Data Processing Addendum
Effective date: July 22, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Terms of Service and the customer agreement (together, the "Agreement") between Roofers Lab, a service of Kraken OS LLC (doing business as Roofers Lab) ("Roofers Lab," "we," "us," or "our"), and the roofing company that purchases the Services ("Client," "you," or "your"). It governs our processing of personal information that we handle on your behalf through the marketing system we provide. If there is a conflict between this DPA and the rest of the Agreement on the subject of data processing, this DPA controls.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. "Applicable Privacy Law" means the state consumer privacy laws that apply to the processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA/CPRA") and comparable laws in other states. The terms "personal information," "sell," "share," "service provider," "processor," "business," "controller" and "consumer" have the meanings given under Applicable Privacy Law. "Client Personal Information" means personal information about your customers and prospective customers (for example, homeowners) that we process on your behalf to provide the Services. "Subprocessor" means a third party we engage to process Client Personal Information.
2. Roles and Scope
For Client Personal Information, you are the business (or controller) and we act as your service provider (or processor). You determine the purposes and means of the processing; we process only on your documented instructions, which are the Agreement, this DPA and your ordinary use of the Services. This DPA does not apply to information we process as a business for our own purposes (for example, information about you as our own client, or visitors to our own Site), which is governed by our Privacy Policy.
The subject matter of the processing is our provision of the Services; the duration is the term of the Agreement plus the wind-down period in Section 8; the nature and purpose is providing marketing-system functionality (lead capture, communications, scheduling, CRM and related functions); the types of personal information are contact and inquiry details such as name, address, email address, phone number and project notes; and the categories of individuals are your customers and prospective customers.
3. Processing Instructions and Restrictions
We will process Client Personal Information only to provide, maintain and support the Services and for the business purposes specified in the Agreement. We will not:
- Sell or share Client Personal Information, as "sell" and "share" are defined under Applicable Privacy Law;
- Retain, use or disclose Client Personal Information for any purpose other than the business purposes specified in the Agreement, including outside the direct business relationship between you and us, except as permitted by Applicable Privacy Law;
- Combine Client Personal Information with personal information we receive from, or on behalf of, another party, or that we collect from our own interactions with individuals, except as permitted for a service provider under Applicable Privacy Law; or
- Process Client Personal Information for our own commercial purposes.
We will provide at least the same level of privacy protection for Client Personal Information as is required of you under Applicable Privacy Law. We will notify you if we determine that we can no longer meet our obligations under Applicable Privacy Law, and you may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized processing. We will comply with your reasonable and documented instructions and will tell you if, in our reasonable opinion, an instruction violates Applicable Privacy Law.
4. Confidentiality and Personnel
We treat Client Personal Information as confidential. We limit access to personnel who need it to provide the Services, and those personnel are bound by written or professional confidentiality obligations. We provide appropriate training on the handling of personal information.
5. Subprocessors
You authorize us to engage Subprocessors to process Client Personal Information in support of the Services. We engage Subprocessors within the following categories: CRM and communications platform provider; telephony and SMS carriers and messaging aggregators; payment processor; hosting and infrastructure providers; scheduling tools; email delivery provider; and AI service providers used for the disclosed AI features. A current list of the specific Subprocessors is available on written request to support@rooferslab.com.
We impose data-protection obligations on each Subprocessor that are consistent with this DPA, including the service-provider restrictions in Section 3, and we remain responsible for our Subprocessors' performance. We will give you at least 30 days' notice before adding or replacing a Subprocessor in a way that materially changes the processing of Client Personal Information. If you have a reasonable, good-faith objection, tell us within that period and we will work with you in good faith to address it; if we cannot, you may cancel the affected Services as your exclusive remedy.
6. Security
We maintain reasonable and appropriate technical and organizational measures designed to protect Client Personal Information against unauthorized access, use, alteration and disclosure, including access controls, encryption of personal information in transit, activity logging and an incident-response process. No safeguards are perfectly secure. If we become aware of a breach of security leading to the unauthorized access to or disclosure of Client Personal Information, we will notify you without undue delay and provide the information reasonably available to us to help you meet your own notification obligations.
7. Consumer Requests and Assistance
You are responsible for responding to requests from your customers to exercise their rights under Applicable Privacy Law. Taking into account the nature of the processing, we will provide reasonable assistance, through appropriate technical and organizational measures, to help you respond to verifiable consumer requests, including requests to access, delete or correct personal information. If we receive a request directly from one of your customers, we will not respond to it substantively (except, where appropriate, to direct the person to you) and will forward it to you without undue delay.
8. Data Retention and Deletion
We retain Client Personal Information only as long as needed to provide the Services or as required by law. On termination of the Agreement, or on your earlier written request, we will delete or return Client Personal Information in our possession, except for information we are required or permitted by law to retain and routine backups that are overwritten in the ordinary course. Your portable data will remain available for export for 30 days after cancellation, after which we may delete it, subject to legal retention. This wind-down does not enlarge the portability terms in the Agreement.
9. Audits
On reasonable written request, and no more than once per year unless required by Applicable Privacy Law or following a security incident, we will make available the information reasonably necessary to demonstrate our compliance with this DPA. Verification is documentation-based; it does not include access to our systems, our premises or the data of other clients, and it is subject to confidentiality.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA does not increase either party's aggregate liability beyond the limits stated there.
11. Contact
Questions or requests under this DPA can be sent to:
Kraken OS LLC (DBA Roofers Lab)
5900 Balcones Drive STE 100, Austin, TX 78731, USA
Email: support@rooferslab.com