Data processing agreement
Effective August 5, 2026 · LateShift LLC · support@proofwalk.io
This agreement applies whenever LateShift LLC processes personal information on behalf of a customer through the Proofwalk service. It forms part of the terms of service. Where a customer's own signed data processing agreement applies instead, that one governs.
1. Roles
For session content, the customer is the controller (or business) and LateShift LLC is the processor (or service provider). For the customer's own account records, LateShift LLC is the controller. Both are described in the privacy policy.
2. What is processed
| Subject matter | Providing remote visual support sessions and producing the resulting job reports. |
|---|---|
| Duration | For as long as the customer's subscription runs, plus the retention periods described below. |
| Nature and purpose | Transmitting live video and audio between two browsers, and storing photographs, chat, checklist progress, recordings, diagnostics and reports. |
| Categories of personal data | Names and email addresses of the customer's staff; mobile phone numbers of technicians; images and video that may show people, premises, equipment and documents; voice within recordings; device and connection diagnostics; text entered into chat, job details and checklists. |
| Categories of data subject | The customer's specialists and administrators; on-site technicians, who are often employed by a third party; and any person incidentally captured by a technician's camera at a work site. |
| Special category data | Not intended and not required. A camera at a work site can capture more than the job needs, so the customer instructs its technicians accordingly. |
3. Instructions
We process session content only on the customer's documented instructions, which include the terms of service, the configuration chosen in the product, and support requests. We will tell the customer if we believe an instruction breaks applicable data protection law. We do not sell personal information, share it for cross-context behavioural advertising, retain or use it for our own purposes, or use it to train machine learning models.
4. Confidentiality
Everyone we allow to access session content is bound by a duty of confidentiality, and access is limited to those who need it to run or support the service.
5. Security
The measures in place today:
- TLS for everything in transit.
- Live video and audio encrypted end to end between the two browsers, which neither our servers nor our relay can decrypt.
- Passwords stored as scrypt hashes; session cookies signed.
- Join tokens and report share tokens stored only as hashes.
- Data separated by tenant, with server-side authorisation on every request.
- Technician input treated as untrusted and validated server-side.
- Rate limiting on authentication and session-code attempts.
- Automatic deletion on the retention schedule in section 8.
- A strict content security policy on every page.
Stated plainly, because customers ask and the answer has to be true: stored photographs, recordings, chat and session records are held unencrypted on disk, protected by access controls and file permissions rather than by encryption at rest. Full disk encryption is not in place. A customer whose obligations require encryption at rest should raise it before signing.
6. Subprocessors
The customer authorises the subprocessors listed at subprocessors. We remain responsible for their performance. We will give at least 30 days' notice before adding or replacing one, and the customer may object on reasonable data protection grounds; if we cannot resolve the objection, the customer may terminate the affected service and receive a refund of prepaid fees for the unused term.
7. Data subject requests
Where someone contacts us directly about session content we will not respond substantively. We will tell them to contact the customer, and tell the customer. We will give the customer reasonable assistance, taking account of what the product can do, in answering requests for access, correction, deletion, restriction, objection and portability.
8. Retention and deletion
- Session recordings are deleted automatically 14 days after upload.
- Photographs and step evidence are deleted one year after the session is closed, unless a longer period is agreed in writing.
- Session records, reports, chat logs and audit trails are kept for the life of the account.
- Sessions abandoned before anyone joined are pruned after 24 hours.
- On termination the customer may request a copy of its content within 30 days. After that we delete it, including from routine backups on their normal cycle, unless the law requires us to keep it.
9. Personal data breach
We will notify the customer without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting its content. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, and what we are doing about it, to the extent we know at the time. We will not delay a first notice in order to complete the picture.
10. Audit
We will make available the information reasonably needed to show we meet these obligations, and will answer security questionnaires. A customer may audit no more than once a year, on 30 days' written notice, at its own cost, during business hours, and without disrupting the service or exposing another customer's data.
11. Where content is stored
Session content is stored on servers in the United States, in Boston, Massachusetts, and stays there. Transactional email is delivered through our mail provider's infrastructure in the European Union, which is the only processing that happens outside the country.
Proofwalk is offered to businesses in the United States only, and this agreement is written on that basis. A customer who needs to run sessions with technicians outside the United States, or who is subject to a non-US data protection regime, should raise it before signing so the necessary terms can be agreed rather than assumed.
12. Liability
Each party's liability under this agreement is subject to the limitations in the terms of service.
Contact
Privacy and security contact: support@proofwalk.io. LateShift LLC, 7901 4th St N STE 300, St. Petersburg, FL 33702, USA.