This is an archived version of this document, published 2026-09-10. The current version is at readybit.com/dpa.
READYBIT DATA PROCESSING ADDENDUM
Version 1.0. Last updated September 10, 2026. Posted at readybit.com/dpa.
This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Readybit Reseller Agreement, Service Agreement, Order Form or click-through Terms of Use between Readybit Inc. (“Readybit”) and the entity that is party to that agreement (“Customer”), as that agreement may be amended (the “Agreement”). Readybit and Customer are each a “party” and together the “parties.” This DPA applies to the extent Readybit Processes Personal Data on behalf of Customer in connection with the Services. If there is a conflict between this DPA and the Agreement about the Processing of Personal Data, this DPA controls. Capitalized terms not defined in this DPA have the meaning given in the Agreement.
1. Definitions
1.1 “Applicable Data Protection Law” means the privacy and data protection laws that apply to the Processing of Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA”), comparable United States state privacy laws, and the Personal Information Protection and Electronic Documents Act (Canada) and comparable Canadian provincial laws, in each case to the extent applicable.
1.2 “Personal Data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable natural person or household. Personal Data includes “personal information” as defined in the CCPA. Personal Data does not include (a) information that has been de-identified or aggregated so that it cannot reasonably be linked to a natural person, or (b) Sensor Data, meaning operational and telemetry data collected or generated by Readybit hardware and the Services, such as fluid levels, usage, cycle counts, device status and diagnostics, in a form that does not identify Customer, any third-party entity or any natural person.
1.3 “Customer Personal Data” means Personal Data contained within Customer Data that Readybit Processes on Customer’s behalf under the Agreement, as described in Annex I.
1.4 “Processing” means any operation performed on Personal Data, whether or not by automated means, such as collection, recording, storage, use, disclosure, transmission or deletion. “Process” and “Processed” have corresponding meanings.
1.5 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Personal Data in Readybit’s possession or control.
1.6 “Sub-processor” means any third party engaged by Readybit to Process Customer Personal Data on Readybit’s behalf.
1.7 “Security Documentation” means Readybit’s security documentation posted at readybit.com/security, as updated from time to time. Annex II of this DPA summarizes the measures described there.
1.8 “Business,” “Service Provider,” “sell” and “share” have the meanings given in the CCPA. “Controller” and “Processor” have the meanings given in Applicable Data Protection Law or, where that law does not define them, their generally accepted meaning in data protection practice.
2. Roles and Scope
2.1 Roles. As between the parties, Customer is the Controller (or Business) and Readybit is the Processor (or Service Provider) of Customer Personal Data. Where Customer acts as a processor or service provider for a third-party controller, such as a reseller or distributor acting for an end customer, Readybit acts as a sub-processor, and Customer represents that it has the authority and any consents needed to engage Readybit on that basis.
2.2 Scope. Readybit will Process Customer Personal Data only for the purposes described in the Agreement and Annex I, and only as necessary to provide, secure and support the Services.
2.3 Data categories. The Services are designed to hold equipment telemetry, site and contact information and user account details. They are not designed for, and Customer must not submit, payment card data, protected health information, government identification numbers, precise personal geolocation, or other sensitive or regulated categories of Personal Data unless an Order Form expressly provides for it. Location data generated by Readybit hardware describes the monitored container or equipment; Annex I explains when location data that can be linked to an individual is treated as Customer Personal Data.
3. Processing Instructions
Readybit will Process Customer Personal Data only on Customer’s documented instructions, which consist of the Agreement, this DPA, and Customer’s configuration and use of the Services, unless Readybit is required to act otherwise by applicable law. In that case Readybit will, where legally permitted, inform Customer of the requirement before Processing. Readybit will promptly inform Customer if, in Readybit’s opinion, an instruction infringes Applicable Data Protection Law.
4. Confidentiality of Personnel
Readybit will ensure that every person authorized to Process Customer Personal Data, including Readybit’s contractors, is bound by a written obligation of confidentiality and is informed of the confidential nature of the data.
5. Security Measures
Readybit will implement and maintain appropriate administrative, physical and technical measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, taking into account the state of the art, the cost of implementation, and the nature, scope and purposes of the Processing. Readybit’s current measures are summarized in Annex II and described in the Security Documentation. Readybit may update its measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data.
6. Sub-processors
6.1 Authorization. Customer gives Readybit general authorization to engage Sub-processors to Process Customer Personal Data. The current list of Sub-processors is set out in Annex III and maintained at readybit.com/security.
6.2 Changes. Before Readybit authorizes a new Sub-processor to Process Customer Personal Data, Readybit will update the list at readybit.com/security and notify Customer by email to the administrator contact on Customer’s account at least fifteen (15) days in advance. Customer may object on reasonable data protection grounds within ten (10) days after notice. If the parties cannot resolve a reasonable objection within thirty (30) days, Customer may terminate the affected Services on written notice as its sole remedy, and Readybit will refund any prepaid fees for the terminated portion of the then-current subscription term.
6.3 Flow-down. Readybit will impose on each Sub-processor data protection obligations that are no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Sub-processor performs, and Readybit remains responsible for each Sub-processor’s performance.
7. Assistance to Customer
7.1 Data subject requests. Taking into account the nature of the Processing, Readybit will provide reasonable assistance to enable Customer to respond to requests from individuals to exercise their rights under Applicable Data Protection Law, such as requests to access, correct or delete Personal Data. Where a request can be fulfilled through the Services’ own user management features, Customer will use those features. If Readybit receives such a request directly, Readybit will, where legally permitted, direct the individual to Customer and will not respond on Customer’s behalf except on Customer’s instructions.
7.2 Assessments. Readybit will provide reasonable assistance, taking into account the information available to it, with any data protection or risk assessment that Customer is required to carry out under Applicable Data Protection Law in relation to the Processing.
8. Personal Data Breach Notification
8.1 Notice. Readybit will notify Customer without undue delay, and in any event within seventy-two (72) hours after confirming a Personal Data Breach, by email to the administrator contact on Customer’s account.
8.2 Content. The notice will describe, to the extent known at the time, the nature of the Personal Data Breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures Readybit has taken or proposes to take, and a point of contact at Readybit. Readybit will supplement the notice as further information becomes available and will provide the information reasonably needed for Customer, and any reseller, distributor or end customer for whom Customer acts, to meet their own notification obligations.
8.3 No admission. Readybit’s notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.
9. United States and Canadian Privacy Laws
9.1 Service Provider. With respect to Personal Data subject to the CCPA, Readybit acts as a Service Provider. Readybit will not (a) sell or share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted for a Service Provider under the CCPA; (c) retain, use or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with Personal Data it receives from other sources, except as permitted for a Service Provider under the CCPA. Readybit certifies that it understands and will comply with these restrictions and will notify Customer if it determines it can no longer meet them. Customer may take reasonable and appropriate steps, consistent with Section 11, to ensure Readybit uses Customer Personal Data in a manner consistent with Customer’s obligations under the CCPA, and to stop and remediate unauthorized use.
9.2 De-identified data. Readybit may use Sensor Data and data that has been de-identified or aggregated so that it no longer identifies Customer or any natural person to operate, secure and improve the Services and to compile aggregate statistics, as provided in the Agreement. Readybit will not attempt to re-identify de-identified data except to test the effectiveness of its de-identification.
9.3 Other laws. Where other United States state privacy laws or Canadian federal or provincial privacy laws apply to Customer Personal Data, the parties intend this DPA to satisfy the contract requirements those laws impose on a processor or service provider, and this DPA will be read accordingly.
10. Cross-Border Transfers
10.1 Where Readybit operates. Readybit offers the Services in the United States and Canada and hosts and Processes Customer Personal Data in the United States, as described in Annex III. Customer authorizes the transfer of Canadian Personal Data to the United States for Processing under this DPA and is responsible for any notice to individuals that Canadian law requires for that transfer.
10.2 Other regions. The Services are not intended for, and Readybit does not intend to Process, Personal Data of individuals located in the European Economic Area, the United Kingdom or Switzerland. Customer will not submit such Personal Data to the Services without Readybit’s prior written agreement. If the parties agree that Readybit will Process such Personal Data, then, before that Processing begins, the parties will execute the European Commission’s Standard Contractual Clauses for the transfer of personal data to third countries (Module Two, controller to processor, or Module Three, processor to processor, as applicable), together with the United Kingdom International Data Transfer Addendum and any Swiss adaptations required by the Swiss Federal Act on Data Protection, or another transfer mechanism that is lawful at the time. Those documents will then form part of this DPA and prevail over it in case of conflict.
11. Audits and Compliance Information
Readybit will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA. Customer may exercise its audit rights by requesting Readybit’s then-current Security Documentation and written responses to a reasonable security questionnaire, no more than once in any twelve (12) month period, unless a Personal Data Breach affecting Customer Personal Data or a requirement of Applicable Data Protection Law justifies an additional request. Readybit will respond within thirty (30) days. Where Applicable Data Protection Law requires an audit that cannot be satisfied by documentation and questionnaire responses, the parties will agree in advance, in writing, on the scope, timing, duration, confidentiality terms and allocation of cost, and the audit will be conducted during normal business hours without unreasonable disruption to Readybit’s operations. Audit information is Readybit’s Confidential Information.
12. Return and Deletion
For thirty (30) days after expiration or termination of the Agreement, Readybit will make Customer Data, including Customer Personal Data, available for export by Customer in a commercially reasonable manner. After that period Readybit will delete Customer Personal Data in its possession or control, including copies held by its Sub-processors, within a commercially reasonable time, except to the extent that retention is required by applicable law or permitted under the Agreement, except for records of each user’s acceptance of the Terms of Use (the version accepted, the time, the user’s email address, IP address and browser identifier), which Readybit retains as evidence of contract formation, and except for copies held in routine backups, which are overwritten in the ordinary course of Readybit’s backup cycle described in the Security Documentation. This DPA continues to apply to any Customer Personal Data that Readybit retains.
13. Liability
Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement. Any reference in the Agreement to the liability of a party means that party’s aggregate liability under the Agreement and this DPA together.
14. General
14.1 Order of precedence. This DPA supplements the Agreement. In the event of a conflict about the Processing of Personal Data, the order of precedence is (a) the Standard Contractual Clauses and related addenda, if executed under Section 10.2; (b) this DPA; and (c) the Agreement.
14.2 Governing law and venue. Except where Applicable Data Protection Law requires otherwise, this DPA is governed by the law, and subject to the venue, stated in the Agreement.
14.3 Term. This DPA takes effect on the effective date of the Agreement, or on the date this DPA is first posted at readybit.com/dpa if later, and continues for as long as Readybit Processes Customer Personal Data.
14.4 Updates. Readybit may update this DPA from time to time to reflect changes in law, its Sub-processors or its Services. Readybit will post the updated version at readybit.com/dpa with a new “Last updated” date and will keep prior versions available. Updates do not reduce the protection of Customer Personal Data under a signed Agreement during its then-current term without Customer’s written agreement.
14.5 Incorporation. This DPA is incorporated into the Agreement by the Agreement’s reference to readybit.com/dpa and applies without separate signature. On request, Readybit will provide a copy of this DPA for countersignature by both parties.
ANNEX I. DETAILS OF PROCESSING
Controller (or Business): Customer, the entity identified in the Agreement. Where Customer is a reseller, distributor or service agent, the end customers it serves are the controllers of their own Personal Data and Customer acts on their behalf.
Processor (or Service Provider): Readybit Inc., 19225 8th Avenue Northeast, Suite 201-1802, Poulsbo, WA 98370, United States. Contact for data protection matters: legal@readybit.com.
Subject matter: Processing of Customer Personal Data to provide the Readybit monitoring platform, consisting of Readybit hardware installed at Customer’s or its end customers’ sites, a hosted dashboard and alerting service, and related support.
Duration: The term of the Agreement, plus the export and deletion periods in Section 12.
Nature and purpose of Processing: Hosting, storage, transmission and display of Customer Personal Data as necessary to create and authenticate user accounts, associate users with sites and devices, deliver alerts and reports by email or through the dashboard, provide customer support, secure the Services, and comply with law.
Categories of Personal Data:
- Account and contact data of Customer’s authorized users and of the personnel of its channel partners and service providers: name, business email address, business or mobile phone number (including a number supplied to receive alerts by text message), role and organization.
- Authentication data: login credentials (passwords are stored only in hashed form), session tokens, and records of sign-in events.
- Usage and technical data: IP address, browser and device information, pages and features used, and support requests and correspondence.
- Site data: location names and addresses, on-site contact names and contact details, and notes entered by users, to the extent they identify a natural person.
- Photographs: images of monitored containers or equipment that users upload during setup or when reporting a problem, to the extent they show an identifiable person or carry location metadata.
- Field and route data: names of drivers, technicians and other personnel entered by users in connection with sites, routes, deliveries or alerts, and route or delivery information to the extent it identifies a natural person.
- Location data linked to an individual: the reported location of a monitored container or asset is Sensor Data. Where Customer associates a mobile container with a named driver or vehicle so that its location history can reasonably be linked to that person, Readybit treats that location data as Customer Personal Data under this DPA.
- Alert and notification preferences, including the email addresses to which alerts are sent.
Categories of individuals: Customer’s employees and contractors who use or are named in the Services; employees and contractors of Customer’s channel partners, distributors and service agents; drivers, technicians and other field personnel named in the Services; and on-site contacts at monitored locations.
Sensitive data: None intended. The Services are not designed to Process payment card data, protected health information, government identification numbers, precise personal geolocation or other sensitive categories, and Customer must not submit them except as expressly agreed in an Order Form.
Data that is not Personal Data: Sensor Data (equipment telemetry such as fill level or fluid level, temperature, orientation, usage, cycle counts, pump status, the location of monitored containers or equipment, device status and diagnostics, and device identifiers) is operational data about equipment and containers, not about people, and is outside the scope of this DPA unless it is linked to an identifiable individual as described above.
ANNEX II. TECHNICAL AND ORGANIZATIONAL MEASURES
Readybit maintains the following measures. The Security Documentation at readybit.com/security describes them in more detail and is updated as they change.
Hosting. The Services run on infrastructure operated by DigitalOcean, LLC in the United States. Physical security of the data centers is the responsibility of the hosting provider under its own certifications and controls.
Encryption. Connections between users’ browsers and the dashboard, between Readybit devices and the platform, and between the platform and its Sub-processors are encrypted in transit using TLS. Customer Personal Data is stored in managed database, block storage and object storage services that encrypt data at rest, and database backups are encrypted.
Device authentication. Each Readybit device authenticates to the platform with credentials unique to that device. Devices send telemetry to the platform; the platform does not accept unsolicited inbound connections from the public internet to devices. Devices monitor and report only and do not control the equipment they are attached to.
Access control. Access to production systems and to Customer Personal Data is limited to the Readybit personnel who need it to operate and support the Services. Each person uses a unique account. Multi-factor authentication is enforced on the hosting console, source code repositories and Readybit’s email and identity provider. Access is reviewed when roles change and removed promptly when no longer needed. Within the Services, role-based access controls limit each user to the organizations, sites and devices they are authorized to see.
Network and application security. Production systems run on a private network with only the public endpoints needed for the dashboard, API and device connections exposed through a load balancer. Secrets are kept out of source code and managed through the hosting platform. Staging and production environments are separate. Code changes are tracked in version control and reviewed before release.
Logging and monitoring. Readybit logs authentication events, administrative actions and application errors, retains application logs for 30 days, and monitors for service errors and unusual activity.
Backups and resilience. The production database is backed up daily, with point-in-time recovery available across a rolling seven-day window, in the same hosting region. Readybit also keeps an independent record of device telemetry from which sensor data has been recovered in production.
Vulnerability and patch management. Readybit updates operating systems, container images and software dependencies as part of its regular release process, reviews dependency advisories, and prioritizes security fixes ahead of other work. Readybit does not currently commission third-party penetration tests and does not represent that it does.
Personnel. Everyone with access to Customer Personal Data, including contractors, is bound by written confidentiality obligations.
Incident response. Readybit investigates suspected security incidents, contains them, and notifies affected customers without undue delay and in any event within 72 hours after confirming a Personal Data Breach, with the information they need for their own notifications.
Retention and deletion. Customer Data, including Customer Personal Data, is retained for the term of the Agreement and made available for export for 30 days after termination, after which Customer Personal Data is deleted from production systems within a commercially reasonable time, and from backups as the backup cycle overwrites them. Records of Terms of Use acceptance are retained as evidence of contract formation. Sensor Data, which does not identify individuals, may be retained as provided in the Agreement.
ANNEX III. SUB-PROCESSORS
The following Sub-processors Process Customer Personal Data on Readybit’s behalf as of the “Last updated” date. The current list is maintained at readybit.com/security.
| Sub-processor | Processing activity | Location |
|---|---|---|
| DigitalOcean, LLC | Cloud hosting, managed database, storage and backups for the Services | United States |
| Okta, Inc. (Auth0) | User identity, authentication and sign-in for the dashboard | United States |
| Twilio Inc. (SendGrid) | Delivery of account, alert, invitation and report emails, and text message alerts where enabled | United States |
| Google LLC | Business email and customer communications, including support correspondence and service notices | United States |
The following providers support the Services but do not receive Customer Personal Data in the ordinary course. The United States Census Bureau, the OpenStreetMap Foundation, Geocodio and Google LLC receive site street addresses, without contact details, to convert them to map coordinates. Google LLC (web fonts), the OpenStreetMap Foundation (map tiles) and jsDelivr (map assets) serve dashboard content that a user’s browser loads directly, and so receive the user’s IP address and browser information in the ordinary course of serving that content. Depending on how a user signs in, the user’s profile image may be loaded by the browser from Automattic (Gravatar) or Google. SitePartners (BlackBean Marketing), Readybit’s website agency in Canada, operates the readybit.com marketing website and its contact forms; support requests are handled by email to support@readybit.com and not through the website. They are listed for transparency.
End of Data Processing Addendum.