Last updated: September 2, 2026
This Data Processing Addendum (“DPA”) forms part of the PestBooker Terms of Service between PestBooker, LLC (“PestBooker”, “we”) and the customer that accepted them (“Customer”, “you”). It applies whenever we process Customer Personal Data on your behalf in providing the service.
For Customer Personal Data, you are the business or controller and PestBooker is the service provider or processor. You determine the purposes and means of processing through your use and configuration of the service; we process only as set out here and on your instructions.
Where you act as a processor for another party, references to you as controller apply to that party, and you warrant you have authority to enter into this DPA on their behalf.
Terms defined in the Terms of Service keep their meaning here.
We process Customer Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, your configuration of the service, and any further written instruction you give that we agree to. We will tell you if we believe an instruction infringes Applicable Data Protection Law.
We do not sell or share Customer Personal Data, and will not retain, use, or disclose it for any purpose other than performing the service, or as otherwise permitted by Applicable Data Protection Law. We will not combine it with personal information received from another source, except as permitted for a service provider.
You are responsible for the lawfulness of the Customer Personal Data you provide and of the instructions you give, including any notice and consent required to contact your End Customers. Section 7 of the Terms of Service governs consent for messaging.
We limit access to Customer Personal Data to personnel and contractors who need it to provide or support the service, and who are bound by written confidentiality obligations or a professional duty of confidence.
We maintain technical and organizational measures designed to protect Customer Personal Data appropriate to its sensitivity and the risk, including:
Security measures may evolve; we will not materially reduce the overall level of protection during your subscription. Our Security page describes current practice.
You give general authorization for PestBooker to engage Subprocessors. Each is bound by written obligations no less protective, in substance, than those in this DPA, and we remain responsible to you for their performance as if we had performed it ourselves.
The current list is published at pestbooker.com/subprocessors, with what each one does and where data is hosted. All Customer Personal Data is hosted in the United States.
We will update that page and email your account administrator at least 14 days before a new or replacement Subprocessor begins processing Customer Personal Data. If you reasonably object on data protection grounds within those 14 days, we will work with you in good faith to offer an alternative; if we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.
The service gives you the ability to access, correct, export, and delete Customer Personal Data yourself, which is normally sufficient to answer a request from a data subject.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to direct them to you, and will inform you promptly unless legally prohibited. Where you cannot answer a request through the service, we will provide reasonable assistance at no charge for a reasonable volume of requests.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe what we know at the time — the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed — and we will supplement it as the investigation progresses.
We will take reasonable steps to contain and remediate. Notifying you is not an admission of fault. Notifying affected individuals or regulators is your decision as the business or controller, and we will provide the information you reasonably need to make and act on it.
For 30 days after termination you may export Customer Personal Data through the service or by written request. After that period we will delete it within 90 days, except for copies in routine backups, which are deleted on their normal cycle, and anything we are required to retain by law or to establish or defend legal claims. Retained copies stay subject to this DPA.
On reasonable written request, no more than once in any 12 months unless required by a regulator or following a Security Incident, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including a description of our controls and answers to a reasonable security questionnaire.
We will cooperate with a data protection impact assessment where one is required and relates to our processing. On-site audits are by agreement, at your expense, subject to confidentiality, and must not compromise the security or privacy of other customers.
This section applies where the CCPA governs. PestBooker is a “service provider” and receives Customer Personal Data solely to perform the business purposes set out in section 3.3. PestBooker certifies that it understands the restrictions in this section and will comply with them.
Deidentified or aggregated data derived from use of the service is not Customer Personal Data. We will not attempt to reidentify it, and will contractually bind any recipient to the same.
The service is operated from the United States and all Customer Personal Data is hosted there. Do not submit personal data that may not lawfully be transferred to or processed in the United States. If we later offer the service to customers subject to a law requiring a specific transfer mechanism, we will put an appropriate one in place before processing under it.
For questions or requests under this DPA: