Overview Definitions Scope of Processing Processor Obligations Sub-processors Security Measures Data Transfers Breach Notification Data Subject Rights Termination Acceptance
Legal — Data Processing Agreement

Data Processing
Agreement

Effective Date: July 17, 2026  ·  Version 1.0  ·  Governed by Arizona Law  ·  GDPR Art. 28 Compliant

Who this agreement is between: This Data Processing Agreement ("DPA") is between RafterCore LLC d/b/a RafterCore ("RafterCore," "Processor") and the merchant (roofing contractor) who has accepted RafterCore's Terms of Service ("Controller," "you"). This DPA is incorporated into and forms part of the RafterCore Terms of Service.

1. Overview & Purpose

RafterCore provides a cloud-based roofing contractor management platform through which you, as a roofing contractor, manage homeowner client records, job data, invoices, estimates, photos, and related information ("Controller Data"). In delivering this service, RafterCore processes personal data on your behalf.

This DPA sets out the terms under which RafterCore processes Controller Data and ensures both parties comply with applicable data protection laws, including:

2. Definitions

For the purposes of this DPA:

TermMeaning
ControllerThe merchant (roofing contractor) who determines the purposes and means of processing Personal Data through the RafterCore platform. That is: you.
ProcessorRafterCore LLC, which processes Personal Data on behalf of and under the instruction of the Controller.
Sub-processorAny third party engaged by RafterCore to process Personal Data in connection with delivering the Service.
Personal DataAny information relating to an identified or identifiable natural person, as defined under applicable data protection law.
ProcessingAny operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
Data SubjectThe natural person (typically a homeowner or prospective customer) to whom Personal Data relates.
Controller DataPersonal Data that you upload to, generate through, or store on the RafterCore platform in connection with your roofing business operations.
Security IncidentAny confirmed unauthorized access, disclosure, alteration, or destruction of Personal Data held by RafterCore.
SCCsThe Standard Contractual Clauses adopted by the European Commission under GDPR Article 46(2)(c) for transfers of personal data to third countries.
ServicesThe RafterCore SaaS platform and all related features as described in the Terms of Service.

3. Scope, Nature, and Purpose of Processing

3.1 Subject Matter

RafterCore processes Controller Data solely to provide, maintain, and improve the Services as instructed by you. RafterCore does not process Controller Data for its own commercial purposes, does not sell Controller Data, and does not use Controller Data for advertising or marketing to third parties.

3.2 Duration

Processing begins on the date you accept these terms (or the date you first upload data to the platform, whichever is earlier) and continues until: (a) your subscription is terminated, or (b) you request deletion of your data, whichever occurs first, subject to retention obligations described in Section 10.

3.3 Nature of Processing

Processing activities include: storage, retrieval, display, backup, transmission to sub-processors (as listed in Section 5), analysis for AI-powered features you initiate, and deletion upon your instruction or upon contract termination.

3.4 Types of Personal Data Processed

Data CategoryExamplesData Subjects
Identity dataName, email address, phone numberHomeowners, leads, contacts
Property dataStreet address, property type, roof measurementsHomeowners, property owners
Job & project dataEstimate amounts, job status, materials, photos, notesHomeowners
Insurance dataClaim numbers, adjuster names, insurance company details, supplement lettersHomeowners
Financial data (limited)Invoice amounts, payment status (payment card data is tokenized by Stripe — RafterCore never stores raw card numbers)Homeowners
Communication dataEmail and SMS correspondence initiated through the platformHomeowners, leads
Contractor account dataBusiness name, license number, contact details, billing informationMerchant (you)

3.5 Special Categories

RafterCore does not intentionally collect or process special categories of personal data (health data, racial or ethnic origin, biometric data, etc.). You must not upload such data to the platform.

4. Processor Obligations (RafterCore)

4.1 Instructions

RafterCore shall process Controller Data only on your documented instructions, including as set out in this DPA and the Terms of Service. If RafterCore is required by applicable law to process Controller Data beyond your instructions, RafterCore will notify you unless prohibited by law.

4.2 Confidentiality

RafterCore shall ensure that all personnel authorized to process Controller Data are subject to binding confidentiality obligations, whether by contract or statutory duty. Access to Controller Data is restricted to personnel who require it to provide the Services.

4.3 Security

RafterCore shall implement and maintain technical and organizational measures appropriate to the risk, as described in Section 6 (Security Measures). These measures are designed to protect Controller Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

4.4 Sub-processors

RafterCore uses third-party sub-processors as listed in Section 5. By accepting this DPA, you grant general authorization for RafterCore to engage sub-processors listed herein. RafterCore will: (a) impose substantially equivalent data protection obligations on each sub-processor; (b) remain liable for the acts and omissions of sub-processors with respect to Controller Data; and (c) provide at least 30 days' written notice before adding or replacing a material sub-processor, giving you the right to object.

4.5 Data Subject Rights Assistance

To the extent technically feasible, RafterCore shall assist you in responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection) under applicable law. You remain primarily responsible for responding to Data Subjects. Submit data subject rights requests to privacy@raftercore.com.

4.6 Privacy Impact Assessments

RafterCore shall provide reasonable assistance to you in carrying out data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, where required by GDPR Articles 35 and 36, taking into account the nature of processing and information available to RafterCore.

4.7 Audit Rights

RafterCore shall make available to you all information necessary to demonstrate compliance with this DPA and, upon 30 days' written notice, shall allow and contribute to audits or inspections conducted by you or a mandated auditor, provided such audits are: (a) conducted during normal business hours; (b) subject to a confidentiality agreement; and (c) limited to information reasonably necessary to verify compliance. RafterCore may charge reasonable fees for audit assistance that exceeds one business day of effort per calendar year.

4.8 Notification of Unlawful Instructions

If RafterCore determines that an instruction from you would violate applicable data protection law, RafterCore will promptly notify you and may suspend the relevant processing activity until you provide a revised instruction or confirm the original instruction in writing (at your risk).

5. Approved Sub-processors

As of the Effective Date, RafterCore has engaged the following sub-processors. Each sub-processor is bound by contractual data protection obligations no less protective than this DPA.

Sub-processorService RoleData LocationPrivacy Policy
Supabase Inc.Database, authentication, file storage, row-level securityAWS us-east-1 (USA)supabase.com/privacy
Netlify Inc.Web hosting, serverless functions, global CDN, DDoS protectionUSA / Global CDNnetlify.com/privacy
Stripe Inc.Payment processing, subscription billing, tokenization of payment card dataUSAstripe.com/privacy
Resend Inc.Transactional and notification email deliveryUSAresend.com/privacy
Vonage / TwilioSMS notifications, phone verificationUSAvonage.com/privacy
Anthropic PBCAI-powered supplement writing, roof analysis, platform intelligence featuresUSAanthropic.com/privacy
Google LLCMaps API for aerial measurements; Analytics for platform usage data (anonymized)USA / Globalpolicies.google.com
VAPI AI Inc.AI voice assistant for lead handlingUSAvapi.ai/privacy

RafterCore reviews sub-processors regularly. Changes will be communicated with at least 30 days' notice via email to your registered account address and at raftercore.com/data-compliance. You may object to a new sub-processor in writing within 30 days. If RafterCore cannot accommodate your objection, you may terminate your subscription under the Terms of Service without early termination fees.

6. Technical & Organizational Security Measures

RafterCore maintains the following security measures, which represent the current state of implementation as of the Effective Date and may be updated to reflect evolving best practices:

MeasureImplementation
Encryption in TransitTLS 1.2+ for all data transmitted between users and the platform. HTTPS enforced across all endpoints.
Encryption at RestAES-256 encryption for all data stored in Supabase (PostgreSQL on AWS). File uploads encrypted at rest.
Access ControlRow-Level Security (RLS) enforced at the database level. Each merchant account is isolated; no cross-account data access is possible at the database layer.
AuthenticationBcrypt-hashed passwords. Session tokens with automatic expiration on inactivity. OAuth 2.0 (Google) supported.
API SecurityHMAC SHA-256 signed API keys for external integrations. Stripe webhook signature verification. Rate limiting on all API endpoints.
InfrastructureNetlify CDN with DDoS protection. Supabase managed infrastructure on AWS with automated backups and point-in-time recovery (PITR).
PersonnelAccess to production systems limited to authorized engineering personnel on a need-to-know basis. Confidentiality obligations contractually required.
Incident ResponseDocumented breach response procedure. See Section 8 for notification timelines.
Vulnerability ManagementDependency monitoring via automated tooling. Security patches applied promptly. No known critical unpatched vulnerabilities at time of Effective Date.

7. International Data Transfers

7.1 Primary Location

Controller Data is stored and processed in the United States (AWS us-east-1, Virginia). RafterCore's principal place of business is Phoenix, Arizona, USA.

7.2 Transfers from the EEA/UK

Where you transfer Personal Data from the European Economic Area (EEA) or the United Kingdom to RafterCore in the United States, such transfers are made pursuant to the EU Standard Contractual Clauses (SCCs) (Module Two: Controller-to-Processor) as adopted by the European Commission Decision 2021/914, or the UK Addendum thereto. By accepting this DPA, both parties are deemed to have executed the applicable SCCs, which are incorporated herein by reference.

To the extent that SCCs apply:

RafterCore shall maintain a Transfer Impact Assessment available upon written request.

7.3 Other Transfers

Sub-processor transfers to third countries (listed in Section 5) are covered by the sub-processors' own SCCs or other approved transfer mechanisms. Details are available in each sub-processor's privacy documentation.

8. Security Incident & Breach Notification

8.1 RafterCore Obligations

Upon confirming a Security Incident that involves Controller Data, RafterCore will:

PhaseTimelineAction
Initial notificationWithin 48 hours of confirmationNotify you via email to your registered account address with available details of the incident
Regulatory notification (GDPR)Within 72 hours of awarenessNotify relevant supervisory authority if required under GDPR Art. 33, in cooperation with you
Ongoing updatesAs new information becomes availableProvide updates on scope, root cause, remediation steps, and data affected
Final reportWithin 14 daysProvide post-incident report including root cause analysis and corrective actions taken

Notification of a Security Incident does not constitute an admission of fault or liability by RafterCore.

8.2 Your Obligations

You are responsible for notifying affected Data Subjects and supervisory authorities as required by applicable law, based on information provided by RafterCore. RafterCore will provide reasonable assistance in preparing required notifications.

8.3 Unconfirmed Incidents

Notification to RafterCore of a potential security concern (e.g., suspicious activity) does not constitute a Security Incident notification. RafterCore will investigate and notify you if a Security Incident is confirmed.

9. Assisting with Data Subject Rights

RafterCore shall provide the following assistance to you in responding to Data Subject requests, to the extent technically feasible:

You remain the primary point of contact for Data Subjects. Data Subjects should direct rights requests to you. You may submit requests on their behalf to privacy@raftercore.com.

RafterCore may charge reasonable fees for Data Subject rights assistance that exceeds two requests per month.

10. Termination & Data Return / Deletion

10.1 Upon Termination

Upon termination or expiration of the Terms of Service for any reason, at your written request submitted within 30 days of termination, RafterCore will:

10.2 Retention for Legal Compliance

Notwithstanding the above, RafterCore may retain Controller Data to the extent and for the duration required by applicable law (e.g., tax records, legal holds). Any retained data will remain subject to the confidentiality and security obligations of this DPA.

10.3 Backups

Automated backup copies of Controller Data will be deleted in accordance with Supabase's backup retention schedule (typically 7–30 days, depending on plan), following deletion from active systems.

10.4 Default Retention

If you do not submit an export or deletion request within 30 days of termination, RafterCore will delete Controller Data from active systems within 90 days of account termination and will not be liable for data loss thereafter.

11. Controller Obligations (You)

As the Controller, you represent and warrant that:

12. Liability

Each party's liability under this DPA shall be subject to the limitations and exclusions set forth in the RafterCore Terms of Service, except to the extent prohibited by applicable law.

Where both parties are responsible for damage caused by a breach of applicable data protection law, liability shall be apportioned in accordance with the degree to which each party is responsible for the damage, as determined by a court of competent jurisdiction.

Nothing in this DPA limits either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any liability that cannot be excluded or limited by law.

13. Governing Law & Jurisdiction

This DPA and any disputes arising from it shall be governed by and construed in accordance with the laws of the State of Arizona, USA, without regard to its conflict of law provisions, except where the SCCs specify otherwise for EEA/UK transfers (see Section 7.2).

Subject to the SCCs where applicable, each party irrevocably submits to the exclusive jurisdiction of the courts of Maricopa County, Arizona for any disputes arising under this DPA.

14. Miscellaneous

14.1 Order of Precedence

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the parties' data protection obligations. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail with respect to EU/EEA data transfers.

14.2 Amendments

RafterCore may update this DPA to reflect changes in law or its processing activities, with 30 days' written notice. Your continued use of the Services after the notice period constitutes acceptance of the updated DPA.

14.3 Severability

If any provision of this DPA is found to be unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.

14.4 Entire Agreement

This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the parties with respect to the processing of Controller Data and supersedes all prior agreements or understandings on this subject.

15. Acceptance

Standard Acceptance (All Merchants)

By creating a RafterCore account and accepting the Terms of Service, you agree to this DPA on behalf of yourself and your business. This constitutes valid acceptance under applicable law for the purposes of GDPR Article 28.

The effective date of your DPA is the date you first accepted the RafterCore Terms of Service.

Enterprise Countersigned DPA

Enterprise customers who require a countersigned DPA (e.g., for procurement compliance or GDPR Article 28 documentation purposes) may request one by emailing legal@raftercore.com with the subject line "DPA Request — [Your Company Name]". We respond within 5 business days.

Processor
RafterCore LLC
RafterCore LLC · Phoenix, Arizona
Authorized Signature & Date
Controller
[Merchant Company Name]
[Legal Entity / Individual]
Authorized Signature & Date

Note: Signature blocks above are for enterprise countersigned versions only. Standard online acceptance via Terms of Service is legally valid for all other merchants.

Contact & DPA Requests

For questions about this DPA, to request a countersigned version, or to submit a data subject rights request:

Email: legal@raftercore.com
Privacy inquiries: privacy@raftercore.com
Mail: RafterCore LLC, Phoenix, Arizona, USA

Related documents: Terms of Service  ·  Privacy Policy  ·  Data Compliance & Security