Data Processing Addendum
Effective September 7, 2026 · Last updated September 7, 2026
This addendum governs our processing of the personal information you put into PestMetrics — including information about your employees and your own customers. It applies automatically to every customer, with no signature required. If your procurement team needs a countersigned copy, email support@pest-metrics.com.
1Parties, Incorporation, and Acceptance
1.1 Parties
This Data Processing Addendum (the "DPA") is entered into between Intelligent Performance Systems LLC, a Texas limited liability company doing business as PestMetrics, of 410 S Bibb Ave, Unit 5348, Eagle Pass, TX 78853, United States ("PestMetrics", "we", "us"), and the entity that has accepted the Terms of Service ("Customer", "you").
1.2 Incorporation and acceptance
This DPA forms part of, and is incorporated by reference into, the PestMetrics Terms of Service at pest-metrics.com/terms (the "Agreement"). It takes effect when you accept the Agreement or first use the Service, whichever is earlier, and it applies for as long as we process Customer Personal Data. No signature is required for this DPA to bind both parties. If your procurement process requires a countersigned copy, or requires our standard terms to be recorded on your paper, contact support@pest-metrics.com and we will provide one.
1.3 Order of precedence
In the event of a conflict, the order of precedence is: (a) any data processing agreement signed by authorized representatives of both parties; (b) this DPA; (c) the Privacy Policy; (d) the Agreement. This DPA prevails over the Agreement only in respect of the processing of Customer Personal Data.
1.4 Definitions
- "Applicable Privacy Law" means the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.) and its regulations at 11 CCR §§7000–7304; the Virginia Consumer Data Protection Act (Va. Code §59.1-575 et seq.); the Colorado Privacy Act (C.R.S. §6-1-1301 et seq.); the Connecticut Data Privacy Act (Conn. Gen. Stat. §42-515 et seq.); the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541); every other United States state comprehensive privacy statute applicable to the processing; and, where applicable under Section 9, the EU and UK General Data Protection Regulation.
- "Customer Personal Data" means personal information or personal data within Customer Data, as Customer Data is defined in the Privacy Policy: the operational records Customer, or a system Customer connects, transmits to or through the Service, together with the metrics, scores, forecasts, and reports we derive from them for Customer.
- "Account Data" means information about Customer and its Authorized Users that we process as a controller in our own right: registration and profile details, billing and subscription records, authentication artifacts, support correspondence, security logs, and website analytics. Account Data is governed by the Privacy Policy and not by this DPA.
- "Subprocessor" means a third party engaged by PestMetrics that processes Customer Personal Data on our behalf. It does not include a destination Customer itself specifies, which is addressed in Section 8.4.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data in our possession or control. It does not include unsuccessful attempts or activity that does not compromise the security of Customer Personal Data.
- Terms used and not defined here — including "business", "service provider", "sell", "share", "controller", "processor", "personal data", and "data subject" — have the meanings given in Applicable Privacy Law.
2Roles of the Parties
2.1 Customer is the controller; PestMetrics is the processor
With respect to Customer Personal Data, Customer is the business, controller, or equivalent, and PestMetrics is the service provider, processor, or equivalent, under Applicable Privacy Law. Customer determines the purposes and means of the processing. PestMetrics does not.
2.2 Why this matters here
The Service holds personal information about two groups with whom PestMetrics has no direct relationship: Customer’s own workforce, and Customer’s end customers. Customer is the party that holds the relationship with those individuals, that owes them notice, and that must answer their requests. Section 5 sets out Customer’s obligations accordingly, and Section 11 sets out the assistance we provide.
2.3 Account Data
PestMetrics is an independent controller of Account Data. We process it to operate the business relationship, bill, secure the Service, and comply with law, as described in the Privacy Policy.
2.4 Factual basis for the processor role
PestMetrics has no independent route into Customer’s source systems. Every call to a connected system is made using credentials Customer supplied for Customer’s own account. Every outbound delivery goes to a destination Customer configured. Every write-back action is performed only on a Customer user’s individual confirmation. This is stated so that the processor characterization rests on how the Service is built, not merely on assertion.
3Scope and Documented Instructions
3.1 Processing only on instructions
PestMetrics processes Customer Personal Data only on Customer’s documented instructions. Those instructions consist of this DPA including its Annexes, the Agreement, the Privacy Policy, Customer’s configuration and use of the Service — including the systems and credentials Customer connects, the synchronization schedule Customer sets, the destinations Customer configures, the files Customer uploads, and the actions Customer’s users confirm — and any further written instruction the parties agree.
3.2 The specific business purposes
Applicable Privacy Law requires the business purposes to be stated specifically rather than in general terms. Customer discloses Customer Personal Data to PestMetrics for the following limited and specified business purposes, and for no others:
- Retrieving service, appointment, ticket, invoice, subscription, customer-account, balance, and cancellation records from Customer’s field service management system; time, shift, and worker records from Customer’s payroll and timekeeping system or from files Customer uploads; vehicle, trip, location, and driving-event records from Customer’s telematics system; accounting records from Customer’s accounting system; and public business review information for the locations Customer identifies — in each case using credentials or authorizations Customer supplies.
- Computing, storing, and displaying revenue per hour, jobs per hour, stops, technician and branch scorecards, composite scores, cancellation and reservice rates, accounts-receivable ageing, annual recurring revenue, market penetration, forecasts, and related metrics derived from those records.
- Generating and delivering dashboards, exports, share cards, alerts, notifications, briefings, webhooks, and scheduled reports to the recipients and destinations Customer configures.
- Where Customer enables them, generating narrative commentary, summaries, and plain-language answers about Customer’s own data using the artificial intelligence providers identified in Annex III.
- Performing write-back actions in a connected system where Customer has enabled the feature and a Customer user has confirmed the specific action.
- Providing technical support, troubleshooting, and reconciliation against Customer’s source systems.
- Maintaining and securing the Service, detecting and preventing security incidents and fraudulent, malicious, deceptive, or illegal activity, and debugging to identify and repair errors that impair intended functionality.
- Building and improving the quality of the Service provided to Customer, provided that PestMetrics does not use Customer Personal Data to build or improve the services of any other person, and does not use it to train, fine-tune, or otherwise improve any generalized artificial intelligence or machine learning model.
- Complying with law and establishing, exercising, or defending legal claims.
3.3 Unlawful instructions
If PestMetrics reasonably determines that an instruction from Customer infringes Applicable Privacy Law, we will promptly notify Customer and may suspend performance of that instruction until it is withdrawn, amended, or confirmed. PestMetrics is not obliged to assess the lawfulness of Customer’s own collection of Customer Personal Data.
3.4 Duration
Processing continues for the term of the Agreement and for the wind-down period described in Section 12.
4Service Provider Restrictions
These restrictions are what make the "service provider" characterization in the Privacy Policy operative rather than merely declared. PestMetrics shall not:
- Sell Customer Personal Data, or share it for cross-context behavioral advertising, as those terms are defined in Applicable Privacy Law.
- Retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in Section 3.2, including retaining, using, or disclosing it for a commercial purpose other than providing the Service, or outside the direct business relationship between the parties.
- Combine Customer Personal Data with personal information received from or on behalf of another person, or collected from PestMetrics’ own interaction with a consumer, except as expressly permitted by Applicable Privacy Law.
- Use Customer Personal Data to build or improve any product or service offered to any person other than Customer, other than as permitted by Section 6 in respect of de-identified and aggregated information.
- Use Customer Personal Data to train, fine-tune, or otherwise develop any generalized artificial intelligence or machine learning model, whether our own or a third party’s.
4.1 Certification
PestMetrics certifies that it understands the restrictions in this Section 4 and will comply with them.
4.2 Notice of inability to comply
PestMetrics will notify Customer promptly if we determine that we can no longer meet our obligations under Applicable Privacy Law. On such notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data, including directing us to cease processing, to delete, or to return the affected data.
4.3 Customer’s right to remediate
Customer has the right to take reasonable and appropriate steps to ensure that PestMetrics uses Customer Personal Data in a manner consistent with Customer’s obligations under Applicable Privacy Law, and to stop and remediate any unauthorized use.
5Customer’s Obligations
Because Customer decides what data enters the Service, Customer represents, warrants, and undertakes on an ongoing basis that:
- Customer has the authority to grant PestMetrics access to the accounts, credentials, files, and data it connects or provides, and doing so does not breach Customer’s agreement with the provider of any connected system.
- Customer has provided all notices and obtained all consents, permissions, and authorizations required by Applicable Privacy Law and by employment law from the individuals whose personal information Customer causes to flow into the Service, including its employees, contractors, and end customers, and has a lawful basis for the processing.
- Where Customer enables telematics ingestion, individual productivity scoring, or other workforce monitoring features, Customer has satisfied every applicable workforce monitoring notice, consent, posting, bargaining, and recordkeeping obligation. These obligations attach to Customer as the employer. Examples include the electronic monitoring notice requirements of New York, Connecticut, and Delaware, and California’s rules on notice and, in some circumstances, consent for location tracking and for personal information collected in the employment context. PestMetrics does not assess and cannot assess Customer’s compliance with them.
- Customer will not enter or upload into the Service, including into free-text fields, special categories of personal data as defined by Article 9 GDPR, protected health information, payment card numbers, government-issued identifiers, biometric identifiers, or data concerning children, unless PestMetrics has agreed in writing in advance that the Service will handle it.
- Customer’s instructions to PestMetrics comply with Applicable Privacy Law.
- Customer is responsible for configuring roles, branch scoping, and view permissions appropriately, for removing users who leave, and for the destinations it configures under Section 8.4.
6De-identified and Aggregated Information
PestMetrics may create de-identified and aggregated information from data processed through the Service, including industry benchmarks and statistical analyses. Such information does not identify Customer, its personnel, or its end customers. PestMetrics will maintain and use it only in de-identified form, will not attempt to reidentify it except as permitted by law to test the effectiveness of de-identification, and will contractually obligate any recipient to the same restrictions. PestMetrics may use and disclose de-identified and aggregated information for any lawful purpose. This Section survives termination.
7Confidentiality and Personnel
7.1 Authorized persons
PestMetrics ensures that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality, and that access is limited to those with a business need to operate, secure, and support the Service, to comply with law, or to act on Customer’s instructions.
7.2 Support access and impersonation
A limited number of PestMetrics operator accounts can enter a Customer account in the context of a named user in order to reproduce or resolve a fault. Such sessions use a token limited to two hours that carries the operator’s identity. The start and end of each session, the operator, the affected user, the session duration, and any stated reason are recorded in an audit record available to Customer. Individual records viewed during such a session are not separately logged. Customer may request prior notice of, or prior approval for, support access as a term of its Agreement.
Stated plainly because a diligence team will ask: operator authorization is currently controlled by a deployment configuration value rather than by a database role. The population of accounts holding this privilege is therefore controlled at the infrastructure level.
8Subprocessors and Onward Disclosure
8.1 General authorization
Customer grants PestMetrics general authorization to engage Subprocessors to process Customer Personal Data, subject to this Section. The current list is maintained at pest-metrics.com/security and is summarized in Annex III.
8.2 Obligations we impose on Subprocessors
Before engaging a Subprocessor, PestMetrics imposes on it, by written contract, data protection obligations that are substantially the same as, and no less protective than, those in this DPA, to the extent applicable to the services it performs. PestMetrics remains liable to Customer for the performance of each Subprocessor’s obligations.
8.3 Notice and objection
PestMetrics will update the list at pest-metrics.com/security before a new Subprocessor begins processing Customer Personal Data, and will notify account administrators by email of any addition that materially changes the categories of data disclosed or the category of recipient. Customer may object on reasonable data protection grounds within thirty days of notice. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees for the terminated portion.
8.4 Destinations Customer configures
Where Customer configures an outbound destination — a webhook endpoint, a chat channel, a notification topic, or an email address — deliveries to it are onward disclosures made on Customer’s instruction. Those destinations are not PestMetrics Subprocessors, PestMetrics does not select them, and PestMetrics is not responsible for their security or their handling of what arrives. Customer is responsible for choosing destinations appropriate to the sensitivity of the content and for restricting access to them.
8.5 Artificial intelligence providers
Where Customer enables AI features, PestMetrics discloses to the applicable provider in Annex III the content described in Annex I, which may include company and branch names, operational metrics, named individuals with their performance figures, review content, the text of user questions, and rows returned from Customer’s own records. PestMetrics engages such providers under terms that prohibit the use of our inputs or outputs to train their generalized models. Providers may retain request content for a limited period for abuse monitoring under their own terms; PestMetrics does not control those periods. AI features may be disabled for Customer’s account on written request, and the remainder of the Service functions without them.
9Processing Location and International Transfers
9.1 United States processing
The Service is operated from, and Customer Personal Data is hosted in, the United States. Customer instructs PestMetrics to process Customer Personal Data in the United States and to disclose it to the Subprocessors in Annex III. The Service does not currently offer data residency in any other region, and PestMetrics does not represent that it does.
9.2 Conditional transfer mechanism
Where Customer is established in, or the processing is subject to the laws of, the European Economic Area, the United Kingdom, or Switzerland, the parties shall enter into the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference on and from that point, with PestMetrics as data importer and Customer as data exporter, Module Two applying where Customer is a controller and Module Three where Customer is itself a processor. Annexes I, II, and III of this DPA serve as the corresponding annexes to those clauses. Where the United Kingdom Addendum or International Data Transfer Agreement applies, it applies in place of or in addition to those clauses as required. This Section is dormant unless and until such processing occurs.
10Security
10.1 Security measures
PestMetrics implements and maintains the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, and the risks to individuals. PestMetrics may update those measures provided the level of protection is not materially reduced.
10.2 No absolute guarantee
No method of transmission over the internet and no method of electronic storage is completely secure, and no set of safeguards eliminates all risk. Annex II describes our program; it is not a warranty that the Service is free of vulnerabilities.
10.3 Security Incident notification
PestMetrics will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notification will describe the nature of the incident, the categories and approximate volume of data and individuals affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not available at the time, PestMetrics will provide information in phases as it is established. PestMetrics will cooperate with Customer and provide reasonable assistance in Customer’s own investigation and in any notification Customer must make to a regulator or to affected individuals.
Notification is anchored to "after becoming aware" rather than "on detection" deliberately. The Service logs authentication events and alerts on bursts of failed sign-ins, and monitors availability and data correctness. It does not run intrusion detection or behavioural analysis, so a party using valid credentials from a plausible location may not generate an alert at all. We would rather state the boundary than imply a detection capability we do not have.
10.4 Customer’s own obligations
Notification to affected individuals and to regulators is Customer’s responsibility as controller. Customer is responsible for credential hygiene, for enabling multi-factor authentication, for role and branch scoping, for removing departed users, and for notifying us promptly of any suspected compromise of its account.
11Data Subject Rights and Compliance Assistance
11.1 Requests received by PestMetrics
If PestMetrics receives a request from a data subject relating to Customer Personal Data, we will not respond to it ourselves except to acknowledge receipt and to state that we act on Customer’s behalf. We will forward the request to Customer promptly where we can reasonably identify the relevant Customer.
11.2 Assistance
Taking into account the nature of the processing, PestMetrics will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests to exercise data subject rights. Customer can action many requests itself using the account management, correction, and export functions of the Service. Where a request cannot be satisfied through those functions, PestMetrics will provide reasonable assistance on written request and will action it within thirty days. PestMetrics may charge on a time-and-materials basis where the assistance required is not trivial.
An honest limitation, so Customer can plan around it: the Service does not currently provide one-click extraction or erasure of a single named individual across every store. A person’s name can persist in stored copies of source-system payloads, in invoice attribution fields, and in audit descriptions after that person is removed from the roster. Requests of that kind are handled as assisted work rather than as a self-service feature.
11.3 Assessments and impact assessments
PestMetrics will provide Customer, on written request, with information reasonably necessary for Customer to conduct a data protection assessment or data protection impact assessment relating to the Service, and to consult a supervisory authority where required.
11.4 Demonstrating compliance and audits
PestMetrics will make available to Customer, on written request and no more than once in any twelve-month period unless required by a regulator or following a Security Incident, the information reasonably necessary to demonstrate compliance with this DPA. That information consists of: this DPA and its Annexes; the Security and Subprocessors page; a written response to Customer’s security questionnaire; an export of Customer’s own audit records and sign-in history for the retained window; and the record of support access sessions affecting Customer’s account. Where PestMetrics obtains an independent audit report or certification, it will be made available in place of a questionnaire response. Any audit right is satisfied by the provision of these materials. On-site inspection is available only by written agreement, on at least thirty days’ notice, at Customer’s cost, subject to confidentiality, and scoped so as not to disrupt the Service or compromise the confidentiality of other customers.
12Return and Deletion
12.1 During the term
Customer may export reports from the Service at any time while its subscription is active. Where Customer needs a copy of data in a form the built-in exports do not provide, PestMetrics will provide a reasonable export of Customer Personal Data in a commonly used machine-readable format on written request.
12.2 On termination
On termination or expiry of the Agreement, and on Customer’s written request, PestMetrics will delete Customer Personal Data within ninety days and will confirm deletion in writing. Deletion is irreversible. Customer should export anything it wishes to retain before requesting it. Where Customer makes no request, PestMetrics may delete Customer Personal Data in the ordinary course after termination.
12.3 Exceptions
PestMetrics may retain after deletion: de-identified and aggregated information under Section 6; billing, tax, and accounting records required by law, which are also held independently by our payment processor; records necessary to comply with a legal obligation, to resolve a dispute, to enforce an agreement, or to establish, exercise, or defend legal claims; security, fraud prevention, and suppression records, including records of opt-out preferences so that they continue to be honored; and copies within encrypted backups until those backups expire on their ordinary rotation cycle. Data retained under this Section remains subject to this DPA for as long as it is retained.
12.4 Backups
Backups are not used to restore individually deleted records. Where a genuine restoration event occurs, PestMetrics will reapply any pending deletions after the restore.
13Liability, Governing Law, and General
13.1 Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA does not increase either party’s aggregate liability beyond the cap in the Agreement, except where Applicable Privacy Law does not permit such a limitation.
13.2 Governing law
This DPA is governed by the laws of the State of Texas, without regard to its conflict of law rules, and the parties submit to the exclusive jurisdiction of the state and federal courts located in Texas — except where Section 9.2 has activated the Standard Contractual Clauses, in which case those clauses are governed as they provide.
13.3 Severability and survival
If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect. Sections 4, 6, 10.3, 12, and 13 survive termination.
13.4 Changes to this DPA
PestMetrics may update this DPA to reflect changes in the Service, our Subprocessors, or Applicable Privacy Law. We will give at least thirty days’ notice of a material change by email to account administrators and by updating the date on this page. A change that materially reduces Customer’s protections entitles Customer to terminate the affected portion of the Service before the change takes effect.
13.5 Contact
Intelligent Performance Systems LLC, d/b/a PestMetrics, 410 S Bibb Ave, Unit 5348, Eagle Pass, TX 78853, United States. Email support@pest-metrics.com for a countersigned copy, a security questionnaire response, or any question about this DPA. Email security@pest-metrics.com to report a security concern.
IAnnex I — Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the PestMetrics performance analytics platform to Customer. |
| Duration | The term of the Agreement, plus the wind-down period in Section 12. |
| Nature and purpose | The business purposes enumerated in Section 3.2: retrieval, storage, computation, display, delivery, narrative generation, support, security, and improvement of the Service for Customer. |
| Categories of data subjects | Customer’s Authorized Users; Customer’s employees, contractors, technicians, and branch managers; Customer’s end customers, being the residential and commercial account holders it services, and their site contacts; and the authors of public business reviews for Customer’s locations. |
| Categories of personal data — account | Name, business email address, company, role, branch and view assignment, salted password hash, multi-factor secret, session and token identifiers, preferences. |
| Categories of personal data — workforce | Name; source-system employee and worker identifiers; work email address; branch, office, and role assignment; active status; hire date and inferred departure or termination date; scheduled and worked hours; shift start and end; stops completed; revenue and sales attributed; cancellation and reservice attribution; composite and per-factor scorecard values and rankings. |
| Categories of personal data — telematics, where Customer connects it | Driver name and identifier; vehicle assignment; precise geolocation as latitude and longitude; trip start and end points, times, and reverse-geocoded street addresses; distance and odometer readings; engine idle time; speed; harsh braking, acceleration, and cornering event counts; driver safety scores; and references or links to dashcam media held in the connected system. |
| Categories of personal data — end customers | Source-system customer identifier; branch and office assignment of the service location; account balance and responsible balance; accounts-receivable ageing; cancellation and pending-cancellation status; appointment and service history; invoice detail; and free-text collections and contact notes entered by Customer’s personnel about a named account. |
| Categories of personal data — public review data | Business location identifiers, ratings, review counts, review text, review timestamps, and the display names and profile image references of review authors. |
| Sensitive data | Precise geolocation, where Customer connects a telematics system, and account credentials. Customer must not submit special categories of data, protected health information, payment card numbers, government identifiers, biometric identifiers, or data concerning children. |
| Frequency | Continuous and scheduled synchronization, plus on-demand retrieval initiated by Customer. |
IIAnnex II — Technical and Organizational Measures
Encryption and key management
- Traffic between Customer’s browser and the Service, and between the Service and the third-party systems and providers we call, is encrypted using industry-standard transport layer security. HTTP Strict Transport Security is enforced.
- Integration credentials, OAuth tokens, webhook signing secrets, and multi-factor secrets are encrypted at rest using AES-256-GCM, with per-record context binding through additional authenticated data so a ciphertext cannot be replayed against another account.
- The encryption key is held as an environment secret outside the database and is validated at application start. Key rotation is scripted and verifies that every stored record round-trips on the new key before writing.
- Data at rest in the managed database and object storage is encrypted by our infrastructure providers.
- PestMetrics does not offer customer-managed encryption keys, per-customer key separation, or hardware security module custody.
Access control and authentication
- Passwords are stored only as salted bcrypt hashes at cost factor 12. Password policy requires at least 12 characters including an uppercase letter, a number, and a symbol.
- Multi-factor authentication is mandatory for Admin accounts, which cannot use the Service until enrolled, and is available to other roles.
- Sessions are signed tokens expiring after seven days, re-validated against the database on each request, revocable individually by identifier, and invalidated in bulk on password change or account deactivation.
- Role-based access control across three roles, with per-user branch and view restrictions enforced server-side.
- New accounts must verify their email address before first sign-in.
- Rate limiting on authentication and other sensitive endpoints.
Tenant separation
- Application queries for Customer Personal Data are scoped to the requesting account, and this scoping is reviewed and tested.
- The AI analyst query path is additionally enforced at the database layer: queries run as a dedicated read-only role under PostgreSQL row-level security, in a read-only transaction with a statement timeout, with SELECT granted only on an analytics allowlist and row policies that fail closed when the tenant context is unset.
- Each Customer synchronizes using its own credentials and its own API budget.
Application and network security
- Standard web security headers, a strict cross-origin allowlist, and schema validation of request payloads.
- Outbound request validation against private and internal address ranges.
- Automated dependency vulnerability scanning on every change and on a scheduled basis, with advisories raised as tracked fix pull requests. Advisories rated critical block the build.
Logging, monitoring, and resilience
- Administrative and configuration actions are recorded and attributed to the acting user, retained on a rolling ninety-day window.
- Authentication events are logged: every sign-in success, failed password, rejected second factor, and attempt against a deactivated or suspended account, together with the source address and client. Repeated failures against one account or from one address raise an operator alert. Customer administrators can review their own account’s sign-in history through the Service, and the last successful sign-in is recorded against each user.
- Support access sessions record operator identity, affected user, start, end, duration, and any stated reason.
- Automated monitoring of synchronization failures, data drift, staleness, and process crashes, with operator alerting.
- Nightly self-tests reconcile stored figures against Customer’s source systems and flag drift.
- Managed PostgreSQL with automated encrypted backups.
Organizational measures
- Access to production systems limited to personnel with a business need, under confidentiality obligations.
- Internal procedures for change management, key management, and incident response.
- Review of service providers before engagement.
Measures PestMetrics does not currently provide, stated so Customer is not misled: no SOC 2, ISO 27001, or third-party penetration test report; and no intrusion detection, security information and event management, centralised log aggregation, or file integrity monitoring. Authentication events are now logged and repeated failures alert the operator, but that is detection of a pattern rather than of a single unauthorised session: a party using valid credentials from a plausible location may not be distinguishable from the legitimate user. A SOC 2 Type 2 audit will be pursued when a Customer requires it, and any resulting report will be made available under Section 11.4.
IIIAnnex III — Subprocessors
The authoritative and current list, with the data each receives, is maintained at pest-metrics.com/security and forms part of this Annex. As at the effective date of this DPA the categories and providers are:
| Category | Provider | Location |
|---|---|---|
| Application and database hosting | Render | United States |
| Web delivery and product analytics | Vercel | United States |
| Payment processing | Stripe | United States |
| Transactional and marketing email | Resend | United States |
| Artificial intelligence providers | Anthropic; Google; Groq | United States |
| Public reference data | National Weather Service; US Census Bureau; Nominatim / OpenStreetMap; Nager.Date; Google Maps Platform | United States; Nominatim and Nager.Date operate from Europe |
Systems Customer connects — including its field service management, payroll, telematics, accounting, and review platforms — are not PestMetrics Subprocessors. PestMetrics calls them using credentials Customer supplies, under Customer’s own agreement with those providers. Destinations Customer configures are addressed in Section 8.4.
Questions? support@pest-metrics.com · See also Privacy Policy, Terms of Service, and Security & Subprocessors.