When InsulatorOS processes personal data on your behalf, this DPA governs that processing. It applies in addition to our Terms of Service. Last updated May 13, 2026.
How to execute. If your organisation requires a counter-signed DPA for procurement, email legal@insulateos.com with your company name and we will return a signed PDF within two business days.
You ("Customer") are the data controller. InsulatorOS is the data processor. Stripe, Replit, Anthropic, OpenAI, Resend and Make.com act as sub-processors on InsulatorOS's behalf. The current list is at /sub-processors.
InsulatorOS processes personal data only as needed to provide the contracted service: customer relationship management, estimating, invoicing, scheduling, and billing for insulation contractors. The categories of data subjects are the Customer's employees and end-customers. Data categories are limited to contact information, job records, payment metadata, and application logs.
InsulatorOS processes personal data only on documented Customer instructions, including those given through the application UI. We will notify the Customer if we believe an instruction violates GDPR, CCPA, or other applicable law.
InsulatorOS personnel with access to personal data are bound by confidentiality obligations. Access is limited to those who need it to operate the service.
Detailed at /security. In summary: TLS in transit, encryption at rest via Replit KV, bcrypt password hashing, JWT auth, RBAC with audit logging, rate-limited authentication, and strict tenant isolation via key namespacing.
Customer authorises InsulatorOS to engage the sub-processors listed at /sub-processors. We will provide 30 days' notice via in-product banner and email before adding any new sub-processor, during which the Customer may object in writing and terminate the contract if the objection cannot be resolved.
InsulatorOS provides self-service tools so the Customer can fulfil access, deletion, and portability requests within statutory timeframes (CCPA: 45 days; GDPR: 30 days). See Settings → Export My Data and Settings → Delete Account.
InsulatorOS will notify affected Customers without undue delay and within 72 hours of becoming aware of a personal-data breach, providing the information required by GDPR Art. 33(3).
Personal data is primarily processed in the United States. Where transfers occur to other regions through sub-processors, they rely on Standard Contractual Clauses and supplementary measures.
The Customer may request, no more than once per year, a copy of our most recent SOC-2 / ISO 27001-equivalent attestation (when available) or a written response to a reasonable security questionnaire. On-site audits are by mutual written agreement.
Upon termination the Customer can export all data via Settings → Export. After 30 days of inactivity post-termination (or sooner if requested via Settings → Delete Account) we permanently delete the data.
Questions? legal@insulateos.com