Data Processing Terms
1. The parties and when these terms apply
These terms are entered into between the client, which is the controller, and SDSI Business Systems, Inc., which is the processor. They apply whenever we process personal data on behalf of a client — including remote support that can see files on the client’s PC, managed IT that gives us access to the client’s systems, and custom-software work that involves the client’s staff or customer data — and they form part of the engagement agreement between us.
Where we act on our own account rather than for a client, we are the controller and our Privacy Notice applies instead of these terms. Running this website, selling a Rapid Estimator license, and verifying that a subscription is current are our own processing, not a client’s.
- Processor: SDSI Business Systems, Inc.
- Registered office: 25060 Hancock Ave #419, Murrieta, CA 92562, United States
- Contact for data-protection matters: pthomas@sdsinow.com
The governing law of these terms is the law of the State of California, unless the engagement agreement states otherwise.
2. Subject matter, nature and purpose
| Term | What it is |
|---|---|
| Subject matter | Remote support, managed IT, training, or custom-software work described in the engagement |
| Duration | The term of the engagement, and the wind-down period in section 10 |
| Nature and purpose | Viewing, diagnosing, repairing or building software and systems the client uses, including material the client shows us or sends us |
| Categories of personal data | Business contact details and any personal data contained in files, screens or systems the client shares |
| Categories of data subject | The client’s staff and, where the client shows them to us, the client’s own customers |
| Sensitive personal information | None. We instruct clients not to share sensitive personal information, and we do not solicit it |
3. Instructions
We process personal data on behalf of the client only on the client’s documented instructions, which are the engagement agreement, these terms, and any later written instruction the client gives. We will tell the client immediately if we consider an instruction unlawful, and we may pause the affected processing while that is resolved.
4. Confidentiality
Every person we authorise to process personal data under these terms is bound by a duty of confidentiality that survives the end of their engagement with us. We limit authorisation to the people who need it to deliver the service.
5. Security
We apply appropriate technical and organisational measures to protect personal data. Personal data is encrypted in transit. Access is limited to SDSI staff who need it. Our full control set is described in our Security Overview.
6. Sub-processors
The client gives general authorisation for us to engage the sub-processors named on our Sub-Processors page. That page is the complete, closed list of recipients, and a party absent from it does not process client personal data.
We give 30 days notice before a new sub-processor begins processing personal data, by publishing the change on that page and writing to every client under contract. A client may object during that period, in writing, on reasonable grounds relating to data protection, and where an objection cannot be resolved the client may terminate the affected service without penalty.
We impose on every sub-processor, by written contract, the same data-protection obligations these terms impose on us, and we remain liable to the client for the performance of each one.
7. Location
Processing under these terms takes place in the United States. Client records we keep are stored in the United States.
8. Artificial intelligence
There is no integrated AI in Rapid Estimator or in this website. AI-assisted work is used in a client engagement only when agreed for that work. We do not send client confidential material or client personal data to a model provider without authorization. We do not use customer data to train models.
9. Assistance and personal data breach
We assist the client to respond to a request from a person exercising a right of access, correction, deletion or opt-out. Where a person contacts us directly about client data, we forward the request to the client without undue delay and do not answer on the client’s behalf.
We will notify the client of a personal data breach affecting client personal data without undue delay and in any event within 72 hours of becoming aware of it. The notification will describe what happened, the categories and approximate number of records affected, the likely consequences and the measures taken. We do not notify a regulator or a data subject on the client’s behalf unless the client instructs us to in writing.
10. Deletion and return
At the end of the engagement we delete or return client personal data at the client’s choice, and delete existing copies, unless a law of the United States requires us to keep it. The client tells us which within 30 days of the end of the engagement; where the client does not, we delete.
Deletion reaches backups, caches and archives on their own cycles, which complete within a further 90 days. License records we hold as controller, described in the Privacy Notice, are kept for 50 years and are not deleted under this section.
11. Audit
We make available to the client the information necessary to demonstrate compliance with these terms, and we allow for an audit conducted by the client or an auditor the client mandates, on 30 days written notice and no more than once a year unless a breach or a regulator requires otherwise.
12. Changes
This is version 1.1, updated on 15 September 2026 to clarify AI-assisted client work. We will not change these terms to the detriment of a client during an engagement without the client’s written agreement. Changes are published at this address with a new version number and date.
13. How to reach us
Write to pthomas@sdsinow.com, or to SDSI Business Systems, Inc., 25060 Hancock Ave #419, Murrieta, CA 92562, United States. Our other published documents are indexed on the Legal page.