Data Processing Addendum
Last updated: July 3, 2026 · Early-access program · Foundational version pending counsel ratification
Roles
For customer content — the floor plans, designs, project records, orders, contacts, and documents your team puts into the platform — your organization determines the purposes of processing and SiteOps Command processes it to provide the service. Formal controller/processor designations for each jurisdiction [GAP: needs legal review — ratified role definitions per jurisdiction] are settled in the signed addendum.
What we process, and why
Customer content is processed to deliver the features you invoke — design and physics computation, document parsing, reporting, portals, and field operations. Where intelligence features process your content, sensitive fields are redacted before a request leaves the platform and restored on return. We do not sell customer data, and we do not use your content to advertise to you or anyone else.
Tenant isolation
The platform is multi-tenant. Your organization's data is scoped to your organization and enforced at the data layer — security rules predicated on your tenant, verified again in application code, with cross-tenant access attempts treated as security events. Customer-portal access is isolated a second time, per portal customer.
Security measures
Data is encrypted in transit and at rest. Access is controlled by role-based permissions and recorded in an append-only audit log. Personal data fields are classified by sensitivity tier, and a supervised erasure mechanism can redact contact PII on request while preserving the non-personal audit record. Backups run daily, and the datastore supports point-in-time recovery.
Retention
Retention is governed by a maintained, per-collection retention schedule — the single source of truth for how long each class of data lives and how it is purged. As examples of current practice: revenue records are retained for seven years for audit purposes, field-technician location pings are minimized to thirty days, and operational media follows shorter windows. The current schedule is available on request.
Sub-processors
We rely on established infrastructure providers — cloud hosting and database (Google Cloud / Firebase), payment processing, transactional email delivery, and model providers for intelligence features. Each processes data only to provide its service to us. A ratified sub-processor list with change-notification mechanics [GAP: needs legal review — published sub-processor list + notification process] ships with the signed addendum.
Data-subject requests
You can request access to, correction of, or deletion of personal data by contacting support@siteopscommand.com. Erasure of contact PII is performed through a supervised redaction mechanism that records proof of erasure without retaining the erased content. Committed response-time windows [GAP: needs legal review — committed DSR response times] are settled in the signed addendum.
International transfers
The service is offered to customers contracting in the United States today. Transfer mechanisms for customers in other regions [GAP: needs legal review — transfer mechanism (e.g., SCCs) for non-US customers] are settled in the signed addendum before the service is offered there.
Incident notification
If a security incident affects your data, we notify you without undue delay. A contractually committed notification window [GAP: needs legal review — committed breach-notification window] is settled in the signed addendum.
Aggregate data
We do not sell customer data. A de-identified, k-anonymous aggregate benchmarking capability exists in the platform but is disabled, and will not operate before its governing terms are ratified with counsel [GAP: needs legal review — aggregate-learning clause (engineering draft on file)]. Raw customer content never crosses tenant boundaries.
Contact
Questions about data processing, or to request the current signed addendum: support@siteopscommand.com.