Data Processing Addendum — United States
The service-provider terms under which Cerrax processes your customers' personal information on your instructions.
This addendum forms part of the Terms of Service and applies whenever Cerrax processes personal information on your behalf. It uses the meanings given in the California Consumer Privacy Act as amended (the "CCPA") and in the other US state privacy laws that apply to your business (together, "state privacy laws"). Where this addendum and the Terms conflict on data protection, this addendum governs.
1. Which of us is which
You are the business (or controller) for your customers’ personal information. We are your service provider (or processor) for it: we act on your instructions and use it for our own purposes only in the ways section 3 lists. That covers personal information about your customers, the people who inquire with you, your other contacts, and your staff and crew in their working role. For your own account information — your team’s logins, your company’s settings and billing — we are a business in our own right, and our Privacy Policy covers that.
Your responsibilities. You are responsible for being allowed to collect the personal information you give us or ask us to collect, for giving the people concerned the notice the law requires (our Privacy Policy describes what we do, and you may point to it), and for any consent your messages need. You have the rights this addendum gives you.
One exception, which is your customer's choice, not yours. When your customer sends a video or photographs of their home, they may tick a separate box allowing Cerrax to keep them to train software that recognizes furniture and rooms. For that use alone, Cerrax is not your service provider: it is a business in its own right, on the customer's opt-in consent, and our Privacy Policy(section 3) covers it: identifying details are blurred before it is ever used for training, nothing uses it today, and the customer can withdraw at any time, after which the video and photographs are deleted under the ordinary ninety-day rule. Everything else in this agreement applies to them as it does to the rest of your customers’ information.
2. What we process, and for how long
- Business purpose: running your moving company on Cerrax — receiving and organizing your inquiries, keeping your customer records (contacts), producing and following up estimates and quotes, booking and running jobs, and sending the messages you set up — on your instructions: the limited and specified purpose for which you disclose personal information to us.
- What we do with it: collecting, storing, organizing, reading (including with AI, to suggest details for a person at your company to confirm), pricing, sending messages on your behalf, de-identifying (section 9), exporting and deleting.
- Duration: for as long as your account is open, and afterwards only as section 8 allows.
- Type of personal information: names, addresses, contact details, move dates, and details of the property and its contents that you or your customer enter; where your crew use Cerrax on the day of the move, photographs of the property, its access and any damage found, together with the name and drawn signature of whoever signs the inventory off; and, where you invite it and your customer chooses to send one, a video of their home. Where you use them: your contacts (names, email addresses, phone numbers, company, preferred language, addresses used, the choices they gave you about your messages and when, where they came from, and your notes); inquiries, including the text of inquiry emails sent to your Cerrax lead address; the messages you send through Cerrax and whether they were delivered; follow-up tasks and their notes; whether a payment has been made (never card details); and reviews and ratings your customers give you.
- People it is about: people who inquire with you (whether or not they become customers); your customers; the people at the properties you move between; other people you keep as contacts; people named in notes, messages, photographs or video; and your staff and crew in their working role.
We do not ask for and do not want sensitive personal information. Please do not enter health, financial-account, government ID or similar information into free-text fields. If it arrives anyway — in an inquiry or a note — we hold it only as part of that record, never use it for pricing or learning, and keep it out of section 9.
A signature captured against an inventory is held as evidence that your customer agreed what was moved and in what condition. Nothing measures, compares or matches it, and nothing recognizes a face in a photograph or video (where faces are blurred, software finds them only to blur them and keeps no measurement of them) — so we do not collect biometric information. Collecting signatures is optional: if you would rather your crew did not, simply do not use it.
3. We act on your instructions
We process your customers’ personal information only on your documented instructions — which include your use of the product and this addendum — unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction breaks a state privacy law, we will say so. In particular, we will not:
- sell or share it (as the CCPA uses those words);
- retain, use or disclose it for any purpose other than the business purpose in section 2, including any commercial purpose of our own — except these, which state privacy laws allow a service provider: the de-identified use in section 9; keeping descriptions of a job's items and rooms, with any email address, phone number or ZIP code removed, for 30 days to improve how Cerrax recognizes items (we keep no other text sent to our AI sub-processor, and we build no profile of anyone); keeping the service secure and preventing fraud; and meeting our own legal obligations;
- retain, use or disclose it outside our direct business relationship with you; or
- combine it with personal information we receive from anyone else or collect ourselves, except as state privacy laws allow a service provider to.
We certify that we understand these restrictions and will comply with them. We will comply with the state privacy laws that apply to us as your service provider, give the personal information the same level of protection they require of you, and tell you if we can no longer meet our obligations under them. You may take reasonable and appropriate steps to make sure we use the information consistently with your obligations, and to stop and fix any use you have not authorized.
Your instructions include these, when you use the features concerned: receiving emails sent to your Cerrax lead address and reading them — using our AI sub-processor where an email has no labeled layout — to suggest details you confirm; keeping contact records and the choices your customers make about your messages; and sending the reminder, thank-you and referral messages you switch on, in your name, with your postal address, honoring every request to stop at once and for all of those messages from you to that person. We keep a record of each choice and each stop, and a scrambled record of a stop for as long as it must be honored.
Also on your instructions, when you use the features concerned: sending your customers the messages about a job that you set up (by WhatsApp where you have connected it, otherwise by email), including a review request and the private rating and comment a customer may give you; creating links you choose to share — a job sheet for your crew, or evidence (the customer's name, photographs, video and signatures, never their contact details) for your insurer, broker or claims handler; publishing your jobs to calendar subscriptions you create; and keeping follow-up tasks and their notes.
4. Confidentiality
Everyone we allow to access your customers’ personal information is bound by a written duty of confidentiality that continues after they leave, and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.
5. Security
We take reasonable technical and organizational security measures appropriate to the nature of the information, described in our security overview — encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have. We will not materially reduce the overall level of security described there while this addendum lasts.
6. Sub-processors
You authorize us to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We bind each of them by written contract to obligations no less protective than these, and we remain fully responsible to you for their performance. We will email your account owner at least 30 days before a new sub-processor starts handling your customers’ information (sooner only in an emergency, such as a provider failing, and then we tell you as soon as we can). You may object within that time on reasonable data protection grounds; if we cannot resolve it, you may end the affected service or your subscription and we will refund any fees paid in advance for the unused period. Services you connect yourself under your own account with them — your own Stripe, WhatsApp Business or Xero account — act on your instruction under your agreement with them, and are not our sub-processors.
If you subscribe your own calendar to your Cerrax calendar link, your calendar provider fetches your jobs under your own agreement with it; it is not our sub-processor.
7. Helping you meet your own obligations
Taking into account the nature of the processing, we will help you respond to requests from consumers — to know, access, correct, delete or port their information — and with your security, breach-notification and risk-assessment duties. If a consumer contacts us directly about information we hold for you, we will tell them to contact you rather than answer for you. You can find, export, correct and delete a contact or a job yourself in the product; for anything the product cannot do, we will act within 10 business days of your written instruction.
Breaches. If we become aware of a breach of security affecting your customers’ information, we will tell you without unreasonable delay and in any event within 48 hours — with what we know then, and the rest as we learn it — with the information you need to meet the breach-notification laws of the states your customers live in.
8. Deletion and return
Your instruction on how long we keep it. Unless you tell us otherwise, you instruct us to keep each job record — the quote, its booking and outcome, the crew's sheets and the photographs attached to them — for six years after the move (or after the quote, if the job did not go ahead), or for longer while a claim or dispute about that job is open, and then to delete it. A video, and any photographs your customer sends with it, are deleted 90 days after the job's last date unless your customer has separately agreed to their longer use. You can change this instruction by telling us.
Unless you tell us otherwise, you also instruct us to delete: an inquiry that was never priced or sent, 12 months after its last activity; a quote that was sent but never accepted, 24 months after it was sent; and a contact record 12 months after the last job record linked to it is deleted (or 12 months after it was made, if it was never linked to a job). A record of a person's consent is kept while their contact record is kept and for six years after; a scrambled record of a request to stop messages is kept for as long as it must be honored.
When your subscription ends you can export your data for 30 days. We then delete your customers’ personal information within 90 days, and it leaves our backups as they expire (within 98 days), except where the law requires us to keep it or you ask us to keep specific records, such as evidence in an open claim. Committed pricing records are never silently altered — personal identifiers within them are removed, which is how deletion is honored without falsifying a record of what was quoted. Section 9 records are not your customers’ personal information and are not affected.
Two records keep their own periods: email delivery records (recipient, subject and whether it was delivered), 90 days; and the audit trail of actions in your account, up to six years after your account closes, with a customer's details removed when that customer is erased.
9. De-identified job data
(a) You instruct us to make de-identified records from the jobs we hold for you. (b) A de-identified record holds only the shape and economics of a job — volume, a distance band, access features, crew, trucks, hours, price and cost, whether the quote was won and why not, the month of the move, and an area no finer than the first two digits of a ZIP code — and never a name, contact detail, full ZIP code, address, map position, free text, photograph, video, signature, your company's identity, or any reference that links it back to the job. (c) We treat a record as de-identified only when it cannot reasonably be linked to a person, taking account of other information we or you hold. Data that can be linked back — for example by a job reference, or while we still hold the original job — is not de-identified and stays under this addendum until the original is deleted or its customer's information deleted. (d) We will not try to re-identify anyone from these records, and require anyone we share them with to make the same commitment. (e) Once a record meets this standard it is not your customers’ personal information; it is ours, and we may keep and use it to improve and provide Cerrax, including after the underlying records are deleted and after this addendum ends. (f) We never show another company, or anyone else, your individual prices or anything that identifies your company.
10. Learning across companies
We use de-identified records under section 9, and statistics made from them, from across all companies using Cerrax, in every country, to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.
11. Your numbers stay yours
Your rates, your margins, your customers and your prices are never visible to another company, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one company’s data by anybody else.
12. Audit
We will make available the information you reasonably need to show we are meeting these obligations — first by written answers and our security documentation — and will allow and contribute to a reasonable assessment by you or an independent assessor you appoint where those are not enough or a regulator requires it: at your cost, on 30 days' notice, under confidentiality, without access to other companies' data, and no more than once a year unless a regulator or a breach requires otherwise.
13. Where the information is
We hold your customers’ personal information in the United Kingdom, in London, and you authorize that. Some sub-processors process it in the United States — the AI provider named in our Privacy Policy is the case today. Where your data is stored on any given day is a question you can ask us at any time, and we will answer it for the day you ask.
Liability. Section 11 of the Terms of Service (limitation of liability) applies to this addendum.
14. Contact
Data protection questions, consumer requests and breach notifications: hello@cerrax.io.
15. State-law terms, in one place
For your own records, this addendum gives you the terms state privacy laws require of a contract with a service provider or processor: the instructions, purpose, type of information and duration (sections 2 and 3); the restrictions on selling, sharing, use, retention and combination, with our certification (section 3); confidentiality (section 4); security (section 5); sub-processors bound by written contract (section 6); assistance with consumer requests and breaches (section 7); deletion or return at the end (section 8); de-identified data (section 9); and information and assessments to show compliance (section 12). If a state privacy law that applies to you requires a term this addendum does not contain, that term is treated as included, to the extent the law requires it.