Data processing addendum

Last updated: 2026-08-21

This Data Processing Addendum ("DPA") supplements our Terms of Service and applies whenever ReconOS processes personal data on behalf of a customer ("Customer") in the course of providing the Service. By using the Service, both parties accept this DPA.

1. Roles

For data processed in connection with the Service:

  • Customer acts as the data controller for personal data they upload (employee names, contact details, vehicle records, photos).
  • ReconOS acts as the data processor, processing personal data only on Customer's documented instructions, which include the actions Customer takes within the Service (adding a tech, uploading a photo, sending an SMS, etc.).
  • For some aggregate, anonymized analytics, ReconOS acts as an independent controller (see §6).

2. Scope and duration

ReconOS processes personal data for the duration of the Customer's subscription and through the post-cancellation retention window described in the Privacy Policy.

3. Categories of data and data subjects

ReconOS processes the following categories of personal data on behalf of Customer:

  • Customer's employees: name, role, phone number, email, login credentials.
  • Customer's parts vendors: name, phone number, email.
  • Customer's leads (via landing-page form): name, dealership, email, phone, approximate inventory volume.
  • Vehicle photos: may incidentally contain images of license plates, VIN plates, or other identifying features.

4. Subprocessors

ReconOS engages the following subprocessors. We will give Customer at least 30 days' notice (by email) before adding a new subprocessor that materially affects the processing of personal data, during which Customer may object in writing.

  • Amazon Web Services, Inc. (US): compute, storage, and infrastructure on which the Service runs
  • Supabase, Inc. (US): database, authentication, and storage software, self-hosted by ReconOS on the AWS infrastructure above
  • Stripe, Inc. (US, with regional infrastructure): payment processing
  • Twilio Inc. / SendGrid (US): outbound SMS delivery, and delivery of product email including recipient addresses and message contents
  • OpenRouter, Inc. (US): routing of AI inference requests, including uploaded vehicle photographs, to the model provider below
  • Anthropic, PBC (US): model inference for photo condition scoring and listing-copy drafting, reached via OpenRouter
  • Functional Software, Inc. (Sentry) (US): error and performance monitoring

5. Security measures

ReconOS maintains the following technical and organizational security measures. This list describes controls that are in place today, not controls that are planned; §5.1 states the known limitations.

  • Encryption in transit: TLS 1.3 between Customer's browser and the Service, with HTTP redirected to HTTPS and HSTS enforced. Certificates are issued and renewed automatically.
  • Encryption at rest: AES-256 via cloud provider managed-key services.
  • Tenant isolation: PostgreSQL row-level security; users of one Customer cannot access data of another.
  • Credential storage: passwords are hashed by the identity provider and never stored in readable form; API keys are stored only as a keyed hash and cannot be recovered from the database.
  • Secret management: credentials are held in the runtime environment of the host and are never committed to source control.
  • Rate limiting: applied to public endpoints, to authentication, and to operations that incur outbound cost, to limit abuse and credential-stuffing.
  • Dependency scanning: automated dependency updates and vulnerability alerts on every dependency of the Service.
  • Audit logging: changes to records, to team access, and to credentials are recorded in an append-only log that Customer's account owner can read in the Service.
  • Backups: the database is backed up nightly to encrypted, version-enabled object storage in a separate failure domain from the host. Each backup is verified before it is retained, and a local copy is kept alongside the offsite one.

5.1 Known limitations

ReconOS is operated by a small team and is offered to pilot customers on that basis. The following are stated so that Customer can assess them rather than discover them:

  • Administrative access: production access is currently held by a single administrator rather than a rotated group with individually attributable, multi-factor-authenticated sessions.
  • Restore testing: backups are verified for integrity when written, but there is no automated restore drill; restores are exercised manually. Point-in-time recovery is not available — recovery is to the most recent nightly backup.
  • Change review: changes are covered by automated typecheck, lint, and test suites, but not by independent human code review.
  • Photograph access: uploaded vehicle photographs are served from unguessable public URLs rather than time-limited signed URLs. Possession of a photograph's URL is sufficient to retrieve it.
  • Deletion: deletion is performed manually on request; there is no automated deletion schedule. See §11.

6. Benchmarks

The Service shows Customer a benchmark comparing Customer's time-to-line against a volume-matched sample. That sample is a fixed set of seeded reference data supplied by ReconOS. It is not derived from other Customers' accounts, and ReconOS does not pool, aggregate, or otherwise process Customer data across tenants to produce it. No Customer data leaves Customer's tenancy for this or any other analytical purpose.

7. Location of processing

The Service is operated from the United States and every subprocessor listed in §4 processes personal data in the United States. ReconOS does not currently offer data residency in any other region, and does not currently offer the Standard Contractual Clauses or the UK International Data Transfer Addendum. A Customer subject to EEA, UK, or Swiss data-protection law should contact ReconOS before entering into this DPA so that the parties can assess whether ReconOS is an appropriate processor for that Customer.

8. Personal data breach notification

ReconOS will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer's data. The notice will describe the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and the measures taken or proposed to address it.

9. Data subject rights

ReconOS will provide reasonable assistance to Customer in responding to requests from data subjects to exercise their rights under applicable law (access, rectification, erasure, portability, restriction, objection). Customer can use the Service's data-export feature to fulfil access and portability requests directly, without contacting ReconOS.

Erasure is not yet self-service. ReconOS performs erasure manually on request and will confirm completion; Customer should factor that turnaround into its own statutory deadlines and contact ReconOS as early as possible after receiving a request. Erasure from the live system does not immediately remove data from backups, which are overwritten on the cycle described in §5.

10. Audits

Customer may, on reasonable notice and not more than once per year, request information demonstrating compliance with this DPA. Audits will be conducted in a way that does not disrupt the Service or compromise the data of other customers; reasonable out-of-pocket costs will be borne by the requesting Customer.

11. Return or deletion on termination

Customer may export its data from the Service at any time, including after termination while the account remains accessible.

Deletion is performed manually on Customer's written request rather than automatically on termination, and ReconOS will confirm when it is complete. Data not deleted on request is retained. Deleted data may persist in backups until those backups are overwritten on the cycle described in §5. Retention required by law (for example, tax records) is excepted in all cases.

12. Conflict

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails for matters related to data protection.

Contact

Questions about this DPA? Email our DPO at dpo@dealerdash.ai.