Skip to content

Data Processing Addendum

Last updated: September 15, 2026

Part of a set with the Terms of Service and the Privacy Policy. Where this addendum and the Terms disagree about personal data, this addendum wins.

1. Who is who

When you put your clients' details into PaloWorks, you decide what is collected and why. For that data you are the controller, and Ferrier Industries LLC, a Wyoming limited liability company, is your processor: we handle it only to run the service for you. For your own account details and billing, we are the controller, as described in the Privacy Policy.

This addendum applies automatically to every workspace for as long as you use PaloWorks. There is nothing to sign; accepting the Terms of Service accepts it.

2. What we process

Whose data:

  • Your clients and their contacts — the people you send intake, scope, contract, change-order, invoice, portal, and status links to
  • People who send an inquiry through your public Book me page
  • Members of your workspace

What kinds:

  • Names, email addresses, company names, and billing addresses or tax numbers you put on an invoice
  • What a client types into an intake form, a message thread, or a Book me inquiry
  • Approval and signing records: the typed name, time, IP address, browser user agent, and a hash of the document text
  • Invoice and payment records: amounts, due dates, and payment status (card details stay with Stripe)
  • Delivery records for the email the product sends on your behalf: the address and whether the message arrived

Why:

  • Hosting and showing your workspace to you and your members
  • Showing each document to whoever holds its link, and recording approvals, signatures, and payments
  • Sending the email you trigger, and the reminders you switch on
  • Taking card payments through your own connected Stripe account
  • Producing an AI draft, only when you press a button that asks for one

We process it for as long as your account is open, and then for the deletion period in section 7. The product is not built for special-category data such as health records, and you should not put it there.

3. Our commitments as processor

  • We process your clients' data only to provide PaloWorks and on your instructions, which are the Terms, this addendum, and what you do in the product. We tell you if we believe an instruction breaks the law.
  • We do not sell it, use it to advertise, or use it to train AI models.
  • Anyone at Ferrier Industries LLC who can reach it is bound to keep it confidential.
  • We help you answer requests from the people whose data it is, and with any assessment or consultation your law requires, as far as the information we hold allows.
  • We tell you without undue delay after we become aware of a breach affecting your clients' data, with what we know and what we are doing about it.

4. Subprocessors

You authorise us to use the subprocessors below. Each receives only what it needs for the purpose given. This list is rendered from the same registry as the Privacy Policy, so the two always match.

  • Vercelhosts the application and serves every page.
  • Supabasestores your account and workspace data.
  • Stripesubscription billing, and card payments from your clients through your own connected Stripe account.
  • Resenddelivers the email the product sends: sign-in links, documents and reminders you send to clients, receipts, and notifications.
  • PostHogproduct analytics. Our servers send it the event name, a timestamp, and your workspace id when something happens in the product (for example “invoice sent”). It never receives the content of a document, a client’s name, or an amount, and no PostHog script runs in your browser.
  • OpenAIthe model provider behind the AI-assisted drafts (draft a scope from a brief, a verdict on a revision request, a payment chase email, a plain-language contract summary). Only when you press one of those buttons, we send the text needed for that draft — which can include your client’s brief and name and the scope or contract text — to OpenAI and show you the result to edit. Nothing is sent automatically, and nothing is sent if you never use those features. OpenAI’s API terms govern its handling of that text.
  • An error-monitoring service (if one is configured)when a page fails on our servers, the error message, the page path with any share token masked, and the time are forwarded so we can fix it. No stack trace, request body, or document content is sent.

When we add or replace a subprocessor, this list and the date at the top change. If the change is material we tell you by email or in the product. If you object on reasonable data-protection grounds, write to support@paloworks.com; if we cannot address it, you may close your account, and the refund terms in the Refund Policy still apply.

5. Security

What protects the data today:

  • Encryption in transit (HTTPS) and at rest by our hosting and database providers
  • Every database query scoped to your workspace, with that boundary covered by its own tests
  • Hashed passwords, optional TOTP two-factor, passkeys, and sessions you can review and revoke
  • Share links built on long random tokens that you can rotate or revoke from the project
  • An activity log per workspace that records approvals, signatures, invoices, and team changes

We do not publish a third-party compliance certification. Security problems go to security@paloworks.com, the contact also listed in /.well-known/security.txt.

6. International transfers

PaloWorks and its subprocessors may store and process data in the United States and other countries where they operate. If your law requires a specific transfer mechanism, such as the EU Standard Contractual Clauses, write to support@paloworks.com before relying on this addendum for that transfer, so we can confirm what is in place.

7. Retention, return, and deletion

  • Return: the workspace owner can download the whole workspace as JSON from Settings → Your data at any time, and clients, invoices, payments, and time as CSV.
  • A deleted project waits in Settings → Recently deleted for 30 days and is then purged.
  • When you close your account, we delete your workspace data within 30 days, except records the law requires us to keep, such as invoices tied to processed payments.
  • While the account is open, the text of an AI draft is erased after 30 days and its remaining record after 365 days; the email delivery log is deleted after 90 days; expired sign-in sessions after 7 days.

8. Information and audits

We answer reasonable written questions about how we process your clients' data and give you the information you need to show that this addendum is being kept. Send them to support@paloworks.com.

9. Liability and disputes

This addendum is part of the Terms of Service and does not enlarge our liability. The limitation of liability, binding individual arbitration, and governing law in those terms apply to it, except where the law that protects the data subjects requires otherwise.

10. Contact

Questions about this addendum: support@paloworks.com. Ferrier Industries LLC is a Wyoming limited liability company. PaloWorks by Ferrier Industries LLC. Write to legal@ferrierindustries.com for the current mailing address.

This addendum is provided by Ferrier Industries LLC. It is not legal advice.