Data Processing Addendum (DPA)

Data Processing Addendum for LedgerDo.

What you get
  • Estimates, work orders, and invoices
  • Stripe payments and customer portal links
  • Scheduling, shop hours, and team workflows
  • Parts, labor, AI, and support tools
Need a copy for your records? Download the PDF.
Download PDF

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between LedgerDo (currently operated by Kyle Coots, United States) (“Processor”) and the customer entity or individual using LedgerDo services (“Controller”). This DPA applies when Controller uses LedgerDo to process Personal Data subject to applicable data protection laws.

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable individual.
  • Processing: Any operation performed on Personal Data including collection, storage, retrieval, use, disclosure, or deletion.
  • Controller: The entity that determines the purposes and means of processing Personal Data.
  • Processor: The entity that processes Personal Data on behalf of the Controller.
  • Subprocessor: A third party engaged by Processor to process Personal Data.

2. Roles of the Parties

Controller is the Data Controller. LedgerDo acts as a Data Processor and processes Personal Data solely on behalf of Controller and in accordance with Controller’s instructions.

3. Subject Matter and Duration

Subject Matter: Provision of cloud-based shop management software including work orders, invoicing, messaging, customer records, and related features.

Duration: For the period during which Controller uses LedgerDo services and until all Personal Data is deleted or returned.

4. Nature and Purpose of Processing

  • Storing customer contact information.
  • Managing work orders and invoices.
  • Storing vehicle information.
  • Facilitating messaging between shops and customers.
  • Processing payment-related metadata (via Stripe).
  • System backups and security monitoring.

5. Types of Personal Data Processed

Depending on Controller’s usage, data may include:

  • Customer names.
  • Email addresses.
  • Phone numbers.
  • Mailing addresses.
  • Vehicle information (VIN, make, model).
  • Service history.
  • Invoice and transaction metadata.
  • Internal employee user accounts.

LedgerDo does not intentionally collect sensitive personal data such as health data, biometric data, or government ID numbers.

6. Categories of Data Subjects

  • Controller’s customers.
  • Controller’s employees or authorized users.
  • Vendors associated with Controller’s business.

7. Processor Obligations

  1. Process Personal Data only on documented instructions from Controller.
  2. Ensure confidentiality of all personnel with access to Personal Data.
  3. Implement appropriate technical and organizational security measures.
  4. Not sell or share Personal Data for advertising or unrelated purposes.
  5. Assist Controller with reasonable requests related to data subject rights.

8. Security Measures

LedgerDo implements reasonable security measures including:

  • HTTPS encryption in transit.
  • Encrypted database connections.
  • Role-based access controls.
  • Tenant data isolation.
  • Token-based secure document access.
  • Regular system updates and patching.
  • Firewall and infrastructure security controls.
  • Periodic backups.

Controller acknowledges that no system can guarantee 100% security.

9. Subprocessors

Controller authorizes LedgerDo to use Subprocessors, including but not limited to:

  • Stripe, Inc. (payment processing).
  • Cloudflare, Inc. (DNS, CDN, security).
  • Hosting infrastructure provider (e.g., VPS or cloud provider).
  • Email delivery provider.
  • Meilisearch (search indexing).

LedgerDo shall impose data protection obligations on Subprocessors. An updated Subprocessor list will be maintained at ledgerdo.com/legal/subprocessors.

10. International Data Transfers

LedgerDo operates primarily in the United States. Controller acknowledges that data may be processed in the United States and consents to such transfers.

11. Data Subject Requests

If LedgerDo receives a request directly from a data subject, it will:

  • Notify Controller.
  • Not respond directly unless legally required.
  • Provide reasonable assistance to Controller.

12. Data Breach Notification

LedgerDo will notify Controller without undue delay upon becoming aware of a confirmed Personal Data breach affecting Controller data.

Notification will include:

  • Nature of the breach.
  • Categories of affected data.
  • Mitigation steps taken.

13. Deletion or Return of Data

  • Controller may export its data.
  • LedgerDo will delete or anonymize Personal Data within a reasonable period unless retention is required by law.

14. Limitation of Liability

Liability under this DPA shall be governed by the Terms of Service.

15. Governing Law

This DPA shall be governed by the laws specified in the Terms of Service.