Who this agreement is between: This Data Processing Agreement ("DPA") is between RafterCore LLC d/b/a RafterCore ("RafterCore," "Processor") and the merchant (roofing contractor) who has accepted RafterCore's Terms of Service ("Controller," "you"). This DPA is incorporated into and forms part of the RafterCore Terms of Service.
RafterCore provides a cloud-based roofing contractor management platform through which you, as a roofing contractor, manage homeowner client records, job data, invoices, estimates, photos, and related information ("Controller Data"). In delivering this service, RafterCore processes personal data on your behalf.
This DPA sets out the terms under which RafterCore processes Controller Data and ensures both parties comply with applicable data protection laws, including:
For the purposes of this DPA:
| Term | Meaning |
|---|---|
| Controller | The merchant (roofing contractor) who determines the purposes and means of processing Personal Data through the RafterCore platform. That is: you. |
| Processor | RafterCore LLC, which processes Personal Data on behalf of and under the instruction of the Controller. |
| Sub-processor | Any third party engaged by RafterCore to process Personal Data in connection with delivering the Service. |
| Personal Data | Any information relating to an identified or identifiable natural person, as defined under applicable data protection law. |
| Processing | Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion. |
| Data Subject | The natural person (typically a homeowner or prospective customer) to whom Personal Data relates. |
| Controller Data | Personal Data that you upload to, generate through, or store on the RafterCore platform in connection with your roofing business operations. |
| Security Incident | Any confirmed unauthorized access, disclosure, alteration, or destruction of Personal Data held by RafterCore. |
| SCCs | The Standard Contractual Clauses adopted by the European Commission under GDPR Article 46(2)(c) for transfers of personal data to third countries. |
| Services | The RafterCore SaaS platform and all related features as described in the Terms of Service. |
RafterCore processes Controller Data solely to provide, maintain, and improve the Services as instructed by you. RafterCore does not process Controller Data for its own commercial purposes, does not sell Controller Data, and does not use Controller Data for advertising or marketing to third parties.
Processing begins on the date you accept these terms (or the date you first upload data to the platform, whichever is earlier) and continues until: (a) your subscription is terminated, or (b) you request deletion of your data, whichever occurs first, subject to retention obligations described in Section 10.
Processing activities include: storage, retrieval, display, backup, transmission to sub-processors (as listed in Section 5), analysis for AI-powered features you initiate, and deletion upon your instruction or upon contract termination.
| Data Category | Examples | Data Subjects |
|---|---|---|
| Identity data | Name, email address, phone number | Homeowners, leads, contacts |
| Property data | Street address, property type, roof measurements | Homeowners, property owners |
| Job & project data | Estimate amounts, job status, materials, photos, notes | Homeowners |
| Insurance data | Claim numbers, adjuster names, insurance company details, supplement letters | Homeowners |
| Financial data (limited) | Invoice amounts, payment status (payment card data is tokenized by Stripe — RafterCore never stores raw card numbers) | Homeowners |
| Communication data | Email and SMS correspondence initiated through the platform | Homeowners, leads |
| Contractor account data | Business name, license number, contact details, billing information | Merchant (you) |
RafterCore does not intentionally collect or process special categories of personal data (health data, racial or ethnic origin, biometric data, etc.). You must not upload such data to the platform.
RafterCore shall process Controller Data only on your documented instructions, including as set out in this DPA and the Terms of Service. If RafterCore is required by applicable law to process Controller Data beyond your instructions, RafterCore will notify you unless prohibited by law.
RafterCore shall ensure that all personnel authorized to process Controller Data are subject to binding confidentiality obligations, whether by contract or statutory duty. Access to Controller Data is restricted to personnel who require it to provide the Services.
RafterCore shall implement and maintain technical and organizational measures appropriate to the risk, as described in Section 6 (Security Measures). These measures are designed to protect Controller Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
RafterCore uses third-party sub-processors as listed in Section 5. By accepting this DPA, you grant general authorization for RafterCore to engage sub-processors listed herein. RafterCore will: (a) impose substantially equivalent data protection obligations on each sub-processor; (b) remain liable for the acts and omissions of sub-processors with respect to Controller Data; and (c) provide at least 30 days' written notice before adding or replacing a material sub-processor, giving you the right to object.
To the extent technically feasible, RafterCore shall assist you in responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection) under applicable law. You remain primarily responsible for responding to Data Subjects. Submit data subject rights requests to privacy@raftercore.com.
RafterCore shall provide reasonable assistance to you in carrying out data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, where required by GDPR Articles 35 and 36, taking into account the nature of processing and information available to RafterCore.
RafterCore shall make available to you all information necessary to demonstrate compliance with this DPA and, upon 30 days' written notice, shall allow and contribute to audits or inspections conducted by you or a mandated auditor, provided such audits are: (a) conducted during normal business hours; (b) subject to a confidentiality agreement; and (c) limited to information reasonably necessary to verify compliance. RafterCore may charge reasonable fees for audit assistance that exceeds one business day of effort per calendar year.
If RafterCore determines that an instruction from you would violate applicable data protection law, RafterCore will promptly notify you and may suspend the relevant processing activity until you provide a revised instruction or confirm the original instruction in writing (at your risk).
As of the Effective Date, RafterCore has engaged the following sub-processors. Each sub-processor is bound by contractual data protection obligations no less protective than this DPA.
| Sub-processor | Service Role | Data Location | Privacy Policy |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage, row-level security | AWS us-east-1 (USA) | supabase.com/privacy |
| Netlify Inc. | Web hosting, serverless functions, global CDN, DDoS protection | USA / Global CDN | netlify.com/privacy |
| Stripe Inc. | Payment processing, subscription billing, tokenization of payment card data | USA | stripe.com/privacy |
| Resend Inc. | Transactional and notification email delivery | USA | resend.com/privacy |
| Vonage / Twilio | SMS notifications, phone verification | USA | vonage.com/privacy |
| Anthropic PBC | AI-powered supplement writing, roof analysis, platform intelligence features | USA | anthropic.com/privacy |
| Google LLC | Maps API for aerial measurements; Analytics for platform usage data (anonymized) | USA / Global | policies.google.com |
| VAPI AI Inc. | AI voice assistant for lead handling | USA | vapi.ai/privacy |
RafterCore reviews sub-processors regularly. Changes will be communicated with at least 30 days' notice via email to your registered account address and at raftercore.com/data-compliance. You may object to a new sub-processor in writing within 30 days. If RafterCore cannot accommodate your objection, you may terminate your subscription under the Terms of Service without early termination fees.
RafterCore maintains the following security measures, which represent the current state of implementation as of the Effective Date and may be updated to reflect evolving best practices:
| Measure | Implementation |
|---|---|
| Encryption in Transit | TLS 1.2+ for all data transmitted between users and the platform. HTTPS enforced across all endpoints. |
| Encryption at Rest | AES-256 encryption for all data stored in Supabase (PostgreSQL on AWS). File uploads encrypted at rest. |
| Access Control | Row-Level Security (RLS) enforced at the database level. Each merchant account is isolated; no cross-account data access is possible at the database layer. |
| Authentication | Bcrypt-hashed passwords. Session tokens with automatic expiration on inactivity. OAuth 2.0 (Google) supported. |
| API Security | HMAC SHA-256 signed API keys for external integrations. Stripe webhook signature verification. Rate limiting on all API endpoints. |
| Infrastructure | Netlify CDN with DDoS protection. Supabase managed infrastructure on AWS with automated backups and point-in-time recovery (PITR). |
| Personnel | Access to production systems limited to authorized engineering personnel on a need-to-know basis. Confidentiality obligations contractually required. |
| Incident Response | Documented breach response procedure. See Section 8 for notification timelines. |
| Vulnerability Management | Dependency monitoring via automated tooling. Security patches applied promptly. No known critical unpatched vulnerabilities at time of Effective Date. |
Controller Data is stored and processed in the United States (AWS us-east-1, Virginia). RafterCore's principal place of business is Phoenix, Arizona, USA.
Where you transfer Personal Data from the European Economic Area (EEA) or the United Kingdom to RafterCore in the United States, such transfers are made pursuant to the EU Standard Contractual Clauses (SCCs) (Module Two: Controller-to-Processor) as adopted by the European Commission Decision 2021/914, or the UK Addendum thereto. By accepting this DPA, both parties are deemed to have executed the applicable SCCs, which are incorporated herein by reference.
To the extent that SCCs apply:
RafterCore shall maintain a Transfer Impact Assessment available upon written request.
Sub-processor transfers to third countries (listed in Section 5) are covered by the sub-processors' own SCCs or other approved transfer mechanisms. Details are available in each sub-processor's privacy documentation.
Upon confirming a Security Incident that involves Controller Data, RafterCore will:
| Phase | Timeline | Action |
|---|---|---|
| Initial notification | Within 48 hours of confirmation | Notify you via email to your registered account address with available details of the incident |
| Regulatory notification (GDPR) | Within 72 hours of awareness | Notify relevant supervisory authority if required under GDPR Art. 33, in cooperation with you |
| Ongoing updates | As new information becomes available | Provide updates on scope, root cause, remediation steps, and data affected |
| Final report | Within 14 days | Provide post-incident report including root cause analysis and corrective actions taken |
Notification of a Security Incident does not constitute an admission of fault or liability by RafterCore.
You are responsible for notifying affected Data Subjects and supervisory authorities as required by applicable law, based on information provided by RafterCore. RafterCore will provide reasonable assistance in preparing required notifications.
Notification to RafterCore of a potential security concern (e.g., suspicious activity) does not constitute a Security Incident notification. RafterCore will investigate and notify you if a Security Incident is confirmed.
RafterCore shall provide the following assistance to you in responding to Data Subject requests, to the extent technically feasible:
You remain the primary point of contact for Data Subjects. Data Subjects should direct rights requests to you. You may submit requests on their behalf to privacy@raftercore.com.
RafterCore may charge reasonable fees for Data Subject rights assistance that exceeds two requests per month.
Upon termination or expiration of the Terms of Service for any reason, at your written request submitted within 30 days of termination, RafterCore will:
Notwithstanding the above, RafterCore may retain Controller Data to the extent and for the duration required by applicable law (e.g., tax records, legal holds). Any retained data will remain subject to the confidentiality and security obligations of this DPA.
Automated backup copies of Controller Data will be deleted in accordance with Supabase's backup retention schedule (typically 7–30 days, depending on plan), following deletion from active systems.
If you do not submit an export or deletion request within 30 days of termination, RafterCore will delete Controller Data from active systems within 90 days of account termination and will not be liable for data loss thereafter.
As the Controller, you represent and warrant that:
Each party's liability under this DPA shall be subject to the limitations and exclusions set forth in the RafterCore Terms of Service, except to the extent prohibited by applicable law.
Where both parties are responsible for damage caused by a breach of applicable data protection law, liability shall be apportioned in accordance with the degree to which each party is responsible for the damage, as determined by a court of competent jurisdiction.
Nothing in this DPA limits either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any liability that cannot be excluded or limited by law.
This DPA and any disputes arising from it shall be governed by and construed in accordance with the laws of the State of Arizona, USA, without regard to its conflict of law provisions, except where the SCCs specify otherwise for EEA/UK transfers (see Section 7.2).
Subject to the SCCs where applicable, each party irrevocably submits to the exclusive jurisdiction of the courts of Maricopa County, Arizona for any disputes arising under this DPA.
In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the parties' data protection obligations. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail with respect to EU/EEA data transfers.
RafterCore may update this DPA to reflect changes in law or its processing activities, with 30 days' written notice. Your continued use of the Services after the notice period constitutes acceptance of the updated DPA.
If any provision of this DPA is found to be unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the parties with respect to the processing of Controller Data and supersedes all prior agreements or understandings on this subject.
By creating a RafterCore account and accepting the Terms of Service, you agree to this DPA on behalf of yourself and your business. This constitutes valid acceptance under applicable law for the purposes of GDPR Article 28.
The effective date of your DPA is the date you first accepted the RafterCore Terms of Service.
Enterprise customers who require a countersigned DPA (e.g., for procurement compliance or GDPR Article 28 documentation purposes) may request one by emailing legal@raftercore.com with the subject line "DPA Request — [Your Company Name]". We respond within 5 business days.
Note: Signature blocks above are for enterprise countersigned versions only. Standard online acceptance via Terms of Service is legally valid for all other merchants.
For questions about this DPA, to request a countersigned version, or to submit a data subject rights request:
Email: legal@raftercore.com
Privacy inquiries: privacy@raftercore.com
Mail: RafterCore LLC, Phoenix, Arizona, USA
Related documents: Terms of Service · Privacy Policy · Data Compliance & Security