1. Parties and incorporation
This Data Processing Addendum (“DPA”) forms part of the agreement between the JunkHQ customer (“Customer”) and TuziSoft LLC d/b/a JunkHQ (“JunkHQ”) governing the Services. It applies when JunkHQ processes Customer Personal Data for Customer. Capitalized terms not defined here have the meaning in the Terms.
2. Roles and instructions
Customer is the controller or business and JunkHQ is the processor or service provider for Customer Personal Data. Customer instructs JunkHQ to process that data to provide, secure, support, and maintain the Services; comply with documented Customer instructions consistent with the agreement; and comply with applicable law. Each party is independently responsible for information it controls, including account, billing, security, and direct business-relationship data.
Where the California Consumer Privacy Act or a similar state law applies, JunkHQ certifies that it will: (a) not sell or share Customer Personal Data; (b) not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Terms, including any commercial purpose outside the direct business relationship between the parties; (c) not combine Customer Personal Data with personal information JunkHQ receives from or on behalf of another source, except to perform a business purpose permitted by that law; and (d) notify Customer if it determines it can no longer meet its obligations under that law.
3. Customer obligations
Customer will provide lawful instructions; establish a valid basis for processing; provide required notices; obtain required consents; configure access appropriately; and ensure its instructions and use of the Services comply with law. Customer is responsible for responding to individuals and for the accuracy and legality of Customer Personal Data.
4. Confidentiality and security
JunkHQ will ensure people authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain reasonable administrative, technical, and organizational safeguards appropriate to risk, including access control, tenant separation, encryption in transit, managed encryption at rest where supported, credential protection, recovery controls, and incident procedures.
5. Subprocessors
Customer generally authorizes the subprocessors on the public Subprocessor List. JunkHQ will impose data-protection duties materially consistent with this DPA and remains responsible for its subprocessors’ performance to the extent required by law. JunkHQ will post intended additions at least 15 days before use when reasonably practicable. Customer may object on reasonable data-protection grounds during that period; the parties will work in good faith on a commercially reasonable solution.
6. Individual requests
Taking into account the nature of processing, JunkHQ will reasonably assist Customer with verified requests for access, correction, deletion, restriction, objection, or portability. If JunkHQ receives a request concerning Customer Personal Data, it will direct the requester to Customer unless law prohibits doing so. Customer may use available product export, correction, and deletion tools or request reasonable assistance.
7. Security incidents
JunkHQ will notify Customer without undue delay after confirming a breach of Customer Personal Data and will provide information reasonably available about its nature, affected data, likely consequences, containment, and remediation. Notification is not an admission of fault. Customer is responsible for notices to individuals and regulators unless law assigns that duty to JunkHQ.
8. Assessments, audits, and government requests
JunkHQ will provide information reasonably necessary to demonstrate compliance and cooperate with legally required assessments. Customer will first use available documentation; any additional audit must be reasonable, confidential, no more than annually absent an incident or regulator request, and avoid disruption. JunkHQ will review government demands and, unless prohibited, notify Customer before disclosing Customer Personal Data.
9. Return and deletion
During the subscription, Customer may export Customer Personal Data using available features or reasonable assistance. On termination or a valid instruction, JunkHQ will delete or return Customer Personal Data unless retention is required by law. Data may remain in encrypted rolling backups until expiration and will remain protected and unavailable for ordinary use during that period.
10. International transfers and priority
Where a restricted international transfer requires a transfer mechanism, the parties will cooperate to execute the applicable standard contractual clauses or equivalent terms. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls.
Processing details
Subject matter and duration: operation of the Services for the agreement term plus deletion/backup periods. Nature and purpose: collection, storage, organization, analysis, transmission, scheduling, support, payment-status processing, and deletion needed to provide the Services. People: Customer personnel, prospects, household and commercial customers, and other individuals whose data Customer submits. Data: contact, account, jobsite, message, image, signature, appointment, payment-record, workforce, timecard, wage, device, usage, and acceptance information. Sensitive data: none is intentionally required; uploaded images, messages, precise addresses, signatures, credentials, and wage information require heightened care.