WS
Weeksolved
Open the app →

Data Processing Addendum

Version 1.1 — Effective September 12, 2026 · Last updated September 12, 2026

This Data Processing Addendum ("DPA") is part of the Weeksolved Terms of Service (the "Agreement") between Weeksolved, a California sole proprietorship ("Weeksolved", "we", "Service Provider") and the customer identified in the Agreement or an order form ("Customer", "you", "Business").

It applies when we process personal information about your personnel on your behalf. Where this DPA and the Agreement conflict on a data protection matter, this DPA controls.

How to accept this DPA: by signing it at the end, by accepting it through the Weeksolved application, or by executing an order form that references it. No signature from us is needed beyond our published, countersigned version at https://weeksolved.com/dpa.html.


1. Definitions

Terms defined in the California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100 et seq., as amended by the California Privacy Rights Act, and its implementing regulations at 11 CCR §§ 7000 et seq. (together, the "CCPA"), have the same meaning here. In particular: "business", "business purpose", "collect", "commercial purpose", "consumer", "personal information", "process", "sell", "service provider", "share", and "third party".

"Customer Personal Information" means personal information within Customer Data that we process on your behalf under the Agreement.

"Customer Data" means the information you or your authorized users enter into or generate in the Service.

"Security Incident" means a breach of our security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Information in our possession. It does not include an unsuccessful attempt or an event that does not compromise the security of Customer Personal Information — pings, port scans, failed log-ins, denial-of-service attempts, and similar events that do not result in unauthorized access.

"Data Protection Law" means all privacy and data protection laws applicable to a party's processing under this DPA, including the CCPA and other US state privacy laws.


2. Roles of the parties

2.1 For Customer Personal Information, you are the Business and we are the Service Provider, as those terms are defined in Cal. Civ. Code § 1798.140. Under other US state privacy laws, you are the controller and we are the processor.

2.2 You determine the purposes and means. You decide what personal information to enter into the Service, about whom, and why. We do not.

2.3 Your responsibilities. You represent and warrant that:

(a) you have the right to provide Customer Personal Information to us and to have us process it as described here;

(b) you have given all notices and obtained all consents or other legal bases that Data Protection Law requires of you, including any notice at collection you owe your employees under Cal. Civ. Code § 1798.100(a) — an obligation that has applied to California employers since the CCPA's employee-data exemption expired on January 1, 2023;

(c) your instructions to us do not require us to violate Data Protection Law; and

(d) you will not enter into the Service any protected health information subject to HIPAA, payment card data subject to PCI DSS, Social Security or government identification numbers, or financial account numbers. We are not a HIPAA business associate and will not execute a business associate agreement.

2.4 Automated decisionmaking. The Service produces draft schedules and warnings that your personnel review and publish. To the extent California's automated decisionmaking technology regulations (11 CCR §§ 7200 et seq., applicable from January 1, 2027) or any comparable law apply to your use of the Service to make significant employment decisions, those obligations are yours as the Business, including pre-use notices, risk assessments, and access and opt-out rights. We will, on request and without additional charge, provide reasonable information about how the Service's logic and outputs work so you can complete a risk assessment or pre-use notice.


3. Scope of processing

3.1 Subject matter. Provision of the Weeksolved staff-scheduling service.

3.2 Duration. For the term of the Agreement, plus the deletion window in section 10.

3.3 Nature and purpose. Storing, organizing, structuring, retrieving, displaying, and deleting Customer Personal Information so you can build, review, and publish staff schedules; providing support you request; maintaining and securing the Service.

3.4 Categories of data subject. Your personnel — the employees and workers you schedule — and your authorized users (managers and administrators). Your employees do not have accounts and do not access the Service.

3.5 Categories of personal information. As determined by you. The Service provides fields for: name; email address; telephone number; employment type; availability; scheduled and worked hours; hourly pay rate (optional); date of birth (optional, used to warn about work-hour limits for workers under 18); license expiry dates; time-off and sick-leave records; callout and no-show records; and free-text notes. Where you enable optional features that are off by default, also: overtime offers and refusals; mandatory-overtime rotation position; and an audit log of changes made to schedules after posting.

3.6 Sensitive personal information. The Service provides no field for sensitive personal information as defined in Cal. Civ. Code § 1798.140(ae). We do not request it. Free-text note fields will accept whatever you enter; you agree not to enter sensitive personal information there.


4. Our obligations as a Service Provider — the CCPA contractual terms

This section states the commitments Cal. Civ. Code § 1798.140(ag) and § 1798.100(d) require. It is drafted to satisfy both.

4.1 Limited and specified purposes

Personal information is disclosed by you to us only for the limited and specified purpose of providing the Service to you as described in section 3 and in the Agreement. That is the "business purpose specified in the contract" for CCPA purposes.

4.2 The four statutory prohibitions

We are prohibited from, and we will not:

(A) Sell or share the personal information. We will not sell or share Customer Personal Information as "sell" and "share" are defined in Cal. Civ. Code § 1798.140(ad) and (ah). We do not sell or share personal information for monetary or other valuable consideration, and we do not disclose it for cross-context behavioral advertising.

(B) Retain, use, or disclose the personal information for any purpose other than for the business purposes specified in the contract, including retaining, using, or disclosing the personal information for a commercial purpose other than the business purposes specified in the contract with you, or as otherwise permitted by the CCPA.

(C) Retain, use, or disclose the information outside of the direct business relationship between us as service provider and you as business.

(D) Combine the personal information that we receive from, or on behalf of, you with personal information that we receive from, or on behalf of, another person or persons, or collect from our own interaction with the consumer, except as the CCPA and its regulations expressly permit.

We will not use Customer Personal Information to build or improve profiles, for advertising, or to train, fine-tune, or evaluate any artificial intelligence or machine learning model.

4.3 Certification

We certify that we understand the restrictions and obligations set out in section 4.1 and 4.2 and this DPA, and that we will comply with them. (Cal. Civ. Code § 1798.140(ag)(1).)

4.4 Same level of privacy protection

We will comply with our applicable obligations under the CCPA and provide the same level of privacy protection as the CCPA requires of you, with respect to Customer Personal Information. (Cal. Civ. Code § 1798.100(d)(2).)

4.5 Your right to monitor

You have the right to take reasonable and appropriate steps to help ensure that we use Customer Personal Information in a manner consistent with your obligations under the CCPA (Cal. Civ. Code § 1798.100(d)(3)), including by exercising the audit rights in section 8 of this DPA, and by ongoing manual review, automated scanning, regular assessments, or audits no more than once every twelve (12) months, as permitted by Cal. Civ. Code § 1798.140(ag)(1).

4.6 Our duty to notify you if we cannot comply

We will notify you if we make a determination that we can no longer meet our obligations under the CCPA (Cal. Civ. Code § 1798.100(d)(4)). We will do so promptly and in writing.

4.7 Your right to stop and remediate

On notice, including notice under section 4.6, you have the right to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information (Cal. Civ. Code § 1798.100(d)(5)).

4.8 Instructions

We process Customer Personal Information only on your documented instructions. The Agreement, this DPA, and your use of the Service's features are your instructions. If we believe an instruction violates Data Protection Law, we will tell you and may pause that processing until it is resolved.

4.9 Compelled disclosure

If we receive a subpoena, warrant, court order, or other legally binding demand for Customer Personal Information, we will notify you before responding so you can seek protection, unless we are legally prohibited from notifying you. We will object to demands that are overbroad, improper, or not legally valid, and will disclose only the minimum required.

4.10 Confidentiality of our personnel

Everyone we authorize to process Customer Personal Information is bound by a written confidentiality obligation and is granted access only to what their role requires.


5. Subprocessors

5.1 Authorization. You give us general written authorization to engage subprocessors, subject to this section.

5.2 Current subprocessors.

Subprocessor Purpose Data processed Location Status
Supabase, Inc. Database, storage, and authentication of Customer's authorized users All Customer Personal Information synced to the account; authorized user email address and hashed password United States (region us-west-1) Becoming live — the system we are migrating to
Stripe, Inc. Payment processing, billing portal, invoicing and refunds. Stripe is the processor; Weeksolved is the seller of record. Customer billing contact name and email, billing address, card details and transaction records. Card numbers are held by Stripe and never received by Weeksolved. No Customer Personal Information about your personnel. United States Not live — begins when paid plans start
Google LLC — Firebase / Cloud Firestore and Firebase Authentication Database, storage and authentication during the transition to Supabase, including Sign in with Google All Customer Personal Information synced to the account; authorized user email address and hashed password; where Sign in with Google is used, the name, email address and profile-picture link Google provides United States Live during the transition — removed from this list when the migration completes
GitHub, Inc. — GitHub Pages Static hosting of the website and application file Authorized users' IP addresses and standard web request logs. No Customer Personal Information: the application executes in the browser and does not transmit Customer Data to the host. United States Live

5.2a Changes made in version 1.1. Supabase, Stripe and GitHub Pages were added to this list, and Paddle.com Market Ltd was removed before it ever processed anything — no payment has been taken through it, and the seller of record for a Weeksolved subscription is Weeksolved, not a reseller. Google Firebase remains listed for the duration of the migration. Publication of this version, and of the matching notice in section 12 of the Privacy Policy, is the notice required by section 5.3, and the objection right in section 5.4 applies to it.

The current list is maintained at https://weeksolved.com/privacy.html.

5.3 New subprocessors. We will give you at least 30 days' written notice before a new subprocessor begins processing Customer Personal Information. You may subscribe to notifications at https://weeksolved.com/privacy.html.

5.4 Your right to object. You may object in writing within 30 days of notice, on reasonable data-protection grounds. We will work with you in good faith to find an alternative. If we cannot within 30 days, you may terminate the Agreement without penalty and receive a pro-rata refund of prepaid unused fees.

5.5 Flow-down and responsibility. Every subprocessor is engaged under a written contract imposing obligations at least as protective as this DPA, including the CCPA service-provider terms in section 4. We remain fully responsible to you for each subprocessor's performance as if we performed it ourselves. (Cal. Civ. Code § 1798.140(ag)(2).)


6. Security

6.1 Measures. We maintain the technical and organizational measures in Annex A, which are appropriate to the risk. We will not materially reduce them during the term.

6.2 Personnel. Access is limited to those who need it, protected by multi-factor authentication, and reviewed on role change and removed on departure.

6.3 Your responsibilities. You are responsible for your own account security: strong unique passwords, not sharing accounts, and promptly removing access for people who leave your organization.


7. Security Incidents

7.1 Notification. We will notify you of a Security Incident affecting your Customer Personal Information without undue delay and no later than seventy-two (72) hours after we become aware of it.

7.2 Contents. Our notice will describe, to the extent known: the nature of the incident; the categories and approximate number of individuals and records affected; the likely consequences; the measures taken or proposed; and a contact point. If we cannot provide all of it at once, we will provide it in phases without undue delay rather than delaying the initial notice.

7.3 Cooperation. We will cooperate reasonably with your investigation and give you the information you reasonably need to meet your notification obligations under Cal. Civ. Code §§ 1798.29 and 1798.82 and any other applicable law.

7.4 Who notifies affected individuals. You are responsible for notifying your personnel and any regulator, because they are your personnel and the notification duty is yours as the Business. We will not contact your personnel about an incident without your written agreement, unless the law requires us to.

7.5 Notification is not an admission. Notifying you is not an acknowledgment of fault or liability.

7.6 Contact. We will notify the security contact you designate in the signature block, and the account owner email. Keep that contact current.


8. Audit and assurance

8.1 Information. On written request, no more than once every twelve (12) months, we will provide the information reasonably necessary to demonstrate our compliance with this DPA — a completed security questionnaire, our Annex A measures, our subprocessor list, and our data flow description. We aim to respond within 30 days.

8.2 Audit. If that information is not sufficient, and where Data Protection Law gives you an audit right, you may audit our compliance:

(a) on at least 30 days' written notice; (b) no more than once every 12 months, unless a Security Incident affecting your data has occurred or a regulator requires it; (c) during business hours, without unreasonable disruption; (d) subject to confidentiality obligations; (e) not extending to our other customers' data, our personnel records, or information subject to legal privilege; and (f) at your expense, unless the audit reveals our material non-compliance, in which case we bear the reasonable cost.

8.3 Our infrastructure providers. We do not control our providers' data centers — Google's, Supabase's, Stripe's or GitHub's — and cannot grant physical access to them. For infrastructure controls we will provide those providers' published third-party audit reports and certifications to the extent each makes them available for onward disclosure.

8.4 Honest disclosure of our current posture. As of the version date of this DPA, we hold no SOC 2 report, no ISO 27001 certification, and no third-party penetration test. We are a small company and we would rather state this plainly than have a procurement review discover it. If your procurement requires such an attestation as a condition of purchase, tell us before you sign so we can discuss what is realistic and on what timeline.


9. Assisting you

We will provide reasonable assistance, taking into account the nature of the processing and the information available to us, with:

9.1 Consumer rights requests. If one of your personnel exercises a right to know, access, correct, delete, or port their information, you handle the request. We will help you locate, export, correct, or delete the relevant data through the Service's features or, where those are not sufficient, by reasonable manual assistance. If your personnel contacts us directly, we will not act on the request. We will refer them to you and notify you within 5 business days.

9.2 Risk assessments and pre-use notices. We will provide information about the Service's logic, inputs, and outputs to help you complete a risk assessment or ADMT pre-use notice as described in section 2.4.

9.3 Regulator inquiries. We will provide reasonable cooperation with a regulator's inquiry relating to our processing of your Customer Personal Information.

Assistance under this section is provided at no additional charge unless the request is manifestly unfounded, excessive, or requires substantial engineering work, in which case we will agree a reasonable fee with you in advance and in writing.


10. Return and deletion

10.1 Self-service, at any time. You can export Customer Data from within the Service at any time during the term. We recommend you do so regularly and before termination.

10.2 On termination. For 30 days after the Agreement terminates, Customer Data remains available for you to export. On your written request during that window, we will provide it in a structured, commonly used, machine-readable format.

10.3 Deletion. After the 30-day window, or earlier on your written instruction, we will delete Customer Personal Information from live systems. Copies in routine backups are overwritten within 14 days and are not restored to live systems in the interim.

10.4 Certification of deletion. We will confirm deletion in writing on request.

10.5 Exceptions. We may retain Customer Personal Information where the law requires it, or for the establishment or defense of legal claims, and only for as long and to the extent necessary. Retained information stays subject to this DPA.

10.6 Data in your browser. The Service stores a copy of Customer Data in your authorized users' browsers (localStorage) so the application works offline. That copy is on your devices and under your control. We cannot reach it or delete it for you. To remove it, clear the browser's site data for weeksolved.com, or use the Service's in-app clear function. Include this step in your own offboarding process.


11. International transfers

11.1 We process and store Customer Personal Information in the United States, and only there. Google Firebase / Cloud Firestore and Firebase Authentication, which hold it during the migration, are hosted in the United States. Supabase, which holds it after the migration, is in the us-west-1 region, in the United States. Stripe processes payment information in the United States. GitHub Pages serves the application from the United States. The migration does not move Customer Personal Information out of the United States at any point.

11.2 We do not currently transfer Customer Personal Information outside the United States. Standard Contractual Clauses, the EU–US Data Privacy Framework, the UK International Data Transfer Addendum, and similar transfer mechanisms are therefore not applicable to this DPA as of its version date.

11.3 If we later process Customer Personal Information outside the United States, or engage a subprocessor that does, we will notify you under section 5.3, and the parties will put an appropriate transfer mechanism in place before the transfer begins. If we cannot agree one, you may terminate under section 5.4.

11.4 If you are established outside the United States, or if you are subject to the GDPR or UK GDPR in a way that requires additional terms, contact us at privacy@weeksolved.com before signing.


12. General

12.1 Term. This DPA takes effect on the date you accept it and continues while we process Customer Personal Information, then survives as to sections 4, 7, 10, and 12.

12.2 Liability. Each party's liability under this DPA is subject to the limitation of liability in the Agreement, including the savings clause at section 12(d) of the Agreement, which applies here in the same terms and with the same carve-outs and no others. Nothing in this DPA or the Agreement limits either party's liability for its own fraud, its own willful injury to the person or property of another, its own willful violation of law, or its own gross negligence. Liability for ordinary negligence is subject to the exclusions and the cap in section 12 of the Agreement. This section 12.2 does not create a separate or higher liability limit than the Agreement, and it does not remove one.

12.3 Changes in law. If Data Protection Law changes so that this DPA no longer satisfies it, the parties will negotiate an amendment in good faith. We may update this DPA to reflect a legal change or a new legally required term on 30 days' notice; if an update materially reduces your protections, you may terminate the Agreement without penalty within that period.

12.4 Order of precedence. This DPA controls over the Agreement on data protection matters. A signed order form controls over this DPA where it expressly says so.

12.5 Assignment. This DPA is assigned together with the Agreement, on the same terms as the Agreement's assignment clause, including assignment to a successor entity on conversion of the business from a sole proprietorship to a limited liability company. Your protections under this DPA transfer with it and are not reduced by the assignment. The successor is bound by every commitment in this DPA.

12.6 Governing law. As stated in the Agreement, except where Data Protection Law requires otherwise.

12.7 Severability. If a provision is unenforceable, it is modified to the minimum extent needed, or severed, and the rest continues.

12.8 Counterparts and signature. This DPA may be signed in counterparts, including electronically, each of which is an original.


Annex A — Technical and organizational measures

Accurate as of September 12, 2026. We will not materially reduce these during the term.

A.1 Architecture

Weeksolved is a single-page browser application. The application code is delivered as static assets from GitHub Pages and runs entirely in the authorized user's browser. We operate no application server that holds Customer Personal Information in transit. Data flows from the user's browser directly to the database — Google Cloud Firestore during the migration, Supabase (Postgres, us-west-1) after it. The host of the static files never receives Customer Personal Information.

A.2 Encryption

Where Measure
In transit HTTPS/TLS between the browser and the database, for all Firestore traffic today and all Supabase traffic after the migration
At rest Platform encryption of stored data — Google Cloud's for Cloud Firestore, Supabase's for Postgres
Passwords Held hashed by the authentication service — Google Firebase Authentication today, Supabase Auth after the migration. Weeksolved personnel never see, receive, or store a user's password and cannot recover one.
Card details Never held by Weeksolved at any point. Card data is entered on Stripe's systems and stays there; Weeksolved receives only the last four digits, brand, expiry and the result of a charge
Browser copy Stored in the browser's localStorage on the Customer's own device, under the Customer's control

We do not offer end-to-end encryption or customer-managed encryption keys. See A.6.

A.3 Access control — tenant isolation

Per-account rules mean each account can read only its own data: Firestore security rules today, Postgres row-level security on Supabase after the migration. In both cases the rules are enforced by the database platform, not by application code alone, so a defect in the browser application does not by itself expose one customer's data to another.

A.4 Access control — authentication

A.5 Operational security

A.6 Operator access — stated plainly

Weeksolved personnel can technically access Customer Personal Information stored in the database, through the provider's console — the Google Firebase console today, the Supabase dashboard after the migration. This is true of the operator of any hosted service. Changing providers does not change it. We state it rather than implying technical impossibility.

Our commitment is a limit on when we exercise that access. We access Customer Personal Information only:

(a) when the Customer requests support that requires it; (b) to investigate or resolve a bug, outage, or data-integrity problem; (c) to investigate or respond to a Security Incident; or (d) where legally compelled, subject to section 4.9.

We do not access Customer Personal Information for product research, marketing, sales, analytics, model training, or curiosity.

A.7 Measures we do NOT currently have

Stated so your review is accurate:

If any of these is a hard requirement for you, raise it before signing.


Signature

Customer

Legal entity name: ____ Signature: ____ Name: ____ Title: ____ Date: ____

Security notification contact (section 7.6) — keep current: Name: ____ Email: ____ Phone: ____

Privacy contact: Name: ____ Email: ____

Weeksolved, a California sole proprietorship

Signature: ____ Name: ____ Title: ____ Date: ____