This addendum forms part of the terms of service between you (the customer) and Agentic Services. It applies to personal data that we process on your behalf when you use Rundown. If you need a signed copy, write to legal@rndwn.app.
1. Roles
You are the controller (or "business") of the personal data in your account, such as information about your clients and their staff. We are the processor (or "service provider"). We process that data only to provide the service and as you instruct.
2. Scope of processing
- Subject matter: providing field service management software.
- Duration: the term of your subscription, plus the deletion period below.
- Data subjects: your clients, their contacts, your team members and subcontractors.
- Types of data: names, phone numbers, email addresses, site addresses, messages, photos, job and financial records. The service is not intended for special categories of data.
3. Our obligations
- Process personal data only on your documented instructions, which include the terms, this addendum and your use of the product's features.
- Not sell personal data, and not use it for any purpose other than providing the service.
- Not use personal data to train AI models, and not allow our subprocessors to do so.
- Ensure that people who can access personal data are bound by confidentiality.
- Help you respond to requests from individuals to exercise their privacy rights, taking into account the tools already available to you in the product.
- Tell you if we believe an instruction breaks the law.
4. Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- isolation of each customer's data by organization, enforced on the server;
- role-based permissions with server-side redaction of restricted fields;
- encryption in transit, and additional encryption of stored vendor credentials with per-customer keys;
- an audit log of financial changes, permission changes, exports and administrative access;
- nightly backups retained for 30 days;
- payment card data handled only by Stripe.
More detail is on the security page.
5. Subprocessors
You authorize us to use the subprocessors listed below. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable grounds.
| Subprocessor | Purpose | Data |
|---|---|---|
| Clerk | Sign-in, organizations, sessions and MFA | Names, emails, credentials, session data |
| Convex | Application database, file storage and server functions | All tenant data stored in Rundown |
| Stripe | Subscription billing and Connect payments | Billing contacts, payment and payout records. Card numbers go to Stripe directly and never reach Rundown |
| Twilio | SMS delivery and phone numbers | Phone numbers, message bodies, delivery status |
| Resend | Transactional and automation email | Email addresses, message bodies, delivery status |
| Anthropic | AI parsing and drafting (Claude models) | Only the fields needed for the task. Not used to train models |
| Google Maps Platform | Address lookup, geocoding and maps | Site addresses |
| Sentry | Error monitoring | Error traces and technical metadata |
| PostHog | Product analytics | Usage events and device metadata |
6. Personal data breaches
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or disclosure of your personal data, we will notify you without undue delay and provide the information you reasonably need to meet your own obligations.
7. International transfers
Personal data is processed in the United States. Where a transfer requires a legal mechanism, such as standard contractual clauses, we will enter into it with you on request.
8. Audits
On reasonable written request, no more than once a year, we will provide information needed to demonstrate compliance with this addendum, including answers to a security questionnaire.
9. Return and deletion
You can export your data at any time. When your account is deleted we hold the data for 30 days, then delete it from active systems. Backups expire within a further 30 days. We may keep data where the law requires it.
10. Order of precedence
If this addendum conflicts with the terms of service on a matter of personal data processing, this addendum controls.