Workly Invoice Maker
Home
Industries ▾
HM Handyman Quote small jobs, invoice them, and get paid the same day. H HVAC Estimate, schedule, and invoice HVAC jobs from one app. P Plumbing All-in-one plumbing software for busy service pros. E Electrical Keep electrical estimates, schedules, and invoices connected. R Roofing Manage roofing estimates, project notes, schedules, and invoices. L Landscaping Quote landscape jobs, schedule crews, and invoice clients. LC Lawn Care Manage lawn care routes, estimates, schedules, and invoices. PS Pool Service Track pool service visits, estimates, schedules, and invoices. PC Pest Control Manage pest control estimates, routes, notes, and invoices. PA Painting Quote painting projects, schedule crews, and invoice clients.
Free tools Blog
Get the app
Home Free tools Blog

Industries

Handyman HVAC Plumbing Electrical Roofing Landscaping Lawn Care Pool Service Pest Control Painting Get the app

Legal

Data Processing Agreement

Last updated: August 13, 2026

This Data Processing Agreement ("DPA") forms part of the Workly Terms of Service (the "Agreement") between Workly LLC, a Wyoming limited liability company with its address at 1021 E Lincolnway, Suite #9696, Cheyenne, Wyoming 82001, United States ("Workly"), and the customer that accepts the Agreement ("Customer").

This DPA applies where, and to the extent that, Workly processes Customer Personal Data (defined below) on Customer's behalf in the course of providing the Service, and that processing is subject to Data Protection Laws. This DPA is deemed accepted and executed by Customer (including for the purposes of the Standard Contractual Clauses incorporated below) upon Customer's acceptance of the Agreement or use of the Service. A countersigned copy is available on request at [email protected].

1. Definitions

  • "Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under the Agreement, including, as applicable: the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); the EU GDPR as it forms part of the law of the United Kingdom ("UK GDPR") and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); U.S. state privacy laws, including the California Consumer Privacy Act as amended ("CCPA"); Canada's PIPEDA; the Australian Privacy Act 1988 (Cth); and the New Zealand Privacy Act 2020.
  • "Customer Personal Data" means personal data contained in Client Data (as described in the Agreement and the Privacy Policy) — that is, personal data relating to Customer's own clients, prospects, and contacts that Customer submits to the Service and that Workly processes on Customer's behalf. Customer Personal Data does not include Account Data (information about Customer and Customer's own use of the Service), which Workly processes as an independent controller as described in the Privacy Policy.
  • "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022).
  • "Sub-processor" means a third party engaged by Workly to process Customer Personal Data on Customer's behalf.
  • The terms "controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings given in the EU GDPR, and their equivalents under other Data Protection Laws (for example, "business," "service provider," "sell," and "share" under the CCPA) apply as the context requires.

2. Roles and Scope

2.1 As between the parties, Customer is the controller of Customer Personal Data and Workly is the processor. If Customer is itself a processor acting for another controller, Customer warrants that its instructions to Workly are consistent with that controller's instructions, Customer remains Workly's sole point of contact, and Workly acts as Customer's sub-processor.

2.2 The subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects are described in Annex 1.

2.3 This DPA does not apply to Account Data or to any data for which Workly is an independent controller.

3. Processing on Instructions

3.1 Workly will process Customer Personal Data only on Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by law to which Workly is subject; in that case, Workly will inform Customer of the legal requirement before processing, unless the law prohibits it on important grounds of public interest.

3.2 Customer's instructions consist of: (a) this DPA and the Agreement; and (b) Customer's use and configuration of the Service (for example, creating, editing, sharing, and deleting records and documents). In addition, Customer instructs and authorizes Workly to: (i) transmit documents, links, and communications to the recipients Customer designates; (ii) facilitate payment collection through Stripe when Customer uses payment features; and (iii) create aggregated or de-identified data that does not identify, and cannot reasonably be used to identify, Customer or any data subject. Once de-identified, such data is no longer Customer Personal Data, and Workly will not attempt to re-identify it.

3.3 Workly will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Workly is not obligated to monitor Customer's compliance or provide legal advice.

4. Customer Responsibilities

Customer is responsible for the lawfulness of the Customer Personal Data it submits and of its instructions, including: having a lawful basis for the processing; providing any required privacy notices to data subjects; ensuring the data is accurate and relevant; and responding to data subjects' requests. Customer agrees not to submit to the Service special categories of personal data (Article 9 GDPR), data relating to criminal convictions and offences, or personal data of children, and not to submit any data it does not have the right to provide.

5. Confidentiality

Workly ensures that persons it authorizes to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality.

6. Security

Workly implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects. Workly may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.

7. Sub-processors

7.1 Customer provides a general authorization for Workly to engage Sub-processors. The current Sub-processors of Customer Personal Data are listed in Annex 3.

7.2 Workly will provide at least 15 days' prior notice of the addition or replacement of a Sub-processor (by email, notice in the Service, or by updating this page at getworkly.io/dpa). Customer may object within the notice period on reasonable, documented data-protection grounds. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected features or the Agreement and, for prepaid web subscriptions, receive a pro-rata refund of fees for the unused period. This is Customer's sole remedy for such an objection.

7.3 Workly will impose on each Sub-processor data protection obligations materially no less protective than those in this DPA, and Workly remains liable to Customer for the Sub-processor's performance of those obligations.

8. Data Subject Requests

Taking into account the nature of the processing, Workly will assist Customer, by appropriate technical and organizational measures — primarily the Service's built-in features for viewing, correcting, exporting, and deleting records — in fulfilling Customer's obligation to respond to data subjects' requests to exercise their rights. If a data subject contacts Workly directly about Customer Personal Data, Workly will, to the extent legally permitted, refer the request to Customer and/or notify Customer, and will not respond substantively except on Customer's instruction or where legally required.

9. Personal Data Breach

Workly will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to Workly to assist Customer in meeting its obligations (including under Articles 33 and 34 of the GDPR), and will take reasonable steps to contain and mitigate the breach. Workly's notification of a breach is not an acknowledgement of fault or liability.

10. DPIAs and Prior Consultation

Workly will provide reasonable assistance to Customer with data protection impact assessments and consultations with supervisory authorities that Customer is required to carry out, insofar as they relate to the Service and Workly has relevant information available.

11. Deletion and Return

During the term, Customer can export and delete Customer Personal Data using the Service's features. Upon termination of the Agreement or deletion of Customer's account, Workly will delete Customer Personal Data within the retention window described in the Privacy Policy (currently up to 90 days for production systems, with encrypted backups purged on a rolling basis thereafter), unless retention is required by applicable law. On Customer's written request, Workly will confirm deletion in writing.

12. Demonstrating Compliance; Audits

Workly will make available to Customer information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR, including this DPA, descriptions of its technical and organizational measures, and, where available, third-party certifications and audit reports covering its infrastructure providers. Where Data Protection Laws grant Customer an audit right that cannot be satisfied by the information above, Workly will allow for and contribute to an audit conducted by Customer or an independent auditor mandated by Customer, subject to the following: no more than once in any 12-month period (except following a personal data breach affecting Customer, or where required by a supervisory authority); at least 30 days' prior written notice; during normal business hours; without access to other customers' data; subject to reasonable confidentiality obligations; and at Customer's expense.

13. International Transfers

13.1 Customer Personal Data is processed primarily in the United States, and in the locations of the Sub-processors listed in Annex 3.

13.2 EEA transfers. To the extent Customer Personal Data protected by the EU GDPR is transferred to Workly in a country not covered by an adequacy decision, the parties incorporate the EU SCCs, Module Two (controller to processor), into this DPA by reference, with Customer as data exporter and Workly as data importer, completed as follows: Clause 7 (docking clause) is not included; under Clause 9(a), Option 2 (general written authorisation) applies with a 15-day notice period; the optional language in Clause 11(a) is not included; under Clause 17, Option 1 applies and the clauses are governed by the law of Ireland; under Clause 18(b), disputes are resolved before the courts of Ireland; the competent supervisory authority under Clause 13 is determined in accordance with that clause; and Annexes I, II, and III of the EU SCCs are completed with the information in Annexes 1, 2, and 3 of this DPA respectively.

13.3 UK transfers. To the extent Customer Personal Data protected by the UK GDPR is transferred to Workly in a country not covered by UK adequacy regulations, the UK Addendum is incorporated into this DPA and amends the EU SCCs as described therein: Table 1 is completed with the party details in Annex 1; Table 2 refers to the EU SCCs as incorporated in Section 13.2; Table 3 is completed with Annexes 1–3 of this DPA; and for Table 4, either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

13.4 Swiss transfers. To the extent Customer Personal Data protected by the FADP is transferred, the EU SCCs as incorporated above apply with these adaptations: references to the EU GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to "Member State" include Switzerland; and data subjects in Switzerland may enforce their rights in Switzerland.

13.5 In the event of any conflict, the EU SCCs (and the UK Addendum, as applicable) prevail over this DPA and the Agreement.

13.6 Onward transfers to Sub-processors are made under appropriate safeguards, including standard contractual clauses between Workly and the Sub-processor and/or the Sub-processor's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.

14. U.S. State Privacy Laws

Where the CCPA or another U.S. state privacy law applies to Customer Personal Data, Workly acts as a "service provider" or "processor." Workly will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than performing the Service under the Agreement or as otherwise permitted for service providers; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal data received from other sources, except as permitted for service providers. Workly certifies that it understands and will comply with these restrictions, will notify Customer if it determines it can no longer meet them, and grants Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.

15. Liability

To the maximum extent permitted by law, each party's liability arising out of or related to this DPA (including the EU SCCs) is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this Section limits a data subject's rights under the EU SCCs or any liability that cannot be limited under Data Protection Laws.

16. General

This DPA takes effect when Customer accepts the Agreement (or first submits Customer Personal Data to the Service, if earlier) and remains in force for as long as Workly processes Customer Personal Data. For the subject matter of data protection, the order of precedence is: the EU SCCs and UK Addendum; then this DPA; then the Agreement. Workly may update this DPA from time to time to reflect changes in law, the Service, or Sub-processors, with notice of material changes as described in the Agreement; updates will not materially reduce the level of protection for Customer Personal Data. Except as required by the EU SCCs or mandatory law, this DPA is governed by the same law and subject to the same dispute-resolution terms as the Agreement. If any provision of this DPA is held invalid, the remainder remains in effect.


Annex 1 — Description of the Processing (Annex I to the EU SCCs)

A. List of parties

  • Data exporter (controller): the Customer — the person or entity that accepted the Agreement; name and contact details are those associated with the Customer's Workly account. Activities: use of the Service to manage its clients, documents, scheduling, and payments. Signature and date: deemed given by acceptance of the Agreement.
  • Data importer (processor): Workly LLC, 1021 E Lincolnway, Suite #9696, Cheyenne, Wyoming 82001, United States; [email protected]. Activities: provision of the Service. Signature and date: deemed given by publication of this DPA and provision of the Service.

B. Categories of data subjects: the Customer's clients and prospective clients, and their personnel and contact persons.

C. Categories of personal data: identification and contact data (name, business name, email address, phone number, postal or service address); appointment and job details (dates, times, locations, notes); commercial and transactional data contained in invoices, estimates, and payment records (line items, amounts, taxes, payment status); and any other personal data the Customer chooses to include in documents, notes, or attachments.

D. Sensitive data: none intended; the Customer has agreed not to submit special categories of personal data or data relating to criminal convictions and offences.

E. Frequency of the transfer: continuous, as initiated by the Customer through use of the Service.

F. Nature and purpose of the processing: hosting, storage, and backup; synchronization across the Customer's devices and the web application; generation and rendering of documents; transmission of documents and communications to recipients designated by the Customer; facilitation of payment collection through Stripe; customer support and troubleshooting at the Customer's request; and securing the Service.

G. Duration: the term of the Agreement plus the deletion window described in Section 11.

H. Transfers to (sub-)processors: as described in Annex 3, for the same purposes and duration.

Competent supervisory authority: determined in accordance with Clause 13 of the EU SCCs.

Annex 2 — Technical and Organizational Measures

  • Encryption of data in transit (TLS); encryption at rest provided by the underlying cloud infrastructure.
  • Hosting on Google Cloud / Firebase infrastructure operating under recognized certifications (including ISO 27001 and SOC 1/2/3), with physical security managed by the infrastructure provider.
  • Access controls based on least privilege; authentication of users including provider-managed identity (Sign in with Apple / Google); logical separation of customer data by account.
  • Payment data handled by Stripe (PCI DSS Level 1 certified); Workly does not store full payment card numbers.
  • Backup and recovery procedures, with encrypted backups purged on a rolling basis.
  • Vulnerability management, including timely updates of dependencies and platform components; logging and monitoring of production systems.
  • Confidentiality obligations for personnel and contractors; internal access to customer content limited to what is necessary for support, operations, security, and legal compliance.
  • Due diligence on Sub-processors and contractual data protection terms with them.
  • Incident response procedures, including customer notification as described in Section 9.

Annex 3 — Sub-processors of Customer Personal Data

Sub-processor Service provided Location
Google LLC (Firebase / Google Cloud Platform) Cloud hosting, database, storage, authentication, backups United States
Stripe, Inc. Payment processing, where the Customer uses payment features United States

Note: providers listed in the Privacy Policy that process only Workly's own Account Data (for example, analytics, attribution, and subscription-management providers) do not process Customer Personal Data and are not Sub-processors under this DPA.


Workly LLC
1021 E Lincolnway, Suite #9696, Cheyenne, Wyoming 82001, United States
[email protected] · https://getworkly.io

Workly AI invoice maker for busy pros

Mobile-first estimating, scheduling, and invoicing for service businesses.

Product

Free templates Blog App Store

Industries

HandymanHVACPlumbingElectricalRoofingLandscapingLawn CarePool ServicePest ControlPainting

Support

Support Contact

Legal

Terms of Use Privacy Policy Data Processing Agreement Billing and Refund Policies
© 2026 Workly, LLC. All rights reserved. Built for pros who want cleaner invoices and less admin drag.

Privacy settings

Cookies, analytics, and browser error reporting

We use necessary storage to keep public pages working. Until you accept, analytics and browser-side error reporting stay cookie-free: nothing optional is stored on your device and you are not identified across visits. Accept turns on cookie-based analytics; Reject keeps it off.

We use necessary storage to keep public pages working, plus cookie-based analytics and browser-side error reporting to see how the site performs. In your region these are on by default. Reject turns them off and clears the analytics cookies; Accept keeps them on.

You can review our Privacy Policy and change your choice at any time in Cookie settings.