← ProjectPacer

Data Processing Addendum

Effective July 23, 2026|Version 2026-07-23

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the ProjectPacer Terms & Conditions (the “Terms”) between ProjectPacer LLC (“ProjectPacer,” “we,” “us”) and the customer agreeing to the Terms (“Customer,” “you”). It applies to the extent ProjectPacer Processes Personal Information on Customer’s behalf in providing the Service. Capitalized terms not defined here have the meanings given in the Terms.

Order of precedence. In the event of a conflict between this DPA and any other provision of the Terms with respect to the Processing of Personal Information, this DPA controls. In all other respects the Terms remain in full force.

1. Definitions

For purposes of this DPA:

TermMeaning
Applicable Privacy LawsThe US state consumer privacy laws applicable to the processing of Personal Information under this DPA, including the California Consumer Privacy Act as amended by the CPRA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, and comparable laws of other US states, in each case as amended.
Business, Controller, Consumer, Sell, Share, Service Provider, ProcessorHave the meanings given to them under the Applicable Privacy Laws.
Customer Personal InformationPersonal Information contained within Customer Data that ProjectPacer Processes on Customer’s behalf in providing the Service.
Permitted PurposeThe purposes set out in Section 3 (Scope, Roles & Permitted Purpose).
Personal InformationInformation that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable individual, as defined under the Applicable Privacy Laws.
Process / ProcessingAny operation performed on Personal Information, including collection, use, storage, disclosure, transmission, retention, and deletion.
Security IncidentA breach of ProjectPacer’s security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Information.
SubprocessorA third party engaged by ProjectPacer to Process Customer Personal Information in connection with providing the Service.

2. Geographic Scope

The Service is offered to Customers located in the United States. This DPA addresses obligations arising under US state privacy laws. ProjectPacer does not currently offer the Service in the European Economic Area, the United Kingdom, or Switzerland. If ProjectPacer begins offering the Service in those regions, it will make available a supplemental addendum containing the terms those laws require, including lawful-basis and international-transfer provisions, before doing so.

3. Scope, Roles & Permitted Purpose

3.1 Roles of the parties

With respect to Customer Personal Information, Customer is the Business or Controller and ProjectPacer is the Service Provider or Processor. Customer determines the purposes and means of Processing; ProjectPacer Processes Customer Personal Information only on Customer’s documented instructions, which include the Terms, this DPA, the Documentation, and Customer’s configuration and use of the Service.

With respect to Personal Information about Customer’s own account, billing relationship, and use of the Service, ProjectPacer acts as a Business or Controller, as described in the Privacy Policy. This DPA does not apply to that Processing.

3.2 Subject matter and details of Processing

Subject matter: provision of the Service. Duration: the term of the Terms, plus the retention periods described in Section 9. Nature and purpose: the Permitted Purpose. Categories of individuals: Customer’s personnel and workspace members, and Customer’s clients, contacts, and other individuals whose information Customer submits or connects. Categories of Personal Information: as described in the Privacy Policy, including names, email addresses, work and time-entry data, calendar and activity data from sources Customer connects, and, where Customer enables the relevant features, mileage addresses and financial-account transaction data.

3.3 Permitted Purpose

ProjectPacer will Process Customer Personal Information only for the following purposes, each of which constitutes a business purpose under the Applicable Privacy Laws:

4. Service Provider Obligations & Restrictions

4.1 Certification

ProjectPacer certifies that it understands the restrictions in this Section 4 and will comply with them. ProjectPacer will not:

ProjectPacer will notify Customer if it determines that it can no longer meet its obligations under the Applicable Privacy Laws.

4.2 No model training

ProjectPacer will not use Customer Personal Information to train or improve any artificial intelligence or machine-learning model, and will not permit any Subprocessor or other provider that Processes Customer Personal Information on ProjectPacer’s behalf to use it to train or improve their models. Suggestions and other automated outputs are generated solely to serve Customer’s own account.

4.3 Confidentiality

ProjectPacer limits access to Customer Personal Information to personnel who need it to provide the Service, and ensures that such personnel are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

4.4 Customer instructions and compliance

Customer is responsible for the accuracy and legality of Customer Personal Information and for having provided any notices and obtained any consents required for its Processing through the Service, as set out in Section 7.6 of the Terms. Customer will not instruct ProjectPacer to Process Customer Personal Information in a manner that would violate the Applicable Privacy Laws. ProjectPacer may refuse or cease Processing that it reasonably believes would violate applicable law, and will inform Customer if it does so.

5. De-identified & Aggregated Information

ProjectPacer may create de-identified or aggregated information from Customer Personal Information for the purposes described in Section 3.3. Where it does so, ProjectPacer will: (a) take reasonable measures to ensure the information cannot be associated with an individual or household; (b) publicly commit to maintaining and using the information in de-identified form and not to attempt to re-identify it, except as permitted by law to test de-identification; and (c) contractually obligate any recipient to comply with the same restrictions. De-identified and aggregated information is not Customer Personal Information and is not subject to the restrictions in Section 4.1.

6. Subprocessors

6.1 Authorization

Customer generally authorizes ProjectPacer to engage Subprocessors to Process Customer Personal Information in providing the Service. ProjectPacer maintains a current list of Subprocessors at projectpacer.com/subprocessors.

6.2 Notice and objection

ProjectPacer keeps the Subprocessor list current and updates it to reflect changes.

For a new or replacement Subprocessor that materially changes the Processing — for example, one that introduces a new category of Customer Personal Information, a new processing location, or a materially different security posture — ProjectPacer will provide notice by updating the Subprocessor list and, where Customer has subscribed to notifications, by email, at least 30 days before that Subprocessor begins Processing Customer Personal Information. If Customer has a reasonable, good-faith objection on data-protection grounds, Customer may notify ProjectPacer within 30 days of the notice. The parties will discuss the objection in good faith. If ProjectPacer is unable to make a commercially reasonable alternative available, Customer may terminate the affected portion of the Service without penalty and receive a pro-rata refund of prepaid fees for the terminated portion.

For routine changes that do not materially affect the nature, scope, or security of the Processing — such as replacing a provider with an equivalent one that performs a similar function under obligations no less protective than this DPA, or a change of Subprocessor arising from an internal reorganization, merger, or acquisition — ProjectPacer will update the Subprocessor list to reflect the change, but the 30-day advance-notice and objection procedure above does not apply. In all cases, every Subprocessor remains subject to the flow-down and liability obligations in Section 6.3.

6.3 Flow-down and liability

ProjectPacer will impose on each Subprocessor data-protection obligations no less protective than those in this DPA, and remains responsible for each Subprocessor’s performance of those obligations to the same extent ProjectPacer would be responsible if performing the Processing itself.

7. Security & Security Incidents

7.1 Security measures

ProjectPacer maintains administrative, technical, and organizational safeguards designed to protect Customer Personal Information against unauthorized access, loss, alteration, and disclosure, appropriate to the nature of the data and the Service. ProjectPacer’s current measures are described in Section 8 of the Terms and Section 8 of the Privacy Policy, and include encryption of traffic in transit, encryption at rest for connected credentials and integration tokens, industry-standard password hashing, server-enforced isolation between workspaces, role-based access controls, rate-limited sign-in, and audit logging of privileged administrative actions. ProjectPacer may update these measures as its practices evolve, provided it does not materially decrease the overall level of protection.

7.2 Security Incident notification

ProjectPacer will notify Customer of a Security Incident affecting Customer Personal Information without undue delay, and in any event within 72 hours of confirming the incident. The notice will describe, to the extent known, the nature of the incident, the categories and approximate volume of Customer Personal Information affected, the likely consequences, and the measures taken or proposed. ProjectPacer will provide updates as further information becomes available.

7.3 Assistance

ProjectPacer will provide Customer with reasonable cooperation and assistance in connection with Customer’s own breach-notification obligations, including information reasonably necessary for Customer to assess and report the incident. ProjectPacer will not make any public statement identifying Customer in connection with a Security Incident without Customer’s prior written consent, except as required by law.

8. Consumer Rights Requests

Taking into account the nature of the Processing, ProjectPacer will provide Customer with reasonable assistance, through the functionality of the Service or otherwise, in responding to requests from individuals to exercise rights of access, correction, deletion, portability, and opt-out under the Applicable Privacy Laws.

If ProjectPacer receives such a request directly from an individual whose Personal Information appears in Customer’s workspace, ProjectPacer will not respond substantively except to acknowledge the request and direct the individual to Customer, and will inform Customer of the request without undue delay, unless prohibited by law.

9. Retention, Return & Deletion

ProjectPacer retains Customer Personal Information for as long as necessary to provide the Service and as described in Section 7 of the Privacy Policy. On termination or expiry of the Terms, ProjectPacer will make Customer Data available for export for the period described in Sections 4.7 and 17.3 of the Terms, and will thereafter delete or de-identify Customer Personal Information in accordance with those Sections and the Privacy Policy, except for information ProjectPacer is required or permitted to retain to comply with law, resolve disputes, or enforce its agreements.

Customer acknowledges that, as described in Section 7 of the Privacy Policy, time entries associated with a deleted user account remain within the parent workspace’s history and are de-linked from that user’s profile, and that the workspace owner controls that content. Deletion from encrypted backups occurs on the rolling backup cycle described in the Privacy Policy.

10. Compliance Verification

On Customer’s written request, no more than once in any twelve-month period, ProjectPacer will provide a written response to a reasonable security and privacy questionnaire, or make available then-current summary documentation of its security practices, sufficient to allow Customer to verify ProjectPacer’s compliance with this DPA. Customer will treat all information received under this Section as ProjectPacer’s confidential information.

11. Prohibited Data

Customer will not submit to the Service any Sensitive Information as defined in Section 7.7 of the Terms. ProjectPacer has no obligation to monitor for or detect such information and disclaims liability arising from its submission, as set out in the Terms. For the avoidance of doubt, account and transaction data imported through an opt-in Financial Account connection under Section 12.1 of the Terms is not prohibited by this Section or by Section 7.7 of the Terms.

12. Liability, Changes & Survival

12.1 Liability

Each party’s liability arising out of or relating to this DPA is subject to the limitations and exclusions in Section 15 of the Terms.

12.2 Changes to this DPA

ProjectPacer may update this DPA from time to time. ProjectPacer will provide notice of material changes to this DPA in accordance with Section 19 of the Terms. ProjectPacer maintains prior versions of this DPA, each identified by version and effective date.

12.3 Survival

Sections 4 (Service Provider Obligations & Restrictions), 5 (De-identified & Aggregated Information), 7.3 (Assistance), 9 (Retention, Return & Deletion), 10 (Compliance Verification), and 12 (Liability, Changes & Survival) survive termination or expiry of the Terms.

13. Contact

Questions or requests relating to this DPA may be directed to:

ProjectPacer LLC 2461 N New Jersey St, Indianapolis, IN 46205 support@projectpacer.com