Proofwalk

Data processing agreement

Effective August 5, 2026 · LateShift LLC · support@proofwalk.io

This agreement applies whenever LateShift LLC processes personal information on behalf of a customer through the Proofwalk service. It forms part of the terms of service. Where a customer's own signed data processing agreement applies instead, that one governs.

1. Roles

For session content, the customer is the controller (or business) and LateShift LLC is the processor (or service provider). For the customer's own account records, LateShift LLC is the controller. Both are described in the privacy policy.

2. What is processed

Subject matterProviding remote visual support sessions and producing the resulting job reports.
DurationFor as long as the customer's subscription runs, plus the retention periods described below.
Nature and purposeTransmitting live video and audio between two browsers, and storing photographs, chat, checklist progress, recordings, diagnostics and reports.
Categories of personal dataNames and email addresses of the customer's staff; mobile phone numbers of technicians; images and video that may show people, premises, equipment and documents; voice within recordings; device and connection diagnostics; text entered into chat, job details and checklists.
Categories of data subjectThe customer's specialists and administrators; on-site technicians, who are often employed by a third party; and any person incidentally captured by a technician's camera at a work site.
Special category dataNot intended and not required. A camera at a work site can capture more than the job needs, so the customer instructs its technicians accordingly.

3. Instructions

We process session content only on the customer's documented instructions, which include the terms of service, the configuration chosen in the product, and support requests. We will tell the customer if we believe an instruction breaks applicable data protection law. We do not sell personal information, share it for cross-context behavioural advertising, retain or use it for our own purposes, or use it to train machine learning models.

4. Confidentiality

Everyone we allow to access session content is bound by a duty of confidentiality, and access is limited to those who need it to run or support the service.

5. Security

The measures in place today:

Stated plainly, because customers ask and the answer has to be true: stored photographs, recordings, chat and session records are held unencrypted on disk, protected by access controls and file permissions rather than by encryption at rest. Full disk encryption is not in place. A customer whose obligations require encryption at rest should raise it before signing.

Needs a decision. Application-layer encryption of photographs and recordings is the practical fix and is not built. Until it is, this section is the honest answer to every security questionnaire, and some buyers will treat it as disqualifying.

6. Subprocessors

The customer authorises the subprocessors listed at subprocessors. We remain responsible for their performance. We will give at least 30 days' notice before adding or replacing one, and the customer may object on reasonable data protection grounds; if we cannot resolve the objection, the customer may terminate the affected service and receive a refund of prepaid fees for the unused term.

7. Data subject requests

Where someone contacts us directly about session content we will not respond substantively. We will tell them to contact the customer, and tell the customer. We will give the customer reasonable assistance, taking account of what the product can do, in answering requests for access, correction, deletion, restriction, objection and portability.

8. Retention and deletion

9. Personal data breach

We will notify the customer without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting its content. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, and what we are doing about it, to the extent we know at the time. We will not delay a first notice in order to complete the picture.

10. Audit

We will make available the information reasonably needed to show we meet these obligations, and will answer security questionnaires. A customer may audit no more than once a year, on 30 days' written notice, at its own cost, during business hours, and without disrupting the service or exposing another customer's data.

11. Where content is stored

Session content is stored on servers in the United States, in Boston, Massachusetts, and stays there. Transactional email is delivered through our mail provider's infrastructure in the European Union, which is the only processing that happens outside the country.

Proofwalk is offered to businesses in the United States only, and this agreement is written on that basis. A customer who needs to run sessions with technicians outside the United States, or who is subject to a non-US data protection regime, should raise it before signing so the necessary terms can be agreed rather than assumed.

12. Liability

Each party's liability under this agreement is subject to the limitations in the terms of service.

Contact

Privacy and security contact: support@proofwalk.io. LateShift LLC, 7901 4th St N STE 300, St. Petersburg, FL 33702, USA.