Summary
1. Introduction and scope
This DPA applies when Ergova processes Customer Personal Data on behalf of Customer in connection with the Services. It does not apply to personal information Ergova processes as an independent controller/business for its own purposes (for example website visitors, account holders, billing contacts, or support contacts), which is described in our Privacy Policy.
Where Customer uses the Services under the Terms and Ergova processes Customer Personal Data on Customer's behalf, this DPA is intended to form part of the Agreement for that processing, as referenced in the Terms and Privacy Policy, unless the parties have executed a separate written DPA or Order Form that expressly governs that processing. A mutually signed Order Form or enterprise DPA controls to the extent it expressly conflicts with this public DPA. Publication of this page alone is not a separately "executed" wet-ink agreement; binding effect for applicable online customers follows the Terms' acceptance mechanism and the precedence framework in the Terms.
2. Key terms
- Services means the Ergova software-as-a-service platform and related services provided under the Agreement.
- Customer Personal Data means personal data (or equivalent terms under Data Protection Laws) that Customer or its Authorized Users submit to the Services about Customer's own customers, leads, personnel, technicians, or other individuals, and that Ergova processes on Customer's behalf.
- Data Protection Laws means privacy and data-protection laws applicable to the processing of Customer Personal Data under this DPA, including where applicable the GDPR, UK GDPR, and U.S. state privacy laws.
- Controller and Processor include equivalent roles under applicable Data Protection Laws (such as "business" and "service provider" / "contractor" under California law), as the context requires.
- Subprocessor means a third party engaged by Ergova to process Customer Personal Data on Ergova's behalf in connection with the Services.
- Personal Data Breach means a personal data breach (or equivalent concept) as defined under applicable Data Protection Laws affecting Customer Personal Data.
- Authorized Users means individuals Customer authorizes to use the Services under Customer's account.
3. Order of precedence
For data-protection matters concerning Customer Personal Data processed under this DPA, this DPA controls over conflicting provisions of the Terms, unless a mutually signed Order Form or other mutually signed enterprise agreement expressly overrides a provision of this DPA. This is consistent with the precedence framework in the Terms.
4. Roles and documented instructions
Customer is the Controller (or equivalent) of Customer Personal Data. Ergova is the Processor (or equivalent) and processes Customer Personal Data only: (a) on documented instructions from Customer; (b) as necessary to provide, secure, maintain, support, and improve the Services as described in the Agreement, this DPA, and our Privacy Policy; (c) as configured or directed through Customer's and Authorized Users' use of the Services; or (d) as required by applicable law.
Customer's instructions are documented in the Agreement, this DPA, Customer's configuration and use of the Services, and any other written instructions Customer provides that Ergova accepts. Ergova will inform Customer if it reasonably believes an instruction infringes applicable Data Protection Laws. That notice is not legal advice.
If Ergova is required by law to process Customer Personal Data other than as instructed by Customer, Ergova will inform Customer of that legal requirement before processing unless the law prohibits that notice.
5. Customer responsibilities
Customer is responsible for:
- Determining that it has lawful authority to provide Customer Personal Data to Ergova
- Providing required notices and obtaining required consents
- Issuing lawful processing instructions
- Configuring its use of the Services appropriately
- Ensuring its own collection and use of Customer Personal Data comply with applicable law
These responsibilities do not reduce Ergova's processor obligations under this DPA.
6. Confidentiality
Ergova will ensure that persons it authorizes to process Customer Personal Data are subject to appropriate confidentiality obligations (contractual or statutory).
7. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Ergova will implement appropriate technical and organizational measures designed to provide a level of security appropriate to the risk. A summary of verified measures is set out in Annex II and on our Security page. Ergova does not warrant that the Services are free from all security risks.
8. Personal Data Breaches
Ergova will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, where required by applicable Data Protection Laws. Notification will include information reasonably available to Ergova at the time that is necessary to help Customer meet applicable breach-notification obligations. Where appropriate, information may be provided in phases as Ergova learns more.
Depending on what is reasonably available and legally appropriate, notice may include the nature of the incident, categories of data and individuals affected, likely consequences, and mitigation or remediation measures taken or proposed. Ergova is not required to disclose information it does not yet possess at the time of initial notice, or information that would compromise an investigation or Ergova's or another party's security.
9. Data subject requests
Taking into account the nature of processing and the information available to Ergova, Ergova will provide Customer with reasonable assistance through appropriate technical or organizational measures to help Customer respond to requests from individuals to exercise rights under applicable Data Protection Laws (such as access, correction, deletion, restriction, objection, or portability, where those rights apply).
If Ergova receives a request directly concerning Customer Personal Data, Ergova may direct the requester to Customer unless prohibited by law. Ergova does not independently adjudicate Customer's legal obligations to individuals.
10. Assistance with compliance
Taking into account the nature of processing and the information available to Ergova, Ergova will provide Customer with reasonable assistance with Customer's obligations under applicable Data Protection Laws relating to security, Personal Data Breaches, data protection impact assessments, and consultations with supervisory authorities, in each case to the extent those obligations relate to Ergova's processing of Customer Personal Data. This assistance does not include unlimited consulting or separate professional services unless the parties agree otherwise in writing.
11. Subprocessors
Customer generally authorizes Ergova to engage Subprocessors to process Customer Personal Data as needed to provide the Services. The current list is maintained at /subprocessors, which is the authoritative inventory for this DPA.
Ergova will impose written data-protection obligations on Subprocessors that provide an appropriate level of protection for Customer Personal Data relevant to the services they perform. Ergova remains responsible for its Subprocessors' performance of applicable data-protection obligations under this DPA to the extent required by applicable law.
Ergova will update the Subprocessors page when it adds, replaces, or materially changes Subprocessors. That page is Ergova's primary public notice mechanism. Where required by applicable Data Protection Laws or an agreed process, Ergova may also notify Customer of material changes (for example by email) and will permit Customer to raise reasonable objections on data-protection or security grounds. This DPA does not grant an unrestricted commercial veto over Subprocessors unrelated to privacy or security concerns, and it does not create termination or refund rights solely because of a Subprocessor change unless required by applicable law or a mutually signed agreement.
12. International transfers
Customer Personal Data may be processed in the United States and other countries where Ergova or its Subprocessors operate. Those countries may have different data-protection laws than Customer's country of establishment.
Where Customer Personal Data is subject to legally restricted international transfers, the parties will use an appropriate transfer mechanism required by applicable Data Protection Laws. This DPA does not by itself constitute Standard Contractual Clauses, a UK International Data Transfer Agreement or Addendum, Binding Corporate Rules, or certification under the EU-U.S. Data Privacy Framework. If the parties need execution-ready EU or UK transfer annexes, they will complete those in a mutually agreed form.
13. California service provider terms
To the extent California privacy law applies to Customer Personal Data that Ergova processes on Customer's behalf as a service provider or contractor, and consistent with our Privacy Policy:
- Customer discloses Customer Personal Data to Ergova for the limited business purposes of providing, securing, maintaining, supporting, and improving the Services under the Agreement and this DPA
- Ergova will process that Customer Personal Data only for those limited purposes and as otherwise permitted by applicable law and Customer's documented instructions
- Ergova will not sell Customer Personal Data, consistent with our Privacy Policy statement that Ergova does not sell personal information
- Ergova will not retain, use, or disclose that Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law or Customer's instructions
- Ergova will cooperate with Customer to support applicable consumer requests as described in Section 9
This section does not independently certify CCPA/CPRA compliance for all Customer use cases, and it does not create a separate California definition of "sharing" beyond what is stated in the Privacy Policy. Broader California contractual schedules, if required, may be agreed separately in writing.
14. Data use and AI-assisted features
Ergova processes Customer Personal Data as necessary to provide, secure, maintain, support, and improve the Services, and to fulfill Customer's documented instructions, as described in the Agreement, this DPA, and the Privacy Policy. Where Customer enables AI-assisted features, Ergova and its AI providers may process relevant content as needed to deliver the requested functionality.
Operating, securing, supporting, and improving the Services is not the same as using Customer Personal Data to train general-purpose AI models. This DPA does not represent that Customer Personal Data is, or is not, used to train general-purpose AI models; that topic is governed by the Privacy Policy and any additional written agreement of the parties.
15. Deletion and return
Upon termination of the Services or upon Customer's written request, Ergova will delete or return Customer Personal Data at Customer's choice, unless applicable law requires retention or retention is reasonably necessary as described in the Terms and Privacy Policy (for example fraud prevention, security, dispute resolution, enforcement, or legitimate recordkeeping). Customer should export any Customer Personal Data it needs before access ends, using available product export or data-access features.
Deletion from backup systems may occur through normal backup-retention and overwrite cycles where legally permissible. This DPA does not promise a specific export format, deletion deadline, or formal deletion certificate.
16. Information and audit rights
Ergova will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. Where appropriate, Ergova may satisfy information requests through security documentation, completed questionnaires, and other written materials describing Ergova's controls.
If Customer reasonably requires an additional audit or inspection of Ergova's processing of Customer Personal Data under this DPA, the parties will cooperate in good faith. Any such audit will: (a) be on reasonable advance notice; (b) occur during normal business hours; (c) be subject to confidentiality obligations; (d) minimize disruption to Ergova's operations; (e) not access other customers' information; and (f) not compromise Ergova's security. Customer may use a qualified independent auditor where appropriate. Ergova does not represent that it currently provides SOC 2 or similar third-party audit reports.
17. Legal and government requests
If Ergova is legally compelled to disclose Customer Personal Data, Ergova will notify Customer before disclosure where legally permitted. Ergova does not promise to challenge every government or legal request. Ergova will cooperate with competent supervisory or regulatory authorities to the extent required by applicable law.
18. Liability
Except where Data Protection Laws require otherwise and cannot be varied by contract, each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement (including the Terms).
19. Term
This DPA remains in effect for as long as Ergova processes Customer Personal Data subject to the Agreement. Provisions that by their nature should survive (including confidentiality, deletion/return obligations, and legally required protections) survive termination as necessary.
Annex I — Details of processing
Subject matter
Processing of Customer Personal Data to provide the Services under the Agreement.
Duration
The term of the Agreement, plus any post-termination period required for deletion, return, or legally required retention.
Nature of processing
As applicable to Customer's use of the Services: collection/receipt, storage, organization, retrieval, use, transmission, communication processing, modification, analysis where part of configured Services, and deletion.
Purposes
Providing and operating the Services as configured by Customer, which may include scheduling, dispatch, job and work-order management, estimates, invoices, payments-related records, customer communications (including SMS and voice where enabled), support, authentication, product operations, AI-assisted features where enabled, integrations Customer enables, and security.
Categories of data subjects
Customer's personnel and Authorized Users; contractors and technicians; Customer's customers, leads, and prospects; billing and contact persons; and other individuals whose information Customer or its Authorized Users submit to the Services.
Categories of personal data
Depending on Customer's use of the Services, categories may include names and contact details; account and role information; service addresses and related location details; scheduling and job information; estimate, invoice, and payment-related records; notes, files, and photos where supported; communications content and metadata associated with jobs or support threads; and related operational records Customer submits. Device, log, and usage information may also be processed as needed to provide and secure the Services.
Sensitive / specially regulated data
Ergova is a general business operations platform and is not designed as a specialized system for specially regulated sensitive data categories. Customer should not submit special-category or other highly regulated sensitive data through the Services unless Customer has determined that its use is lawful and the parties have expressly agreed that such processing is supported.
Annex II — Technical and organizational measures
The following summarizes measures Ergova uses, based on current product and public security documentation. Details may evolve as the platform matures. See also /security.
Access control and authentication
- Authentication through a third-party identity provider together with Ergova application controls (see /security)
- Role-based permissions within Customer organizations (for example owner, admin, dispatcher, technician, and other supported roles)
Tenant separation
- Organization membership and authorization controls designed to restrict users to data they are permitted to access for their company, including organization-scoped data access and server-side authorization checks as part of how the product is built
Data protection
- Encryption in transit (HTTPS/TLS) for customer traffic to the Services
- Encryption at rest provided through infrastructure providers as part of how those platforms store data
- Application secrets and sensitive credentials stored using protected environment and configuration mechanisms and not intentionally exposed in client-side application code
- Subscription billing and payment-method details handled through Stripe; Ergova is designed to avoid directly storing full payment-card numbers on Ergova systems
Infrastructure and security operations
- Use of specialized service providers for hosting, databases, authentication, payments, communications, and related functions, as listed on /subprocessors
- Application and operational logging used to help operate, troubleshoot, and improve the Services
Incident handling
- Investigation of suspected security incidents and remediation steps Ergova determines are appropriate, with Customer notifications as described in Section 8 and as required by law or contract
This Annex does not claim SOC 2, ISO 27001, HIPAA, specific encryption algorithms, RPO/RTO values, or 24/7 security operations center monitoring.
