SpudgerHQ
ProductWorkflowPricing
DocsGuidesFree ToolsComparisons
LoginStart Free
Legal

Data Processing Addendum

Last updated: August 20, 2026

This Data Processing Addendum forms part of the SpudgerHQ Terms of Service where SpudgerHQ processes personal data on behalf of a repair shop or other business customer.

This Data Processing Addendum ("DPA") forms part of the SpudgerHQ Terms of Service or another agreement governing a business customer's use of SpudgerHQ (the "Agreement"). It applies automatically to the extent SpudgerHQ processes Customer Personal Data on the customer's behalf.

For this DPA, "Customer" means the repair shop or other business using SpudgerHQ, "Customer Personal Data" means personal information contained in Shop Data that SpudgerHQ processes on Customer's behalf, and "SpudgerHQ" means Vu Thanh Toan ("Philip Vu"), operating SpudgerHQ from Vietnam.

1. Roles

Where Customer determines why personal information about its customers, staff, suppliers, or other individuals is processed through SpudgerHQ, Customer acts in the role generally described under applicable law as controller, organisation, agency, or business.

SpudgerHQ processes that information to provide the service on Customer's behalf and acts in the corresponding role generally described as processor, data intermediary, agent, or service provider.

This DPA does not prevent SpudgerHQ from acting independently for information it processes for its own account administration, security, support, website operations, legal compliance, or subscription administration purposes. Those activities are addressed in the SpudgerHQ Privacy Policy.

2. Processing instructions

SpudgerHQ will process Customer Personal Data only as reasonably necessary to provide, secure, maintain, and support the service; on Customer's documented instructions expressed through use and configuration of the service; as otherwise authorised by the Agreement; or as required by applicable law.

If SpudgerHQ reasonably believes a Customer instruction would require unlawful processing, SpudgerHQ may suspend the affected processing and notify Customer where legally permitted.

3. Customer responsibilities

  • Have appropriate authority or another lawful basis to provide Customer Personal Data to SpudgerHQ
  • Provide privacy notices and obtain permissions or consent where applicable
  • Configure and use SpudgerHQ lawfully
  • Respond to individual privacy-rights requests where Customer controls the relevant records
  • Avoid entering unnecessary highly sensitive information into free-text or other fields
  • Choose retention periods appropriate for Customer's records and legal obligations

4. Confidentiality and access

SpudgerHQ will limit access to Customer Personal Data to persons and authorised service providers that need access to provide, support, secure, or maintain the service or to comply with applicable law.

Persons acting under SpudgerHQ's authority who receive access to Customer Personal Data must be subject to an appropriate duty of confidentiality.

5. Security

SpudgerHQ will maintain reasonable technical and organisational measures appropriate to the nature of the service and the information processed. Security measures may evolve as technology, the product, and risks change.

  • HTTPS/TLS for network transport
  • Authentication and role-based access controls
  • Tenant-separation controls
  • Restricted production access
  • Security and reliability logging and monitoring
  • Backup and recovery procedures
  • Dependency and vulnerability management
  • Secure handling of secrets and credentials
  • Controls designed to reduce unnecessary Customer Personal Data in analytics and diagnostic reporting

6. Subprocessors

Customer generally authorises SpudgerHQ to use subprocessors required to provide the service. SpudgerHQ will require subprocessors that process Customer Personal Data on its behalf to protect that information consistently with obligations appropriate to their role.

Current core subprocessors that may process Customer Personal Data are listed below. SpudgerHQ may update this list as providers change and will provide reasonable notice of material changes where required by applicable law or the Agreement.

  • Vultr — application hosting, database infrastructure, and file storage; primary SpudgerHQ infrastructure is currently in Sydney, Australia
  • Google / Firebase — authentication and technical diagnostics; provider infrastructure may operate internationally
  • Brevo — transactional email delivery, including customer-facing messages initiated by a shop

7. International processing

Customer acknowledges that SpudgerHQ is operated from Vietnam, primary application infrastructure is currently located in Australia, and authorised service providers may process information in additional jurisdictions.

Each party is responsible for transfer or cross-border safeguards required for its own role under applicable law. SpudgerHQ will reasonably cooperate with Customer where contractual safeguards are required for recurring cross-border processing.

8. Individual rights requests

If SpudgerHQ receives a request from an individual relating primarily to Customer Personal Data, SpudgerHQ may direct the individual to Customer and will not independently alter Customer-controlled records unless authorised by Customer or required by law.

Taking into account the nature of the processing, SpudgerHQ will provide reasonable assistance where Customer cannot reasonably fulfil an access, correction, deletion, or similar request using available product functionality.

9. Security incidents

SpudgerHQ will notify Customer without undue delay after becoming aware of a confirmed security incident involving unauthorised access to, acquisition of, disclosure of, alteration of, or destruction of Customer Personal Data where notice is reasonably necessary for Customer to meet its legal obligations.

Where reasonably available, the notice will describe the nature of the incident, information affected, affected individuals or records if known, measures taken or planned to contain or remediate the incident, and a contact point for follow-up.

Customer remains responsible for determining whether it must notify individuals or regulators in its role as controller, organisation, agency, or business, except where applicable law places a direct notification duty on SpudgerHQ.

10. Return and deletion

Customer may request account deletion through support@spudgerhq.com. SpudgerHQ will process deletion requests within a reasonable period and within any timeframe required by applicable law, subject to legitimate legal, security, fraud-prevention, and technical requirements.

Deleted information may remain temporarily in backup copies until those backups expire through the normal backup lifecycle. If a backup containing previously deleted tenant data must be restored for disaster recovery, SpudgerHQ will use reasonable procedures designed to ensure deletion requirements are re-applied before the restored environment returns to ordinary production use.

SpudgerHQ does not currently promise a fixed seven-day deletion period. Any future fixed deletion commitment will only take effect after the relevant production and backup lifecycle has been implemented and published.

11. Audit and compliance information

On reasonable request, SpudgerHQ will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and protection of other customers' information.

If applicable law requires an audit and information already supplied is insufficient, the parties will cooperate on a reasonable audit method designed to minimise security risk, disruption, and unnecessary disclosure.

12. U.S. state privacy restrictions

To the extent an applicable U.S. state privacy law treats Customer as a regulated business or controller and SpudgerHQ as its service provider or processor for Customer Personal Data, SpudgerHQ will not sell Customer Personal Data or use it for targeted advertising on SpudgerHQ's own behalf.

SpudgerHQ will not retain, use, or disclose Customer Personal Data outside the purposes permitted by the Agreement, Customer's instructions, and applicable law.

13. Processing details

The subject matter and purpose of processing is operation of a repair-shop management platform, including repair intake, customer and device records, repair agreements, repair lifecycle management, inventory, purchasing, POS, customer orders, reporting, and related workflows selected by Customer.

Processing lasts for the term of Customer's use of SpudgerHQ plus the applicable deletion and backup lifecycle and any legally required retention.

  • Data subjects: Customer's repair-shop customers, Customer's staff or users, supplier or business contacts, and other individuals whose information Customer lawfully enters into shop records
  • Personal data: names and contact information; addresses, phone numbers, and email addresses; customer or company information; device information including IMEI and serial numbers; repair details, condition information, notes, and damage documentation; repair agreements and signatures; orders; transaction, deposit, payment-method, and payment-status information; staff identity, role, activity, and access information; and supplier or business contact information
  • Restricted data: the service is not intended for full payment-card numbers, account passwords, device unlock passcodes, unnecessary government identifiers, health information, or other highly sensitive information unrelated to supported workflows

14. Minimum security objectives

  • Secure network transport
  • Strong authentication and authorisation
  • Tenant separation
  • Least-privilege production access
  • Secret management
  • Security logging and incident detection
  • Backup and recovery procedures
  • Dependency and vulnerability management
  • Secure software-development practices
  • Deletion and retention controls
  • Controls to reduce personal information in logs, analytics, and crash reports

15. Conflict and duration

If this DPA conflicts with the Agreement on a matter specifically concerning the processing of Customer Personal Data, this DPA controls to the extent of that conflict.

This DPA applies for as long as SpudgerHQ processes Customer Personal Data on Customer's behalf. Other provisions of the Agreement continue to apply according to their terms.

16. Contact

SpudgerHQ is operated by Vu Thanh Toan ("Philip Vu"), Vietnam. Privacy Officer / Data Protection Officer contact: support@spudgerhq.com.

SpudgerHQ

Repair shop software for intake, tickets, checkout, inventory, customers, and daily operations.

Start Free

Product

Fast IntakeRepair TicketsPhone Repair Shop SoftwarePricing

Guides

Speed Up Repair IntakeRepair Shop Intake ProcessCondition NotesCustomer Approval Workflow

Resources

SpudgerHQ DocsRepair Shop GuidesFree Repair ToolsSoftware ComparisonsPhone Repair Estimate Calculator

Company

AboutContactLogin

Legal

PrivacyTerms
LinkedInFacebookInstagramXThreadsTikTokYouTube

© 2026 SpudgerHQ. All rights reserved.

Built for small phone repair shops that want one connected workflow from check-in to daily closeout.

DPA