Data Processing Agreement
1. When this applies
This Data Processing Agreement applies where your organisation uses Snapline and, in doing so, gives us personal data to process on your behalf — for example the names and site addresses of your own customers, or photographs in which a person is identifiable. It forms part of the Terms of Service and takes effect automatically when you accept them. You do not need to sign anything separately, though we will sign a copy on request.
2. Roles
For that content you are the controller and we are the processor. You decide what to photograph, what to record and whose details to enter; we store and process it on your instructions. Where we act as controller instead — your own account details, and our diagnostics — our Privacy Policy governs.
3. Details of the processing
| Subject matter | Providing the Snapline job-site documentation service. |
|---|---|
| Duration | For as long as your organisation has an account, plus the retention window described in §10. |
| Nature and purpose | Storage; generation of image derivatives; AI captioning, classification and transcription; indexing for search; report generation; sharing where you initiate it. |
| Types of personal data | Images that may contain identifiable people or property; names, site addresses and contact details you enter about your customers; voice recordings and their transcripts; location data where your organisation has enabled photo location. |
| Categories of data subject | Your customers and site occupants; your employees and crew members; anyone visible in a photograph you take. |
4. Our obligations
We will process personal data only on your documented instructions, including as to international transfers, unless a law we are subject to requires otherwise — in which case we will tell you before processing, unless that law forbids it. Your use of the app, and this agreement, constitute your instructions. We will tell you if in our opinion an instruction breaches data protection law.
5. Confidentiality
Everyone we authorise to process your personal data is bound by an appropriate obligation of confidentiality, and is given access only to what their role requires.
6. Security
We implement appropriate technical and organisational measures, including: encryption in transit and at rest; per-organisation isolation enforced in the data layer rather than by convention; individually authenticated staff access on a need-to-know basis; audit logging of destructive operations; and a vulnerability disclosure programme. See Privacy §11 and our disclosure policy.
7. Sub-processors
You give general authorisation for us to engage sub-processors. Those in use today are:
| Sub-processor | Purpose |
|---|---|
| Convex | Application database and file storage |
| Clerk | Authentication |
| OpenAI | Image captioning, classification, transcription, search indexing |
| Anthropic | Image captioning, classification, search indexing |
| Image captioning, classification, search indexing | |
| RevenueCat | Subscription state |
| OneSignal | Push notification delivery |
| Apple | App distribution and subscription payment |
Each is engaged under terms no less protective than this agreement, and we remain liable to you for their performance. We will give you at least 30 days' notice before adding or replacing one; if you reasonably object on data protection grounds you may terminate your subscription and we will refund any prepaid, unused portion.
8. Assisting you
Taking into account the nature of the processing, we will assist you with: responding to requests from data subjects exercising their rights; your security obligations; breach notification; data protection impact assessments; and prior consultation with a supervisory authority. Most data subject requests can be answered without us, because the app lets you search, correct, export and delete the content yourself.
9. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting your personal data, with the information you need in order to meet your own notification duties.
10. Return and deletion
You can delete content at any time in the app. Deleted content is retained in a recoverable state and then permanently destroyed once it has been in that state longer than your organisation's retention window (365 days by default); deleting the organisation destroys live content as well, without waiting. On termination we will delete your personal data on that basis, or return it to you first if you ask before deleting, except where a law requires us to keep something.
11. Audits
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and allow for and contribute to audits, at your expense and no more than once a year unless a supervisory authority requires otherwise or a breach has occurred. Audits must not compromise the confidentiality or security of other customers.
12. International transfers
Our sub-processors operate in the United States and elsewhere. Where personal data is transferred out of the EEA, the UK or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this agreement by reference, with us as data importer and you as data exporter, module two (controller to processor).
13. Liability
Each party's liability under this agreement is subject to the limitations in the Terms of Service, except where those limitations are not permitted by data protection law.
14. Contact
Data protection enquiries and requests for a signed copy: privacy@voice2jobs.com
Voice2Jobs Inc.
2727 Steeles Ave W, Unit 103
North York, ON M3J 3G9
Canada