MoveOS

Data Processing Agreement

How MoveOS handles personal information on behalf of a moving company: instructions, security, sub-processors, breach notification and deletion.

Last updated 24 July 2026

Draft — counsel review required

This document describes how MoveOS works today and is published so you can read it before you sign up. It has not yet been reviewed by legal counsel and is not final. If you are evaluating MoveOS for a signed agreement, ask us for the executed version.

1. Roles

This agreement applies when MoveOS processes personal information on behalf of a subscribing moving company. It forms part of the Terms of Service.

Your company is the organization accountable for that personal information under PIPEDA and equivalent provincial law — the "controller" in international terms. MoveOS is the service provider processing it on your behalf — the "processor". Where GDPR applies to a customer, the parallel terms apply as written.

2. Scope and duration

We process personal information only for as long as you hold an account, plus the deletion and export periods described in section 9. The subject matter, categories and purposes are set out in Annex A.

3. Our instructions

We process personal information only on your documented instructions. Using the product is an instruction: creating a job, sending a quote, enabling call recording, and configuring a retention window are all instructions.

We will tell you if an instruction appears to conflict with applicable privacy law. If we are legally compelled to disclose personal information, we will notify you first unless the law forbids it.

4. Personnel

Our staff are bound by confidentiality obligations that survive their employment, receive privacy and security training, and reach customer data only through least-privilege access that is logged.

5. Security measures

We maintain the technical and organizational measures described in Annex C.

6. Sub-processors

You authorize us to engage the sub-processors listed in Annex B. Each is under a written contract with data-protection obligations no less protective than these.

We will give at least 30 days notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds within that period and we cannot offer an alternative, you may terminate the affected service without penalty and receive a pro-rated refund.

7. Helping you meet your obligations

  • Access, correction and deletion requests from your customers: the product lets you handle these yourself. Where it does not, we assist within 10 business days.
  • Privacy impact assessments: we provide the information you reasonably need about our processing.
  • Confidentiality incidents: we notify you without undue delay and in any case within 72 hours of confirming one, with what we know about scope and cause, and we support your notification to regulators and affected individuals.

8. Transfers

Where a sub-processor processes personal information outside Canada, Annex B says so and where. We complete the assessment Quebec’s Law 25 requires before such a transfer and put contractual protections in place.

9. Return and deletion

You can export your data at any time. After termination we keep it available for export for 30 days and then delete it, subject to the retention periods in the Privacy Policy — signed documents and financial records are retained because you and we are required to keep them, not for our own purposes.

Encrypted backups are purged as the 35-day backup cycle turns.

10. Audit

On request and no more than once a year, we will provide the security documentation and answers you reasonably need to confirm we are meeting this agreement. On-site audits are available under a signed agreement, at your cost, with reasonable notice.

Annex A — details of processing

Categories of individuals
Your staff and crew; your customers and their household members; contacts at partner and subcontracted movers; people who call your business.
Categories of personal information
Contact details; origin and destination addresses; household inventory and its photographs; signatures and signed documents; payment status (never card numbers); crew timesheets and GPS positions while on an active job; call recordings and transcripts where enabled; message history.
Sensitive information
Photographs of a household interior can be revealing. They are access-controlled per tenant and deleted about 30 days after the move completes.
Purposes
Quoting, scheduling, dispatch, performing the move, customer communication, tracking, invoicing and payment, claims handling, and accounting.
Duration
As set out in section 4 of the Privacy Policy.

Annex B — sub-processors

The current list is published in the product under Settings → Privacy, and changes are announced there and by email. As of the date above, the categories are:

Cloud database and authentication
Application data. Canadian region where offered.
Object storage
Photographs and documents.
Stripe
Payment processing. Card data goes directly to Stripe.
Telephony and messaging
SMS, voice and email delivery.
Mapping and routing
Addresses and route calculation.
Error monitoring
Diagnostics, scrubbed of personal information where possible.

Annex C — security measures

  • TLS in transit; encryption at rest for databases, object storage and backups.
  • Row-level tenant isolation enforced in the database, not only in application code.
  • Multi-factor authentication for MoveOS platform administrators; available for all staff accounts.
  • Administrative access to customer data is time-limited, reason-logged and auditable by you.
  • Change management with code review and automated testing before release.
  • Encrypted backups on a 35-day cycle with rehearsed restores.
  • Documented incident response with a confidentiality incident register.