Firehouse 360

Data Processing Addendum

Last updated July 1, 2026 · Version 2026-07-01

This Data Processing Addendum (the "DPA") describes how Firehouse 360 processes personal information contained in Customer Data on behalf of the customer ("you"). It supplements our Terms of Service and Privacy Policy. For most Customer Data you are the controller/business and we are the processor/service provider acting on your documented instructions.

1. Roles and scope of processing

We process Customer Data only to provide, secure, support, and improve the Service, and as otherwise instructed by you or permitted by these documents and applicable law. We will not process Customer Data for our own independent purposes, and (under the California Consumer Privacy Act and similar laws) we do not sell or "share" Customer Data and will not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the Service.

2. Confidentiality

We limit access to Customer Data to personnel who need it to provide the Service and who are bound by confidentiality obligations.

3. Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Data, including encryption of sensitive data at rest, role-based access controls, audit logging, and per-department data isolation. See our Security page. No method of transmission or storage is completely secure; we do not guarantee absolute security.

4. Subprocessors

You authorize us to engage the subprocessors listed at Subprocessors to help provide the Service. We impose data-protection obligations on our subprocessors that are consistent with this DPA, and we remain responsible for their performance. We will post material changes to that list; if you reasonably object to a new subprocessor, contact us to discuss alternatives.

5. Assistance and data-subject requests

Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from individuals to access, correct, delete, or port their information, and to meet your security, breach-notification, and impact-assessment obligations. Because you control the Service's data, many such requests can be fulfilled directly using the Service's administrative tools.

6. Breach notification

If we become aware of a security incident affecting Customer Data, we will notify you without unreasonable delay and provide information reasonably available to help you meet your notification obligations.

7. Return and deletion

While your subscription is active, you can export Customer Data at any time (e.g., CSV). After termination, we will make Customer Data available for export for a limited period (generally thirty (30) days), after which we may delete it in the ordinary course, subject to legal retention requirements. We may retain de-identified or aggregated data that does not identify any individual.

8. Demonstrating compliance

On reasonable request, we will provide information reasonably necessary to demonstrate our compliance with this DPA. A Public Entity or regulated customer that needs a signed DPA should contact us.

← Back home