Data Processing Addendum
Last updated 1 September 2026
What this covers
This addendum forms part of the Terms & Conditions between you and The Tool Belt, a division of Pareto Tech Inc. It governs our handling of personal information about your customers and prospects — the people who call you, fill in your forms and receive your messages.
It does not cover information about you as our customer. That is dealt with in our Privacy Policy.
Who is responsible for what
You are the organisation that decides why and how your customers' information is used. Canadian privacy law makes you accountable for it. We handle it only to provide the services, which makes us your service provider — the equivalent of a processor under laws that use that term.
In practice: it is your job to have consent to contact these people, and to answer them if they ask what you hold. It is our job to keep the data secure, use it only as you have asked, and help you meet those obligations.
The data we process for you
| Category | What it includes |
|---|---|
| Contact details | Names, phone numbers, email addresses and service addresses of your customers and leads |
| Communications | SMS sent and received through the platform, call records and voicemail, form submissions, and messages in the shared inbox |
| Job and quote information | Property details, photographs supplied for estimating, measurements, quoted prices and invoices |
| Review activity | Which customers were asked for a review and whether they responded |
We process this for as long as you are a customer, for the sole purpose of running the services you subscribe to. We do not sell it, and we do not use your customers' data to market anything to them on our own behalf.
The services are not designed for sensitive categories of information — health details, financial account numbers, government identifiers. Please do not put them into the platform.
Acting on your instructions
We process your customers' personal information only on your documented instructions, which include your configuration of the platform and your day-to-day use of it. If we believe an instruction breaks the law, we will tell you rather than simply carrying it out.
Where the law compels us to disclose data, we will tell you first unless we are legally barred from doing so.
Confidentiality
Access is limited to the people who need it to do their work or support you. Everyone with access is bound by confidentiality obligations that survive their engagement with us.
Security measures
We maintain, at a minimum:
- Encryption in transit: every page and form submission travels over HTTPS
- Credentials for third-party services held in encrypted secret storage, never in application code or in anything served to a browser
- Access limited to the people who need it, and removed when they no longer do
- Regular backups, held to the same standard as live data
- Logical separation of each customer’s data from every other customer’s
- Patching of infrastructure and dependencies as fixes become available
- Rate limiting and origin checks on the endpoints that accept data from the public web
We will apply further measures as the platform grows, and will not describe a control here before it is actually in place.
Subprocessors
We use third-party providers to deliver parts of the service. Each is bound by terms no less protective than these, and we remain responsible to you for what they do.
| Provider | Purpose | Location |
|---|---|---|
| Twilio | SMS and voice — messages sent and received on your behalf, and the phone numbers involved | United States |
| Postmark (ActiveCampaign) | Transactional email — lead notifications and system mail | United States |
| DigitalOcean | Application and database hosting | United States / Canada |
| Cloudflare | DNS, CDN and the endpoint that receives your website form submissions | Global edge |
| Anthropic (Claude) | AI estimating and content generation — the text and images submitted for a quote | United States |
| OpenAI (ChatGPT) | AI estimating and content generation | United States |
| Stripe | Subscription billing and card processing — your own billing details, not your customers’ | United States / Ireland |
We will give you at least 30 days' notice before adding or replacing a subprocessor. If you have a reasonable objection on data protection grounds, tell us within that period and we will work to resolve it; if we cannot, you may cancel the affected service without penalty.
Where data is processed
Some of our providers operate in the United States, so your customers' information may be processed outside Canada and be subject to the laws of that country, including lawful access by its authorities. Where that happens we rely on contractual protections with the provider.
In practice this means your customers’ contact details, the messages sent and received on your behalf, and any photographs submitted for an estimate are processed in the United States. If you have a data residency requirement — some contractors doing government or institutional work do — tell us before you sign up, because we cannot currently keep this data inside Canada.
Requests from individuals
If one of your customers contacts us directly asking to see, correct or delete their information, we will not answer it ourselves. We will pass it to you promptly, because it is your relationship and your obligation.
We will give you the tools and, where needed, the hands-on help to find, export, correct or delete an individual's records. We do not charge for reasonable assistance of this kind.
Breach notification
If we become aware of a breach of security affecting your customers' personal information, we will notify you within 72 hours of becoming aware, and will include what we know about what happened, who is affected, what we are doing about it, and what we suggest you do.
Deciding whether to notify affected individuals and the Privacy Commissioner is yours to make, as the accountable organisation. We will give you what you need to make it.
Return and deletion
During your subscription you can export your data at any time. When the agreement ends, we will provide an export on request within 30 days of the end date, and will then delete your customers' personal information from our live systems.
Backups age out on their normal cycle rather than being edited, so data may persist in backup for up to 20 days after deletion. It stays protected by this addendum until it is gone.
Audit
On reasonable written notice, and no more than once a year unless a breach has occurred, we will provide the information reasonably needed to demonstrate we are meeting this addendum. We will answer a security questionnaire rather than host an on-site audit, unless a regulator requires otherwise.
Contact
Privacy and data protection questions:
The Tool Belt, a division of Pareto Tech Inc.
460–60 Bristol Rd E
Mississauga, Ontario L4Z 3K8
Canada
[email protected]