Skip to content
HomeLegal
Apply for beta
Home/Legal/Data Processing Addendum

Data Processing Addendum

Effective October 8, 2026

This Data Processing Addendum ("DPA") is part of the agreement under which AllyNow Holdings, Inc. ("AllyNow") provides AllyNow to Customer: the Master Subscription Agreement or, for a design partner, its Design Partner Agreement (the "Agreement"). It applies when AllyNow processes Customer Personal Data to provide AllyNow to Customer. In this DPA, "Services" means AllyNow as provided under the Agreement, and "Customer Data" means the data Customer and its users put into AllyNow and what AllyNow creates from it for Customer. Other capitalized terms have the meanings in the Agreement.

1. Definitions #

  • "Customer Personal Data" means personal data or personal information within Customer Data.
  • "Data Protection Laws" means the laws that apply to processing Customer Personal Data under the Agreement, including, where they apply, the California Consumer Privacy Act ("CCPA") and other U.S. state privacy laws.
  • "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss or alteration of, or unauthorized access to or disclosure of, Customer Personal Data. Unsuccessful attempts that do not compromise Customer Personal Data are not Security Incidents.
  • "Subprocessor" means a third party that AllyNow uses to process Customer Personal Data.
  • Terms such as "controller," "processor," "business," "service provider," "sell," "share" and "deidentified" have the meanings given in the applicable Data Protection Laws.

2. Roles #

Customer is the controller or business for Customer Personal Data, or a processor acting for another controller with authority to use AllyNow. AllyNow processes Customer Personal Data as Customer's processor or service provider. AllyNow is a controller of the personal data it uses for its own account management, billing, security and marketing, as its Privacy Policy describes. Annex 1 describes the processing.

3. Customer's instructions #

AllyNow will process Customer Personal Data only on Customer's instructions, unless the law requires otherwise. The Agreement, this DPA, and Customer's use and settings of the Services are Customer's instructions. If the law requires other processing, AllyNow will tell Customer first unless the law prohibits it. AllyNow will tell Customer if it believes an instruction violates Data Protection Laws, and may pause the affected processing until the issue is resolved.

4. Service provider commitments #

AllyNow will not:

  • sell or share Customer Personal Data, as Data Protection Laws define those terms;
  • keep, use or disclose Customer Personal Data for any purpose other than providing the Services, or outside its direct business relationship with Customer, except as Data Protection Laws allow;
  • combine Customer Personal Data with personal data from other sources, except as Data Protection Laws allow a service provider to do;
  • use Customer Personal Data for advertising or marketing; or
  • use Customer Personal Data to train AI models, except after de-identifying it under Section 5.

AllyNow understands these restrictions and will comply with them, and it will comply with its obligations as a service provider under the CCPA. Where the CCPA applies, AllyNow will provide the level of privacy protection it requires, allow Customer to take reasonable steps to confirm that AllyNow is complying and to stop and fix any unauthorized use, and tell Customer if it can no longer meet its obligations.

5. De-identified data #

Customer authorizes and instructs AllyNow to de-identify Customer Personal Data and to use the de-identified data as the Agreement allows, including to train AI models and build analytics. When it does, AllyNow will: (a) take reasonable technical and organizational measures so the data cannot reasonably be linked to an identified or identifiable person, household or device, including controls against re-identification and accidental release; (b) publicly commit to keep and use the data only in de-identified form and not to try to re-identify it, except to test its de-identification methods; (c) require by contract that anyone who receives the data does the same and passes these duties on; (d) reasonably oversee recipients' compliance and act on any breach; and (e) leave out sensitive personal information. If a Data Protection Law sets a stricter standard, AllyNow will meet it. Data de-identified this way is not Customer Personal Data.

6. Personnel and security #

AllyNow will limit access to Customer Personal Data to personnel who need it to provide the Services, who are bound by confidentiality duties and who are trained on data protection. AllyNow will maintain technical and organizational measures appropriate to the risk, including the measures in Annex 2. AllyNow may change how it carries out those measures if the change does not materially reduce the overall protection of Customer Personal Data.

7. Subprocessors #

7.1 Approved Subprocessors. Customer approves the Subprocessors listed in Annex 3. AllyNow will have a written contract with each one with data protection terms at least as protective as this DPA, including Section 4, and AllyNow remains responsible for their performance.

7.2 Changes. AllyNow will email Customer's administrator at least 15 days before a new Subprocessor starts processing Customer Personal Data, and will update its published list. Customer may object on reasonable data protection grounds within those 15 days. If it does, AllyNow will work in good faith to resolve the objection or offer an alternative. If that is not possible, either party may end only the affected Services, and AllyNow will refund prepaid fees for those Services for the rest of the term.

8. Data location #

AllyNow and its Subprocessors process Customer Personal Data in the locations listed in Annex 3. AllyNow personnel and Subprocessors may access it from other locations when needed to provide and support the Services, and that access stays subject to this DPA. If the law requires a safeguard for a transfer, the parties will put it in place before the transfer happens.

9. Help with requests and assessments #

If AllyNow receives a request from a person about Customer Personal Data, it will send the request to Customer and will not answer it on its own, unless the law requires otherwise. Taking into account the nature of the processing, AllyNow will give Customer reasonable help to respond to these requests, to complete data protection assessments the law requires, and to meet its security and breach notification duties under Data Protection Laws.

10. Security Incidents #

AllyNow will notify Customer without undue delay after becoming aware of a Security Incident, and within any deadline the law sets. The notice will describe what AllyNow knows at the time, including the nature of the incident, the data affected, the likely consequences and the steps taken. AllyNow will update Customer as it learns more and will reasonably help Customer with any notices the law requires. Each party is responsible for the notices the law requires of it. A notice is not an admission of fault.

11. Return and deletion #

11.1 Export. For 30 days after the Services end, Customer may export or request return of Customer Personal Data as the Agreement describes.

11.2 Deletion. Unless Customer asks for earlier deletion or the law requires otherwise, AllyNow will delete active copies within 90 days after that 30-day export period ends. Deletion does not apply to de-identified data under Section 5.

11.3 Backups and required copies. Backup copies stay protected under this DPA and are deleted or overwritten on AllyNow's normal backup cycle. If a backup is restored, AllyNow will reapply any deletion before the restored data is used. Copies the law requires AllyNow to keep are limited to what the law requires and are used only for that purpose. On request, AllyNow will confirm deletion in writing.

12. Audits #

Once a year, on written request, AllyNow will complete a reasonable security questionnaire and provide information showing that it complies with this DPA. If Data Protection Laws or a regulator require an audit, AllyNow will allow it with at least 30 days' notice, during business hours, at Customer's cost and under confidentiality, in a way that does not disrupt the Services or expose other customers' data. The parties will use existing reports and questionnaires first where they answer the question.

13. General #

Liability under this DPA is subject to the limits on liability in the Agreement. If this DPA conflicts with the Agreement about personal data, this DPA controls. This DPA ends when AllyNow no longer processes Customer Personal Data.

Signing this DPA #

This DPA is part of the Agreement when an Order Form that lists it is signed, or when both parties sign a copy of it. To sign it separately, email support@ally-now.com.

Annex 1: Details of processing #

Item Description
Subject matter Providing the Services under the Agreement
Duration The term of the Agreement, plus the export and deletion periods in Section 11
Nature and purpose Hosting, storing, organizing, displaying and sending Customer Data for field documentation, project management, invoicing, document exports, AI features, support and security
People whose data is processed Customer's employees, contractors and crews; clients, property owners, tenants and managers; insurance and claim representatives; vendors; other people who appear in project materials Customer uploads
Types of personal data Names and contact details; job titles and roles; time and attendance records; signatures; photos, including the date, time and location information stored in them; notes, including notes entered by voice; property and project details; receipts and invoices; device, log and usage data
Sensitive data Not intended. Customer will not upload government ID numbers, full payment card numbers, health records, biometric data or similar sensitive information unless AllyNow agrees in writing first, and will redact it where it is not needed.

Annex 2: Security measures #

AllyNow maintains these minimum measures for the production Services:

  • Encryption of Customer Personal Data in transit and at rest, including in backups.
  • Access controls that limit each customer and user to the data their roles allow, with separately restricted administrative access.
  • Authentication and session controls suited to the Services.
  • Security logging to support incident investigation.
  • Separate development, test and production environments, with safeguards so test work does not expose production data.
  • Monitoring, vulnerability management and regular backups, with testing of restore procedures.
  • Production access limited to authorized personnel with a business need, reviewed periodically and removed promptly when no longer needed.
  • Confidentiality duties and data protection training for personnel.
  • Incident response procedures that meet Section 10.
  • Review of Subprocessors' security commitments.

Annex 3: Subprocessors #

Subprocessor Purpose Processing location
Supabase Database, sign-in and file storage United States
Vercel Web hosting United States
PowerSync Syncing data between mobile devices and the database United States
Resend Sending email United States
Sentry Error monitoring United States
Anthropic AI model provider for AI features United States

AllyNow requires each third-party AI model provider not to use Customer Personal Data to train its own models. Changes to this list follow Section 7.2.

From field capture to supported T&M invoices.

Apply for beta
© 2026 AllyNow Holdings, Inc.team@ally-now.comPrivacyTermsLegalBack to top