LedgerDo LedgerDo
Sign in Create account

Data Processing Addendum

Last Updated: Sep 18, 2026

Download PDF

LedgerDo LLC, an Iowa limited liability company

Effective Date: September 18, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between LedgerDo LLC, an Iowa limited liability company (“LedgerDo” or “Processor”), and the business that holds a LedgerDo or MyDVI account (“Customer” or “Controller”).

This DPA applies whenever LedgerDo processes Personal Data on Customer’s behalf in the course of providing the LedgerDo web application, the LedgerDo mobile app, and MyDVI (together, the “Services”). Customer accepts this DPA when it creates an account. We record the date, IP address, and browser used to accept, together with the effective date of the DPA version accepted.

If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

  • Personal Data: any information relating to an identified or identifiable individual that LedgerDo processes on Customer’s behalf under the Agreement.
  • Processing: any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, transmission, or deletion.
  • Controller: the party that determines the purposes and means of processing Personal Data. Under this DPA, Customer is the Controller.
  • Processor: the party that processes Personal Data on behalf of the Controller. Under this DPA, LedgerDo is the Processor.
  • Subprocessor: a third party engaged by LedgerDo to process Personal Data in order to provide the Services.
  • Data Protection Laws: all laws that apply to the processing of Personal Data under the Agreement, which may include U.S. state privacy laws (including the Iowa Consumer Data Protection Act and the California Consumer Privacy Act) and, where applicable, the EU and UK General Data Protection Regulations.
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Roles of the Parties

Customer is the Controller of Personal Data about its own customers, employees, and vendors. LedgerDo is a Processor (and, where the California Consumer Privacy Act applies, a “service provider”) and processes that Personal Data solely on behalf of Customer and in accordance with Customer’s documented instructions.

For information LedgerDo collects about Customer’s account itself (the account holder’s contact details, billing records, acceptance records, and security logs), LedgerDo is the Controller and our Privacy Policy applies.

3. Subject Matter and Duration

Subject matter: provision of cloud-based business management software for automotive repair, construction, landscaping, and similar service businesses, including customer, vehicle, property, and job-site records, digital inspections, estimates, work orders, invoicing, payments, scheduling, messaging, reporting, and related features.

Duration: for as long as Customer uses the Services and until LedgerDo has deleted or returned all Personal Data in accordance with Section 12.

4. Nature and Purpose of Processing

LedgerDo processes Personal Data only as needed to:

  • Store and display customer, vehicle, property, job-site, and service-history records
  • Create and manage inspections, estimates, work orders, and invoices, including photos, technician notes, and customer signatures
  • Send, receive, and log messages between Customer and its customers (SMS/MMS, email, and portal messages) and maintain consent and opt-out records
  • Process payments and record payment metadata through the payment provider Customer chooses
  • Sync appointments, payments, and accounting records with third-party services that Customer chooses to connect
  • Look up parts, labor times, VIN details, and safety recalls that Customer requests
  • Generate AI suggestions where Customer has enabled AI features using its own provider account
  • Synchronize customer, vehicle, and work order records between LedgerDo and MyDVI where Customer links the two accounts
  • Operate, secure, back up, support, and improve the Services

5. Types of Personal Data

Depending on how Customer uses the Services, Personal Data may include:

  • Names, email addresses, phone numbers, and mailing addresses
  • Vehicle information, including VIN, year, make, model, mileage, and license plate
  • Property and job-site addresses, project and equipment details, and seasonal or recurring service contracts
  • Service history, estimates, work orders, invoices, and payment metadata
  • Inspection results, photos, technician notes, and approval decisions
  • Signatures captured on completed work
  • Message content, delivery metadata, and SMS consent and opt-out records
  • Appointment and calendar data, where Customer connects a calendar
  • Employee and staff user accounts, roles, time clock entries, and job assignments
  • IP address and browser details recorded when an individual approves an estimate, work order, or inspection through a link sent by Customer

The Services are not designed to process sensitive Personal Data such as health information, government identification numbers, biometric identifiers, or payment card numbers. Customer agrees not to enter such data except where a feature is expressly designed for it. Card numbers are collected directly by the payment provider and never stored by LedgerDo; biometric unlock in the mobile app is verified on the device and never sent to LedgerDo.

6. Categories of Data Subjects

  • Customer’s customers and their authorized contacts (vehicle owners and drivers, property owners, and site contacts)
  • Customer’s employees, contractors, and other authorized users
  • Vendors and suppliers associated with Customer’s business

7. LedgerDo’s Obligations

LedgerDo will:

  1. Process Personal Data only on Customer’s documented instructions. The Agreement, this DPA, and Customer’s use of the Services’ features and settings are Customer’s instructions. LedgerDo will inform Customer if it believes an instruction violates Data Protection Laws.
  2. Not sell Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it for any purpose other than providing the Services, or combine it with Personal Data received from other customers except as permitted by Data Protection Laws. LedgerDo certifies that it understands these restrictions.
  3. Ensure that personnel with access to Personal Data are bound by confidentiality obligations and receive access only as needed to provide, support, and secure the Services.
  4. Implement the technical and organizational security measures described in Section 8.
  5. Assist Customer, by appropriate technical and organizational measures and taking into account the nature of the processing, in responding to data subject requests (Section 10) and in meeting its security, breach notification, and data protection assessment obligations.
  6. Delete or return Personal Data at the end of the Services as described in Section 12.
  7. Make available the information reasonably necessary to demonstrate compliance with this DPA, as described in Section 13.

8. Security Measures

LedgerDo maintains reasonable and appropriate safeguards designed to protect Personal Data, including:

  • HTTPS/TLS encryption for all traffic, including the mobile app
  • Encrypted storage of integration credentials, API keys, and OAuth tokens
  • Role-based access controls and logical isolation of each Customer’s data
  • Unguessable token-based links for documents shared with Customer’s customers, which Customer can rotate or revoke at any time
  • Firewall protections, rate limiting, and security and audit logging
  • Regular software updates and patching
  • Encrypted, off-host backups with scheduled restore testing

Our Security page describes these measures in more detail and how to report a vulnerability. LedgerDo may update its security measures over time, provided the updates do not materially reduce the overall protection of Personal Data. Customer acknowledges that no system can guarantee absolute security.

9. Subprocessors

Customer gives LedgerDo general authorization to engage Subprocessors to provide the Services. The current list of Subprocessors, their purpose, and their location is published at ledgerdo.com/legal/subprocessors. Some Subprocessors receive Personal Data only if Customer chooses to connect that service (for example, Google Calendar, Square, QuickBooks, or an AI provider); those integrations are governed by Customer’s own account with the provider.

LedgerDo will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, to the extent applicable to the services the Subprocessor provides, and remains responsible for each Subprocessor’s performance.

Changes. LedgerDo will update the Subprocessors page and its “last updated” date at least 15 days before a new Subprocessor begins processing Personal Data, except where a replacement is needed urgently for security or continuity, in which case LedgerDo will update the page as soon as practicable. Customer may object in writing to [email protected] on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro-rated refund of any prepaid fees for the remainder of the term.

10. Data Subject Requests

Customer is responsible for responding to requests from individuals to access, correct, delete, or port their Personal Data, or to restrict or object to its processing. The Services allow Customer to view, correct, export, and delete customer and vehicle records directly.

If LedgerDo receives such a request directly from an individual about Personal Data it processes for Customer, LedgerDo will promptly forward the request to Customer, will not respond to the individual except to confirm that the request has been forwarded or where required by law, and will provide reasonable assistance to Customer in responding.

11. Personal Data Breach Notification

LedgerDo will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer’s Personal Data. Notification will be sent to the account owner’s email address on file.

To the extent known at the time, and supplemented as information becomes available, the notification will describe:

  • The nature of the breach, including the categories and approximate number of individuals and records affected
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its effects
  • A contact point for further information

LedgerDo’s notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.

12. Deletion and Return of Personal Data

Customer may export its records at any time from the account settings area as a machine-readable (JSON) file that includes every record in the account and a manifest of its stored files. Photos, signatures, and attachments can be downloaded from each record while the account is open; Customer may request a bulk copy of stored files from [email protected] before closing its account, and LedgerDo will provide it within 30 days.

When Customer closes its account, LedgerDo will delete or anonymize Personal Data within 90 days. LedgerDo may also delete or anonymize an inactive account’s data under the Agreement after warning the account owner. In each case the following are excepted:

  • Messaging consent and opt-out records (phone number, status, source, keyword, and timestamps only) are kept for at least 4 years after the last message to demonstrate consent under carrier and regulatory requirements
  • LedgerDo’s own billing records for Customer’s subscription are kept for 7 years to meet tax and accounting obligations
  • Personal Data in encrypted backups ages out on the rolling schedule described in the Privacy Policy and is restored only for disaster recovery
  • Personal Data that LedgerDo is required by law to retain

Retained data remains subject to this DPA for as long as LedgerDo holds it.

13. Audit and Compliance Information

On written request no more than once per year (or following a Personal Data Breach affecting Customer’s data), LedgerDo will provide Customer with the information reasonably necessary to demonstrate compliance with this DPA, which may include written responses to a reasonable security questionnaire, summaries of its security measures, and the results of any third-party assessments LedgerDo has obtained. Where Data Protection Laws require an on-site audit, the parties will agree in advance on its scope, timing, duration, and confidentiality, and Customer will bear its own costs.

14. International Data Transfers

LedgerDo stores and processes Personal Data on infrastructure located in the United States. Our hosting provider is headquartered in the European Union and may perform support operations from there. Customer instructs LedgerDo to process Personal Data in the United States.

Where Personal Data subject to the EU or UK GDPR is transferred to LedgerDo, the parties will enter into the European Commission’s Standard Contractual Clauses (Module Two, controller to processor) or the UK International Data Transfer Addendum on request to [email protected], and this DPA will serve as the description of the transfer.

15. Customer’s Obligations

Customer is responsible for: having a lawful basis for the Personal Data it enters into the Services; providing its own customers with any privacy notice required by Data Protection Laws, including notice that LedgerDo processes their data on Customer’s behalf; obtaining and recording consent before sending text messages; and configuring user roles, integrations, and retention settings appropriately for its business.

16. Liability, Governing Law, and Changes

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the law and dispute resolution provisions of the Agreement.

LedgerDo may update this DPA to reflect changes in the Services or in Data Protection Laws. The effective date at the top of this page shows when it last changed. Material changes will be announced to account holders by email or in-product notice at least 30 days before they take effect, and continued use of the Services after that date constitutes acceptance.

17. Contact

LedgerDo LLC
6701 CORPORATE DR
STE N
JOHNSTON, IA, 50131, USA
Email: [email protected]

© 2026 LedgerDo — All rights reserved Terms Privacy Security SMS Consent Data Deletion Contact