Legal
Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the agreement between Virtual Manager Services, Inc. and each business customer that uses Pool Management System to process personal data on its behalf.
- Published September 21, 2026. Effective upon acceptance for accounts created on or after that date (version 1.0).
- This DPA is incorporated into the Terms of Use. It controls over conflicting general terms on processing Customer Personal Data.
- 1.
Parties, scope and incorporation
This DPA is between Virtual Manager Services, Inc., a Florida corporation at 6097 Balboa Circle, Apt 402, Boca Raton, FL 33433, United States (PMS), and the business identified as the customer in the applicable account, order or subscription (Customer).
The DPA applies when PMS processes personal data submitted by or for Customer through the contracted Service (Customer Personal Data). It becomes binding when Customer accepts the Terms of Use, signs an order or other agreement that incorporates it, or continues using the Service after the effective date following legally required notice.
This DPA does not govern information PMS processes for its own purposes as described in the Privacy Policy, including website visits, account administration, billing, security and direct communications.
- 2.
Roles and documented instructions
For Customer Personal Data, Customer acts as controller or business and PMS acts as processor or service provider, to the extent those terms apply. Each party remains responsible for obligations arising from its own role.
PMS will process Customer Personal Data only to provide, secure, support and maintain the Service; comply with documented settings and lawful instructions from authorized users; perform the operations described below; and meet applicable legal obligations. PMS will notify Customer if it reasonably believes an instruction violates applicable data-protection law, unless prohibited from doing so.
Processing may include receiving, organizing, storing, consulting, updating, displaying to authorized users, transmitting operational communications, securing, returning and deleting data for the duration of the subscription and the exit period described below.
- 3.
Customer responsibilities
Customer determines the purposes and lawful basis for Customer Personal Data, provides required notices, obtains required permissions, configures access appropriately and gives PMS only lawful instructions. Customer must not use the Service to collect or process data prohibited by the Terms or unnecessary for its pool-service operations.
Customer is responsible for the actions of its authorized users and for responding to data subjects, except for the assistance PMS commits to provide under this DPA.
- 4.
Confidentiality and security
PMS will ensure that people authorized to process Customer Personal Data are subject to confidentiality duties and access it only as needed for their responsibilities.
PMS will maintain risk-appropriate administrative, technical and organizational safeguards, including authentication and authorization controls, tenant separation, transport protection, secrets management, event logging, vulnerability and patch management, backup and recovery procedures, supplier management and incident response. Safeguards may evolve, but PMS will not materially reduce the overall protection of the Service during a subscription.
No security measure makes an online service invulnerable. Customer remains responsible for account credentials, endpoint security and lawful configuration of user access.
- 5.
Subprocessors
Customer gives PMS general authorization to use subprocessors needed to provide the Service. Depending on the features used, these may include Microsoft Azure for hosting and storage, SendGrid for email delivery, Stripe for subscription payments, and the configured mapping or artificial-intelligence provider where a Customer-enabled feature sends Customer Personal Data to that provider.
Calendly is used to schedule meetings on the public /contact page. In the current implementation it processes website-visitor or prospect data described in the Privacy Policy and does not receive Customer Personal Data from the Service, so it is not relied upon as a subprocessor under this DPA. If that use changes, the new-subprocessor notice below applies.
PMS will bind each subprocessor that receives Customer Personal Data to written protections appropriate to the delegated processing and remains responsible to Customer for that subprocessor's performance of those obligations.
PMS will give reasonable advance notice of a new subprocessor that will receive Customer Personal Data. Customer may object on reasonable data-protection grounds. The parties will seek a practical resolution; if none is available, either may discontinue the affected feature or terminate the affected Service under the Terms.
- 6.
Data-subject requests and assistance
If PMS receives a request concerning Customer Personal Data, PMS will direct the requester to Customer unless the law requires PMS to respond. Taking into account the nature of the processing, PMS will provide reasonable assistance so Customer can access, correct, export, restrict or delete Customer Personal Data and meet applicable privacy obligations.
Customer must authenticate and scope its instructions. PMS may charge reasonable fees for exceptional, repetitive or technically disproportionate assistance that is not included in the Service, after giving Customer prior notice, unless applicable law requires otherwise.
- 7.
Security incidents and government requests
PMS will notify Customer without undue delay after determining that a breach of security has compromised Customer Personal Data. The notice will include information reasonably available about the nature of the incident, affected data, likely consequences and mitigation. Notification is not an admission of fault or liability.
PMS will take reasonable steps to contain, investigate and remediate the incident and will provide information reasonably needed for Customer's legally required notifications. Customer is responsible for deciding whether and how to notify individuals or authorities, except where law assigns that duty directly to PMS.
PMS will notify Customer of a legally binding government demand for Customer Personal Data when permitted, review the demand for validity and disclose only what it is legally required to disclose.
- 8.
Return, deletion and retention
During an active subscription, Customer may access and export data through available Service features. Following termination, PMS will provide the export opportunity stated in the Terms or applicable order and then delete Customer Personal Data from active systems, unless Customer requests earlier deletion or law requires retention.
Deletion from backups follows the ordinary secure rotation cycle. Until deletion, remaining data stays protected and may be used only for recovery, security or documented legal retention. PMS will not keep Customer Personal Data indefinitely for an undefined future purpose.
- 9.
Verification and audit
On reasonable written request, PMS will provide information reasonably necessary to demonstrate compliance with this DPA. Review begins with existing policies, responses and evidence. If those materials are insufficient for a legally required assessment, the parties will agree on a proportionate additional review that protects other customers, security and confidential information.
Customer will not conduct penetration testing, access another customer's information or disrupt the Service. Each party bears its own ordinary review costs; extraordinary Customer-specific work may be charged with prior notice.
- 10.
International transfers and artificial intelligence
Customer Personal Data may be hosted, processed or accessed in the United States and in other locations used by an authorized subprocessor. Where applicable law requires a transfer mechanism or additional safeguards, the parties will cooperate to put them in place before the affected transfer.
When a Customer-enabled artificial-intelligence feature processes Customer Personal Data, PMS will limit the data sent to what is needed for that feature and will not use or authorize its use to train general-purpose models without Customer's specific authorization and a valid legal basis. Artificial-intelligence output requires appropriate human review.
- 11.
Processing details
Data subjects may include Customer's clients and contacts and Customer's authorized users, employees and contractors. Data may include identifiers and contact information, customer and property records, service visits, schedules, notes, chemistry readings, location associated with service activity, photos and attachments, communications, commercial records and technical audit events, depending on the features Customer uses.
The purpose is to provide the contracted pool-service management features. Processing is continuous for the subscription term and the limited exit, backup and legally required retention periods. Customer should not submit data that the Service does not need.
- 12.
Order of precedence, liability and term
For conflicts about processing Customer Personal Data, this DPA controls over the Terms and other general subscription provisions. A signed agreement may change this DPA only if it identifies the provision being changed. The liability limits and remedies in the governing subscription agreement apply to this DPA unless mandatory law requires otherwise.
This DPA remains in effect while PMS processes Customer Personal Data. Confidentiality, security, use restrictions and deletion duties survive for data that legitimately remains after termination.
- 13.
Contact and changes
Privacy and DPA notices to PMS must be sent to contact@poolmanagementsystem.com. Customer must keep an authorized privacy and incident contact current in its account or provide it by authenticated communication.
PMS may update this DPA to reflect law, subprocessors or the Service. PMS will give account holders advance notice of material changes and will not materially reduce protection of Customer Personal Data without a lawful basis or Customer agreement where required.
Questions about this DPA?
Write to contact@poolmanagementsystem.com and identify your company and the data-processing question.