Skip to content

Data processing addendum

Last updated October 6, 2026 · Agentic Services

This addendum forms part of the terms of service between you (the customer) and Agentic Services. It applies to personal data that we process on your behalf when you use Rundown. If you need a signed copy, write to legal@rndwn.app.

1. Roles

You are the controller (or "business") of the personal data in your account, such as information about your clients and their staff. We are the processor (or "service provider"). We process that data only to provide the service and as you instruct.

2. Scope of processing

  • Subject matter: providing field service management software.
  • Duration: the term of your subscription, plus the deletion period below.
  • Data subjects: your clients, their contacts, your team members and subcontractors.
  • Types of data: names, phone numbers, email addresses, site addresses, messages, photos, job and financial records. The service is not intended for special categories of data.

3. Our obligations

  • Process personal data only on your documented instructions, which include the terms, this addendum and your use of the product's features.
  • Not sell personal data, and not use it for any purpose other than providing the service.
  • Not use personal data to train AI models, and not allow our subprocessors to do so.
  • Ensure that people who can access personal data are bound by confidentiality.
  • Help you respond to requests from individuals to exercise their privacy rights, taking into account the tools already available to you in the product.
  • Tell you if we believe an instruction breaks the law.

4. Security measures

We maintain technical and organizational measures appropriate to the risk, including:

  • isolation of each customer's data by organization, enforced on the server;
  • role-based permissions with server-side redaction of restricted fields;
  • encryption in transit, and additional encryption of stored vendor credentials with per-customer keys;
  • an audit log of financial changes, permission changes, exports and administrative access;
  • nightly backups retained for 30 days;
  • payment card data handled only by Stripe.

More detail is on the security page.

5. Subprocessors

You authorize us to use the subprocessors listed below. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable grounds.

SubprocessorPurposeData
ClerkSign-in, organizations, sessions and MFANames, emails, credentials, session data
ConvexApplication database, file storage and server functionsAll tenant data stored in Rundown
StripeSubscription billing and Connect paymentsBilling contacts, payment and payout records. Card numbers go to Stripe directly and never reach Rundown
TwilioSMS delivery and phone numbersPhone numbers, message bodies, delivery status
ResendTransactional and automation emailEmail addresses, message bodies, delivery status
AnthropicAI parsing and drafting (Claude models)Only the fields needed for the task. Not used to train models
Google Maps PlatformAddress lookup, geocoding and mapsSite addresses
SentryError monitoringError traces and technical metadata
PostHogProduct analyticsUsage events and device metadata

6. Personal data breaches

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or disclosure of your personal data, we will notify you without undue delay and provide the information you reasonably need to meet your own obligations.

7. International transfers

Personal data is processed in the United States. Where a transfer requires a legal mechanism, such as standard contractual clauses, we will enter into it with you on request.

8. Audits

On reasonable written request, no more than once a year, we will provide information needed to demonstrate compliance with this addendum, including answers to a security questionnaire.

9. Return and deletion

You can export your data at any time. When your account is deleted we hold the data for 30 days, then delete it from active systems. Backups expire within a further 30 days. We may keep data where the law requires it.

10. Order of precedence

If this addendum conflicts with the terms of service on a matter of personal data processing, this addendum controls.