Data Processing Agreement (DPA)
Last updated: July 6, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between DIGITALPRODUCT&SERVICE LLC ("Processor", "GardyProp") and the subscribing company ("Controller", "you").
1. Definitions
- Personal Data: Any data relating to an identifiable natural person processed through GardyProp.
- Processing: Any operation performed on Personal Data (collection, storage, retrieval, deletion, etc.).
- Sub-processor: A third party engaged by GardyProp to process Personal Data on behalf of the Controller.
2. Scope & Purpose
GardyProp processes Personal Data solely to provide the pool service management platform, including:
- Customer management (names, contact details, addresses)
- Service documentation (visit records, photos, chemical readings)
- Route optimization (GPS coordinates)
- Billing and invoicing
- Notifications (email, WhatsApp)
3. Controller's Obligations
- Ensure lawful basis for data collection (consent, legitimate interest, or contract)
- Inform data subjects about data processing
- Respond to data subject requests (with GardyProp's assistance)
- Not upload special category data (health, biometric, etc.) unless explicitly agreed
4. Processor's Obligations
- Process data only on documented instructions from the Controller
- Ensure personnel are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests
- Delete or return all Personal Data upon termination (within 30 days)
- Make available information necessary to demonstrate compliance
5. Security Measures
GardyProp implements the following measures to protect Personal Data:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Password hashing (bcrypt, 12 rounds)
- Role-based access control (admin, technician, customer)
- Address masking for field technicians
- Geofence verification (GPS-based access control)
- Cloudflare Turnstile (bot protection)
- Sentry error monitoring (anonymized)
- Regular security audits
6. Sub-processors
GardyProp uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting & CDN | EU (Frankfurt) |
| Neon Inc. | PostgreSQL Database | EU |
| Cloudflare Inc. | R2 Storage, Turnstile | EU |
| Stripe Inc. | Payment Processing | EU/US |
| Resend Inc. | Transactional Email | US |
| Sentry (Functional Software) | Error Monitoring | US |
The Controller will be notified of any changes to sub-processors at least 14 days in advance.
7. International Transfers
Where Personal Data is transferred outside the EU/EEA, GardyProp ensures adequate safeguards through Standard Contractual Clauses (SCCs) or adequacy decisions.
8. Data Breach Notification
In the event of a Personal Data breach, GardyProp will notify the Controller without undue delay (within 72 hours) and provide all information necessary to comply with GDPR Article 33/34.
9. Data Subject Rights
GardyProp assists the Controller in fulfilling data subject rights:
- Right of Access (Art. 15)
- Right to Rectification (Art. 16)
- Right to Erasure (Art. 17)
- Right to Restriction (Art. 18)
- Right to Data Portability (Art. 20)
- Right to Object (Art. 21)
Data subjects can submit requests via our data request form or by emailing legal@gardyprop.com.
10. Duration & Termination
This DPA remains in effect for the duration of the service agreement. Upon termination, GardyProp will delete all Personal Data within 30 days, unless retention is required by law.
11. Governing Law
This DPA is governed by the laws of the State of California, United States, and, where it applies to personal data of individuals in the European Union, by the EU General Data Protection Regulation (GDPR).
Contact
GardyProp DIGITALPRODUCT&SERVICE LLC 15442 Ventura Blvd., Ste 201-2863 Sherman Oaks, California 91403 USA Email: legal@gardyprop.com