Data Processing Terms
The short version
- The homeowner, applicant and staff records you keep in RadonCRM are yours. You decide what goes in and why; we hold and process them only to run the Service for you.
- We never sell them, use them for our own purposes, or pool them with another company’s data.
- If something goes wrong we tell you without delay, and in any case within 72 hours of confirming it.
- When you leave, you can have a copy, and then it is deleted.
Contents
Scope and roles
These Data Processing Terms form part of the Terms of Service between RadonCRM (“we”) and the Customer (“you”). They apply to personal information within Customer Data that we process on your behalf (“Customer Personal Information”).
You are the organisation responsible for Customer Personal Information under PIPEDA and Alberta’s Personal Information Protection Act. We act as your service provider: we process it on your behalf, under your control, and for no purpose of our own. If these terms conflict with the Terms of Service on the handling of Customer Personal Information, these terms prevail.
What is processed
Whose information: your customers and property owners; people who book through your booking page, or through software using your Partner API keys; job applicants who apply through your careers page; your staff and technicians; and anyone else you choose to record.
What information: names, email addresses, phone numbers and property addresses; appointment and job details; radon readings and test results; quotes, including the signer’s name, signature image, time of signing and IP address; invoices and payment status; applicants’ details, resumes and notes; and anything you put in notes or attachments.
The Service is not designed for health records, government identification numbers or payment card numbers. Do not put them in notes or attachments.
Processing only on your instructions
We process Customer Personal Information only to provide, secure and support the Service, as you direct through your use and configuration of it, and as you otherwise instruct us in writing. Specifically, we will not:
- sell it, rent it, or use it for advertising or marketing;
- combine it with another customer’s data, or use it to train or improve models or services for anyone else;
- disclose it to anyone except the providers listed below or where the law requires (see Requests from individuals and authorities).
The Radon Risk Map in your account, and on your website if you embed it, uses only your own readings together with public datasets, summarised by area and never shown by address. Your readings are never shown to another company.
If we believe an instruction from you breaks the law, we will tell you and need not follow it.
Your responsibilities
- Give the individuals concerned whatever notice the law requires, and obtain any consent it requires, for collecting their information and for having us process it for you. That includes a privacy notice on the website where you embed our booking or careers pages.
- Send email through the Service only in compliance with Canada’s Anti-Spam Legislation and other applicable law.
- Keep the information accurate, and decide how long you keep it. Customers, jobs and other records can be deleted or archived in the app.
- Control which of your staff have logins, and remove access for people who leave.
Who at RadonCRM can see it
Our platform console shows operators account-level information — your users, the number of records in your account, recent activity and billing status. Operators look at the contents of Customer Personal Information only when you ask us to for support, when it is necessary to investigate abuse or a security incident, or when the law requires it. Everyone with that access is bound by confidentiality obligations, and administrative actions in the console are recorded in an audit log.
Security
We maintain technical and organisational safeguards appropriate to the sensitivity of the information, including:
- TLS encryption for all traffic to and from the Service;
- company scoping on every request, so one customer cannot read or change another’s records;
- salted scrypt hashing for passwords, hashed single-use tokens for password resets and email verification, and revocable, individually issued API keys;
- rate limits on sign-in, sign-up, password reset, the careers form and the Partner API;
- daily backups, with the most recent 14 retained;
- access to production systems restricted to named operators.
Service providers (sub-processors)
You authorise us to use the providers listed under Who we share it with in our Privacy Policy to process Customer Personal Information. We hold each of them to obligations that protect the information at least as well as these terms, and we remain responsible for them.
Before adding or replacing a provider that will process Customer Personal Information, we will update that list and email account contacts at least 30 days in advance. If you object on reasonable privacy grounds and we cannot address the concern, you may cancel and we will refund any fees prepaid for the period after the change.
Providers you connect yourself — your own SMTP or SendGrid account, Calendly, or the website you embed our pages on — are engaged by you, not by us.
Where it is stored
Customer Personal Information may be stored and processed outside Alberta and outside Canada, including in the United States, by us and the providers above. Where you have to tell individuals about this, you can rely on this section.
Security incidents
If we become aware of unauthorised access to, or loss or disclosure of, Customer Personal Information, we will notify your account contact without undue delay, and in any case within 72 hours of confirming it. We will tell you what we know: what happened, the information and individuals likely to be affected, and what we are doing about it. We will then cooperate with you so you can assess whether the incident creates a real risk of significant harm and meet any obligation to report it to the Privacy Commissioner or to notify individuals.
Requests from individuals and authorities
- If an individual asks us for access to, or correction of, information you hold about them, we will refer them to you, and help you answer where you cannot do it yourself in the app.
- If an authority asks us for Customer Personal Information, we will refer it to you and tell you about the request, unless the law forbids that. We disclose only what we are legally compelled to disclose.
Return and deletion
When your account closes, we keep Customer Personal Information for 30 days so you can request an export or reopen the account. We then delete it from the live system; it leaves our rolling backups within the following 14 days. If the law requires us to keep part of it longer, we keep only that part, only for that purpose, and continue to protect it under these terms.
Information and audits
On reasonable request, we will give you the information you need to show that we meet these terms, including written answers to a security questionnaire once a year. If the Privacy Commissioner or another regulator requires more, we will cooperate with it.
Contact
Questions about these terms, and notices under them, go to RadonCRM, Calgary, Alberta, Canada, steven@radoncrm.com.