This Addendum forms part of the Strawboss Terms of Service between Pragmatic Safety Services Ltd. ("Strawboss") and the Customer, and applies whenever Strawboss processes personal information on the Customer's behalf.
1. Roles
The Customer is the organization responsible for the personal information it enters ("controller" or, under Canadian law, the organization "in control" of the information). Strawboss processes that information only on the Customer's documented instructions, which are these Terms, the product's settings and the actions Users take in the Service.
2. What is processed
The categories are listed in Schedule A. Data subjects are the Customer's workers, supervisors and administrators, witnesses and other individuals named in safety records, subcontractor contacts who submit forms through a shared link, and learners who take a publicly shared course.
Special categories the Customer may enter include injury and first-aid details, photographs of people, precise location, voice recordings converted to text. The Customer decides whether to enter them. The Service has no fields for dates of birth, home addresses, emergency contacts or driver's licence details, and the Customer should not enter them in free-text fields.
3. Strawboss's obligations
- Process personal information only to provide, secure and support the Service and as the law requires.
- Keep it confidential and limit staff access to what support requires, under a documented least-privilege review.
- Apply the safeguards in Schedule B.
- Assist the Customer with access, correction and deletion requests from individuals, and with breach notification, at no charge for reasonable requests.
- Notify the Customer without undue delay after confirming a breach, with what is known about the data affected, the likely consequences and the measures taken.
- Delete or return personal information at the end of the subscription as section 6 describes.
- Not sell personal information or use it to train models for other customers.
4. Subprocessors
The Customer authorizes the subprocessors in Schedule C. Strawboss will post changes at strawboss.ai/subprocessors and email workspace owners at least 15 days before a new subprocessor handles Customer Data. A Customer that objects on reasonable data-protection grounds may terminate the affected feature or the subscription with a prorated refund of prepaid fees.
5. International transfers
Production data and backups are stored in Canada (AWS ca-central-1 and a Canadian backup region). The dashboard application and the connected-assistant (MCP) server run in the United States, and AI, email, push and payment providers are located in the United States, as stated in Schedule C. The Customer acknowledges that personal information may be accessed from those jurisdictions and be subject to their laws.
6. Retention and deletion
- During the subscription the Customer controls retention through the product. Permanent deletion of a crew member removes the person's profile and credentials; safety records that reference them are kept with the link removed because they are the Customer's compliance records.
- On closure of a workspace, access is revoked immediately. Records are retained, inaccessible, unless the Customer's owner requests permanent deletion at closure. That request is verified by email and runs 14 days after confirmation, during which the Customer may cancel it. Execution erases every database record and uploaded file belonging to the workspace.
- A Customer that closed without requesting deletion may request it later in writing from the owner's email address; Strawboss will schedule it the same way. Ninety days after closure Strawboss deletes a retained workspace without a request, after emailing the owner at least 30 days before, unless the Customer has asked in writing for a legal hold.
- Billing ledgers, the deletion request itself and legal holds are retained. Encrypted backups expire under the retention in Schedule B.
7. Audit
On written request no more than once a year, Strawboss will provide its current security documentation and answer a reasonable security questionnaire. An on-site audit requires a separate agreement.
8. Contact and notices
Notices to Strawboss under this Addendum, including an objection to a subprocessor under section 4 and a request for security documentation under section 7, go in writing to [email protected], marked for the Privacy Officer, David Dunham, or to the registered office named in the Terms.
Strawboss sends notices to the Customer under this Addendum, including a breach notice under section 3 and a subprocessor change under section 4, to the email address of the workspace owner on file. The Customer keeps that address current and monitored. This section applies the notice terms in the Terms and adds no new obligation.
Schedule A — Categories of personal information
See docs/privacy/data-inventory.md section 1 for the source. Summarize for
publication as: identity and contact details; employment details (role, hire
date); training and certification records;
safety records including incidents, injuries, first aid, hazards,
inspections, orientations and sign-offs; photographs and uploaded documents;
device identifiers; location where a form collects it; voice transcripts;
signatures with the signer's network address; billing contact details for the
owner.
Schedule B — Security measures
Written from the controls present in the repository on 2026-09-29.
- Tenant isolation by row-level security in the database, tenant-scoped storage paths, and ownership checks on every resource identifier.
- Encryption in transit (TLS, HSTS) and at rest (provider-managed); partner credentials encrypted with AES-256-GCM.
- Hashed-at-rest bearer and invitation tokens with expiry and revocation.
- Content Security Policy, frame denial, same-origin checks on mutations, request body size limits, rate limiting.
- Static analysis, secret scanning and dependency updates in continuous integration; weekly scheduled scans.
- Error monitoring with personal information scrubbed.
- Independent encrypted daily backups to a Canadian region with 30-day compliance-locked retention that the automation credential cannot shorten or delete; a documented restore procedure exercised on synthetic data, with an isolated hosted restore drill scheduled as the next verification step.
- Documented incident, disaster-recovery and secret-rotation runbooks.
- Least-privilege account review of provider consoles (ADR 077).
Schedule C — Subprocessors
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All Customer Data | Canada (ca-central-1) |
| Railway | Application hosting | Data in transit and memory, logs | United States (Virginia), dashboard and connected-assistant server |
| Stripe | Payments | Owner name, email, billing details | United States |
| Anthropic | AI assistant and generators | Prompts and records the User asks about | United States |
| Google (Gemini, Firebase) | Voice transcription; push notifications | Voice audio, transcripts; device tokens | United States |
| Groq | AI fallback tier | Prompts | United States |
| OpenAI, ElevenLabs | Course and media generation | Scripts, voice samples | United States |
| Voyage AI | Search embeddings | Text of records | United States |
| Resend | Transactional email | Recipient details and message bodies | United States |
| Sentry | Error monitoring | Scrubbed error reports | United States |
| GitHub | Support ticket mirror | Ticket text, no contact details | United States |
| eazyBackup e3 (Backblaze B2 configured as fallback) | Backups | Encrypted database and files | Canada (ca-central-1) |
| Environment and Climate Change Canada, NOAA | Weather for site diaries | Worksite coordinates | Canada, United States |
Locations reflect the regions Strawboss selects where a provider offers a choice, and the provider's published primary processing location otherwise. AI providers are used under their commercial API terms, which exclude training on customer content; zero-data-retention is enabled where offered.