Back to home
Legal

Data Processing Addendum

Last updated: September 2, 2026

1. Scope and Roles

This Data Processing Addendum (“DPA”) forms part of the PestBooker Terms of Service between PestBooker, LLC (“PestBooker”, “we”) and the customer that accepted them (“Customer”, “you”). It applies whenever we process Customer Personal Data on your behalf in providing the service.

For Customer Personal Data, you are the business or controller and PestBooker is the service provider or processor. You determine the purposes and means of processing through your use and configuration of the service; we process only as set out here and on your instructions.

Where you act as a processor for another party, references to you as controller apply to that party, and you warrant you have authority to enter into this DPA on their behalf.

2. Definitions

  • Customer Personal Data: personal information within Customer Data — principally your End Customers’ names, addresses, phone numbers, email addresses, property details, appointment history, message content, and payment metadata.
  • Applicable Data Protection Law: privacy and data protection laws that apply to the processing, including the California Consumer Privacy Act as amended by the CPRA, and comparable US state laws.
  • Subprocessor: a third party engaged by PestBooker to process Customer Personal Data on our behalf.
  • Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data in our control.

Terms defined in the Terms of Service keep their meaning here.

3. Processing of Customer Personal Data

3.1 Instructions

We process Customer Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, your configuration of the service, and any further written instruction you give that we agree to. We will tell you if we believe an instruction infringes Applicable Data Protection Law.

3.2 Purpose Limitation

We do not sell or share Customer Personal Data, and will not retain, use, or disclose it for any purpose other than performing the service, or as otherwise permitted by Applicable Data Protection Law. We will not combine it with personal information received from another source, except as permitted for a service provider.

3.3 Details of Processing

  • Subject matter: provision of the PestBooker booking and scheduling platform.
  • Duration: the term of the Terms of Service, plus the deletion window in section 9.
  • Nature and purpose: hosting, storage, transmission, scheduling, messaging to End Customers on your behalf, payment coordination through your merchant provider, analytics for you, and support.
  • Categories of data subjects: your End Customers and prospective customers, and your personnel who use the service.
  • Categories of personal data: identifiers, contact details, service address and property characteristics, appointment and service history, message content, and payment metadata. We do not require, and ask you not to submit, special categories of personal data.

3.4 Your Responsibilities

You are responsible for the lawfulness of the Customer Personal Data you provide and of the instructions you give, including any notice and consent required to contact your End Customers. Section 7 of the Terms of Service governs consent for messaging.

4. Confidentiality

We limit access to Customer Personal Data to personnel and contractors who need it to provide or support the service, and who are bound by written confidentiality obligations or a professional duty of confidence.

5. Security

We maintain technical and organizational measures designed to protect Customer Personal Data appropriate to its sensitivity and the risk, including:

  • Encryption of data in transit over public networks, and at rest at our hosting providers
  • Role-based access control, with tenant isolation enforced on every request
  • Authentication managed by a specialist identity provider, with multi-factor authentication available
  • Segregation of credentials for your connected systems, stored encrypted and never exposed to other tenants
  • Logging and error monitoring, with alerting on anomalous conditions
  • Regular dependency patching, and least-privilege access for our own personnel

Security measures may evolve; we will not materially reduce the overall level of protection during your subscription. Our Security page describes current practice.

6. Subprocessors

6.1 Authorization

You give general authorization for PestBooker to engage Subprocessors. Each is bound by written obligations no less protective, in substance, than those in this DPA, and we remain responsible to you for their performance as if we had performed it ourselves.

6.2 Current Subprocessors

The current list is published at pestbooker.com/subprocessors, with what each one does and where data is hosted. All Customer Personal Data is hosted in the United States.

6.3 Changes and Objection

We will update that page and email your account administrator at least 14 days before a new or replacement Subprocessor begins processing Customer Personal Data. If you reasonably object on data protection grounds within those 14 days, we will work with you in good faith to offer an alternative; if we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.

7. Assistance with Data Subject Requests

The service gives you the ability to access, correct, export, and delete Customer Personal Data yourself, which is normally sufficient to answer a request from a data subject.

If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to direct them to you, and will inform you promptly unless legally prohibited. Where you cannot answer a request through the service, we will provide reasonable assistance at no charge for a reasonable volume of requests.

8. Security Incidents

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe what we know at the time — the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed — and we will supplement it as the investigation progresses.

We will take reasonable steps to contain and remediate. Notifying you is not an admission of fault. Notifying affected individuals or regulators is your decision as the business or controller, and we will provide the information you reasonably need to make and act on it.

9. Deletion and Return

For 30 days after termination you may export Customer Personal Data through the service or by written request. After that period we will delete it within 90 days, except for copies in routine backups, which are deleted on their normal cycle, and anything we are required to retain by law or to establish or defend legal claims. Retained copies stay subject to this DPA.

10. Audits and Assessments

On reasonable written request, no more than once in any 12 months unless required by a regulator or following a Security Incident, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including a description of our controls and answers to a reasonable security questionnaire.

We will cooperate with a data protection impact assessment where one is required and relates to our processing. On-site audits are by agreement, at your expense, subject to confidentiality, and must not compromise the security or privacy of other customers.

11. California-Specific Terms

This section applies where the CCPA governs. PestBooker is a “service provider” and receives Customer Personal Data solely to perform the business purposes set out in section 3.3. PestBooker certifies that it understands the restrictions in this section and will comply with them.

  • We do not sell or share Customer Personal Data, as those terms are defined by the CCPA
  • We do not retain, use, or disclose it for any purpose other than the business purposes specified, including any commercial purpose of our own
  • We do not combine it with personal information received from another source, except as a service provider is permitted to do
  • We will notify you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorized use

Deidentified or aggregated data derived from use of the service is not Customer Personal Data. We will not attempt to reidentify it, and will contractually bind any recipient to the same.

12. International Transfers

The service is operated from the United States and all Customer Personal Data is hosted there. Do not submit personal data that may not lawfully be transferred to or processed in the United States. If we later offer the service to customers subject to a law requiring a specific transfer mechanism, we will put an appropriate one in place before processing under it.

13. General

  • Precedence. Where this DPA conflicts with the Terms of Service on the processing of Customer Personal Data, this DPA controls. Everything else in the Terms of Service continues to apply.
  • Term. This DPA takes effect with the Terms of Service and continues until we have deleted or returned all Customer Personal Data under section 9.
  • Liability. The limitation of liability in section 15 of the Terms of Service applies to claims under this DPA, in the aggregate across both documents rather than separately.
  • Changes. We may update this DPA as the service or the law changes. A material change is notified and requires acceptance in the same way as a change to the Terms of Service.

14. Contact

For questions or requests under this DPA:

  • Email: privacy@pestbooker.com
  • Address: PestBooker, LLC, 8690 Aero Dr, Ste 115 #1076, San Diego, CA 92123