Effective September 3, 2026
This Data Processing Addendum (“Addendum”) forms part of the Cortex Terms of Service & Subscription Agreement (the “Agreement”) between Job-Dox, LLC, a Texas limited liability company (“Company”), and the subscriber identified on the applicable order documentation (“Subscriber”). It governs Company’s processing of Personal Data contained within Subscriber Data.
Capitalized terms not defined here have the meanings given in the Agreement.
| Term | Definition |
|---|---|
| Applicable Privacy Laws | All laws and regulations governing the processing of Personal Data applicable to a party, including the Texas Data Privacy and Security Act, the California Consumer Privacy Act as amended, and comparable state statutes in effect where Subscriber or its customers are located. |
| Controller | The party that determines the purposes and means of processing Personal Data. Subscriber is the Controller. |
| Processor | The party that processes Personal Data on behalf of the Controller. Company is the Processor. Where the California Consumer Privacy Act applies, Company acts as a “service provider.” |
| Personal Data | Information within Subscriber Data that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person. |
| Data Subject | The natural person to whom Personal Data relates, including property owners, occupants, tenants, adjusters, and Subscriber personnel. |
| Processing | Any operation performed on Personal Data, including collection, storage, use, transmission, disclosure, alteration, and deletion. |
| Sub-processor | Any third party engaged by Company to process Personal Data on Company’s behalf. |
| Security Incident | A confirmed breach of security leading to unauthorized access to, acquisition of, or disclosure of Personal Data in Company’s possession or control. |
Subscriber is the Controller of Personal Data submitted to the Platform. Company is the Processor and processes such Personal Data solely on Subscriber’s documented instructions.
Subscriber’s documented instructions consist of the Agreement, this Addendum, Subscriber’s configuration of the Platform, and any written instruction subsequently agreed by the parties. Company will notify Subscriber if, in Company’s reasonable opinion, an instruction violates Applicable Privacy Laws.
Company does not sell, share, rent, or otherwise disclose Personal Data for cross-context behavioral advertising or for any commercial purpose other than performing the Agreement.
Company processes Personal Data only as necessary to provide, maintain, secure, and support the Platform, and to comply with law. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in the Annex to this Addendum.
Company shall not retain, use, or disclose Personal Data outside the direct business relationship between the parties, or for any purpose other than the specific purposes set out in the Annex.
The Agreement permits Company to use aggregated, de-identified usage data. Company shall implement measures to prevent re-identification, shall not attempt to re-identify such data, and shall contractually obligate any recipient to the same. De-identified data processed in accordance with this Section is not Personal Data for purposes of this Addendum.
Subscriber represents, warrants, and covenants that:
Subscriber acknowledges that photographs and video captured at loss sites and uploaded to the Platform routinely depict the interiors of private residences and may incidentally capture Personal Data beyond the scope of the claim, including images of occupants and minors, correspondence, prescription medications, financial documents, and personal effects.
Subscriber is solely responsible for obtaining any authorization required to capture, store, and transmit such imagery, and for limiting capture to what is reasonably necessary to document the loss. Company processes such imagery as instructed and does not review it for the presence of incidental Personal Data.
The Platform is not designed or offered as a compliant environment for the following, and Subscriber shall not submit them without Company’s prior written agreement:
Submission of excluded data in breach of this Section is at Subscriber’s sole risk, and Subscriber shall indemnify Company for claims arising from it in accordance with the indemnification provisions of the Agreement.
Company maintains administrative, technical, and organizational safeguards appropriate to the nature, scope, and sensitivity of the Personal Data processed. Those safeguards include:
Company selects and may change the specific technologies, vendors, and configurations by which these safeguards are achieved, provided the overall level of protection is not materially reduced.
A current description of Company’s security measures is available at our Security Overview.
Subscriber provides general written authorization for Company to engage Sub-processors to process Personal Data in connection with the Platform. A current list of Sub-processors is maintained on our Sub-processors page and is incorporated into this Addendum by reference.
Company may add, remove, or replace Sub-processors in the ordinary course of operating the Platform. Company shall update the Sub-processor list before a new Sub-processor begins processing Personal Data, and shall provide a mechanism by which Subscriber may subscribe to notification of changes to that list.
Subscriber may notify Company in writing of a good-faith objection to a Sub-processor on reasonable data protection grounds. Company shall consider the objection in good faith and shall use commercially reasonable efforts to make available an alternative arrangement, a configuration change, or a description of compensating controls that addresses the concern. Company is not obligated to discontinue use of a Sub-processor.
Company shall impose on each Sub-processor data protection obligations no less protective than those in this Addendum, and remains fully liable to Subscriber for the performance of each Sub-processor.
Automated analysis of Subscriber Data using artificial intelligence and machine learning is an integral part of the Platform. Personal Data within Subscriber Data may be transmitted to one or more model providers for processing. Each such provider is a Sub-processor subject to this Section 6 and is identified on our Sub-processors page.
Output generated by such processing constitutes Subscriber Data and is subject to this Addendum.
Model providers are engaged under commercial terms that govern the retention of submitted data and whether it may be used for model training. The terms applicable to each provider currently in use are described on our Sub-processors page. Company will update that page before a change in model provider takes effect.
Applicable Privacy Laws grant Data Subjects rights including access, correction, deletion, and portability. As Controller, Subscriber is responsible for responding to Data Subject requests.
Company shall, taking into account the nature of the processing, provide reasonable assistance to enable Subscriber to respond, including through the correction and deletion functionality available within the Platform. Where a request cannot be fulfilled through Platform functionality, Company shall provide reasonable assistance within ten (10) business days of Subscriber’s written request.
If Company receives a request directly from a Data Subject relating to Subscriber Data, Company shall not respond substantively and shall promptly forward the request to Subscriber, except where required by law to respond.
Company shall notify Subscriber without undue delay, and in any event within seventy-two (72) hours of confirming a Security Incident affecting Personal Data. Notification shall be delivered to the contact recorded on Subscriber’s account.
The notification shall include, to the extent known at the time and supplemented as further information becomes available:
Company shall cooperate reasonably with Subscriber in investigating and remediating the incident and in fulfilling Subscriber’s own notification obligations under Applicable Privacy Laws. Subscriber, as Controller, is responsible for determining whether notification to Data Subjects, regulators, or a state attorney general is required and for making any such notification.
Company’s notification is not an acknowledgment of fault or liability.
Company shall make available to Subscriber, upon written request no more than once per twelve (12) month period, information reasonably necessary to demonstrate compliance with this Addendum. Company may satisfy this obligation by providing a current security overview, third-party audit report, security questionnaire response, or written summary of its controls. Company is not obligated to disclose information that would compromise the security of the Platform or the confidentiality of other subscribers.
Where Applicable Privacy Laws entitle Subscriber to a more extensive assessment and Company’s standard documentation is insufficient, the parties shall agree in advance on scope, timing, and cost. Any on-site assessment shall be conducted during business hours, subject to reasonable confidentiality and security requirements, and at Subscriber’s expense.
Company processes and stores Personal Data on Company-controlled infrastructure located within the United States. Company shall not relocate Personal Data on Company-controlled infrastructure outside the United States without providing Subscriber prior written notice and implementing a lawful transfer mechanism.
Certain Sub-processors are incorporated outside the United States. The corporate domicile of each Sub-processor is stated on our Sub-processors page, and Company will confirm a Sub-processor’s processing location on written request.
Export, retention, and deletion of Subscriber Data upon expiration or termination are governed by the Terms of Service. In summary: a complete export is delivered at no charge on or before the effective date of cancellation; data is retained for sixty (60) days thereafter; and it is then permanently deleted from production systems, with backup copies expiring in the ordinary course. Where the Agreement is terminated by Company for cause, the retention period is thirty (30) days and the export is delivered upon written request.
Company may retain Personal Data beyond that period only to the extent required by law, in which case Company shall continue to protect it in accordance with this Addendum and shall process it only for the purpose requiring retention.
In the event of conflict between this Addendum and any other provision of the Agreement with respect to the processing of Personal Data, this Addendum controls.
Each party’s liability arising out of or in connection with this Addendum is subject to the limitations and exclusions set forth in the Agreement.
This Addendum takes effect on the date Subscriber activates a paid subscription and continues until Company has deleted all Personal Data in accordance with Section 11.
This Addendum is governed by the laws of the State of Texas, with exclusive venue in Denton County, Texas, in accordance with the Agreement.
This Addendum is incorporated into the Cortex Terms of Service & Subscription Agreement and applies to all subscribers. No separate signature is required. Subscribers requiring a countersigned copy may request one at info@job-dox.com.
| Item | Detail |
|---|---|
| Subject matter | Provision of the Cortex project management and field service platform for restoration and field service operations. |
| Duration | The subscription term, plus the retention period set forth in Section 11. |
| Nature and purpose | Storage, organization, retrieval, transmission, and display of job, claim, and property data to enable Subscriber to manage restoration projects; provision of support; security monitoring; and automated analysis under Section 6.4. |
| Categories of Data Subjects | Property owners and occupants; tenants; Subscriber personnel and authorized users; insurance adjusters and carrier representatives; subcontractors and vendors; third parties incidentally depicted in loss-site imagery. |
| Categories of Personal Data | Name; residential and mailing address; telephone number; email address; insurance carrier, policy number, and claim number; adjuster identity and contact details; loss description and cause; scope and estimate detail; job notes and correspondence; photographic and video imagery of loss sites including residential interiors; signatures on authorizations and completion certificates; user credentials and activity logs. |
| Sensitive data | Not intentionally collected. May be incidentally captured within loss-site imagery as described in Section 4.1. |
| Frequency | Continuous, for the duration of the subscription term. |
Questions about this Addendum: info@job-dox.com