This Data Processing Addendum ("DPA") forms part of the Master Services Agreement (the "Agreement") between Obra Tech LLC, a California limited liability company ("Provider") and the contractor who accepted the Agreement ("Contractor"). Capitalized terms not defined here have the meaning given in the Agreement.
1. Scope and Roles
1.1 What this covers. This DPA governs Provider's handling of Personal Information collected from visitors to Contractor's Site — principally the contact and project details a homeowner submits through a quote form.
1.2 Roles under privacy law. Contractor determines why visitor Personal Information is collected and how Contractor uses it. To the extent Contractor is a covered "Business" under the CCPA, Contractor acts as the Business and Provider acts as a Service Provider or Contractor for that Personal Information. If Contractor is not a covered CCPA Business, the parties still agree by contract that Provider will use visitor Personal Information only as stated in this DPA.
1.3 Definitions. "Personal Information," "Business," "Service Provider," "Consumer," "process," "sell," and "share" have the meanings given in the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, Cal. Civ. Code § 1798.100 et seq. (the "CCPA").
2. What Provider Processes
2.1 Categories of Personal Information.
| Category | Fields |
|---|---|
| Identifiers | Name, phone number, email address (optional), ZIP code |
| Commercial information | Project type, approximate square footage, project timeline |
| Free-text content | Any message the visitor writes, which may contain additional personal information the visitor chooses to include |
| Internet activity | IP address and browser user agent, captured incidentally in hosting logs |
2.2 Categories of Consumers. Visitors to Contractor's Site who submit a quote request — typically homeowners and property owners in Contractor's service area.
2.3 Purpose of processing. Provider processes this Personal Information for one purpose: to transmit the inquiry to Contractor so Contractor can respond. Provider also processes it incidentally to operate, secure, and debug the Site.
2.4 Duration. Processing is transient. See Section 5.
3. Provider's Obligations as a Service Provider or Contractor
Provider certifies that it understands the restrictions in this Section and will comply with them. Provider shall not:
3.1 Sell or share Personal Information, as "sell" and "share" are defined in the CCPA. Provider does not and will not sell or share Personal Information collected through Contractor's Site.
3.2 Retain, use, or disclose Personal Information for any purpose other than the specific business purpose of performing the Services specified in the Agreement and this DPA, or as otherwise permitted by the CCPA.
3.3 Retain, use, or disclose Personal Information outside the direct business relationship between Provider and Contractor.
3.4 Combine Personal Information received from Contractor with personal information Provider receives from another source, except as permitted under CCPA regulations for a service provider or contractor performing services on behalf of more than one business.
3.5 Use Personal Information for cross-context behavioral advertising.
3.6 Use Personal Information to build or improve a profile of any Consumer, to market to any Consumer, or to train any machine-learning or artificial-intelligence model.
3.7 Same level of protection. Provider will provide the same level of privacy protection for Personal Information as required of service providers and contractors under the CCPA, including reasonable cooperation with Contractor's obligations concerning notices, requests, deletion, correction, and security incidents.
3.8 Monitoring and remediation. Contractor may take reasonable and appropriate steps to help ensure Provider uses Personal Information consistently with Contractor's obligations under the CCPA, including the written audit process in Section 10. If Contractor reasonably believes Provider is using Personal Information in an unauthorized manner, Contractor may notify Provider, and Provider will take reasonable and appropriate steps to stop and remediate the unauthorized use.
3.9 Notice of inability to comply. Provider will notify Contractor promptly if Provider determines it can no longer meet the obligations in this DPA.
4. Subprocessors
4.1 Authorization. Contractor authorizes Provider to engage the subprocessors listed below. Provider will impose contractual terms on each subprocessor that are no less protective, in substance, than the restrictions in this DPA for the Personal Information the subprocessor receives.
4.2 Current subprocessors.
| Subprocessor | Purpose | Data it receives |
|---|---|---|
| Vercel Inc. | Hosting, serverless execution, logging | All submitted form data transits Vercel's infrastructure; IP address and request metadata appear in function logs |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | The full contents of each lead email, including name, phone, email, ZIP, and message |
| Google LLC | Maps embed on the Site | Visitor IP address and browser information, disclosed when the map loads. Google receives this directly from the visitor's browser; it does not pass through Provider. |
| Cloudflare, Inc. | Domain registration and DNS | Domain registration details only; no visitor Personal Information |
| Stripe, Inc. | Contractor billing | Contractor's own billing information only; no visitor Personal Information |
4.3 Not currently engaged. Twilio (SMS lead alerts) and Anthropic (AI editing assistant) appear in the Agreement as features of certain Plans. As of this version they are not in production and receive no Personal Information. Provider will update this DPA before either begins processing.
4.4 Changes. Provider will give Contractor at least thirty (30) days' notice before adding or replacing a subprocessor that will process Personal Information. If Contractor reasonably objects on data-protection grounds, Contractor may terminate the Agreement without penalty before the change takes effect.
5. Retention and Storage
This section describes what the system actually does. It is deliberately specific.
5.1 No database. Provider does not operate a database for leads. A submitted form is validated, formatted into an email, transmitted to Contractor's inbox through Resend, and discarded from Provider's application memory. There is no persistent lead store on Provider's side.
5.2 Where copies nonetheless exist.
- Contractor's own email inbox — the primary and intended copy. Retention is entirely under Contractor's control.
- Resend — retains message logs and content according to its own retention schedule.
- Vercel function logs — request metadata and, in a misconfiguration scenario where the email provider key is absent, the full lead payload may be written to server logs. Vercel retains logs per its own schedule. Provider treats this as a defect and is remediating it; see Section 5.4.
- Provider's master inbox — see Section 6.
5.3 Deletion. Because Provider maintains no lead database, ordinary deletion work will usually concern Contractor's own inbox and any service-provider logs or monitoring copies. Provider will delete or de-identify any lead copy under Provider's control when Contractor makes a verified deletion request, subject to legal retention requirements and ordinary backup/log retention. Provider will forward any deletion request it receives directly to Contractor, who controls the primary copies that exist.
5.4 Known limitations. Provider discloses the following honestly rather than describing controls it does not have:
- Lead payloads may be written to hosting logs when the email provider is misconfigured.
- Provider does not currently encrypt lead content at rest beyond the encryption its subprocessors apply by default.
- Provider does not currently maintain a formal access log for the master inbox described in Section 6.
Provider will update this DPA as these are addressed.
6. Provider's Copy of Leads
6.1 What happens. Provider's system may copy Provider's own monitoring inbox on lead emails sent from Contractor's Site. Provider uses these copies to confirm that lead delivery is working, diagnose failures, maintain security, preserve delivery evidence, and comply with legal obligations.
6.2 Restrictions. Provider will not use these copies to contact the Consumer, to market to the Consumer, to build any profile, or for any purpose outside the limited operational purposes in Section 6.1. Section 3 applies to them in full.
6.3 Disclosure, retention, and opt-out. This copying is disclosed in the privacy policy deployed on Contractor's Site. Provider keeps monitoring copies only as long as reasonably needed for delivery verification, debugging, security, dispute evidence, and legal compliance. Contractor may instruct Provider in writing to disable it at any time, at no cost, by emailing support@obraup.com. Provider recommends leaving it enabled for the first thirty (30) days after launch, when delivery failures are most likely.
7. Security
7.1 Measures in place. Provider maintains the following:
- TLS encryption for all data in transit between the visitor, the Site, and subprocessors
- Encryption at rest as provided by default by Vercel and Resend
- Input validation and schema enforcement on all submitted data
- Bot filtering on submission endpoints
- Access to production infrastructure restricted to Provider and credentialed personnel
- Secrets held in environment configuration, never in source control
7.2 Proportionality. Provider is a small business. The measures above are proportionate to the sensitivity of the data — contact details and home-improvement project descriptions. Provider does not process financial account numbers, government identifiers, health information, or biometric data through Contractor's Site, and Contractor must not configure the Site to collect them.
7.3 Personnel. Provider will ensure that anyone authorized to process Personal Information is bound by confidentiality obligations.
8. Security Incidents
8.1 Notice. Provider will notify Contractor without undue delay and no later than seventy-two (72) hours after becoming aware of a security incident affecting Personal Information processed under this DPA.
8.2 Contents. The notice will describe, to the extent known: the nature of the incident, the categories and approximate number of Consumers affected, the likely consequences, and the measures taken or proposed.
8.3 Cooperation. Provider will reasonably cooperate with Contractor's investigation and with any notification Contractor is required to make under Cal. Civ. Code § 1798.82 or other applicable law.
8.4 Who notifies Consumers. Contractor is responsible for determining whether notice to affected Consumers or any regulator is required and for providing that notice, unless the parties agree otherwise in writing.
9. Consumer Rights Requests
9.1 Requests to Provider. If a Consumer contacts Provider directly to exercise a CCPA right, Provider will not respond substantively and will forward the request to Contractor within five (5) business days.
9.2 Assistance. Provider will provide commercially reasonable assistance to help Contractor respond to verified requests to know, delete, correct, or opt out. Given Section 5.1, that assistance will usually consist of confirming whether Provider holds any monitoring copy or persistent lead record and deleting any copy under Provider's control where required. Provider may charge reasonable fees for unusually burdensome, repetitive, or custom assistance unless prohibited by law.
9.3 Contractor's responsibility. Contractor is responsible for verifying requests, responding within statutory deadlines, and maintaining any required records.
10. Audit and Compliance Information
On written request, no more than once per twelve-month period, Provider will provide Contractor with reasonable written information about its processing under this DPA sufficient for Contractor to confirm compliance. Provider may satisfy this obligation through written responses, security summaries, subprocessor lists, policies, or third-party reports if available. Provider is not obligated to permit on-site inspection, disclose information about other customers, reveal trade secrets, or provide information that would compromise security.
11. Termination
11.1 This DPA remains in effect while Provider processes Personal Information under the Agreement.
11.2 On termination of the Agreement, Provider will cease all processing. Given Section 5.1 there is generally nothing for Provider to return or delete; if Provider holds any persistent copy at that time, Provider will delete it within thirty (30) days of Contractor's written request, except where retention is required by law.
12. General
12.1 Precedence. If this DPA conflicts with the Agreement on the subject of personal information, this DPA controls.
12.2 Governing law. California law governs this DPA.
12.3 Changes. Provider may update this DPA on thirty (30) days' notice, consistent with Section 1.4 of the Agreement.
12.4 Contact. Privacy questions: support@obraup.com.
Data Processing Addendum v1.0 · October 3, 2026 · Incorporated by reference into the Master Services Agreement.
Questions? Email support@obraup.com