Data Processing Addendum
Effective 29 August 2026
This addendum sets out what we do with personal data that belongs to your residents. You are the controller of it and we are the processor, and this document is the contract Texas law requires between those two roles.
1What this is and who it binds
This Data Processing Addendum ("DPA") forms part of the Subscription Agreement between Innovations App Lab LLC ("Processor", "we") and the Customer identified there ("Controller", "you"). It applies to our processing of Personal Data contained in Customer Data.
Where this DPA and the Subscription Agreement conflict on the handling of Personal Data, this DPA controls.
2Definitions
"Personal Data", "Controller", "Processor", "Process", "Sensitive Data", "Consumer" and "Sale" have the meanings given in Tex. Bus. & Com. Code ch. 541, and equivalent meanings under other applicable state privacy laws. "Data Subject" means the individual a piece of Personal Data relates to — in practice, most often a resident.
3Roles, and what we are instructed to do
You are the Controller. You determine the purpose and means of processing residents' Personal Data. You decide which residents are entered, which properties are enforced, what the permit rules are, and how long records live within the limits the Service offers.
We are the Processor. We process Personal Data only on your documented instructions.
Your documented instructions are: this DPA, the Subscription Agreement, your Order, the configuration you set in the Service, and any further written instruction you give us that is consistent with those. We will not process Personal Data for any other purpose, and in particular we will not sell it, share it for targeted or cross-context behavioural advertising, use it for our own advertising, or use it to train machine learning models.
If we believe an instruction from you would breach applicable privacy law, we will tell you and may pause that processing rather than carry it out.
We are the Controller, not your Processor, for a narrow set of data we handle for our own purposes: the accounts of your staff as account holders, our billing records, security and operational logs, and records of agreement acceptance. The Privacy Policy governs those.
4Nature, purpose, duration and categories
Required by §541.104(b).
Nature and purpose of processing. Hosting, storing, transmitting, displaying, backing up and deleting Personal Data so that the Service can register vehicles, issue and check parking permits, record enforcement events, notify residents about their own permits, and maintain the audit trail those functions depend on.
Duration. For the term of the Subscription Agreement, plus the 30-day export window after termination, plus the retention periods in section 9 for records we are instructed to retain longer.
Types of Personal Data.
- Identifiers and contact details — name, email address, and telephone number where a resident supplies one.
- Residency information — the unit a resident is linked to, and when.
- Vehicle information — licence plate, plate state, make, model, colour, year.
- Permit and enforcement records — permits, permit requests, plate check records, tow records, tow amendments and tow photographs.
- Sensitive Data — precise geolocation. The coordinates of the recording device at the moment a tow is recorded, with an accuracy measure. See section 5.
- Authentication data — email address and a salted password hash held by our authentication provider.
Categories of Data Subject. Residents of properties you service; occupants and owners of vehicles recorded in the Service; and your own staff in their capacity as users appearing in records.
5Sensitive Data, and the consent that is yours to obtain
The geolocation captured with a tow record is Sensitive Data under §541.001 where it identifies a location within 1,750 feet, which a device GPS fix ordinarily does.
We process it only on your instruction, when your operator records a tow. We do not capture location at any other time and we do not track a device between events.
WHERE CONSENT IS REQUIRED TO PROCESS SENSITIVE DATA, OBTAINING IT IS THE CONTROLLER'S OBLIGATION UNDER §541.101(b)(4), NOT OURS. WE CANNOT OBTAIN IT ON YOUR BEHALF AND WE DO NOT PURPORT TO.
Neither party may sell Sensitive Data. We do not sell any Personal Data, and you may not instruct us to.
Biometric data. The Service does not capture, generate or store a biometric identifier as defined by Tex. Bus. & Com. Code ch. 503. We do not run facial recognition or automated plate recognition. If that changes, we will amend this DPA and give notice before the capability ships.
6Confidentiality
We will keep Personal Data confidential and will ensure that every person we authorise to process it is bound by an appropriate obligation of confidentiality, and is granted access only to what their role requires.
7Sub-processors
You give general authorisation for us to engage the sub-processors below, each under a written contract imposing data protection obligations no less protective than this DPA. We remain responsible for their performance.
- Supabase Inc. — database, authentication, file storage. United States (AWS us-east-2).
- Vercel Inc. — application hosting, delivery, request logging. United States.
- Resend (Plus Five Five, Inc.) — transactional email delivery. United States.
Cloudflare provides DNS for our domains. It resolves names and does not process Personal Data in that role.
Changes. We will give at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, tell us; we will work with you in good faith, and if we cannot resolve it you may terminate the affected part of the Subscription Agreement without penalty and receive a pro-rata refund of prepaid fees.
8Security
We will maintain reasonable and appropriate administrative, technical and physical safeguards, taking into account the nature of the Personal Data and the risks to Data Subjects. Those in place today include:
- Encryption in transit (TLS) and at rest.
- Authorization enforced inside the database by row-level security, so that separation between customer accounts does not depend on application code being correct, with an automated test suite that attempts to cross those boundaries and confirms it cannot.
- Least-privilege access, including column-level restrictions preventing even an authenticated user from altering audit fields such as record creation times.
- Tow photographs stored in a private bucket, reachable only through short-lived signed links.
- Rate limiting, per-unit lockouts on repeated failed access-code attempts, and audit logging of sensitive administrative actions such as revealing or rotating a unit's access code.
- Periodic security review of the database's authorization rules, recorded in writing.
THESE ARE REAL CONTROLS, NOT A GUARANTEE. NO SET OF SAFEGUARDS MAKES A SYSTEM IMPENETRABLE AND WE DO NOT REPRESENT OTHERWISE.
9Retention, deletion and return
- Plate check records are deleted automatically 24 months after they are created, by a scheduled job in the database. A plate check that a tow record refers back to is retained with that tow record instead, for the same seven years, so that the tow is not left without the check that preceded it. No other plate check survives 24 months.
- Tow records, tow amendments and tow photographs are retained for seven years and are append-only: they cannot be edited or deleted through the Service by you, by a Data Subject, or by us. This is a deliberate design decision, disclosed to you here so that you can account for it when answering a deletion request.
- All other Customer Data is retained for the term. On termination we retain it for 30 days so you can export it, then delete it. On your written request we will delete it sooner.
- Backups. Deleted data may persist in encrypted backups until those backups age out on their ordinary cycle, during which it remains protected by this DPA and is not restored into production except as part of a whole-system recovery.
On termination, and at your option, we will return Customer Data in a machine-readable export or delete it, and confirm deletion in writing on request.
10Helping you answer a Data Subject
If a Data Subject contacts us directly about Personal Data we process for you, we will not respond substantively on your behalf. We will acknowledge them, tell them to contact you, and notify you promptly with what we were asked.
We will provide reasonable assistance, at no charge for a reasonable volume of requests, in helping you to:
- Confirm whether Personal Data about a Data Subject is held, and produce a copy.
- Correct inaccuracies.
- Delete a resident's identity. The Service provides a function that removes the resident account, name, email address, unit link, permits and vehicle registrations, while leaving tow records intact for the reason in section 9.
- Export data in a portable, machine-readable format.
Where a Data Subject asks you to delete a tow record, the exception for data retained to establish or defend legal claims is available to you, and we will support that position with the record of what was retained and why.
11Security incidents
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data we process for you.
Our notice will describe what we know: the nature of the incident, the categories and approximate volume of Personal Data and Data Subjects involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once we will provide it in phases without undue delay.
Notifying regulators and affected individuals is the Controller's decision and obligation, including under Tex. Bus. & Com. Code ch. 521 — which requires notice to affected Texas residents without unreasonable delay, and notice to the Texas Attorney General not later than the 30th day after determining a breach occurred where at least 250 Texas residents are affected. We will give you the information you need to meet those deadlines and will not obstruct them.
We will not notify a regulator or a Data Subject about an incident affecting your data without telling you first, unless the law requires us to.
12Demonstrating compliance, and assessments
On request, and no more than once a year unless there has been a security incident affecting your data or a regulator requires it, we will:
- Make available the information reasonably necessary to demonstrate our compliance with this DPA, including a written description of our security controls and the record of our most recent security review.
- Allow and contribute to a reasonable assessment of our processing, which may be conducted by you or an independent assessor you appoint who is bound by confidentiality and who is not our competitor.
Assessments will be at your cost, on at least 30 days' notice, during business hours, and conducted so as not to disrupt the Service or other customers' data. We may satisfy an assessment request by providing a third-party audit report if we hold a current one covering the scope.
13Transfers
All processing takes place in the United States. We will tell you before that changes.
14Liability, term and precedence
Liability under this DPA is subject to the limitations in the Subscription Agreement.
This DPA takes effect with the Subscription Agreement and continues until we have deleted or returned all Personal Data processed for you. It is amended in the same way as the Subscription Agreement.