Cortex by JobDox
← Back to Home Start Free Trial

Data Processing Addendum

Effective September 3, 2026

This Data Processing Addendum (“Addendum”) forms part of the Cortex Terms of Service & Subscription Agreement (the “Agreement”) between Job-Dox, LLC, a Texas limited liability company (“Company”), and the subscriber identified on the applicable order documentation (“Subscriber”). It governs Company’s processing of Personal Data contained within Subscriber Data.

1. Definitions

Capitalized terms not defined here have the meanings given in the Agreement.

TermDefinition
Applicable Privacy LawsAll laws and regulations governing the processing of Personal Data applicable to a party, including the Texas Data Privacy and Security Act, the California Consumer Privacy Act as amended, and comparable state statutes in effect where Subscriber or its customers are located.
ControllerThe party that determines the purposes and means of processing Personal Data. Subscriber is the Controller.
ProcessorThe party that processes Personal Data on behalf of the Controller. Company is the Processor. Where the California Consumer Privacy Act applies, Company acts as a “service provider.”
Personal DataInformation within Subscriber Data that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person.
Data SubjectThe natural person to whom Personal Data relates, including property owners, occupants, tenants, adjusters, and Subscriber personnel.
ProcessingAny operation performed on Personal Data, including collection, storage, use, transmission, disclosure, alteration, and deletion.
Sub-processorAny third party engaged by Company to process Personal Data on Company’s behalf.
Security IncidentA confirmed breach of security leading to unauthorized access to, acquisition of, or disclosure of Personal Data in Company’s possession or control.

2. Roles of the Parties

Subscriber is the Controller of Personal Data submitted to the Platform. Company is the Processor and processes such Personal Data solely on Subscriber’s documented instructions.

Subscriber’s documented instructions consist of the Agreement, this Addendum, Subscriber’s configuration of the Platform, and any written instruction subsequently agreed by the parties. Company will notify Subscriber if, in Company’s reasonable opinion, an instruction violates Applicable Privacy Laws.

Company does not sell, share, rent, or otherwise disclose Personal Data for cross-context behavioral advertising or for any commercial purpose other than performing the Agreement.

3. Scope and Purpose of Processing

Company processes Personal Data only as necessary to provide, maintain, secure, and support the Platform, and to comply with law. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in the Annex to this Addendum.

Company shall not retain, use, or disclose Personal Data outside the direct business relationship between the parties, or for any purpose other than the specific purposes set out in the Annex.

3.1 Aggregated and De-identified Data

The Agreement permits Company to use aggregated, de-identified usage data. Company shall implement measures to prevent re-identification, shall not attempt to re-identify such data, and shall contractually obligate any recipient to the same. De-identified data processed in accordance with this Section is not Personal Data for purposes of this Addendum.

4. Subscriber Obligations

Subscriber represents, warrants, and covenants that:

  • It has provided all notices and obtained all consents, permissions, or other lawful bases required under Applicable Privacy Laws to submit Personal Data to the Platform and to have Company process it as contemplated by the Agreement;
  • Its instructions to Company comply with Applicable Privacy Laws;
  • It is solely responsible for the accuracy, quality, and legality of Personal Data it submits and the means by which it acquired that data; and
  • It will not submit Personal Data of a category identified in Section 4.2 without first notifying Company in writing and agreeing any additional terms Company reasonably requires.

4.1 Property Photography and Interior Imagery

Subscriber acknowledges that photographs and video captured at loss sites and uploaded to the Platform routinely depict the interiors of private residences and may incidentally capture Personal Data beyond the scope of the claim, including images of occupants and minors, correspondence, prescription medications, financial documents, and personal effects.

Subscriber is solely responsible for obtaining any authorization required to capture, store, and transmit such imagery, and for limiting capture to what is reasonably necessary to document the loss. Company processes such imagery as instructed and does not review it for the presence of incidental Personal Data.

4.2 Excluded Data Categories

The Platform is not designed or offered as a compliant environment for the following, and Subscriber shall not submit them without Company’s prior written agreement:

  • Protected health information subject to HIPAA, except incidental imagery captured in the ordinary documentation of a residential loss;
  • Cardholder data subject to PCI DSS, including full payment card numbers;
  • Government-issued identification numbers, including Social Security numbers, except where required for a documented claim purpose;
  • Biometric identifiers; and
  • Personal Data of individuals located in the European Economic Area, the United Kingdom, or Switzerland.

Submission of excluded data in breach of this Section is at Subscriber’s sole risk, and Subscriber shall indemnify Company for claims arising from it in accordance with the indemnification provisions of the Agreement.

5. Security

Company maintains administrative, technical, and organizational safeguards appropriate to the nature, scope, and sensitivity of the Personal Data processed. Those safeguards include:

  • Encryption of Personal Data in transit, and encryption at rest provided by Company’s infrastructure providers for both database and object storage;
  • Logical isolation of each subscriber’s data, enforced at the database layer by rules that scope every read and write to the requesting user’s own company;
  • Role-based access control with unique user credentials and access granted on the principle of least privilege;
  • Application-level encryption of stored payment field data using a key held outside the database;
  • Logical separation of production from non-production environments, which operate as separate infrastructure projects;
  • Logging of access to and activity within the Platform, recording actor identity, permission level, action, target, source IP address, and timestamp, retained for four hundred (400) days; and
  • Written confidentiality obligations binding all personnel with access to Personal Data, with access limited to those who require it to perform their duties.

Company selects and may change the specific technologies, vendors, and configurations by which these safeguards are achieved, provided the overall level of protection is not materially reduced.

A current description of Company’s security measures is available at our Security Overview.

6. Sub-processors

Subscriber provides general written authorization for Company to engage Sub-processors to process Personal Data in connection with the Platform. A current list of Sub-processors is maintained on our Sub-processors page and is incorporated into this Addendum by reference.

6.1 Changes

Company may add, remove, or replace Sub-processors in the ordinary course of operating the Platform. Company shall update the Sub-processor list before a new Sub-processor begins processing Personal Data, and shall provide a mechanism by which Subscriber may subscribe to notification of changes to that list.

6.2 Objection

Subscriber may notify Company in writing of a good-faith objection to a Sub-processor on reasonable data protection grounds. Company shall consider the objection in good faith and shall use commercially reasonable efforts to make available an alternative arrangement, a configuration change, or a description of compensating controls that addresses the concern. Company is not obligated to discontinue use of a Sub-processor.

6.3 Flow-Down and Liability

Company shall impose on each Sub-processor data protection obligations no less protective than those in this Addendum, and remains fully liable to Subscriber for the performance of each Sub-processor.

6.4 Artificial Intelligence Processing

Automated analysis of Subscriber Data using artificial intelligence and machine learning is an integral part of the Platform. Personal Data within Subscriber Data may be transmitted to one or more model providers for processing. Each such provider is a Sub-processor subject to this Section 6 and is identified on our Sub-processors page.

Output generated by such processing constitutes Subscriber Data and is subject to this Addendum.

Model providers are engaged under commercial terms that govern the retention of submitted data and whether it may be used for model training. The terms applicable to each provider currently in use are described on our Sub-processors page. Company will update that page before a change in model provider takes effect.

7. Data Subject Rights

Applicable Privacy Laws grant Data Subjects rights including access, correction, deletion, and portability. As Controller, Subscriber is responsible for responding to Data Subject requests.

Company shall, taking into account the nature of the processing, provide reasonable assistance to enable Subscriber to respond, including through the correction and deletion functionality available within the Platform. Where a request cannot be fulfilled through Platform functionality, Company shall provide reasonable assistance within ten (10) business days of Subscriber’s written request.

If Company receives a request directly from a Data Subject relating to Subscriber Data, Company shall not respond substantively and shall promptly forward the request to Subscriber, except where required by law to respond.

8. Security Incident Notification

Company shall notify Subscriber without undue delay, and in any event within seventy-two (72) hours of confirming a Security Incident affecting Personal Data. Notification shall be delivered to the contact recorded on Subscriber’s account.

The notification shall include, to the extent known at the time and supplemented as further information becomes available:

  • The nature and approximate timing of the incident;
  • The categories and approximate volume of Personal Data affected;
  • The Data Subjects or Subscriber accounts affected;
  • The likely consequences of the incident;
  • Measures taken or proposed to address the incident and mitigate harm; and
  • A contact point for further information.

Company shall cooperate reasonably with Subscriber in investigating and remediating the incident and in fulfilling Subscriber’s own notification obligations under Applicable Privacy Laws. Subscriber, as Controller, is responsible for determining whether notification to Data Subjects, regulators, or a state attorney general is required and for making any such notification.

Company’s notification is not an acknowledgment of fault or liability.

9. Audits and Assessments

Company shall make available to Subscriber, upon written request no more than once per twelve (12) month period, information reasonably necessary to demonstrate compliance with this Addendum. Company may satisfy this obligation by providing a current security overview, third-party audit report, security questionnaire response, or written summary of its controls. Company is not obligated to disclose information that would compromise the security of the Platform or the confidentiality of other subscribers.

Where Applicable Privacy Laws entitle Subscriber to a more extensive assessment and Company’s standard documentation is insufficient, the parties shall agree in advance on scope, timing, and cost. Any on-site assessment shall be conducted during business hours, subject to reasonable confidentiality and security requirements, and at Subscriber’s expense.

10. Location and Transfer of Data

Company processes and stores Personal Data on Company-controlled infrastructure located within the United States. Company shall not relocate Personal Data on Company-controlled infrastructure outside the United States without providing Subscriber prior written notice and implementing a lawful transfer mechanism.

Certain Sub-processors are incorporated outside the United States. The corporate domicile of each Sub-processor is stated on our Sub-processors page, and Company will confirm a Sub-processor’s processing location on written request.

11. Return and Deletion

Export, retention, and deletion of Subscriber Data upon expiration or termination are governed by the Terms of Service. In summary: a complete export is delivered at no charge on or before the effective date of cancellation; data is retained for sixty (60) days thereafter; and it is then permanently deleted from production systems, with backup copies expiring in the ordinary course. Where the Agreement is terminated by Company for cause, the retention period is thirty (30) days and the export is delivered upon written request.

Company may retain Personal Data beyond that period only to the extent required by law, in which case Company shall continue to protect it in accordance with this Addendum and shall process it only for the purpose requiring retention.

12. General

12.1 Precedence

In the event of conflict between this Addendum and any other provision of the Agreement with respect to the processing of Personal Data, this Addendum controls.

12.2 Liability

Each party’s liability arising out of or in connection with this Addendum is subject to the limitations and exclusions set forth in the Agreement.

12.3 Term

This Addendum takes effect on the date Subscriber activates a paid subscription and continues until Company has deleted all Personal Data in accordance with Section 11.

12.4 Governing Law

This Addendum is governed by the laws of the State of Texas, with exclusive venue in Denton County, Texas, in accordance with the Agreement.

13. Incorporation

This Addendum is incorporated into the Cortex Terms of Service & Subscription Agreement and applies to all subscribers. No separate signature is required. Subscribers requiring a countersigned copy may request one at info@job-dox.com.

Annex — Details of Processing

ItemDetail
Subject matterProvision of the Cortex project management and field service platform for restoration and field service operations.
DurationThe subscription term, plus the retention period set forth in Section 11.
Nature and purposeStorage, organization, retrieval, transmission, and display of job, claim, and property data to enable Subscriber to manage restoration projects; provision of support; security monitoring; and automated analysis under Section 6.4.
Categories of Data SubjectsProperty owners and occupants; tenants; Subscriber personnel and authorized users; insurance adjusters and carrier representatives; subcontractors and vendors; third parties incidentally depicted in loss-site imagery.
Categories of Personal DataName; residential and mailing address; telephone number; email address; insurance carrier, policy number, and claim number; adjuster identity and contact details; loss description and cause; scope and estimate detail; job notes and correspondence; photographic and video imagery of loss sites including residential interiors; signatures on authorizations and completion certificates; user credentials and activity logs.
Sensitive dataNot intentionally collected. May be incidentally captured within loss-site imagery as described in Section 4.1.
FrequencyContinuous, for the duration of the subscription term.

Contact

Questions about this Addendum: info@job-dox.com

© 2026 Job-Dox LLC. All rights reserved.

Privacy PolicyTerms & ConditionsSub-processorsCookie Notice