Data Processing Addendum
Last updated August 5, 2026
This addendum forms part of the Terms of Service between PatrolOS (processor) and the subscribing company (controller) when PatrolOS processes personal data on the customer's behalf. A counter-signed copy is available on request.
1. Roles and scope
The Customer is the controller of personal data submitted into its workspace. PatrolOS is the processor and processes that data only to provide, secure, and support the platform, and on the Customer's documented instructions.
2. Categories of data and data subjects
- Data subjects: the Customer's officers, dispatchers, supervisors, administrators, client contacts, and individuals named in incident or visitor records.
- Personal data: identity and contact details, role and permissions, shift and time records, GPS location and accuracy, checkpoint and patrol activity, incident narratives and media, visitor logs, device diagnostics, and audit log entries.
3. Customer obligations
- Establish a lawful basis for the processing, including any employee location monitoring.
- Give required notices to, and obtain required consents from, workers and other data subjects.
- Configure roles, site assignments, and client access correctly, and keep them current.
- Avoid uploading special-category data unless a separate written agreement covers it.
4. PatrolOS obligations
- Process personal data only as instructed and not for our own unrelated purposes.
- Keep personnel with access bound by confidentiality and limited to least privilege.
- Maintain technical and organizational measures appropriate to the risk (see the Trust Center).
- Assist the Customer with data subject requests, impact assessments, and regulator enquiries at the Customer's reasonable request.
5. Subprocessors
The Customer authorizes the subprocessors listed in the Privacy Policy. Each is engaged under written terms no less protective than this addendum. We will give notice of new subprocessors so the Customer can object on reasonable data-protection grounds.
6. Security incidents
PatrolOS will notify the Customer without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting the Customer's data, with the information reasonably available at the time, and will cooperate on investigation and remediation.
7. International transfers
Where transfers require a safeguard, the parties rely on standard contractual clauses or another approved mechanism, incorporated by reference into this addendum.
8. Return and deletion
On termination the Customer may export its data for 30 days, after which PatrolOS deletes or irreversibly anonymizes it, except where retention is required by law or exists in time-limited backups.
9. Audits
On reasonable written request and no more than once a year, PatrolOS will provide available documentation about its security measures and answer a reasonable security questionnaire. On-site audits require a separate written agreement.
10. Requesting a signed copy
Email angel18almanza@gmail.com with your legal entity name and signatory to receive an executable copy.
Questions about this document? Contact PatrolOS at angel18almanza@gmail.com.
