RoofHyve Data Processing Addendum / Customer Data Addendum
For customer, employee, project, attendance, payroll-related, and portal data
Owner / Publisher
RoofHyve Inc.
Product
RoofHyve
Effective Date
June 12, 2026
Last Updated
June 29, 2026
Audience
Roofing company customers/subscribers and RoofHyve
Applies To
Processing of customer data, employee/team data, project/proposal data, attendance/location data, payroll-related data, customer portal data, and related records
1. Parties and Scope
This Data Processing Addendum (“DPA”) forms part of the agreement between RoofHyve Inc. (“RoofHyve”) and the roofing company customer (“Customer”). This DPA applies when RoofHyve processes Customer Data on behalf of Customer through the RoofHyve platform.
2. Definitions
Term
Meaning
Customer Data
Personal information, personal data, records, files, images, messages, signatures, logs, and other information submitted to or generated in RoofHyve by or for Customer, including customer/homeowner, employee, contractor, project, proposal, attendance, payroll, and location data.
Controller / Business
The party that determines the purposes and means of processing personal information. For Customer Data, this is generally the roofing company.
Processor / Service Provider
The party that processes personal information on behalf of the controller/business. For Customer Data, this is generally RoofHyve.
Subprocessor / Service Provider
A third-party provider engaged by RoofHyve to process Customer Data to provide the Services.
Security Incident
A confirmed unauthorized access to, acquisition of, disclosure of, or loss of Customer Data processed by RoofHyve that triggers notification obligations under applicable law or the agreement.
3. Processing Instructions
RoofHyve will process Customer Data only to provide, secure, support, maintain, improve, and administer RoofHyve; to comply with Customer’s documented instructions; to satisfy legal obligations; and as otherwise permitted by the agreement and applicable law. Customer is responsible for ensuring its instructions are lawful.
4. Customer Responsibilities
Provide required notices and obtain required consents from customers, employees, contractors, sales reps, and other individuals.
Ensure lawful collection and use of customer, insurance, employee, payroll, tax, SSN, bank, location, and project information.
Configure roles, permissions, attendance/location settings, proposal terms, cancellation windows, warranties, payment instructions, and integrations lawfully.
Respond to privacy requests where Customer is the controller/business, with reasonable assistance from RoofHyve where required.
Avoid submitting unnecessary sensitive information.
5. RoofHyve Responsibilities
Process Customer Data according to this DPA and the agreement.
Use reasonable administrative, technical, and organizational safeguards.
Limit personnel access to those with a business need.
Maintain confidentiality obligations for personnel with access to Customer Data.
Provide reasonable assistance for privacy rights requests, security incidents, and compliance inquiries, taking into account the nature of processing.
Maintain records reasonably necessary to demonstrate compliance with this DPA.
6. Nature and Purpose of Processing
Processing Area
Description
Account and role management
User invitations, roles, permissions, login, access control.
Customer/project operations
Lead, estimate, appointment, proposal, invoice, project, task, document, warranty, draw schedule, discount, and communication workflows.
Customer portal
Customer login, file/image/message upload, proposal review, signature, rejection/cancellation, document download.
Employee/team/attendance/payroll
Employee records, emergency contacts, attendance, time entries, travel, overtime, location during attendance, leave, payroll-related records, salary/hourly rates, bank details, tax IDs, SSNs, payouts.
Sales rep/CSR workflows
Onboarding, referral invite status, assigned account management, subscription/revenue visibility, percentage-based commission calculations.
Security and support
Logs, audit trails, troubleshooting, fraud/security monitoring, support communications.
7. Categories of Individuals and Data
Individuals may include roofing company admins, employees, contractors, sales reps/CSRs, customer/homeowner users, insurance agents/adjustors, support contacts, and website/app users. Data categories are described in the Privacy Policy and may include identifiers, customer records, commercial/project information, geolocation, electronic signatures, uploaded content, employment/payroll records, sensitive information, logs, and communications.
8. Subprocessors
Customer authorizes RoofHyve to use subprocessors to provide the Services. RoofHyve will impose appropriate contractual obligations on subprocessors to protect Customer Data.
Provider / Category
Purpose
Stripe
Subscription checkout, payment processing, billing references, payment-event records.
QuickBooks / Intuit
Accounting and bookkeeping integration where enabled by the Customer.
Twilio
SMS, phone, verification, and communication delivery where enabled.
Microsoft Azure
Cloud hosting, storage, infrastructure, compute, and related security tooling.
Microsoft SignalR
Real-time updates and live notification delivery.
Google Maps Platform
Maps, address lookup, geocoding, routing, and location-related features.
Google Cloud / Firebase
Authentication support, Firebase Cloud Messaging push notifications, and app infrastructure where enabled.
Google Analytics / Tag Manager
Website/app analytics and performance measurement, subject to cookie and consent settings.
Microlink
URL metadata and link-preview generation.
Email, push, monitoring, security, and support providers
Transactional communications, support, error logging, service monitoring, and security operations.
Customer may request a current subprocessor list at dpa@roofhyve.com. RoofHyve will provide notice of any new subprocessor that will materially process Customer Data, for example by updating its subprocessor list and, where Customer has subscribed to such notices, by email before authorizing the new subprocessor to process Customer Data. Customer may object to a new subprocessor on reasonable, good-faith data-protection grounds within thirty (30) days of notice. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Services as its sole remedy.
9. Security Measures
Role-based access controls and permission management.
Authentication and credential protection.
Hosting safeguards through cloud infrastructure providers.
Logging and monitoring of access and activity.
Encryption in transit and encryption at rest where available in the applicable storage or infrastructure layer.
Backup, recovery, and availability controls appropriate to the service.
Internal confidentiality obligations and restricted personnel access.
Incident response procedures.
10. Security Incidents
RoofHyve will notify Customer without undue delay after confirming a Security Incident involving Customer Data, consistent with applicable law, the nature of the incident, and the information available to RoofHyve. Customer is responsible for notifications to individuals or regulators where Customer is the controller/business, unless law requires RoofHyve to notify directly. RoofHyve will provide reasonable information and assistance required for Customer to evaluate and respond to the incident.
11. Privacy Rights Requests
If RoofHyve receives a request from an individual relating to Customer Data controlled by Customer, RoofHyve may redirect the request to Customer or provide reasonable assistance to Customer. RoofHyve may respond directly where legally required or where the information relates to RoofHyve’s own controller/business activities.
11A. Individual Account Deletion Requests
RoofHyve may receive deletion requests directly from individuals from the relevant portal users. To the extent the relevant information is Customer Data controlled by Customer, RoofHyve may direct the individual to Customer, notify Customer, or assist Customer in responding, depending on applicable law, product functionality, and the parties’ roles.
Where RoofHyve processes a verified individual account deletion request, the request is limited to the requesting user account and related personal account profile information where deletion, anonymization, or restriction is reasonably possible. Such a request does not require RoofHyve to delete the Customer tenant, other user accounts, customer/project records, estimates, proposals, signed documents, invoices, job history, audit logs, security logs, or other Customer Data that Customer controls or that must be retained for lawful purposes.
Customer is responsible for determining whether and how Customer-controlled records should be retained, deleted, anonymized, or restricted, subject to applicable law and the Agreement. RoofHyve will provide reasonable assistance as required by applicable data protection law and the Agreement.
12. Return, Deletion, Retention, and Export Limitations
Upon termination, Customer Data may remain stored but access may be locked unless Customer maintains an eligible subscription or hibernation/read-only plan. RoofHyve does not currently provide a general self-service bulk export feature. This product limitation does not limit any access, copy, portability, deletion, or return obligations required by applicable law or a signed agreement. Deletion, anonymization, restriction, or copy requests may be handled upon verified request, subject to legal retention, backups, audit logs, security records, accounting/tax obligations, dispute records, signed proposal/audit records, and product limitations.
Individual user account deletion requests do not override retention obligations or permitted retention exceptions for Customer Data, including records retained for legal, tax, accounting, compliance, audit, security, fraud prevention, dispute resolution, backup, contract enforcement, or business recordkeeping purposes. Where feasible, RoofHyve may delete, anonymize, restrict, or de-identify personal account profile information while preserving required Customer Data and system records.
13. California Service Provider / Contractor Terms
To the extent CCPA/CPRA applies and RoofHyve processes personal information as a service provider/contractor for Customer, RoofHyve will not sell or share Customer Data, retain/use/disclose Customer Data outside the business purposes specified in the agreement, combine Customer Data with other personal information except as permitted by law, or use Customer Data for cross-context behavioral advertising, unless authorized by law and agreement. Customer remains responsible for consumer notices and rights handling where Customer is the business.
14. Canada Terms
For Canadian personal information, Customer remains responsible for meaningful consent, identifying purposes, limiting collection, accuracy, retention, safeguards, openness, individual access, correction, and complaint handling where Customer controls the information. RoofHyve will process Canadian personal information in accordance with the agreement, this DPA, and applicable law. Where Quebec law applies, Customer remains responsible for required notices, privacy impact assessments, and rights handling for systems and processing controlled by Customer, with reasonable assistance from RoofHyve where required.
15. Audit and Information Rights
Upon reasonable request and subject to confidentiality, security, and operational limits, RoofHyve may provide information reasonably necessary to demonstrate compliance with this DPA, such as security summaries, policy descriptions, subprocessor information, or relevant certifications if available. On-site audits are subject to separate written agreement, reasonable scope limits, security restrictions, scheduling, and fees unless required by law.
16. International Transfers
Customer acknowledges that RoofHyve and its subprocessors may process Customer Data in the United States and other jurisdictions. Where required by applicable law, the parties will use appropriate contractual, organizational, and technical safeguards for cross-border processing.
17. Order of Precedence
For matters concerning processing of Customer Data, this DPA controls over conflicting terms in the Terms of Service or other incorporated policies, unless a signed agreement expressly states that it supersedes this DPA.
Contact Information
RoofHyve Inc.
Legal Mailing Address: 2146 Pine St, Redding, CA 96001
Legal Notices: legal@roofhyve.com
DPA / Subprocessor Requests: dpa@roofhyve.com
Security: security@roofhyve.com
Privacy Requests: privacy@roofhyve.com
Support: support@roofhyve.com