Legal

Data Processing Agreement

Last updated: 2026-07-26

These Data Processing terms (the "DPA") form part of the agreement between O'Shea & Sons, LLC ("Processor", "we", "us") and the customer that uses ControlDrill ("Controller", "Customer", "you"). This DPA is the operative processor terms that apply to all customers of the Service unless a separately signed DPA expressly replaces it.

Together with the Terms of Service and Privacy Policy, this DPA governs processing of Customer Personal Data. Capitalized terms not defined here have the meaning in the Terms.

1. Roles

Each party will comply with data protection laws applicable to its role. For Processor's own account and billing contact data about Customer, Processor may act as an independent controller as described in the Privacy Policy; that account data is not "Customer Personal Data" under this DPA.

2. Processing details

3. Customer instructions

Processor will process Customer Personal Data only on documented instructions from Customer, including via the Service UI and features, and as required by law (in which case Processor will inform Customer unless legally prohibited). Customer is responsible for the lawfulness of its instructions, for notices to participants, and for the content of uploaded plans.

4. Confidentiality

Processor ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.

5. Security measures

Processor implements reasonable technical and organizational measures appropriate to the nature of the Service, including: edge hosting on Cloudflare Workers with Durable Objects and D1; storage of uploaded plan originals in Cloudflare R2; inference for tailoring and moderation on Cloudflare Workers AI so plan content does not leave Cloudflare for an external LLM; encrypted transport (HTTPS); authenticated buyer sessions; magic-link access for participants; and access limited to operating the product. No security measure is perfect. Processor does not claim SOC 2, ISO 27001, or other certifications it does not hold, and does not promise absolute security.

6. Subprocessors

Customer authorizes Processor to use the following subprocessors (complete current disclosed list):

Processor will impose data-protection obligations on subprocessors no less protective than this DPA. Processor remains responsible for subprocessors' performance. Processor will update this page (or otherwise notify Customer) when the subprocessor list changes. Customer may object to a new subprocessor on reasonable data-protection grounds within thirty (30) days of notice; if the parties cannot resolve the objection, Customer may stop using the affected Service as its sole remedy for that objection.

7. No model training; no external LLM subprocessor

Processor does not use Customer Personal Data or uploaded plans to train models. Inference for the Service runs on Cloudflare Workers AI. There is no external LLM subprocessor: plan content is not sent to a third-party model API outside Cloudflare for tailoring or moderation.

8. International transfers

Where Customer Personal Data is transferred internationally, Processor relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms provided via subprocessors as applicable, together with any supplementary measures those providers document.

9. Assistance with data-subject rights

Taking into account the nature of processing, Processor assists Customer in responding to data-subject requests by providing in-product deletion for uploaded documents where available and by handling written requests at hello@controldrill.com. Customer remains responsible for verifying requestors who are its participants or employees and for responding to those data subjects.

10. Breach notification

Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.

11. Return and deletion

Upon termination of the Service, completion of the relevant purchase lifecycle under the stated retention policy, or on Customer's written request, Processor will delete or return Customer Personal Data in accordance with product tools and operational practice, except where retention is required by law. Uploaded plan originals and extracted corpus are deleted on request (including in-product delete where available) and otherwise under the stated 12-month retention window. Customer should export evidence packets before requesting deletion if a copy is needed.

12. Audits

Upon reasonable written request, and no more than once per twelve (12) months (unless a regulator or confirmed breach requires more), Processor will provide information reasonably necessary to demonstrate compliance with this DPA (for example up-to-date subprocessor list and high-level security description). On-site audits are not offered by default for a small multi-tenant SaaS; the parties will discuss good-faith alternatives if required by law.

13. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where prohibited by applicable data-protection law.

14. Order of precedence

If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls for that subject. A separately signed DPA between the parties controls over this page if it expressly says so.

15. Governing law

This DPA is governed by the laws of the State of Illinois, USA, without regard to conflict-of-law rules, except where mandatory data-protection law requires otherwise. Courts in Illinois have exclusive jurisdiction for disputes under this DPA, subject to those mandatory rules.

16. Contact

O'Shea & Sons, LLC
Email: hello@controldrill.com
Website: https://controldrill.com/