Helix Field Back to site

Helix Field Data Processing Addendum

Effective date: August 7, 2026 · Last updated: August 21, 2026

This Data Processing Addendum ("DPA") forms part of the Helix Field Terms of Service (the "Agreement") between BAW International Inc. ("BAW," "we") and the customer that accepts the Agreement ("Customer," "you"). It governs BAW's Processing of Personal Information contained in Service Data on Customer's behalf. If this DPA conflicts with the Agreement regarding the handling of Personal Information in Service Data, this DPA controls.

1. Definitions

2. Roles and Scope

For Personal Information in Service Data, Customer is the Controller and BAW is the Processor. Service Data includes records about Customer's personnel, such as technician time clock, route, and location records, and BAW acts as Processor for those records as well.

This DPA does not apply to data BAW collects for its own purposes as an independent Controller, as described in the Helix Field Privacy Policy: Customer's account and billing information, and platform usage metadata such as sign in events, feature usage, and device diagnostics. Platform usage metadata does not include the contents of Service Data.

3. Customer Instructions and Responsibilities

3.1 Instructions. Customer instructs BAW to Process Personal Information as needed to provide, secure, support, and maintain the Service as described in the Agreement, this DPA, and Customer's own configuration and use of the platform. Any additional instructions require BAW's written agreement.

3.2 Customer responsibilities. Customer is responsible for: (a) having a lawful basis for the Personal Information it collects and submits to the Service; (b) providing any legally required notices to, and obtaining any legally required consents from, the individuals concerned, including notices to Customer's own personnel regarding location and activity information collected through the technician app, and consent for any text messages sent through the Service; (c) the accuracy and lawfulness of Service Data; and (d) ensuring its users keep their credentials secure. The Service is offered for United States operations, and Customer will not submit Personal Information about individuals located outside the United States.

3.3 Restricted data. The Service is not designed for, and Customer must not submit: Social Security numbers or other government identification numbers; full payment card numbers in any free text, notes, or attachment field (card payments taken through the Service must use its integrated payment features); health or medical records; or Personal Information about children under 13.

4. BAW's Processing Commitments

BAW will:

Customer may, upon notice to BAW from any source of unauthorized Processing of Personal Information, take reasonable and appropriate steps to stop and remediate that Processing, and BAW will cooperate. Customer may also take reasonable and appropriate steps, including the measures in Section 11, to help ensure that BAW Processes Personal Information consistently with Customer's obligations under Data Protection Laws.

BAW certifies that it understands the obligations and restrictions in this DPA and in Data Protection Laws applicable to it as a Processor and service provider, and that it will comply with them.

5. Confidentiality

BAW limits access to Personal Information to personnel who need it to provide the Service, and ensures that those personnel are bound by written confidentiality obligations.

6. Security

BAW maintains the technical and organizational security measures described in Annex B. BAW may improve those measures over time, and will not materially reduce the overall protection of Service Data during any then current paid subscription term.

7. Subprocessors

7.1 Authorization. Customer provides general authorization for BAW to engage the Subprocessors listed in Annex C. The current list is maintained at /legal/subprocessors.

7.2 Changes. At least 30 days before adding or replacing a Subprocessor, BAW will update the subprocessor page and notify the Customer account owner by email. Where a Subprocessor must be added or replaced urgently to preserve the security, legal compliance, or continuity of the Service, BAW may do so immediately and will give notice as soon as reasonably practicable, and the objection right in Section 7.3 runs from that notice.

7.3 Objection. Customer may object in writing, on reasonable data protection grounds, within 30 days of the notice. The parties will work in good faith to resolve the objection. If it cannot be resolved, Customer may terminate the affected subscription and BAW will refund prepaid fees for the unused remainder of the term.

7.4 Flow down and responsibility. BAW engages each Subprocessor under a written contract imposing data protection obligations that are, in substance, no less protective than those in this DPA with respect to the Processing that Subprocessor performs, and BAW remains responsible to Customer for its Subprocessors' performance.

8. Assistance

8.1 Individual requests. If BAW receives a privacy request directly from an individual whose Personal Information is in Service Data (for example, an access or deletion request from Customer's end customer), BAW will direct the individual to Customer and will not otherwise respond unless required by law. The tools built into the Service allow Customer to access, correct, export, and delete Service Data. Insofar as reasonably practicable, and taking into account the nature of the Processing, BAW will provide reasonable additional assistance where those tools are not sufficient.

8.2 Compliance assistance. Taking into account the nature of the Processing, BAW will provide reasonable assistance with Customer's data protection assessments and with inquiries from data protection authorities, in each case as they relate to the Service.

8.3 Fees. BAW may charge a reasonable fee for assistance under this Section that goes materially beyond the capabilities built into the Service.

9. Security Incidents

9.1 Notice. BAW will investigate suspected Security Incidents without undue delay after becoming aware of them, and will notify Customer of a Security Incident affecting Customer's Service Data without undue delay after becoming aware of it, and in any event within 72 hours of confirming it. The notice will describe, to the extent known: the nature of the incident, the categories and approximate number of individuals affected, the measures taken or proposed, and a contact point. BAW will provide material updates at reasonable intervals as the investigation progresses. Notification is not an admission of fault. BAW may delay notice to the extent a law enforcement agency requests a delay in writing.

9.2 Mitigation. BAW will take reasonable measures to contain and remediate the Security Incident and to mitigate its adverse effects.

9.3 Communications. As between the parties, Customer is responsible for any legally required notifications to individuals or regulators regarding Service Data, and BAW will provide the information Customer reasonably needs to make them. BAW will not communicate about the Security Incident with Customer's end customers or the public except as required by law or with Customer's prior consent.

If BAW receives a subpoena, warrant, court order, or government demand seeking Service Data, BAW will notify Customer unless legally prohibited from doing so, will disclose only what is legally required, and will, where lawful, refer the requesting party to Customer.

11. Export, Return, and Deletion

11.1 During the term. The Service provides export tools that allow Customer to retrieve its Service Data, including its records in CSV form and its photos, signatures, and other media in their original file formats, self serve and at no charge. Export remains available at no charge even while an account is suspended for nonpayment. BAW will provide any Service Data not covered by the tools built into the Service within a reasonable time after written request, at no charge.

11.2 After termination. For 30 days after termination or expiration of the subscription, Customer may continue to export Service Data at no charge.

11.3 Deletion. After the export window closes, or earlier on Customer's written instruction, BAW will delete Service Data from production systems within 30 days. Backup copies expire and are overwritten in the ordinary course of backup rotation, and in any event within 35 days after production deletion. BAW may retain Personal Information where required by law, and any retained data remains protected under this DPA. On written request, BAW will confirm deletion from production systems within 30 days of the request.

12. Verification and Assessments

12.1 Documentation. Upon Customer's reasonable written request, BAW will make available the information in its possession reasonably necessary to demonstrate BAW's compliance with this DPA and with Data Protection Laws. BAW will respond within 30 days by providing its then current standard security documentation, together with written answers to supplemental questions to the extent that documentation does not reasonably address them. BAW may limit such requests to one in any period of 12 months, except following a Security Incident affecting Customer's Service Data and except where and to the extent Data Protection Laws require BAW to make the information available more frequently.

12.2 Assessments. BAW will allow and cooperate with reasonable assessments of its Processing of Service Data by Customer or Customer's designated assessor. Assessments proceed first by remote review of BAW's documentation and written responses. Any component conducted on site requires at least 30 days' written notice, occurs no more than once in any period of 12 months except following a Security Incident, takes place during normal business hours at Customer's expense under a mutually agreed scope, is subject to BAW's confidentiality and security requirements, and excludes access to any other customer's data or systems. BAW may instead satisfy an assessment request by providing a report of an assessment performed by a qualified and independent assessor under a recognized control standard, where such a report exists.

13. Liability and Precedence

Claims arising under this DPA are subject to the limitations and exclusions of liability in the Agreement and count toward the same aggregate liability cap, not in addition to it. For the handling of Personal Information in Service Data, this DPA takes precedence over the Agreement.

14. Term and Updates

This DPA is effective for as long as BAW Processes Personal Information in Service Data and survives termination of the Agreement until deletion under Section 11 is complete, including the backup expiration period stated in Section 11.3. BAW may update this DPA to reflect changes in Data Protection Laws or in the Service, following the modification notice process in the Agreement; updates will not materially reduce the protections in this DPA during any then current paid subscription term.


Annex A: Details of Processing

Categories of individuals. Customer's end customers and their household or property contacts; Customer's personnel (technicians, office staff, administrators); other business contacts Customer enters into the Service.

Categories of Personal Information. Names, addresses, phone numbers, and email addresses; service addresses and property details; job and service history, notes, and communications sent through the Service; photos and signatures collected in the field; invoice and payment records (not full card numbers); technician time clock, route, and location records connected to work activity.

Sensitive data. None intended; Section 3.3 prohibits submission of restricted categories.

Frequency and duration. Continuous during the subscription term, plus the export and deletion windows in Section 11.

Nature and purpose. Hosting, storage, transmission, display, backup, and related operations strictly to operate the Service: scheduling, dispatch, job management, invoicing, payment collection through the processor Customer connects, notifications, and support.

Annex B: Security Measures

Annex C: Subprocessors

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, storage, and infrastructureUnited States
Stripe, Inc.Subscription billing for Helix Field, and customer payment collection for customers who use a Stripe account set up through the Service (Stripe also acts as an independent controller for its fraud prevention services, as described in its own privacy policy)United States
Block, Inc. (Square)Customer payment collection, only for customers who connect their own Square account (Square also acts as an independent controller for fraud prevention, the digital receipts it sends on its own behalf, and its own legal obligations, as described in its own privacy notice)United States, with Square affiliates and service providers in other countries under Square's own transfer safeguards
BrevoEmail deliveryUnited States and European Union
Google LLC (Firebase)Push notificationsUnited States
Mapbox, Inc.Maps and geocoding of service addressesUnited States
Geocodio (Dotsquare LLC)Geocoding of service addressesUnited States
Intuit Inc. (QuickBooks Online)Accounting sync of customer, invoice, and payment records, only for customers who connect their own QuickBooks accountUnited States

Service Data is stored at rest in the United States and Processed only in the locations listed above. Email delivery data handled by Brevo may be processed in the European Union in accordance with that provider's terms, and payment data sent to Square may be processed by Square's affiliates and service providers outside the United States in accordance with Square's terms.

A Customer connects one customer payment processor, Stripe or Square, and Service Data is sent only to the processor that Customer has connected: the invoice number, the amount, and the paying customer's name and email, with payment status returned to the Service. Card details are entered on the processor's hosted payment page and never reach BAW systems. Customer's own agreement with its processor governs its processor account.

If text messaging features launch, the SMS delivery provider will be added to this list with the notice described in Section 7.2 before any Service Data is sent through it.

Contact: helixfielddispatch@gmail.com · BAW International Inc., an Oklahoma corporation · Legal notices by mail: BAW International Inc., c/o Corporation Service Company, registered agent, 10300 Greenbriar Place, Oklahoma City, Oklahoma 73159

Terms of ServicePrivacy PolicySubprocessorsWebsite Terms of UseWebsite Privacy PolicyRefund & CancellationHome