Legal
Data Processing Addendum
Last updated: October 8, 2026
This addendum applies automatically to business customers and explains how Porchlight handles your clients', pets' and staff members' information on your behalf.
Scope and roles
This Data Processing Addendum ("DPA") is part of the Terms of Service between Hive Asset Group, LLC ("Porchlight") and the business customer ("Customer"). It applies to personal information that Customer or its clients and staff put into Porchlight ("Customer Personal Data"), such as client contact details, addresses, home access information, pet and vaccination records, staff information and GPS location.
For Customer Personal Data, Customer is the business (controller) and Porchlight is Customer's service provider (processor). Porchlight is the business for Customer's own account and billing information, as set out in the Privacy Policy. This DPA starts when Customer first uses Porchlight and lasts as long as Porchlight holds Customer Personal Data.
Processing on instructions
Porchlight will process Customer Personal Data only to provide Porchlight to Customer under the Terms, following Customer's documented instructions. Customer's use of the product's features, settings, API and exports are its instructions. Porchlight will tell Customer if it believes an instruction breaks the law.
- Subject matter and duration: providing Porchlight, for as long as Customer has an account plus the deletion period below.
- Nature and purpose: hosting, storage, scheduling, messaging, invoicing, payments support, support and security.
- Data subjects: Customer's clients (pet parents), their emergency contacts, Customer's staff and contractors.
- Types of data: contact details, addresses, home access information, pet information including medical and vaccination records, visit records, photos and videos, GPS location of staff, messages and payment history.
Porchlight will not sell or share Customer Personal Data, will not keep, use or disclose it outside the direct business relationship with Customer or for any purpose other than the services, and will not combine it with personal information from other sources, except as the law allows. Porchlight may use de-identified or aggregated data that does not identify Customer or any person to operate and improve the service.
Confidentiality and security
Porchlight will make sure that people who access Customer Personal Data are bound to confidentiality, and will keep reasonable technical and organizational security measures, described on the Security page. Porchlight may update those measures if the update does not reduce overall protection.
Subprocessors
Customer authorizes Porchlight to use the subprocessors on the Subprocessors page. Porchlight will give Customer notice of a new subprocessor (by updating that page and emailing the account owner) at least 15 days before the new subprocessor processes Customer Personal Data. Customer may object on reasonable data protection grounds within that time. If the parties cannot resolve it, Customer may cancel the affected service. Porchlight will have a written agreement with each subprocessor with data protection terms no less protective than this DPA, and remains responsible for its subprocessors' performance.
Assistance with requests and obligations
Customer can access, correct, delete and export Customer Personal Data using the product. Where Customer cannot, Porchlight will give reasonable help in responding to requests from individuals exercising privacy rights, and in meeting Customer's obligations on security, breach notice and privacy assessments, taking into account the nature of the processing. If Porchlight gets a request directly from someone about Customer Personal Data, it will point them to Customer and will not respond itself, unless the law requires.
Security incidents
Porchlight will notify Customer without undue delay after it becomes aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data. The notice will describe what Porchlight knows about the incident and the steps it is taking. Porchlight will give reasonable help so Customer can meet its own notice obligations.
Return and deletion
Customer can export its data at any time. After the subscription ends, Porchlight keeps the account read-only for a 30-day export window and then deletes or de-identifies Customer Personal Data within 30 days, unless the law requires it to keep some. Backups are removed as they expire. Customer can ask for earlier deletion by writing to hello@porchlight.pet.
Information and audits
On written request, Porchlight will give Customer information reasonably needed to show that it follows this DPA. If that does not satisfy a legal requirement, Customer may have an audit by an independent party under a confidentiality agreement, on reasonable notice, once a year, during business hours, without disrupting operations, at Customer's cost.
Customer responsibilities
Customer is responsible for the lawfulness of Customer Personal Data and its instructions, including giving the notices and getting the consents required for its clients and staff (for example, for text messages and GPS location). Customer must not put information into Porchlight that it has no right to use.
Order of precedence, liability and contact
If this DPA conflicts with the Terms on the handling of Customer Personal Data, this DPA controls. The limits of liability in the Terms apply to this DPA. This DPA is governed by the same law as the Terms.
Questions or a signed copy: hello@porchlight.pet.