Pillar

Data Processing Agreement

This Data Processing Agreement ("DPA") governs how Pillar Software Solutions LLC processes personal data on behalf of the businesses that use Pillar. It contains only commitments we can actually keep.

Version 2.0 — Effective August 10, 2026

1. Scope and Relationship to the Terms

This DPA supplements and forms part of the Terms of Service (the "Agreement") between Pillar Software Solutions LLC ("Pillar", "Processor", "we", "us") and the customer entity agreeing to those terms ("Controller", "you", "your"). Where this DPA and the Agreement conflict on the handling of Personal Data, this DPA governs.

It applies to the extent Pillar processes Personal Data on your behalf while providing the Pillar field service management platform (the "Services").

This is a United States agreement. Pillar is a Pennsylvania limited liability company, the Services are operated from and hosted in the United States, and this DPA is written for United States requirements. We do not offer international data transfer terms, and the Services are not offered to Controllers who require them. See our Privacy Policy for the full posture.

2. Definitions

  • Controller means the customer entity that determines the purposes and means of processing Personal Data through the Services.
  • Processor means Pillar, which processes Personal Data on the Controller's behalf in connection with providing the Services.
  • Personal Data means information relating to an identified or identifiable person that Pillar processes while providing the Services. This includes customer and employee names, email addresses, telephone numbers, physical and service addresses, service records, payment records, message logs, location data, and canvassing records.
  • Processing means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, combination, erasure, or destruction.
  • Sub-processor means a third-party provider engaged by Pillar that processes Personal Data in the course of delivering the Services.
  • Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data processed under this DPA.

3. Nature and Purpose of Processing

Pillar processes Personal Data to deliver the Services to you, in accordance with your instructions as expressed through your use and configuration of the Services and through the Agreement. We do not sell Personal Data and do not use it for purposes unrelated to providing, securing, supporting, and improving the Services.

Processing activities include:

  • Storing and managing customer records, job data, and scheduling information
  • Processing estimates, invoices, and payment transactions
  • Sending email and text messages on your behalf to your customers, and logging those messages with the opt-out records that messaging rules require
  • Converting addresses into map coordinates, and coordinates into approximate addresses, for mapping and dispatch
  • Recording location data where you enable the location features, including technician tracking and sales rep canvassing breadcrumbs
  • Generating reports and analytics from your operational data
  • Maintaining audit logs for security and accountability
  • Synchronizing records with the accounting and calendar accounts you choose to connect

The duration of processing is the term of the Agreement, plus the retention windows described in Section 9.

4. Confidentiality and Personnel Access

Pillar personnel authorized to process Personal Data are bound by confidentiality obligations that survive the end of their engagement. Access is limited to personnel who need it to support, secure, and operate the Services.

We will not disclose Personal Data to any third party except as set out in this DPA, as you instruct, or where disclosure is required by law. Where we are legally compelled to disclose Personal Data, we will tell you before doing so unless the law forbids it.

Our Privacy Policy describes operator access plainly, including the fact that our personnel can reach tenant data and cross-tenant application logs when supporting and running the platform. Nothing in this DPA implies a technical barrier between Pillar and the data it hosts for you.

5. Sub-processors

You authorize Pillar to engage the sub-processors listed below. Each is engaged under terms requiring it to protect Personal Data and to process it only for the purpose named. Where a row says the integration is connected by the Controller, no Personal Data reaches that sub-processor unless you connect it.

Sub-processorPurpose
DigitalOcean, LLCCloud infrastructure hosting the application servers and database
Cloudflare, Inc.Object storage for uploaded files and documents (R2), and the anti-abuse check on the sign-up form (Turnstile)
Stripe, Inc.Payment processing, subscription billing, and saved payment methods
Twilio Inc.Text messaging, voice calls, call recording where enabled, and communication logging
Twilio SendGridEmail delivery and sending-domain authentication
Functional Software, Inc. (Sentry)Error reporting and diagnostics, including the request context attached to a failure
Google LLCCalendar synchronization for Controllers that connect a Google account. Events written to the connected calendar carry the customer name, the full service address, and the appointment notes
Intuit Inc.QuickBooks Online synchronization for Controllers that connect a QuickBooks account (customers, invoices, estimates, payments)
U.S. Census Bureau geocoder / OpenStreetMap NominatimConverting street addresses into map coordinates, and coordinates into an approximate address for canvassing pins

Caching, rate limiting, background job queues, and map tiles run on infrastructure Pillar operates itself, so no additional sub-processor receives Personal Data for those purposes. No third-party analytics or tracking tool is loaded inside the Services; the analytics described in our Privacy Policy runs on our public marketing website only and does not process Personal Data you provide as Controller.

Changes. Material additions to this list are announced on this page, with the version and effective date at the top updated accordingly. Continued use of the Services more than 30 days after such an announcement constitutes acceptance of the change. If a new sub-processor is unacceptable to you, tell us at admin@pillarfsm.com within that window; if we cannot reasonably accommodate you, you may terminate the affected Services. We do not promise advance email notification to every Controller, and we will not put a commitment in writing that we cannot guarantee to meet.

6. Security Measures

Pillar maintains technical and organizational measures appropriate to the risk. Specifically, and only what is actually in place:

  • Multi-tenant isolation — every record carries a company identifier and the filter is applied automatically on every database query, so one Controller's data is not reachable from another Controller's session.
  • Encryption in transit — all traffic between clients and our servers is carried over TLS.
  • Credential protection — passwords are stored as one-way bcrypt hashes. Access tokens for connected accounts, such as QuickBooks, Google Calendar, and messaging sub-accounts, are encrypted with AES-256-GCM before they are written to the database.
  • Role-based access control — access is restricted by user role and enforced on every API endpoint, on every request.
  • Session security — session tokens are issued in HttpOnly cookies that page scripts cannot read, with short expiry and refresh.
  • Audit logging — security-relevant events are recorded with actor, IP address, timestamp, and action, for accountability and incident investigation.
  • Rate limiting — endpoints are rate limited, with stricter limits on authentication and other sensitive operations.
  • Input validation — inputs are validated and sanitized, and unknown request properties are rejected.
  • File access — uploaded files are served through short-lived signed links rather than public URLs.

What we deliberately do not claim. Pillar holds no SOC 2, ISO 27001, PCI, or HIPAA certification, and this DPA makes no representation about encryption of data at rest, backup schedules, uptime, or penetration testing. Our infrastructure providers apply their own storage-level protections, which are theirs to describe, not ours to warrant.

7. Requests From Individuals

You are responsible for responding to requests from the individuals whose Personal Data you process through the Services. Pillar will provide reasonable assistance, principally through the platform's own tools: you can view, correct, export, and delete records directly, and you can request permanent erasure of specific records from us.

If we receive a request directly from an individual about Personal Data we process on your behalf, we will not act on it ourselves. We will refer the individual to you and notify you of the request, unless we are legally prohibited from doing so.

8. Security Incident Notification

If we confirm a Security Incident affecting Personal Data processed on your behalf, we will notify you without undue delay after confirming the incident, by email to the account owner. We commit to a prompt, honest notification rather than to a fixed clock we cannot guarantee to meet.

The notification will describe, to the extent known at the time:

  • What happened, and the categories and approximate volume of data and individuals affected
  • The likely consequences
  • The measures taken or proposed to contain the incident and mitigate its effects
  • A point of contact for further information

Information not available at first notification will follow as we establish it, rather than delaying the notification itself. We will cooperate with you in the investigation, mitigation, and remediation of the incident, and will not require you to keep the existence of an incident confidential where you have your own notification duties.

9. Retention, Return, and Deletion

Personal Data is retained for the term of the Agreement, and for the specific windows described in our Privacy Policy. Note that deleting a record inside the Services deactivates it and retains the underlying row; permanent erasure of specific records is available on request.

For 30 days after termination of the Agreement, you may request an export of Personal Data in writing. Within 30 days of termination, or of your written deletion request if earlier, we will delete Personal Data from active systems — the production database and file storage.

Backups. Backup copies are not edited record by record. Personal Data contained in backups is removed as those backups age out on our normal rotation, and remains subject to this DPA until it does. Any promise to purge backups on demand would be one we could not keep.

Data may be retained beyond these windows where the law requires it, for example financial and transaction records. In that case it continues to be protected under this DPA.

10. Verification and Audits

You may verify our compliance with this DPA through documentation. On written request, and no more than once in any twelve-month period unless a Security Incident has occurred, we will provide the information reasonably necessary to demonstrate compliance with the obligations in this agreement, and answer a reasonable written security questionnaire.

Audits are documentation-based. Pillar does not offer on-site audits, auditor site visits, or customer-directed penetration testing of the production environment. Pillar is a small operation without offices to host an audit in, and promising one would be theatre.

11. Term and Changes

This DPA is effective for the duration of the Agreement and terminates with it, except that Section 9 (Retention, Return, and Deletion) and Section 4 (Confidentiality) survive termination.

We may update this DPA to reflect changes in law, sub-processors, or security practices. The version number and effective date at the top of this page change with it, and material changes are announced here. Continued use of the Services after a change takes effect constitutes acceptance.

12. Contact

Questions about this DPA, sub-processor objections, erasure requests, and incident correspondence all go to:

Pillar Software Solutions LLC

Email: admin@pillarfsm.com

Mailing address: c/o Northwest Registered Agent LLC, 502 W 7th St, Ste 100, Erie, PA 16502, USA