Legal

Data Processing Addendum

For review · A product of RightMove Properties

This Data Processing Addendum is provided for review and forms part of the agreement between Fieldkeep and the customer. It is not binding until executed by both parties, and the signed version governs. It is adapted from the Bonterms Data Protection Addendum v1.0 (used under CC BY 4.0). Nothing on this page is legal advice.

1. Parties and scope

This Data Processing Addendum (“DPA”) forms part of the agreement (the “Agreement”) between RightMove Properties, LLC, operating the Fieldkeep service (“Fieldkeep,” “Provider,” “we”) and the customer that licenses Fieldkeep (“Customer,” “you”). It governs Fieldkeep’s processing of Personal Data on Customer’s behalf in connection with the service. If this DPA conflicts with the Agreement on the subject of data protection, this DPA controls.

2. Roles of the parties

For Personal Data about Customer’s workers and operations processed through the service, Customer is the Controller and Fieldkeep is the Processor. Fieldkeep processes that Personal Data only to provide and support the service and only on Customer’s documented instructions, including those set out in the Agreement and this DPA. Customer is responsible for the lawfulness of the Personal Data it provides and the instructions it gives, including providing any notice to, or obtaining any consent from, its workers that the law requires (for example, written notice or acknowledgment of location tracking where a jurisdiction requires it).

3. Processing of Personal Data

  • The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are described in Schedule 1.
  • Fieldkeep will process Personal Data only on Customer’s documented instructions, unless required to do otherwise by law, in which case Fieldkeep will inform Customer first unless that law prohibits it.
  • Fieldkeep ensures that personnel authorized to process Personal Data are bound by confidentiality.
  • Fieldkeep does not sell Personal Data and does not use it for advertising. Fieldkeep does not use Customer Personal Data to train general-purpose AI models.

4. Sub-processors

Customer authorizes Fieldkeep to engage the sub-processors listed on the Trust and Security page to process Personal Data in connection with the service. Fieldkeep imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors’ performance. Fieldkeep will give Customer at least thirty (30) days’ notice before adding or replacing a sub-processor; if Customer reasonably objects on data-protection grounds, the parties will work in good faith to resolve the objection.

5. Security and breach notification

Fieldkeep maintains appropriate technical and organizational measures to protect Personal Data, described in Schedule 2. If Fieldkeep becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data (a “Security Incident”), Fieldkeep will notify Customer without undue delay, and in any event within forty-eight (48) hours of becoming aware, and will provide information reasonably available to help Customer meet its own notification obligations.

6. Assistance to Customer

Taking into account the nature of the processing, Fieldkeep will provide reasonable assistance to Customer for data-protection impact assessments and consultations with supervisory authorities, to the extent these relate to Fieldkeep’s processing.

7. Data-subject requests

Fieldkeep will, taking into account the nature of the processing, provide reasonable assistance to enable Customer to respond to requests from data subjects to exercise their rights (such as access, correction, and deletion). If Fieldkeep receives such a request directly, it will advise the data subject to submit it to Customer and will not respond except on Customer’s instructions.

8. Return or deletion of data

On termination of the service, Fieldkeep will, at Customer’s choice, return or delete Customer’s Personal Data within a reasonable period, except where retention is required by law. Routine retention during the term follows the tiered schedule described in Schedule 1 and on the Trust and Security page: raw location points are purged on a short window (currently about 45 days), while time records and the related records needed for payroll and recordkeeping are retained on a longer (seven-year) basis.

9. Audits

Fieldkeep will make available information reasonably necessary to demonstrate compliance with this DPA, including any third-party reports it maintains. Where that information is insufficient, Customer may, no more than once per year and on reasonable prior notice, audit Fieldkeep’s relevant practices, subject to confidentiality and to not unreasonably disrupting Fieldkeep’s operations. The parties will bear their own costs.

10. International transfers

Fieldkeep operates in the United States and processes Personal Data in the United States. Fieldkeep does not currently target or rely on cross-border transfer mechanisms such as the EU Standard Contractual Clauses. If the parties later agree that the service will process Personal Data subject to such requirements, they will execute the appropriate transfer mechanism as an addendum to this DPA.

11. Liability and order of precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA does not expand either party’s liability beyond what the Agreement permits.


Schedule 1 - Details of processing

  • Subject matter and duration. Provision of the Fieldkeep service for the duration of the Agreement, plus the retention periods described below.
  • Nature and purpose. Recording and reporting on field work: time capture, background location while on the clock, automatic mileage, job coding, and reading operational and financial data from Customer’s property-management system to produce briefings, reports, and answers.
  • Types of Personal Data. Worker name and work contact details; precise location while on the clock and derived trips and mileage; clock-in and clock-out events and job codes; manager and administrator account and authentication data; and operational and financial data Customer connects from its property-management system, which may incidentally include personal data about residents and vendors.
  • Categories of data subjects. Customer’s field workers, managers, and administrators; and, incidentally, residents and vendors referenced in Customer’s operational data.
  • Retention. Raw location points: a short window, currently about 45 days, then automatically purged. Time records and the location breadcrumbs and audit log that support them: a seven-year design, for payroll, reimbursement, and wage-and-hour recordkeeping. Other operational and financial data: for the term of the service and as needed for the agreed operations and reporting. Return or deletion on termination per Section 8.

Schedule 2 - Technical and organizational measures

  • Encryption. Personal Data is encrypted in transit (TLS) and at rest.
  • Hosting. The service runs on Google Cloud Platform (Cloud Run, Cloud SQL for PostgreSQL, and Cloud Storage) in United States regions; Fieldkeep operates no data centers of its own.
  • Tenant isolation. Customer data is segregated by an organization identifier enforced on every request, with a fail-closed default that refuses a request that cannot be resolved to a specific organization.
  • Access control. Role-based access within the product (owner through field technician); administrative access to underlying systems limited to operating personnel.
  • Auditability. Captured time is preserved write-once, and later changes by managers are recorded in an append-only, immutable audit log recording who changed what, when, and why.
  • Resilience. Automated managed database backups on Google Cloud SQL.
  • Incident response. A process to detect, contain, and notify on Security Incidents, with the notification commitment in Section 5.

Adapted from the Bonterms Data Protection Addendum v1.0, used under the Creative Commons Attribution 4.0 license. This adaptation is not endorsed by Bonterms. For questions, contact support@fieldkeep.app.