Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Fixty Inc. ("Fixty," "Processor," "we," or "us") and the mechanic subscribing to the Fixty platform ("Controller," "you," or "your"). It governs the processing of personal data that you entrust to Fixty through your use of the platform.
When you use Fixty to manage your customers, vehicles, jobs, quotes, invoices, and communications, you act as the data controller for the personal data of your customers. Fixty acts as the data processor, processing that data on your behalf and in accordance with your instructions as described in this DPA.
This DPA is designed to ensure compliance with applicable data protection laws, including the California Consumer Privacy Act (CCPA) and, where applicable, the General Data Protection Regulation (GDPR).
Definitions
The following terms have the meanings set out below when used in this DPA.
Controller
The natural or legal person (the mechanic) who determines the purposes and means of the processing of personal data. In the context of Fixty, the Controller is the mechanic who subscribes to the platform and enters customer data.
Processor
The natural or legal person that processes personal data on behalf of the Controller. Fixty Inc. acts as the Processor when handling customer data entered by mechanics into the platform.
Personal Data
Any information relating to an identified or identifiable natural person. In the context of Fixty, this includes customer names, phone numbers, email addresses, physical addresses, vehicle identification numbers (VINs), license plate numbers, and any other information entered into the platform that can be used to identify an individual.
Processing
Any operation or set of operations performed on personal data, whether or not by automated means. This includes collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction.
Sub-processor
A third-party service provider engaged by Fixty to assist in processing personal data on behalf of the Controller. Sub-processors are subject to contractual obligations consistent with this DPA.
Data Subject
The identified or identifiable natural person to whom personal data relates. In the context of Fixty, Data Subjects are primarily the customers of mechanics who use the platform.
Scope of Processing
Fixty processes the following categories of personal data on behalf of the Controller: customer records (names, phone numbers, email addresses, and physical addresses), vehicle data (VINs, license plate numbers, mileage, make, model, and year), job records (service descriptions, labor hours, parts used, and job status), job and inspection photos, quotes and invoices (itemized pricing, payment status, and approval records), appointment data (scheduling information and location details), and communications (text messages and calls sent and received through the platform via Twilio, and emails sent through the platform).
This data is processed solely for the purposes of storing, organizing, and managing CRM data on behalf of the mechanic. Specific processing activities include maintaining customer and vehicle databases, storing job and inspection photos, generating and delivering estimates, inspections and invoices, scheduling and managing appointments, sending text messages and emails to customers, routing calls to the mechanic's Fixty number, processing card payments and payment references through Stripe, sending notifications to the mechanic's devices, and running the Fixty Assistant, AI quote drafts and the voice assistant when the mechanic uses them.
Fixty does not process personal data for any purpose other than those specified by the Controller or as required by applicable law.
Obligations of the Processor
As the Processor, Fixty commits to the following obligations.
Processing on Controller Instructions
Fixty will process personal data only on documented instructions from the Controller, including with respect to transfers of personal data to a third country, unless required to do so by applicable law. If Fixty is required by law to process personal data beyond the Controller's instructions, Fixty will inform the Controller of that legal requirement before processing, unless prohibited by law from doing so.
Confidentiality
Fixty ensures that all persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to personal data is restricted to personnel who require it to perform their duties.
Security Measures
Fixty implements and maintains appropriate technical and organizational security measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures are described in detail in the Security Measures section of this DPA.
Assistance with Data Subject Requests
Fixty will assist the Controller by implementing appropriate technical and organizational measures, insofar as this is possible, to fulfill the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection laws.
Breach Notification
Fixty will notify the Controller without undue delay after becoming aware of a personal data breach. The notification procedures are described in detail in the Data Breach Notification section of this DPA.
Deletion on Termination
If the Controller deletes its own account, Fixty erases all personal data immediately, and it cannot be recovered, so the Controller should request a copy first by emailing [email protected]. If Fixty terminates the account, the Controller may request a copy of its data by emailing [email protected] within 30 days of termination. After that 30-day period, Fixty will delete all personal data unless retention is required by applicable law.
Security Measures
Fixty implements the following technical and organizational security measures to protect personal data processed on the platform.
Authentication is handled through JSON Web Tokens (JWT) issued by Supabase Auth. Tokens are short-lived and validated on every API request. Fixty's servers limit the records each authenticated request can read or change to the signed-in mechanic's account.
Pages Fixty shows to a mechanic's customers, such as estimate approval, inspection and payment pages, open without a login from a link that identifies the one record they show.
The public keys built into Fixty's web and mobile apps are not granted access to any database table, and row-level security is enabled on every table, so those keys cannot be used to read or change database tables directly.
Job and inspection photos are stored in Supabase Storage at long, randomly generated web addresses. Anyone who has a photo's address can open it.
All data is encrypted at rest using AES-256 encryption provided by Supabase's underlying infrastructure. Data transmitted between users and the platform is encrypted in transit using TLS.
Access to production systems and personal data is limited to the Fixty personnel who operate and support the platform, and is removed when it is no longer needed.
Fixty monitors the platform for errors, investigates suspected security incidents, and notifies the Controller of personal data breaches as described in the Data Breach Notification section.
Sub-processors
The Controller authorizes Fixty to engage the following sub-processors for the processing of personal data.
Supabase Inc. (United States; database hosted in the AWS us-west-2 region, Oregon) provides database hosting, authentication and file storage. Supabase stores all personal data entered into the Fixty platform, including photos.
Railway Corporation (United States) hosts the Fixty API, the application server behind the Fixty mobile and web apps. Railway processes the personal data in the requests it serves and stores Fixty's server logs.
Vercel Inc. (United States) hosts the Fixty website and web application, including the pages Fixty shows to a mechanic's customers, and processes the personal data in the requests it serves, such as booking requests.
Cloudflare Inc. (United States) provides the content delivery and security network in front of the Fixty website. Every request to the website passes through Cloudflare's servers around the world, including the visitor's IP address and the address of the page requested.
Stripe Inc. (United States) provides payment processing. Stripe processes subscription billing, the card payments a mechanic's customers make through Stripe Connect, including the customer's email address, payment amounts and order details, and the card details entered on Stripe's payment forms.
Twilio Inc. (United States) provides text messaging and calling. Twilio processes customer phone numbers, the content of text messages sent and received through the platform, including photos customers send and links to estimates, inspections and payment pages, and calls placed to a mechanic's Fixty number. If a mechanic turns on the voice assistant, Twilio also processes the call audio, using Deepgram Inc. (United States) for speech recognition and Google LLC (United States) for text-to-speech.
Plus Five Five, Inc., doing business as Resend (United States), delivers email. Resend processes customer names, email addresses and the content of the estimates, invoices and other emails a mechanic sends through the platform.
Anthropic PBC (United States) provides the AI models behind the Fixty Assistant, AI quote drafts and the voice assistant. Anthropic processes the content of assistant conversations and the records the assistant reads to answer them, such as a customer's name and phone number, recent text messages, and the details of a job, appointment or estimate; the vehicle details and complaint in a quote draft request; and, when the voice assistant is on, the transcript of the call. Fixty's team also uses Anthropic's AI tools to operate and support the platform, and those tools can read platform data when a task requires it.
650 Industries, Inc., doing business as Expo (United States), delivers push notifications to the mechanic's devices through Apple Inc. (United States) and Google LLC (United States). A notification can include a customer's name and the beginning of their message or booking request.
Functional Software, Inc., doing business as Sentry (United States), provides error monitoring. When something fails, Sentry receives a technical report that can include the address of the page or request involved, record identifiers and the error message.
Upstash, Inc. (United States) stores short-lived counters that protect the platform from abuse. The counters are keyed by IP address and, on booking and sign-up forms, by the phone number or email address submitted.
Usercentrics A/S (Denmark) provides Cookiebot, the cookie consent tool on Fixty's web pages, including the pages Fixty shows to a mechanic's customers. Cookiebot records each visitor's consent choice with a shortened IP address.
Telegram Messenger Inc. (outside the United States) relays support conversations when a mechanic asks to talk to a person from the assistant. Telegram receives the mechanic's support messages, the recent assistant conversation, which can include the names and phone numbers of customers the mechanic asked about, and the account details needed to answer them, such as name, phone, email, plan and billing status. Telegram does not receive the mechanic's customer list or records beyond what appears in that conversation.
When a VIN is decoded in the Fixty apps, the user's browser or phone sends the VIN to the free vPIC service of the U.S. National Highway Traffic Safety Administration, which returns the vehicle's make, model and year. NHTSA is a government agency, not a sub-processor, and receives only the VIN and the IP address of the device making the request.
Fixty will provide the Controller with at least 30 days' advance written notice before engaging any new sub-processor. The notice will include the name of the sub-processor, the nature of the processing, and the location of processing. The Controller may object to the engagement of a new sub-processor by notifying Fixty in writing within the 30-day notice period.
Data Subject Rights
Fixty will assist the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection laws, including the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object to processing.
Upon receiving a Data Subject request that relates to data processed through the Fixty platform, the Controller should notify Fixty at [email protected]. Fixty will provide reasonable assistance to facilitate the Controller's response within 10 business days of receiving the request.
If Fixty receives a Data Subject request directly, Fixty will promptly redirect the request to the relevant Controller and will not respond to the Data Subject directly unless authorized by the Controller or required by law.
Data Breach Notification
In the event of a personal data breach, Fixty will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach.
The notification will include, to the extent available: a description of the nature of the breach, including the categories and approximate number of Data Subjects and personal data records concerned; the name and contact details of the point of contact at Fixty where more information can be obtained; a description of the likely consequences of the breach; and a description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects.
Fixty will cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach. Fixty will document all personal data breaches, including the facts surrounding the breach, its effects, and the remedial actions taken.
Data Transfers
Fixty's database and file storage are hosted in the United States, in the AWS us-west-2 region (Oregon). Some of the sub-processors listed above process personal data outside the United States: Cloudflare, whose network serves each visitor from a nearby data center; Usercentrics, in the European Union; Telegram, whose company and servers are located outside the United States; and Apple and Google, which deliver push notifications through their global networks.
Fixty will inform the Controller before engaging any new sub-processor that processes personal data outside the United States, as described in the Sub-processors section, and will put in place the transfer safeguards that applicable law requires, such as Standard Contractual Clauses approved by the European Commission.
Term and Termination
This DPA takes effect when the Controller creates a Fixty account and remains in effect for as long as the Controller maintains an active account on the platform.
Upon termination of the Controller's account, Fixty will cease processing personal data on behalf of the Controller. If the Controller deleted its own account, Fixty erases all personal data immediately. If Fixty terminated the account, the Controller may request a copy of its data by emailing [email protected] within 30 days of termination. After that 30-day period, Fixty will delete all personal data unless retention is required by applicable law.
The obligations of confidentiality, data protection, and breach notification set forth in this DPA will survive the termination of the Controller's account.
Audit Rights
The Controller may request an audit of Fixty's data processing activities and security measures to verify compliance with this DPA. Audit requests must be submitted in writing to [email protected] with at least 30 days' advance notice.
Audits may be conducted no more than once per calendar year, unless a data breach or a specific compliance concern necessitates an additional audit. Audits will be conducted during normal business hours and in a manner that minimizes disruption to Fixty's operations.
Fixty may satisfy audit requests by providing the Controller with relevant certifications, audit reports from independent third-party auditors, or other documentation that reasonably demonstrates compliance with the obligations set forth in this DPA.
Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of its obligations under applicable data protection laws to the extent such limitations are not permitted by law.
Contact
For any questions, requests, or concerns regarding this Data Processing Agreement, please contact us at [email protected].
Fixty Inc., a Delaware corporation. Mailing address: 8 The Green Ste B, Dover, DE 19901, United States.