Skip to main content
werkd logo

werkd.

AI-powered business manager

Data Processing Addendum

Last updated: July 1, 2026

Introduction

This Data Processing Addendum ("DPA") forms part of the Terms of Service between 122ai, LLC, a limited liability company organized under the laws of the State of Utah ("Service Provider", "we", "us"), and you ("Business", "you"), collectively the "Parties".

This DPA applies when you use werkd to store, manage, or process personal information of your customers, employees, or other individuals ("End-User Data") on your behalf. It establishes the rights and obligations of each party regarding the processing of personal information in compliance with applicable data protection laws.

In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of personal information.

Definitions

  • "Applicable Data Protection Laws" means all U.S. federal and state laws governing the processing of personal information, including but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), and the Montana Consumer Data Privacy Act (MCDPA), each as amended from time to time.
  • "Business" (also known as "Controller" under certain state laws) means you, the werkd subscriber who determines the purposes and means of processing End-User Data.
  • "Service Provider" (also known as "Processor" under certain state laws) means 122ai, LLC, which processes End-User Data on behalf of the Business pursuant to the Terms of Service and this DPA.
  • "End-User Data" means any personal information that the Business submits to werkd about the Business's customers, employees, prospects, or other individuals.
  • "Personal Information" has the meaning given under the CCPA (Cal. Civ. Code §1798.140(v)), and includes equivalent terms ("personal data") used under other Applicable Data Protection Laws.
  • "Sub-processor" means any third party engaged by the Service Provider to process End-User Data on behalf of the Business.
  • "Security Incident" means any unauthorized access, acquisition, use, or disclosure of unencrypted or unredacted personal information that compromises the security, confidentiality, or integrity of the personal information.

Scope & Roles

You are the Business (Controller). You determine why and how End-User Data is collected and processed through werkd. You are responsible for ensuring that you have a lawful basis to collect and share End-User Data with us, including providing any required notices and obtaining any required consents from your customers.

We are the Service Provider (Processor). We process End-User Data solely on your behalf and according to your instructions as documented in this DPA, the Terms of Service, and through your use of the Service. We do not sell End-User Data, share it for cross-context behavioral advertising, or use it for any purpose other than performing the services specified in the Terms of Service.

Important for your customers

Your own privacy obligations to your customers (notices, consent, rights requests) are your responsibility. We provide tools to help you fulfill those obligations, but compliance with the laws governing your relationship with your customers is ultimately your duty as the Business.

Processing Details (Schedule A)

The following describes the nature, purpose, and scope of data processing under this DPA:

Categories of Data Subjects

Your customers, prospects, employees, and subcontractors whose personal information you enter into werkd.

Categories of Personal Information Processed

  • Identifiers: name, email address, phone number, mailing/service address
  • Commercial Information: job details, invoices, line items, payment history, quotes, expense records
  • Geolocation Data: service addresses geocoded for routing and scheduling
  • Communications: email messages, in-app notes, customer-portal messages, and other correspondence sent through werkd (werkd does not transmit, store, or process SMS message contents — see Purposes of Processing below)
  • Financial Information: invoice amounts, payment status (full payment card data is processed by Stripe and never stored by werkd)
  • Photos/Media: expense receipt images and job-related photos uploaded by you

Purposes of Processing

  • Providing the werkd platform services as described in the Terms of Service
  • Job scheduling, routing, and customer management on your behalf
  • Generating and sending invoices, quotes, and payment reminders
  • AI-powered features (smart scheduling, quote generation, invoice drafting) using anonymized or pseudonymized data where feasible
  • Drafting suggested SMS message text and handing it off to your device's native messaging app for your manual review and send (werkd is not the sender of record and does not transmit, store, or have access to the contents of any SMS sent from your device)
  • Producing analytics and reports for your business

Duration of Processing

For the term of your werkd subscription, plus the data retention period described in the Data Retention & Deletion section of this DPA.

Service Provider Obligations

As your Service Provider, 122ai, LLC agrees to the following obligations:

  • Purpose Limitation. We will process End-User Data only for the specific business purposes set forth in this DPA and the Terms of Service, and only in accordance with your documented instructions. We will not process End-User Data for any other commercial purpose.
  • No Selling or Sharing. We will not sell End-User Data or share it for cross-context behavioral advertising as those terms are defined under the CCPA.
  • No Combining. We will not combine End-User Data with personal information received from or on behalf of another person, or collected from our own interactions with consumers, except as expressly permitted by the CCPA and its implementing regulations.
  • Confidentiality. We will ensure that all personnel authorized to process End-User Data are bound by appropriate confidentiality obligations.
  • Compliance Assistance. We will reasonably assist you in responding to consumer rights requests and complying with your obligations under Applicable Data Protection Laws, taking into account the nature of processing and the information available to us.
  • CCPA Certification. We certify that we understand and will comply with the restrictions and obligations set forth in this DPA and the CCPA, including the prohibition on selling or sharing personal information, and will not take any action that would cause any transfer of personal information to or from us to qualify as "selling" or "sharing" personal information under the CCPA.

Sub-processors (Schedule B)

You authorize us to engage the following sub-processors to assist in providing the Service. Each sub-processor is contractually bound to data protection obligations no less protective than those in this DPA.

Sub-processorPurposeLocation
Vercel, Inc.Application hosting & CDNUnited States
Neon, Inc.PostgreSQL database hostingUnited States
Cloudflare, Inc.Encrypted database backup storageUnited States
Clerk, Inc.Authentication & user managementUnited States
Stripe, Inc.Payment processing (Stripe Connect)United States
Anthropic, PBCAI processing (Claude API — not used to train models)United States
HERE Global B.V.Geocoding, routing & mappingNetherlands (EU)
Resend, Inc.Transactional email deliveryUnited States
Functional Software, Inc. (Sentry)Error monitoring & diagnosticsUnited States
Upstash, Inc.Redis caching & rate limitingUnited States

Changes to Sub-processors. We will notify you at least 30 days before engaging a new sub-processor or replacing an existing one by updating this page and, where you have provided an email address, by email. If you object to a new sub-processor on reasonable data protection grounds, you may notify us in writing within 15 days of our notice. We will work with you in good faith to find a resolution. If no resolution is possible, you may terminate the affected portion of the Service without penalty.

Sub-processor Liability. We remain fully liable for the acts and omissions of our sub-processors to the same extent we would be liable if performing the processing directly.

Security Measures (Schedule C)

We implement and maintain reasonable administrative, technical, and physical security measures designed to protect End-User Data against unauthorized access, destruction, use, modification, or disclosure, including:

  • Encryption in Transit. All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
  • Encryption at Rest. End-User Data is encrypted at rest via our database and infrastructure providers' encryption capabilities (AES-256 or equivalent).
  • Access Controls. Access to End-User Data is restricted to authorized personnel on a need-to-know basis, protected by multi-factor authentication.
  • Authentication. User authentication is managed by Clerk with support for multi-factor authentication, session management, and secure credential storage.
  • Infrastructure Security. Our application is hosted on Vercel with automatic security patches, DDoS protection, and network isolation. Our database is hosted on Neon with automated backups and point-in-time recovery.
  • Monitoring. We use Sentry for real-time error monitoring and anomaly detection to identify potential security issues.
  • Vendor Security. All sub-processors are evaluated for their security practices. We select vendors that maintain industry-standard security certifications (e.g., SOC 2 Type II, PCI DSS where applicable).

Consumer Rights Requests

As the Business, you are responsible for responding to privacy rights requests from your customers (e.g., access, deletion, correction, portability, opt-out). We will assist you in fulfilling these requests as follows:

  • Forwarding. If we receive a verifiable consumer request directly from one of your customers regarding End-User Data, we will promptly inform you and will not respond directly unless you instruct us to do so or we are legally required to respond.
  • Data Export. Upon your request, we will provide you with End-User Data in a structured, commonly used, machine-readable format (JSON or CSV) to facilitate your response to access or portability requests.
  • Deletion. Upon your verified request, we will delete or de-identify End-User Data within 30 days, and direct our sub-processors to do the same, except where retention is required by law or necessary to complete a transaction you requested.
  • Correction. We will implement reasonable measures to allow you to correct inaccurate End-User Data stored in werkd through the normal operation of the Service.
  • Opt-Out Signals. We do not track your customers across third-party websites or apps, and we do not process Global Privacy Control (GPC) signals in the context of End-User Data, as we do not engage in cross-context behavioral advertising with that data.

Security Incident Notification

In the event of a Security Incident involving End-User Data, we will:

  • Notify you without unreasonable delay and in any event within 72 hours of becoming aware of the incident, via email to the address associated with your werkd account.
  • Provide details including: the nature of the incident, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate its effects.
  • Cooperate with your investigation of the incident and provide reasonable assistance in your efforts to comply with any breach notification obligations under Applicable Data Protection Laws.
  • Document the incident and our response, including remediation steps taken, and make this documentation available to you upon request.

A Security Incident does not include unsuccessful attempts such as pings, port scans, denial-of-service attacks, or other network-level attacks on firewalls or edge servers.

Audit Rights

Upon your reasonable written request (no more than once per 12-month period, unless a Security Incident has occurred), we will make available information necessary to demonstrate our compliance with this DPA. This may include:

  • Summaries of our security policies and practices relevant to the processing of End-User Data.
  • Results of any third-party security assessments or certifications (e.g., SOC 2 reports) that we have obtained, subject to confidentiality obligations.
  • Written responses to reasonable questions regarding our data processing practices.

If you require an on-site audit beyond the documentation described above, it will be conducted at your expense, during normal business hours, with at least 30 days' prior written notice, and subject to reasonable confidentiality and scope limitations. We may offer an equivalent third-party audit report as an alternative.

Data Retention & Deletion

  • During Subscription. We retain End-User Data for the duration of your active werkd subscription. You may delete individual records (customers, jobs, invoices) at any time through the Service.
  • Account Termination. Upon termination of your werkd subscription, we will retain your End-User Data for a grace period of thirty (30) days after cancellation to allow you to export your data. After the 30-day grace period, we will delete or de-identify End-User Data within a reasonable timeframe, except as required by law or reasonably necessary to protect our rights and yours (e.g., financial records required for tax compliance, fraud-prevention records, or records subject to ongoing legal hold). You are responsible for exporting End-User Data you wish to retain before the end of the grace period.
  • Deletion Confirmation. Upon your written request following deletion, we will confirm in writing that End-User Data has been deleted or de-identified in accordance with this section.
  • Backup Copies. End-User Data in automated backups will be overwritten in accordance with our standard backup rotation schedule (typically within 30 days). We will not actively process backup copies of deleted data.
  • Sub-processor Deletion. We will direct our sub-processors to delete End-User Data in accordance with their standard deletion procedures, which are no less protective than the timelines set forth in this section.

CCPA/CPRA-Specific Provisions

To the extent the CCPA (Cal. Civ. Code §1798.100 et seq.) applies to the processing of End-User Data, the following provisions apply in addition to the obligations above:

  • We are a "Service Provider" as defined in Cal. Civ. Code §1798.140(ag). We process End-User Data solely for the business purposes specified in the Terms of Service and this DPA.
  • We shall not sell or share (as defined in §1798.140(ad) and §1798.140(ah)) personal information provided to us by or on behalf of you.
  • We shall not retain, use, or disclose personal information provided by you for any purpose other than the business purposes specified in this DPA and the Terms of Service, including retaining, using, or disclosing the personal information for a commercial purpose other than providing the services specified in the Terms of Service, or as otherwise permitted by the CCPA.
  • We shall not retain, use, or disclose the personal information outside of the direct business relationship between you and us, except as permitted by the CCPA.
  • We grant you the right to take reasonable and appropriate steps to help ensure that we use End-User Data in a manner consistent with your obligations under the CCPA (per 11 CCR §7051(a)(5)).
  • We will notify you if we determine that we can no longer meet our obligations under the CCPA and this DPA, and in such event, you may take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
  • We certify that we understand the restrictions in Cal. Civ. Code §1798.140(ag) and 11 CCR §7051 and will comply with them.

Multi-State Privacy Compliance

To the extent other state privacy laws apply to our processing of End-User Data on your behalf, the following additional commitments apply:

  • Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA). We act as a "Processor" under these laws. We will process End-User Data only according to your instructions, assist you with data protection assessments upon reasonable request, and delete or return End-User Data at the end of the service relationship.
  • Utah (UCPA). We act as a "Processor" and will adhere to your instructions with respect to End-User Data. We will maintain appropriate confidentiality with respect to such data.
  • Texas (TDPSA), Oregon (OCPA), Montana (MCDPA). We act as a "Processor" under these laws and will comply with any applicable processor obligations, including assisting with consumer rights fulfillment and data protection impact assessments where required.
  • Future State Laws. As additional U.S. state privacy laws take effect, we will use commercially reasonable efforts to comply with any processor or service provider obligations imposed by such laws with respect to End-User Data, and will update this DPA accordingly.

General Terms

  • Governing Law. This DPA is governed by the laws of the State of Utah, consistent with the governing law provision of the Terms of Service.
  • Term. This DPA is effective as of the date you accept the Terms of Service and continues for the duration of your use of werkd. Provisions that by their nature should survive termination (including data deletion, audit rights, and confidentiality) will survive.
  • Amendments. We may update this DPA from time to time to reflect changes in Applicable Data Protection Laws or our data processing practices. Material changes will be communicated to you via email or in-app notification at least 30 days before they take effect. Your continued use of werkd after the effective date of any changes constitutes acceptance of the updated DPA.
  • Entire Agreement. This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the parties regarding the processing of End-User Data and supersedes all prior or contemporaneous agreements on this subject.
  • Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions will continue in full force and effect.

Contact

For questions about this DPA or to exercise any rights described herein, contact us at:

122ai, LLC

517 N 2000 W, Ste 2 #2109

Marriott-Slaterville, UT 84404

Data Processing Inquiries

privacy@werkd.pro

Last updated: July 1, 2026

© 2026 122ai, LLC. All rights reserved.

werkd - AI Business Manager for Trades