BroomDesk
FeaturesPricingCompareBlogFree tools
Log inStart free trial

Data processing addendum

Last updated August 12, 2026. This is our own document, written by the operator of BroomDesk. It is not legal advice from a law firm, and it is not a substitute for advice about your own business.

The short version

  • This is the GDPR paperwork. You do not need to sign it or email anyone: it applies automatically to every customer from the day they accept the terms of service.
  • The deal in one line: your clients' data is yours, we only touch it to run the product for you, and we do not use it for anything else.
  • It lists the security we actually have, the companies that help us run the service, and what happens if something goes wrong.
  • If you need a copy for your own files, print this page to PDF. If a client of yours needs a signed one, email support@broomdesk.com and we will countersign it.

The summary is here to be read. The full text below is what applies.

1. Parties and status

This addendum forms part of the terms of service between you (the "customer") and Amortoae Petru PFA (CUI 52361814), Romania ("BroomDesk", "we"). It applies from the moment you accept those terms. No signature is required and no request is needed. Where it conflicts with the terms of service on the handling of personal data, this addendum wins.

For personal data your business puts into BroomDesk, you are the controller and we are the processor. For your own account and billing data, we are the controller and the privacy policy describes what we do. Some of your clients are themselves controllers of data they give you, in which case you may be acting as their processor. That relationship is between you and them.

2. What we process, and why

ItemDetail
Subject matterProviding the BroomDesk platform: scheduling, client records, quoting, invoicing and payment records, messaging, the client portal, the cleaner mobile view, payroll calculation, reporting and the integrations you switch on.
DurationFor as long as your subscription is active, plus the read-only window after cancellation, which runs at least 90 days and until you ask for deletion, plus the retention periods in section 8.
Nature and purposeStoring, organising, retrieving, transmitting and deleting data on your instructions. Sending the messages you trigger. Calculating schedules, prices and pay. Producing exports and reports. Generating AI drafts and estimates where you use those features.
Categories of data subjectYour clients and the people at their properties, your employees and contractors, your job applicants, and your own staff users.
Categories of personal dataNames, postal addresses, email addresses, phone numbers, property and access details including entry instructions and door codes, appointment and service history, message content and consent records, invoices and payment records, photographs taken on jobs, worker pay rates and clock-in times and locations, and application details for candidates.
Special category dataNone is required by the product and none should be entered. Free text fields could contain it if you type it there, so do not.

We process personal data only on your documented instructions. Your use of the product, its settings and this addendum are those instructions. We do not sell personal data, we do not use it for advertising, and we do not use your clients' data to train AI models. If a law forces us to process beyond your instructions, we will tell you first unless that law prevents it.

3. Confidentiality

Access to production data is limited to the operator of BroomDesk and to anyone we later authorise, each bound by confidentiality obligations that survive the end of their engagement. Access is granted on need, and significant actions taken inside an organisation are written to an audit log.

4. Security measures

These are the measures the product actually implements today, not a wish list.

  • Tenant isolation in the database. Every table holding customer data has Postgres row-level security enabled, with policies keyed on the organisation the signed-in user belongs to. One customer cannot read another's rows even if application code has a fault. Cross-tenant isolation is asserted by an automated test that iterates every table.
  • Encryption at rest for the most sensitive fields. Integration access tokens and property entry details, meaning door codes and alarm instructions, are encrypted with AES-256-GCM using a 32-byte key held in the environment rather than in the database, with a fresh nonce per value and a version byte for rotation. The underlying database and file storage are encrypted at rest by our hosting provider.
  • Encryption in transit. TLS on every connection to the application, the database and every provider API.
  • Access control inside your account. Roles decide who can see and do what. Cleaners see the jobs assigned to them without financial columns. Entry details are readable only by roles that need them, and the read is audited.
  • Audit logging. Significant actions record the actor, their role, the action, the affected record, the before and after values and the originating IP address. The log takes no writes from the browser.
  • Private file storage. Job and inspection photos live in private buckets scoped by organisation and are served through short-lived signed links, never public URLs.
  • Input validation and abuse controls. Server actions and API routes validate every input against a schema. Rate limits apply to sign-in, sign-up, password reset, magic links, the contact form, widget endpoints and the public API. Widget endpoints check the calling domain against an allowlist you control.
  • Verified webhooks. Callbacks from Stripe, Twilio and Resend are signature-verified and processed idempotently before anything is trusted or written.
  • Error monitoring without personal data. Sentry is configured not to attach personal data to events, so message bodies and email addresses do not travel into error reports.
  • Secrets handling. No secrets in the code repository, secret scanning and dependency auditing in continuous integration, and the privileged database key restricted to server code paths that have already checked authorisation.
  • Backups. Managed database backups through our hosting provider, in the same region as the database. Independent off-platform backups and scheduled restore drills are planned before public launch and are not in place yet, which we would rather say than imply.

Security is a moving target. We may change a measure as long as the overall level of protection does not drop.

5. Subprocessors

You give general authorisation for us to use subprocessors. The current list, with what each does and where it processes, is at /legal/subprocessors and forms part of this addendum.

One provider is deliberately outside that relationship. Plausible counts page views on our public marketing pages only. It is not loaded anywhere inside the application, it sets no cookie and it receives none of the personal data you process here, so it is not a subprocessor of your data. The cookie policy describes it.

We impose data protection obligations on each of them that are no less protective than these, and we stay responsible to you for their performance. Before adding or replacing one, we give account owners at least 14 days notice by email. If you object on reasonable data protection grounds within those 14 days, write to support@broomdesk.com and we will look for an alternative. If there is not one, you may terminate the affected part of the service and export your data, and we will refund the unused portion of what you paid.

6. International transfers

Personal data is processed in the United States, primarily in the AWS us-east-1 region. Where you transfer personal data originating in the EEA, the UK or Switzerland, the transfer relies on the European Commission's standard contractual clauses of 4 June 2021, module two, controller to processor, which are incorporated into this addendum by reference and completed as follows: you are the data exporter and we are the data importer; the optional docking clause applies; for clause 9 the general authorisation option applies with the 14 day notice period in section 5; for clause 11 the independent dispute resolution option is not selected; for clause 17 the governing law is the law of Romania; for clause 18 the forum is the courts of Romania. Annex one is section 2 of this addendum, annex two is section 4, and annex three is the subprocessors page.

For UK transfers, the UK international data transfer addendum to those clauses applies, with the start date being the date you accepted the terms of service and the tables completed from the same sections.

7. Data subject requests

Requests from your clients or workers are yours to answer. Where the product does not already let you answer one yourself, we help. Tell us what you need at support@broomdesk.com and we act within 30 days at the latest.

If a data subject contacts us directly about data held in your account, we do not answer for you. We tell them to contact you, and we tell you it happened.

We also assist you, taking into account the nature of the processing and the information available to us, with security obligations, breach notification, impact assessments and prior consultation with a supervisory authority.

8. Deletion and return

  • Three exports run from the app at any time, on every plan and behind no feature gate: your client list, your visits and your invoices, each as a CSV, each accepting an optional date range. They keep working after cancellation while the account is read-only, because that window exists for exactly this. An export is the whole book of business rather than one person's slice of it, so it needs an owner, admin or office role. A file that would run past 10,000 rows is refused rather than truncated, with the instruction to take one date range at a time, so you never receive a file that looks complete and is not.
  • Approved payroll periods export as well, either line by line or in the Gusto format, on the plans that include payroll and to a user who manages it. Anything outside those four files, job photos and message threads included, is produced by us on request.
  • On cancellation the account becomes read-only and stays retrievable for at least 90 days. Deletion of the organisation's data is performed by us on your instruction, within 30 days of the request. This is a commitment we carry out, not an automated purge: no scheduled job deletes data at the end of the 90 days today, so nothing disappears without you asking, and nothing is retained against your instruction either.
  • Two carve-outs, both required rather than convenient: messaging consent records are kept at least 5 years as legal evidence, and financial records are kept for the period accounting law requires, in anonymised form where the personal detail is no longer needed.
  • Backups age out on their own retention cycle. Data in a backup is not restored to live use after a deletion request.

9. Personal data breach

If we become aware of a personal data breach affecting personal data we process for you, we notify you without undue delay and in any case within 72 hours of confirming it, at the account owner's email address. The notice describes what we know: the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed. We keep updating you as we learn more, and we do not wait for a complete picture before the first notice. We do not notify your data subjects or a supervisory authority on your behalf unless you ask us to.

10. Audits

On reasonable request, no more than once a year unless a supervisory authority or a breach requires otherwise, we make available the information needed to demonstrate compliance with this addendum and answer a reasonable security questionnaire. We are a small operation and do not hold a SOC 2 report; we say so rather than implying certifications we do not have. Where a written response is not enough, we will agree a proportionate alternative with you, at your cost and under confidentiality, and without giving access to other customers' data.

11. Liability and term

Liability under this addendum is subject to the limitations in the terms of service. Nothing here limits any liability a data subject or a supervisory authority may enforce directly under the standard contractual clauses or applicable data protection law. This addendum lasts as long as we process personal data for you, and the obligations that by their nature should survive, do.

Questions

Questions about this addendum, a signed copy, or a security review. Email support@broomdesk.com, or use the contact form. We reply within one business day.

BroomDesk is operated by Amortoae Petru PFA (CUI 52361814), Romania. Postal address and registration details are on any invoice we issue you through Stripe.

BroomDesk

Software for cleaning businesses. Flat price, unlimited team members, your clients stay yours.

Amortoae Petru PFA (CUI 52361814)

Product
  • Features
  • Booking widget
  • Scheduling
  • AI receptionist
  • Payroll
  • Commercial cleaning
  • Pricing
Compare
  • All comparisons
  • vs ZenMaid
  • vs Jobber
  • vs Automaid
  • vs BookingKoala
  • vs Housecall Pro
Learn
  • Blog
  • RSS feed
  • Free tools
  • Price calculator
  • Widget docs
  • API docs
Company
  • About
  • Contact
  • Live demo
  • FAQ
  • Log in
  • Start free trial
Legal
  • Terms of service
  • Privacy policy
  • Refund policy
  • SMS policy
  • Acceptable use
  • Cookies
  • Cookie preferences
  • Data processing
  • Subprocessors
© 2026 BroomDesk. Built for the people who keep places clean.Made in the EU, built for US cleaning teams