Effective January 1, 2026

This Data Processing Addendum (“DPA”) forms part of the Master Software-as-a-Service Agreement, Order, or other written agreement between Phoenix Consultants Group, Inc. (“Phoenix”) and the applicable customer (“Customer”) governing access to FireFlight Data Systems and related services (the “Agreement”).

This DPA applies only to the extent Phoenix processes Personal Data on behalf of Customer in connection with the Services. If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement. “Personal Data,” “process,” “processor,” “controller,” and similar terms have the meanings assigned under applicable Data Protection Laws.

2. Roles of the Parties

Customer is the controller of Personal Data submitted to the Services, or a processor acting on behalf of another controller. Phoenix is the processor, or subprocessor where Customer acts as a processor.

Customer determines the purposes and means of processing. Phoenix will process Personal Data only on Customer’s documented instructions, including the Agreement, applicable Orders, this DPA, and Customer’s authorized use of the Services, unless applicable law requires otherwise.

3. Details of Processing

Item Description
Subject matter Provision, hosting, maintenance, security, support, and operation of FireFlight Data Systems and related services.
Duration The applicable Subscription Term, plus the retention and deletion periods stated in the Agreement.
Nature and purpose Hosting, storage, organization, retrieval, transmission, analysis, support, security, backup, and other processing necessary to provide the Services as directed by Customer.
Categories of data subjects Customer personnel, contractors, customers, prospects, leads, vendors, project participants, contacts, authorized users, and other individuals whose information Customer submits to the Services.
Categories of Personal Data Names, business contact information, account and user information, project and project-related information, CRM and lead information, vendor information, operational records, inspection and work records, safety and incident information, compliance and regulatory records, assets, inventory, estimates, invoices, purchasing data, and other information selected by Customer.
Sensitive or regulated data Customer must not submit Regulated Data unless expressly authorized in an Order and any required supplemental terms have been executed.

4. Customer Instructions and Responsibilities

  • Customer will provide lawful, documented instructions for processing.
  • Customer is responsible for establishing a lawful basis for collecting and processing Personal Data.
  • Customer will provide required notices and obtain required consents.
  • Customer is responsible for the accuracy, quality, and legality of Personal Data submitted to the Services.
  • Customer will not instruct Phoenix to process Personal Data in violation of applicable law.

5. Confidentiality

Phoenix will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations and access Personal Data only as necessary to perform their duties.

6. Security Measures

Phoenix will maintain appropriate administrative, physical, and technical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, or destruction. Current security measures are described in Phoenix’s Security Overview.

These measures include, as applicable:

  • Hosting on infrastructure owned and operated by Phoenix;
  • TLS 1.2 or higher for data in transit across public networks;
  • AES-256 or equivalent encryption for data at rest and backup media;
  • Least-privilege, role-based access controls;
  • Unique credentials and multi-factor authentication for administrative access;
  • System and access logs retained for at least 60 days;
  • Risk-prioritized patch management, including critical patches within 30 days of availability;
  • Encrypted backups stored at a geographically separate location;
  • A documented incident response process.

7. Subprocessors

Customer authorizes Phoenix to use the subprocessors identified in Phoenix’s Subprocessor List.

Phoenix will remain responsible for each subprocessor’s performance of its data protection obligations to the extent required by applicable law and the Agreement. Phoenix will provide at least thirty (30) days’ notice before engaging a new subprocessor that will process Personal Data.

As of the Effective Date, PayPal, Inc. processes billing and payment information. PayPal does not receive Customer Data submitted to FireFlight, and payment card numbers are not stored or processed by Phoenix systems.

8. Data Subject Requests

Taking into account the nature of the processing, Phoenix will provide reasonable assistance to Customer in responding to requests from individuals to exercise rights under applicable Data Protection Laws.

If Phoenix receives a request directly relating to Personal Data processed on Customer’s behalf, Phoenix will direct the requester to Customer unless applicable law requires Phoenix to respond.

9. Security Incidents

Phoenix will notify Customer without undue delay, and in any event within seventy-two (72) hours after confirming a Security Incident affecting Customer Data. Phoenix will provide known details, take reasonable mitigation and remediation steps, and cooperate with Customer’s legally required response and notification obligations.

10. Assistance and Compliance Information

Phoenix will provide information reasonably necessary to demonstrate compliance with this DPA, including reasonable security questionnaires and written information concerning the safeguards applied to the Services.

Customer audit requests must be reasonable, proportionate, subject to confidentiality obligations, and not unreasonably interfere with Phoenix’s operations. Unless required by law or triggered by a confirmed Security Incident, such requests may be limited to once per twelve-month period.

11. Return and Deletion of Personal Data

During the Subscription Term, Customer may export Customer Data using available functionality. For thirty (30) days after expiration or termination, Phoenix will retain Customer Data and make it available for export in a commercially standard format.

After that period, Phoenix will delete Customer Data from active systems within thirty (30) days and from backups within ninety (90) days, subject to applicable legal retention obligations. Phoenix will certify deletion on written request.

12. International Data Transfers

Phoenix sells the Services to United States customers and hosts Customer Data in the United States. If Customer submits Personal Data subject to the GDPR, UK GDPR, Swiss data protection law, or another law requiring a recognized transfer mechanism, the parties will execute or incorporate the applicable Standard Contractual Clauses, UK Addendum, Swiss terms, or another legally valid transfer mechanism as required.

Any applicable transfer terms will apply only to the extent required by law and will take precedence over conflicting terms in this DPA solely with respect to the regulated transfer.

13. California and Other U.S. Privacy Laws

To the extent Phoenix processes Personal Data on behalf of Customer under a U.S. state privacy law, Phoenix will act as a service provider, contractor, or processor, as applicable. Phoenix will not sell Personal Data, retain, use, or disclose Personal Data outside the business purposes specified in the Agreement, or combine such Personal Data with data received from another person except as permitted by applicable law.

14. No Sale of Personal Data

Phoenix does not sell Customer Personal Data to third parties. Phoenix processes Personal Data only to provide, secure, maintain, support, and improve the Services, or as otherwise directed by Customer or required by law.

15. Updates

Phoenix may update this DPA to reflect changes in law, security practices, or the Services, provided that no update materially reduces Customer’s data protection rights during an active paid Subscription Term without Customer’s written agreement.

16. Governing Terms

This DPA is governed by the governing-law and dispute-resolution provisions of the Agreement, except where applicable Data Protection Laws require otherwise.

Contact

Privacy and data protection questions may be sent to in**@************ts.com.

Phoenix Consultants Group, Inc.
9 Wilson Drive
Northfield, New Jersey 08225