Surveyors.io

Data processing agreement

Version 2026-10. Part of the Enterprise plan; the account owner accepts it in the Enterprise console.

1. Parties and scope

This Data Processing Agreement ("DPA") is part of the Surveyors.io Terms of Service between Surveyors.io ("Processor", "we") and the surveying firm that accepts it from its Enterprise console ("Controller", "you"). It applies to personal data we process on your behalf while providing the service.

Where this DPA and the Terms of Service differ on personal data, this DPA prevails.

2. Subject matter, nature and purpose

We host and process personal data to run your account on the service: your profile and firm page, your team and crews, roles and single sign-on, leads and quotes, client details released to you when a client accepts your quote, calendar feeds, SMS alerts, API export, invoices and the audit log.

We process it only to provide, secure and support the service, and only as long as your account exists, plus the retention periods in section 9.

3. Categories of data subjects and data

Data subjects are your owner, team members and crew members, and the clients whose jobs you claim, quote or win.

Personal data includes names, business email addresses, phone numbers, mobile carrier for SMS alerts, sign-in events and IP addresses, job addresses and property details, quote content, invoice details and messages that pass through the service. We do not ask for and you agree not to upload special categories of personal data.

4. Instructions

We process personal data only on your documented instructions. The Terms of Service, your settings in the console and your use of the service are your instructions. If we believe an instruction breaks applicable data protection law, we tell you and may suspend that processing until it is clarified.

5. Confidentiality and security

Everyone at Surveyors.io with access to your personal data is bound by confidentiality.

We keep technical and organizational measures appropriate to the risk, including encryption in transit (TLS) on every page and API call, hashed access tokens and API keys, encrypted single sign-on secrets, role based access inside your firm, an audit log of account changes, and access to production limited to named staff with key based authentication.

6. Subprocessors

You give general authorization for subprocessors in these categories: cloud hosting and backups, transactional email delivery, payment processing for your subscription, and SMS delivery through mobile carrier gateways. Each one is bound by written terms that protect personal data at least as well as this DPA.

Before we add or replace a subprocessor in a new category we tell the account owner by email at least 30 days ahead. You may object on reasonable data protection grounds; if we cannot resolve it, you may cancel the subscription, effective at the end of the paid period, without any further charge.

7. Assistance and data subject requests

If a data subject asks us directly about data we process for you, we pass the request to you without undue delay and do not answer it ourselves unless you instruct us to.

We help you, as far as the service allows, to answer access, correction, deletion, portability and objection requests: the console and the API export give you your data in CSV and JSON, and [email protected] handles anything the console does not cover.

8. Personal data breaches

We notify the account owner without undue delay, and in any case within 72 hours after becoming aware of a personal data breach affecting your data, with what we know about its nature, the data and people concerned, likely consequences and the measures taken. We update you as we learn more.

9. Return and deletion

When your subscription ends you can export your data from the console and the API until the paid period runs out. Within 90 days after that we delete or anonymize personal data we process for you, except where the law requires us to keep it (for example billing records) or it sits in backups that expire on their normal cycle.

10. Audits and information

We make available, on request to [email protected], the information you reasonably need to show compliance with this DPA, including a written description of our security measures. Further audits are by written agreement, at a mutually agreed time, at your cost, and under confidentiality.

11. International transfers

Where personal data moves to a country that the law of the data subject treats as not giving adequate protection, the transfer relies on the safeguard that law requires, such as the Standard Contractual Clauses, which are then part of this DPA.

12. US state privacy laws

For personal information covered by the California Consumer Privacy Act as amended and similar US state laws, we act as your service provider or processor. We do not sell or share that personal information, do not keep, use or disclose it outside our direct business relationship with you or for any purpose other than providing the service, and do not combine it with personal information from other sources except as those laws allow. We tell you if we can no longer meet these obligations.

13. Term

This DPA starts when you accept it and lasts as long as we process personal data for you. Liability under this DPA follows the limits in the Terms of Service.

Get matched quotes