Standard processor terms for applicable Customer Personal Data. Version September 27, 2026.
This DPA applies to Customer Personal Data processed by MaintenanceAI on Customer's behalf in connection with the Services. Customer determines the purposes and means of the relevant processing and acts as controller, business, or equivalent role. MaintenanceAI acts as processor, service provider, contractor, or equivalent role to the extent it processes that data solely on Customer's documented instructions.
MaintenanceAI will process Customer Personal Data only to provide, secure, support, and troubleshoot the contracted Services in accordance with the Customer Agreement, Order Form, documented Customer instructions, and applicable law. Product improvement using Customer Personal Data will occur only where permitted by the applicable agreement and law, or after the information has been aggregated or de-identified so that it no longer reasonably identifies the Customer, Customer personnel, Customer facilities, or specific Customer assets. If MaintenanceAI determines purposes and means outside Customer instructions, its role for that processing will be determined under applicable law.
Subject matter: provision of maintenance, reliability, asset, planning, analytics, reporting, and related software or professional services.
Duration: the applicable service term plus any permitted retention period.
Nature and purpose: collection, organization, storage, analysis, retrieval, use, transmission, support, security, deletion, and other processing necessary to provide contracted Services.
Categories of data subjects: Customer personnel, contractors, business contacts, technicians, planners, engineers, managers, or other individuals whose business information may appear in Customer Data.
Categories of personal data: business contact information, usernames or identifiers, technician or planner names, work-order authorship, notes, maintenance activity information, and other business-context personal information included by Customer in submitted data.
Sensitive data: not intentionally required. Customer must not submit specialized sensitive or regulated data unless separately authorized in writing.
MaintenanceAI will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations appropriate to their role.
MaintenanceAI will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the processing and current Services. Controls may include access restriction, controlled pilot access, transport security, security headers, request validation, rate limiting, audit logging, input controls, and security monitoring. Security measures may evolve as the Services change.
Customer will provide only personal data reasonably necessary for the Services. MaintenanceAI will process personal data consistent with the applicable instructions and will not intentionally require unrelated sensitive personal data for maintenance analysis.
Taking into account the nature of processing and information available to MaintenanceAI, MaintenanceAI will provide commercially reasonable assistance to Customer with verified requests for access, correction, deletion, portability, or other applicable rights where Customer cannot reasonably fulfill the request without MaintenanceAI's assistance.
MaintenanceAI will notify Customer without unreasonable delay after confirming a security incident involving unauthorized access to Customer Personal Data when notification is required by applicable law or the parties' agreement. MaintenanceAI will provide information reasonably available to support Customer's response obligations.
Customer authorizes MaintenanceAI to use subprocessors reasonably necessary to provide the Services, including providers of cloud infrastructure, hosting, artificial-intelligence infrastructure, email, security, anti-bot protection, analytics, communications, and file-processing functions. Where applicable law requires it, MaintenanceAI will provide reasonable prior notice of a new subprocessor and a reasonable opportunity for Customer to object on legitimate data-protection grounds before that subprocessor begins processing applicable Customer Personal Data.
MaintenanceAI will bind subprocessors that process Customer Personal Data to written data-protection obligations appropriate to the services provided and consistent with MaintenanceAI's applicable obligations to Customer. MaintenanceAI remains responsible for its contractual obligations under this DPA notwithstanding use of subprocessors, subject to the liability provisions of the Customer Agreement.
Taking into account the nature of processing and information available, MaintenanceAI will provide information reasonably necessary for Customer to conduct applicable data-protection assessments or demonstrate compliance with processor-related obligations. Requests must be reasonable, proportionate, and designed to protect MaintenanceAI Confidential Information and other customers.
Where applicable law requires audit rights, MaintenanceAI will provide reasonable information demonstrating compliance with this DPA. The parties will first use available documentation, questionnaires, reports, and remote review before requiring an on-site audit. Any on-site audit must be legally required, reasonably scoped, scheduled with reasonable notice, protect other customers and confidential information, and avoid unreasonable disruption.
Following termination, MaintenanceAI will delete or return Customer Personal Data in accordance with the Customer Agreement, applicable Order Form, documented Customer instructions, and applicable law. Backup copies may remain temporarily until removed through ordinary backup and retention cycles, subject to continuing protection.
If applicable law requires a specific transfer mechanism for processing across jurisdictions, the parties will cooperate in good faith to implement an appropriate lawful mechanism.
This DPA forms part of the applicable Customer Agreement when incorporated by reference or accepted by the parties. If this DPA conflicts with the Customer Agreement solely concerning processing of Customer Personal Data, this DPA controls for that issue. Liability remains subject to the limitations and exclusions in the Customer Agreement unless applicable law requires otherwise.
XRVE Group LLC
MaintenanceAI
135 Lullaby Ln, Castle Rock, CO 80109
[email protected]