Data Processing Addendum
You are the controller of the contact data you photograph. We process it for you.
1. What this is
This addendum forms part of the Terms of Service and governs Snapfiled's processing of personal data on your behalf. Where it conflicts with the Terms on a data protection question, this document wins.
2. Roles
For the personal data contained in the documents you capture — the homeowner, the adjuster, the person on the business card — you are the controller and Snapfiled is the processor. You decide what to photograph, why, and what happens to it afterwards.
For your own account data — your name, your crew's addresses, your billing details, our server logs — Snapfiled is the controller, and the Privacy Policy governs it.
3. Your instructions
We process customer personal data only on your documented instructions. Your instructions are: this addendum, the Terms, and your use of the product's own controls — which CRM you connect, which senders you allow, whether automatic filing is on, and your retention setting. If we believe an instruction breaks data protection law, we will tell you.
4. Annex A — the details of the processing
- Subject matter
- Reading documents you photograph and filing the results into your CRM.
- Duration
- For as long as your account is open, plus the retention periods in section 8 of the Privacy Policy.
- Nature and purpose
- Receiving, storing, transmitting to an AI model provider for optical and semantic extraction, normalising, deduplicating, presenting for human review, and transmitting to your CRM.
- Types of personal data
- Names, job titles, employers, phone numbers, email addresses, postal and property addresses, insurance claim and policy numbers, adjuster and carrier details, appointment dates, measurements, amounts, handwritten notes, and the images themselves. Whatever is on the document is in scope, because we cannot know in advance what you will photograph.
- Categories of data subject
- Your prospects and customers; homeowners; insurance adjusters and carrier staff; other agents, contractors and suppliers; your own employees and crew.
- Special categories
- Not intended and not requested. If you send them anyway, you are instructing us to process them and you carry the basis for doing so.
5. Confidentiality
Access to customer data is limited to the people who need it to run and support the service, and they are bound to confidentiality. In practice, on a deployment this size, that is the operator and anyone they name — not a support department. Ask us who, and we will tell you.
6. Security measures
The technical and organisational measures are set out on the Security
page and, in engineering detail, in docs/SECURITY.md. That page includes the
current weaknesses, which are part of this disclosure rather than an appendix to it.
7. Subprocessors
You give general authorisation for the subprocessors below. We will give notice by email to account owners before adding a new one that can see capture content, and you may object; if we cannot resolve an objection, you may terminate and get a pro-rata refund of prepaid fees. The live list, with exactly what each one sees, is at /subprocessors.
| Subprocessor | What it does | Location |
|---|---|---|
| Anthropic PBC (Claude) (not enabled) | Reads the photograph and returns the fields on it. | United States |
| DeepSeek | Optional cheap first pass on easy documents before Claude is asked. | China |
| SignalWire | Receives inbound picture messages and sends reply texts. | United States |
| Cloudflare | Routes mail sent to your @in.snapfiled.com address into Snapfiled. | United States (global anycast network) |
| Outbound email relay | Sends sign-in links, invites and reply emails. | Depends on the relay configured |
| Stripe (not enabled) | Subscription billing. | United States |
| Object storage (S3-compatible) (not enabled) | Stores the photographs. | us-east-1 |
| Hosting provider (the VPS) | Runs the application, the Postgres database and, by default, the file store. | Wherever the server is; see the operator |
| Your CRM | Where approved records are filed — HubSpot, JobNimbus, Follow Up Boss, Pipedrive, or your own webhook. | Set by the CRM you chose |
Your own CRM is listed for completeness. It is your system under your own agreement; we send to it on your instruction and are not its processor.
8. Transfers
Processing takes place primarily in the United States. Where personal data of people in the UK or EEA is transferred, the transfer relies on the appropriate safeguards — Standard Contractual Clauses or an adequacy mechanism as applicable. [TRANSFER MECHANISM — needs legal review before any EU/UK customer — not configured]
9. Helping you with data subject requests
The product does most of this for you: export and deletion are self-service in Settings → Your data, and individual captures and records can be deleted from their own pages. Where a request needs more than that, we will assist you, taking into account the nature of the processing. If a data subject comes to us directly we will not answer for you — we will pass it on and help you answer.
10. Breach notification
If we become aware of a personal data breach affecting your data we will notify you without undue delay, and in any event within 72 hours, with what we know: what happened, what data was involved, likely consequences and what we are doing. We will not sit on it while we work out the wording.
11. Deletion and return
On termination, or on request, we delete customer personal data. Deleting an organisation removes the database rows and unlinks the stored photographs from disk or object storage, and writes an entry to a deletion log that carries no personal data. Backup images can hold a copy until they rotate out. Export first — the same page gives you the whole thing as JSON.
12. Audit
We will make available the information reasonably necessary to demonstrate compliance with this addendum and will contribute to audits carried out by you or an auditor you mandate, on reasonable notice and no more than once a year unless a regulator or a breach requires otherwise. We do not have a third-party audit report today; see Security.
13. Signing it
If your organisation needs a countersigned DPA rather than an online one, write to [email protected].