor that are substantially similar to those in this DPA and remains responsible for its Subprocessors' performance.
- NextForge will provide a mechanism to notify the Customer of new Subprocessors. The Customer may object on reasonable, data-protection grounds within 14 days; the parties will work in good faith to resolve the objection.
8. Data Subject requests
Taking into account the nature of the processing, NextForge will provide reasonable assistance (including through Service features) to help the Customer respond to Data Subject requests to exercise their rights under Data Protection Laws. If NextForge receives such a request directly, it will, where permitted, direct the Data Subject to the Customer or forward the request to the Customer.
9. Personal Data breach
NextForge will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations. NextForge will take reasonable steps to mitigate and remediate the breach. NextForge's notification is not an acknowledgment of fault or liability.
10. Assistance and audits
NextForge will provide the Customer with reasonable assistance in carrying out data-protection impact assessments and prior consultations, where required and taking into account the nature of processing and information available to NextForge. On reasonable request and subject to confidentiality, NextForge will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, which may be satisfied by NextForge providing relevant certifications, reports, or a summary of controls, no more than once per year absent a specific regulatory requirement or a breach.
11. Return and deletion
On termination or expiration of the Agreement, NextForge will, at the Customer's choice, make Customer Personal Data available for export and then delete or de-identify it within the period described in the Agreement, unless retention is required by law. NextForge's routine backups are deleted on a rolling basis.
12. International transfers
If NextForge processes Personal Data subject to laws that restrict cross-border transfers, the parties will implement an appropriate transfer mechanism (for example, Standard Contractual Clauses) as required.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
14. General
This DPA is governed by the same law and dispute-resolution terms as the Agreement (the State of Illinois), except where Data Protection Laws require otherwise. If any provision is unenforceable, the rest remains in effect.
Annex A — Details of processing
- Subject matter: provision of the RouteHouse field-service management Service.
- Duration: the term of the Agreement, plus the post-termination retention period.
- Nature and purpose: hosting, storing, organizing, transmitting, and otherwise processing Customer Data to provide the Service, including scheduling, service records, report/PDF generation, email, and — if enabled — text messaging.
- Categories of Data Subjects: the Customer's own customers and contacts (for example, property owners), and the Customer's Authorized Users (employees, technicians, contractors).
- Categories of Personal Data: names, service and mailing addresses, phone numbers, email addresses, job and service details, message content, and similar business-record data submitted through the Service.
Annex B — Security measures (summary)
- Encryption of Personal Data in transit (and at rest where applicable).
- Access controls and authentication for the Service; least-privilege access for personnel.
- Logical separation of Customer environments in a multi-tenant architecture.
- Monitoring, logging, and vulnerability-management practices.
- Regular backups and a documented restoration process.
- Personnel confidentiality obligations and security awareness.
- Vendor/subprocessor due diligence and contractual data-protection terms.