Legal · Kontracks

Data Processing Addendum

Effective August 24, 2026 · How LWR Technologies, Inc. processes personal information on behalf of businesses that use Kontracks.

1. How this Addendum works

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between LWR Technologies, Inc. ("Kontracks", "we", "us") and the business that operates a Kontracks workspace (the "Customer", "you"). It governs our processing of personal information contained in Customer Data on your behalf. If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA controls.

This DPA applies to the extent your use of Kontracks is subject to a data-protection law that requires a data-processing agreement, including the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and comparable U.S. state privacy laws. It takes effect on the effective date above without a signature; if your organization requires a countersigned copy, email legal@kontracks.com.

2. Definitions

Capitalized terms not defined here have the meaning given in the Terms. "Personal Information" means information within Customer Data that identifies or relates to an identifiable individual and is protected as "personal data", "personal information", or the equivalent under an applicable data-protection law. "Controller", "Processor", "Data Subject", "Business", "Service Provider", "Sub-processor", and "Personal Data Breach" have the meanings given under the applicable data-protection law.

3. Roles and scope of processing

As between the parties, you are the Controller (and, under the CCPA, the Business) of the Personal Information you put into Kontracks, and we are the Processor (and, under the CCPA, the Service Provider) acting on your behalf. Where your customers or other individuals are themselves subject to another controller, you warrant that you are authorized to instruct us as set out in this DPA.

The subject matter, duration, nature and purpose of the processing, the types of Personal Information, and the categories of Data Subjects are described in Annex A.

4. Your instructions

We will process Personal Information only on your documented instructions, including with regard to international transfers, unless we are required to process it by a law to which we are subject (in which case we will inform you of that requirement before processing, unless the law prohibits it). Your instructions are: (a) the Terms and this DPA; (b) your and your team's use of the platform's features and configuration; and (c) any written instructions you give us through a support channel that we agree to act on. You are responsible for ensuring your instructions comply with applicable law, and for the accuracy, quality, and legality of the Personal Information and the means by which you acquired it.

We will inform you if, in our opinion, an instruction infringes an applicable data-protection law, without obligation to actively monitor your compliance.

5. Confidentiality

We ensure that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities, and we limit access to Personal Information to personnel who need it to provide, secure, or support the service.

6. Security measures

We implement and maintain appropriate technical and organizational measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Those measures are summarized in Annex B. You are responsible for the security of the credentials and access controls within your own workspace (for example, who on your team you invite and at what role).

7. Sub-processors

You give us general authorization to engage the Sub-processors listed in Annex C to process Personal Information in order to provide the service. We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible to you for a Sub-processor's performance of its obligations.

We will give you reasonable notice (by updating Annex C and, where you have subscribed to notifications, by email or in-app notice) before adding or replacing a Sub-processor that processes Personal Information. You may object on reasonable data-protection grounds within 30 days; if we cannot reasonably accommodate the objection, your sole remedy is to stop using the affected feature or to terminate the affected subscription as described in the Terms.

8. Assisting you with Data Subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as reasonably possible, to respond to requests from Data Subjects to exercise their rights (access, correction, deletion, portability, restriction, and objection). The platform provides self-service tools to view, edit, export, and delete records within your workspace, which you can use to fulfill most requests directly. If a Data Subject contacts us directly about Personal Information we process on your behalf, we will refer them to you.

9. Personal Data Breach notification

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Information we process on your behalf, and will provide you with information reasonably available to us to help you meet your own breach-notification obligations. Our notification is not an acknowledgment of fault or liability.

10. Data protection impact assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your data-protection impact assessments and prior consultations with supervisory authorities, where required by an applicable data-protection law.

11. International data transfers

We and our Sub-processors are located in the United States, and providing the service involves processing Personal Information there. Where you transfer Personal Information subject to the EU or UK GDPR to us, the parties agree that the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) are incorporated into this DPA by reference and apply to that transfer, with the parties' details, the processing details in Annex A, and the security measures in Annex B completing the required annexes. If a transfer mechanism we rely on is invalidated, we will work with you in good faith to implement an alternative.

12. CCPA — Service Provider terms

When we process Personal Information that is subject to the CCPA on your behalf, we act as your Service Provider. We will not: (a) sell or share that Personal Information; (b) retain, use, or disclose it for any purpose other than performing the service specified in the Terms, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between you and us; or (d) combine it with personal information we receive from other sources, except as permitted by the CCPA. We certify that we understand and will comply with these restrictions.

13. Audits and information

We will make available to you information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once per twelve-month period (absent a Personal Data Breach or a regulator's requirement), require reasonable prior written notice, must be conducted during business hours without unreasonably disrupting our operations, and are subject to confidentiality. Where available, we may satisfy an audit request by providing a then-current third-party report or security documentation.

14. Return and deletion of Personal Information

On termination or expiry of your subscription, we will, at your choice, delete or return the Personal Information we process on your behalf, and delete existing copies, except to the extent applicable law requires us to retain it. This is subject to the retention window and export process described in Section 6 of the Terms. Residual copies held in routine backups are deleted in the ordinary course of our backup cycle and remain protected by this DPA until then.

15. Liability, term, and precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA takes effect on the effective date above and continues for as long as we process Personal Information on your behalf. If a specific negotiated data-processing agreement is signed by both parties, that agreement controls over this DPA for the affected subscription.

Annex A — Details of processing

Subject matterProvision of the Kontracks CRM, estimating, proposal, scheduling, invoicing, payment, and communication platform to the Customer.
DurationFor the term of the Customer's subscription, plus the retention window in Section 14.
Nature and purposeHosting, storing, transmitting, backing up, displaying, and otherwise processing Customer Data to operate the platform's features, including AI-assisted features, email and SMS delivery, mapping, and payment facilitation.
Types of Personal InformationContact identifiers (name, postal address, email, phone number); property and project details; proposal, invoice, and payment records; photos, documents, and measurements the Customer uploads; email and SMS message content and metadata; and any other Personal Information the Customer chooses to store in its workspace.
Categories of Data SubjectsThe Customer's prospects, homeowners and other customers, property occupants, and the Customer's own team members and crew.

Kontracks is not designed to store special categories of personal data (such as health, biometric, or government-ID data) or the personal data of children. The Customer should not upload such data.

Annex B — Technical and organizational security measures

  • Encryption of Personal Information in transit (TLS) and at rest at the hosting and database layer; sensitive tokens are additionally encrypted at the application layer.
  • Strict per-tenant data isolation enforced in the data-access layer, so one workspace cannot read or write another workspace's data, with automated tests and a static check guarding that boundary in our build pipeline.
  • Role-based access control within each workspace, and least-privilege access to production systems for our personnel.
  • Authentication safeguards including hashed credentials, session controls, and rate limiting on sensitive endpoints.
  • Network and platform security provided by our hosting and database providers, including managed backups and infrastructure hardening.
  • Logging and error monitoring to detect and investigate anomalies.
  • Confidentiality obligations and security awareness expectations for personnel with access to Personal Information.

Security is a shared responsibility: the Customer is responsible for managing its own users and roles, protecting its credentials, and configuring the platform appropriately.

Annex C — Approved Sub-processors

Sub-processorPurposeLocation
Amazon Web Services / VercelApplication hosting and content deliveryUnited States
NeonManaged PostgreSQL database (Customer Data at rest)United States
Stripe, Inc.Subscription billing and Customer-initiated payment processingUnited States
ResendTransactional and outbound email deliveryUnited States
Telnyx LLCSMS/MMS messaging delivery (10DLC / toll-free)United States
Google LLCMaps/geocoding, Gmail API (where a user connects an inbox), and AI model processingUnited States
Apple Inc.Apple Maps imagery and geocodingUnited States
Anthropic, PBCAI-assisted features (drafting, extraction, vision, summaries)United States
OpenAI, L.L.C.AI-assisted voice transcription and text-to-speech (optional features)United States

Some Sub-processors are engaged only when the Customer uses the related feature (for example, email delivery, SMS, a connected Gmail inbox, or optional voice features). This list may be updated as described in Section 7.

Contact

Data-protection and DPA questions: privacy@kontracks.com · Countersignature requests: legal@kontracks.com

© 2026 LWR Technologies, Inc. — Kontracks platform. Delaware, USA.