Data Processing Agreement
Last updated: July 2026
Roles
The dealership ("Customer") is the Controller of consumer personal data submitted to RooftopOS through any module. RooftopOS ("Processor") processes the data solely on documented instructions from the Customer to deliver the Service.
Categories of data processed
- Consumer identifiers (name, address, email, phone)
- Vehicle data (VIN, condition, photos, ownership documents)
- Transaction data (offer amount, addendum line items, signatures, timestamps)
- Communication data (SMS / email content sent through the platform under the dealership's brand)
- Service data (MPI photos and videos, customer e-approvals — AutoFilm only)
Marketing newsletter data
Newsletter subscribers (the "operator brief" signup in our footer) are stored separately from customer and consumer records, under their own access boundary. Newsletter emails are never sold, never shared with sub-processors beyond our email sender (Resend), and can be deleted independently of any commercial relationship.
Sub-processors
The list below is generated from the sub-processor register maintained in RooftopOS’s codebase, which is kept against the vendors actually in the production request path rather than written by hand. The full table, including data categories and processing regions, is published on the Security page. RooftopOS gives 30 days’ notice before adding a sub-processor.
- Cloudflare — Hosting, content delivery, TLS termination, DoS protection
- Supabase (Postgres) — Primary database and authentication
- Sentry — Error monitoring, performance tracing, session replay
- Resend — Transactional and confirmation email
- Slack — Internal notification of a lead, signup or review
- Cal.com — Demo and briefing scheduling
Named in earlier versions of this agreement but not currently provable in RooftopOS's production code path, and therefore not represented as active: Cloudflare R2, Twilio, OpenAI. These are being confirmed or removed.
Security measures
RooftopOS’s current security posture — including what is implemented, what is not, and what has not been independently verified — is published in full on the Security page, including its certification position. One point belongs here because it is commonly assumed: RooftopOS operates no customer-facing audit-logging control — there is no log the Customer can read, query or export for itself — and this agreement therefore makes no commitment to produce, retain, or export an audit trail. The versioned disclosure and consent records the applications write against a deal are Customer data under the categories above, not a control this agreement grants.
Data subject rights
RooftopOS will assist the Customer in responding to consumer requests for access, deletion, correction, or portability under applicable laws (CCPA, state privacy acts). Requests are made by contacting RooftopOS and are carried out by the RooftopOS team. There is no self-service export or deletion control in the Customer-facing product today, and none is represented in this agreement. The timeframes that apply to a request are set in the executed agreement and by applicable law.
Breach notification
RooftopOS will notify the Customer of any confirmed personal-data breach within 72 hours, including known scope, mitigations taken, and recommended Customer next steps.
Cross-border transfers
Persistent storage of Customer and consumer data is in United States regions. The delivery network is global: a connection terminates at the edge location nearest the visitor and is proxied to US origin and storage, so describing the whole system as US-only would be false. International transfer of stored data is not made without prior Customer consent.
Term & deletion
On termination, RooftopOS returns or deletes Customer data on the schedule written into the executed agreement. No return window, retention period, or deletion turnaround is published here, because none has been set for publication. Where the Customer is required to preserve records under federal or state record-keeping rules, the categories and periods are identified in that agreement.
Contact & signature
Email Contact support to receive a signed countersigned copy of this DPA on RooftopOS letterhead for your dealership's compliance file.