Legal
Data Processing Information
This page provides general information about how SPRINGS-C LLC ("SPRINGS-C," "we," "us," or "our") approaches the processing of personal information in connection with the SPRINGS-C CRM and operations platform.
SPRINGS-C provides business software to cleaning companies and related organizations. Customers may use the platform to process information concerning their own customers, employees, cleaners, contractors, applicants, suppliers, contacts, service locations, and other business relationships.
Depending on the processing activity, SPRINGS-C may act as a controller, processor, service provider, or equivalent role under applicable privacy law.
This page is provided for transparency and customer due diligence. It is not itself a Data Processing Agreement ("DPA") and does not replace any binding DPA, Order Form, subscription agreement, or other contract between SPRINGS-C LLC and a Customer.
Where a binding DPA is required by applicable law or agreed as part of a Customer's commercial relationship, the executed DPA governs the applicable processing and takes precedence over this informational page in the event of a conflict.
- Last updated
- August 12, 2026
- Applies to
- springs-c.com
- Provided by
- SPRINGS-C LLC
This page is provided for transparency and customer due diligence. It is not itself a Data Processing Agreement and does not replace any binding agreement between SPRINGS-C LLC and a Customer.
Data-Processing Roles
1. SPRINGS-C LLC
The SPRINGS-C Services are provided by:
- Legal entity
- SPRINGS-C LLC
- Entity ID
- 0008102431
- Address
- 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States
- [email protected]
- Phone
- +1 (505) 298-3585
- Website
- https://springs-c.com
2. Understanding Our Data-Processing Roles
Privacy laws assign different responsibilities depending on who determines why and how personal information is processed.
The applicable role therefore depends on the specific processing activity rather than on a single label applied to the entire SPRINGS-C relationship.
3. When SPRINGS-C Acts as a Controller
SPRINGS-C generally acts as a controller or equivalent responsible business when SPRINGS-C determines the purposes of processing for its own business operations.
Examples may include processing relating to:
- website visitors;
- Contact submissions;
- Demo requests;
- Solution Quiz submissions;
- prospective customers;
- commercial communications;
- Customer account administration;
- Customer administrative contacts;
- subscription management;
- invoicing;
- billing;
- payment administration;
- refund administration;
- fraud prevention;
- security monitoring;
- SPRINGS-C support records;
- legal and compliance activities;
- SPRINGS-C's own business records.
For these activities, SPRINGS-C determines the purposes of processing and handles the information according to its Privacy Policy and applicable law.
4. When SPRINGS-C Acts as a Processor or Service Provider
A Customer may enter personal information into the SPRINGS-C platform as part of the Customer's own business operations.
Where SPRINGS-C processes that information on behalf of the Customer and according to the Customer's documented instructions, SPRINGS-C may act as a processor, service provider, or equivalent role under applicable privacy law.
In this context, the Customer generally determines the purposes for which the Customer Data is processed.
The exact legal role depends on the processing activity, applicable privacy law, and the applicable contractual arrangement.
SPRINGS-C does not become the owner of Customer Data merely because the information is processed through the SPRINGS-C Services.
Customer Instructions
5. Customer Responsibilities as Controller
Where the Customer acts as the controller or equivalent responsible business, the Customer is responsible for determining that its use of personal information through SPRINGS-C is lawful.
Depending on applicable law, Customer responsibilities may include:
- determining lawful purposes for processing;
- establishing an appropriate legal basis;
- providing required privacy notices;
- obtaining required consents;
- responding to privacy rights;
- limiting collection to appropriate information;
- maintaining accurate information;
- determining appropriate retention;
- managing Authorized Users;
- configuring permissions;
- determining whether sensitive information should be processed;
- evaluating integrations;
- complying with employment and workplace privacy requirements;
- complying with laws applicable to the Customer's own customers, employees, contractors, and other individuals.
SPRINGS-C does not determine the Customer's legal basis for collecting information about its own customers, employees, contractors, or other data subjects.
6. Processing Under Customer Instructions
Where SPRINGS-C acts as a processor or service provider, SPRINGS-C processes Customer Personal Data to provide, secure, maintain, support, and improve the contracted Services according to the applicable agreement and the Customer's documented instructions.
Documented instructions may include:
- the applicable commercial agreement;
- Order Form;
- Data Processing Agreement;
- product configuration;
- Authorized User actions;
- API instructions;
- integration configuration;
- support requests;
- other documented directions permitted by the applicable agreement.
SPRINGS-C may determine technical and organizational methods reasonably necessary to operate the Services while remaining within the scope of the Customer's instructions and applicable law.
If SPRINGS-C believes that an instruction would violate applicable data-protection law, SPRINGS-C may inform the Customer and may suspend the affected processing to the extent reasonably necessary while the issue is reviewed.
Processing Details
7. Subject Matter of Processing
The subject matter of processing is the provision of the SPRINGS-C CRM and operations platform and any related implementation, configuration, support, integration, maintenance, and other Services purchased by the Customer.
8. Duration of Processing
The duration of processing generally corresponds to the Customer's use of the applicable SPRINGS-C Services, subject to any additional retention required or permitted by the applicable agreement or law.
Some information may continue to be processed after termination for a limited period where reasonably necessary for:
- data export;
- account closure;
- backup lifecycle;
- billing;
- fraud prevention;
- security;
- dispute resolution;
- legal compliance;
- enforcement of agreements;
- other legitimate obligations.
Specific contractual retention or deletion commitments may be stated in the applicable DPA or other Customer agreement.
9. Nature and Purpose of Customer Data Processing
Depending on the Customer's use of SPRINGS-C, processing may include:
- collection;
- recording;
- organization;
- structuring;
- storage;
- retrieval;
- consultation;
- display;
- transmission;
- synchronization;
- modification;
- analysis;
- reporting;
- export;
- deletion;
- other processing necessary to provide configured Services.
Processing may support purposes such as:
- customer relationship management;
- lead management;
- service-location management;
- job scheduling;
- workforce coordination;
- employee administration;
- time-related operational records;
- customer communications;
- operational finance;
- invoicing records;
- inventory;
- equipment;
- quality control;
- inspections;
- reporting;
- document management;
- workflow management;
- integrations;
- AI-assisted functions;
- other Customer-configured business processes.
10. Categories of Data Subjects
Depending on the Customer's use of SPRINGS-C, Customer Personal Data may concern individuals such as:
- Customer employees;
- cleaners;
- contractors;
- temporary workers;
- job applicants;
- Customer administrators;
- Authorized Users;
- Customer customers;
- prospective customers;
- customer contacts;
- property or service-location contacts;
- suppliers;
- vendors;
- business partners;
- other individuals whose information the Customer lawfully processes through the Services.
Customer Data
11. Categories of Customer Personal Data
Depending on Customer configuration, Customer Personal Data may include:
- Identification and contact data
- Names; business and personal contact details where entered; telephone numbers; email addresses; addresses; job titles; roles.
- Employment and workforce information
- Employee records; contractor records; work assignments; schedules; availability; time-related records; operational performance records; training or qualification information where entered.
- Customer and service information
- Customer contact information; service locations; service requirements; schedules; communications; notes; job history; quality-control information.
- Operational information
- Tasks; work orders; checklists; inspection records; documents; inventory-related records; equipment assignments; internal operational notes.
- Commercial and financial information
- Invoice information; payment status; expenses; pricing records; operational financial information; other Customer-entered commercial records.
- Technical information
- User identifiers; account information; authentication-related information; permission information; logs and operational records.
The exact categories depend on the features selected and information entered by the Customer.
12. Sensitive and Regulated Information
Customers should avoid entering sensitive or specially regulated personal information unless it is reasonably necessary for an authorized business purpose and the Customer has determined that appropriate legal, technical, and contractual safeguards are in place.
Sensitive information may include, depending on applicable law:
- government identification numbers;
- health information;
- biometric information;
- genetic information;
- financial-account credentials;
- information revealing racial or ethnic origin;
- religious or philosophical beliefs;
- trade-union membership;
- sexual orientation;
- highly sensitive employment information;
- other specially protected categories.
SPRINGS-C does not represent through this page that the platform is approved for every category of regulated information.
Organizations that require HIPAA-regulated processing must complete a separate legal, technical, and contractual review before using SPRINGS-C for protected health information.
13. Payment Data and Customer CRM Data
Payment information relating to a Customer's purchase of SPRINGS-C Services is generally processed as part of SPRINGS-C's own commercial, billing, fraud-prevention, and accounting activities rather than as Customer CRM Data processed solely on behalf of the Customer.
Customer-entered payment-status information or financial records concerning the Customer's own business may instead form part of Customer Data.
The classification therefore depends on the relevant processing activity.
Additional information about subscription and payment processing is available in the Privacy Policy and Billing, Cancellation & Refund Policy.
Security and Confidentiality
14. Confidentiality
SPRINGS-C restricts access to Customer Personal Data according to role, authorization, operational need, and applicable security controls.
Personnel or other individuals authorized to process Customer Personal Data are expected to be subject to appropriate confidentiality obligations or equivalent duties.
SPRINGS-C does not authorize personnel to access Customer Personal Data merely because the information is technically accessible through infrastructure.
Access should be limited to purposes reasonably necessary to operate, secure, maintain, support, or otherwise provide the applicable Services.
15. Access Control
SPRINGS-C uses organization-level and role-based access controls designed to restrict access to authorized information and functionality.
Customers are responsible for:
- assigning appropriate roles;
- limiting administrator access;
- reviewing Authorized Users;
- disabling accounts that are no longer required;
- protecting authentication credentials;
- configuring Customer-side permissions appropriately.
SPRINGS-C may apply additional controls to administrative or operational access according to the relevant system and security requirements.
16. Security Measures
SPRINGS-C maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure.
Measures may include, as applicable to the configured systems:
- authentication controls;
- role-based authorization;
- least-privilege practices;
- organization-level access restrictions;
- transport security;
- infrastructure security controls;
- separation of development and production environments;
- controlled change management;
- input validation;
- selected authentication, administrative, security, and operational logging;
- availability and error monitoring;
- backup and recovery processes;
- secure development practices;
- incident-management processes.
The precise measures may depend on the Services, infrastructure, providers, Customer configuration, and applicable agreement.
SPRINGS-C does not claim through this page that any security system eliminates all risk.
17. Encryption
Data transmitted between supported SPRINGS-C interfaces and configured production services is protected using transport-security mechanisms appropriate to the relevant connection.
Production databases, file storage, backups, and other stored information are protected using the security controls available in the configured infrastructure and service environment.
Subprocessors
18. Subprocessors and Service Providers
SPRINGS-C may engage third-party service providers to assist in providing the Services.
Where a provider processes Customer Personal Data on behalf of SPRINGS-C in a processor role, that provider may constitute a subprocessor under applicable privacy law.
Subprocessor categories may include providers supporting:
- hosting;
- infrastructure;
- databases;
- storage;
- authentication;
- communications;
- email;
- security;
- monitoring;
- customer support;
- AI functionality;
- integrations;
- other technical operations required to provide the Services.
The actual providers used may depend on the Services, Customer configuration, region, and technical environment.
Where a binding DPA applies, subprocessor authorization, notification, objection, and contractual requirements will be governed by that DPA and applicable law.
SPRINGS-C does not publish an invented or incomplete list of subprocessors on this page.
Customers conducting formal procurement or privacy review may request current information about relevant subprocessors through the applicable contracting or due-diligence process at [email protected].
19. Subprocessor Obligations
Where SPRINGS-C engages a subprocessor to process Customer Personal Data on behalf of a Customer, SPRINGS-C seeks to impose data-protection obligations appropriate to the processing and applicable contractual requirements.
The applicable obligations may address matters such as:
- confidentiality;
- security;
- processing scope;
- use of information;
- incident handling;
- assistance;
- deletion or return;
- international transfers;
- other obligations required by applicable law or Customer agreement.
The precise obligations depend on the provider relationship and applicable DPA.
International Transfers
20. International Data Processing
SPRINGS-C LLC is established in the United States.
Customer Personal Data may therefore be processed in the United States or in other jurisdictions where SPRINGS-C or its approved service providers operate.
The location of processing may depend on the configured infrastructure, providers, integrations, Customer requirements, and commercial arrangement.
SPRINGS-C does not represent on this page that all Customer Personal Data remains in a single country.
21. International Transfer Safeguards
Where applicable law requires a legal safeguard for an international transfer of Customer Personal Data, SPRINGS-C evaluates appropriate transfer mechanisms based on the relevant jurisdictions, provider, processing activity, Customer agreement, and applicable law.
Depending on the circumstances, an appropriate mechanism may include:
- an adequacy mechanism recognized by applicable law;
- approved standard contractual clauses;
- another recognized contractual transfer mechanism;
- another lawful transfer basis available under applicable law.
The transfer mechanism applicable to a particular Customer should be confirmed in the relevant DPA or commercial documentation.
SPRINGS-C does not state that Standard Contractual Clauses apply to every transfer.
SPRINGS-C does not claim participation in the EU-U.S. Data Privacy Framework unless that participation is separately verified and current.
22. Customer Instructions Concerning Location
Where a Customer requires specific data-location, residency, or international-transfer conditions, those requirements must be reviewed during the commercial and technical process.
A specific data-residency commitment applies only if expressly included in the Customer's applicable written agreement.
The public website does not itself create a data-residency guarantee.
Data-Subject Rights
23. Data-Subject Rights Assistance
Where SPRINGS-C acts as a processor or service provider, the Customer generally remains responsible for responding to requests from individuals concerning Customer Personal Data.
Depending on the Services, applicable law, and DPA, SPRINGS-C may provide reasonable assistance to help the Customer respond to requests involving:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection;
- other applicable privacy rights.
Where an individual contacts SPRINGS-C directly about Customer Personal Data controlled by a Customer, SPRINGS-C may direct the individual to the relevant Customer or otherwise handle the request according to the applicable contractual and legal requirements.
Retention, Export and Deletion
24. Customer Data Access and Export
SPRINGS-C may provide product functionality or reasonable operational processes that allow authorized Customers to access or export Customer Data.
Available export formats, scope, and functionality may depend on the relevant product module and Customer configuration.
Customers are responsible for protecting information after exporting it from SPRINGS-C.
Any additional contractual data-export commitments are governed by the applicable commercial agreement or DPA.
25. Correction and Deletion
Authorized Customers may be able to correct or delete Customer Data through available product functionality.
Where direct functionality is not available or appropriate, SPRINGS-C may assist with reasonable correction or deletion requests according to the applicable Customer agreement.
Deletion from active systems may not cause information to disappear immediately from every backup or security record.
Residual information may remain for a limited period according to backup lifecycle, security, technical, contractual, or legal requirements.
26. Return or Deletion After Termination
After termination or expiration of the relevant Services, Customer Data will be handled according to the applicable commercial agreement, DPA, product functionality, and applicable law.
Depending on the agreement, the Customer may have an opportunity to export relevant Customer Data before final account closure.
Where SPRINGS-C acts as a processor and applicable law or the DPA requires deletion or return of Customer Personal Data after the Services end, SPRINGS-C will handle the data according to those requirements, subject to any lawful retention obligation.
Any specific export window, deletion period, backup lifecycle, or return procedure should be stated in the applicable binding agreement rather than on this public page.
27. Retention
SPRINGS-C does not apply one universal retention period to every category of Customer Data.
Retention depends on factors including:
- Customer instructions;
- duration of the Services;
- Customer configuration;
- data type;
- account status;
- backup lifecycle;
- security requirements;
- contractual obligations;
- dispute-resolution needs;
- legal requirements.
Where SPRINGS-C processes Customer Personal Data solely as a processor, Customer instructions and the applicable DPA are important factors in determining retention.
Where SPRINGS-C processes information for its own controller purposes, retention is governed by the SPRINGS-C Privacy Policy and applicable law.
Security Incidents
28. Personal Data Breaches and Security Incidents
SPRINGS-C maintains processes intended to identify, investigate, contain, and respond to security incidents affecting the Services.
Where SPRINGS-C becomes aware of a personal data breach affecting Customer Personal Data for which a Customer has applicable notification rights, SPRINGS-C will handle notification and cooperation according to applicable law and the relevant DPA or Customer agreement.
Information provided may depend on the nature of the incident and information reasonably available at the time.
SPRINGS-C may continue to provide relevant updates as additional material information becomes available where required by the applicable agreement or law.
29. Customer Incident Responsibilities
Customers are responsible for promptly notifying SPRINGS-C when they become aware of suspected unauthorized use of their SPRINGS-C accounts or credentials.
Customers are also responsible for:
- maintaining appropriate internal access controls;
- protecting credentials;
- managing Authorized Users;
- reviewing access after personnel changes;
- protecting exported Customer Data;
- securing Customer-managed integrations;
- maintaining security for systems outside SPRINGS-C's control.
Compliance Assistance
30. Assistance With Compliance Obligations
Where SPRINGS-C acts as a processor and applicable law or a binding DPA requires assistance, SPRINGS-C may provide reasonable cooperation concerning relevant Customer compliance obligations.
Depending on the circumstances, this may include assistance relating to:
- data-subject requests;
- security;
- personal data breaches;
- data-protection impact assessments;
- regulator inquiries concerning SPRINGS-C processing;
- information reasonably necessary to demonstrate processor compliance.
The scope and method of assistance depend on the processing, Services, applicable law, and Customer agreement.
31. Data Protection Impact Assessments
The Customer is generally responsible for determining whether its use of SPRINGS-C requires a data-protection impact assessment or similar privacy-risk assessment.
Where SPRINGS-C acts as a processor and reasonable information about SPRINGS-C's processing is necessary for that assessment, SPRINGS-C may provide relevant information according to the applicable DPA, Customer agreement, confidentiality requirements, and security considerations.
32. Regulatory Cooperation
SPRINGS-C may cooperate with competent privacy, regulatory, law-enforcement, judicial, or governmental authorities where legally required.
Where a regulatory inquiry concerns processing performed on behalf of a Customer, SPRINGS-C may coordinate with the Customer where legally permitted and appropriate.
Nothing on this page requires SPRINGS-C to disclose privileged information, confidential security information, another Customer's information, or information that SPRINGS-C is legally prohibited from disclosing.
33. Government and Legal Requests
SPRINGS-C may receive legal demands for information, such as subpoenas, court orders, warrants, or other lawful governmental requests.
SPRINGS-C evaluates such requests according to applicable law and may seek clarification, limitation, or other appropriate protection where reasonably available.
Where legally permitted and appropriate, SPRINGS-C may notify an affected Customer of a request concerning that Customer's data.
SPRINGS-C will not intentionally provide Customer Personal Data to a governmental authority merely because an informal request is made where lawful process is required.
34. Audit and Compliance Information
Customers conducting reasonable privacy, security, procurement, or vendor due diligence may request information concerning SPRINGS-C's processing practices.
Where a binding DPA creates audit or information rights, SPRINGS-C will address those rights according to the DPA and applicable law.
The method of demonstrating compliance may take into account:
- confidentiality;
- security;
- protection of other Customers;
- system integrity;
- the scope and sensitivity of the requested information;
- available documentation;
- reasonable operational burden.
This public page does not create an unrestricted right to access SPRINGS-C systems, source code, infrastructure, offices, credentials, or other Customers' information.
35. Security and Due-Diligence Requests
SPRINGS-C may provide appropriate information during a legitimate Customer, procurement, enterprise, or payment-service-provider due-diligence review.
Certain information may be provided only under confidentiality restrictions or through an appropriate review process because public disclosure could create security or privacy risk.
Requests may be sent to [email protected].
AI and Integrations
36. AI Processing
Some SPRINGS-C functionality may use AI-assisted services.
Where Customer Personal Data is processed through an AI-assisted feature, the applicable processing depends on:
- the feature used;
- Customer permissions;
- Customer instructions;
- product configuration;
- configured provider;
- provider terms;
- applicable Customer agreement;
- applicable privacy law.
SPRINGS-C does not state on this page that Customer Personal Data is never retained or used for model improvement by every possible AI provider unless that statement has been verified for the actual configured provider and contractual arrangement.
Where AI providers process Customer Personal Data on behalf of SPRINGS-C, their role will be addressed according to applicable contractual and subprocessor requirements.
37. Automated Actions and Human Control
SPRINGS-C may provide AI-assisted recommendations, summaries, drafts, search functionality, or workflow assistance.
Customers remain responsible for determining how such functionality is used in their business.
Where configured product functionality requires confirmation for critical actions, the relevant Authorized User remains responsible for reviewing the action before confirmation.
Customers should apply appropriate human review when using AI-assisted functionality for employment, financial, legal, safety, customer-facing, or other material decisions.
38. Customer-Authorized Integrations
Customers may authorize integrations between SPRINGS-C and third-party services.
Where an integration is enabled, Customer Data may be transmitted to or received from the third-party service as necessary to provide the integration.
The Customer is responsible for ensuring that it has authority to enable the integration and disclose relevant information.
A third-party integration provider may act independently under its own terms and privacy obligations.
SPRINGS-C does not control the independent processing of a third-party service after information has been lawfully transmitted to that service at the Customer's direction.
39. Data Minimization
Customers should configure SPRINGS-C and enter Customer Personal Data in a manner appropriate to their legitimate business needs.
Customers should avoid collecting or storing personal information that is unnecessary for the intended business process.
SPRINGS-C may design product fields, permissions, and workflows to support structured data use, but the Customer remains responsible for determining which Customer Personal Data it chooses to process.
40. Accuracy of Customer Data
Customers are responsible for the accuracy and quality of Customer Data they submit to the Services.
SPRINGS-C does not independently verify the factual accuracy of ordinary Customer-entered CRM records unless verification is part of a separately agreed Service.
41. Privacy by Configuration
SPRINGS-C may provide configuration options relating to roles, permissions, workflows, integrations, and other processing features.
Customers should review their configuration based on the sensitivity of their data and their own privacy obligations.
The availability of a technical feature does not by itself determine whether the Customer's use of that feature is lawful in every jurisdiction.
Data Processing Agreement
42. Data Processing Agreement
A binding Data Processing Agreement may be entered into where required by applicable privacy law or the Customer's commercial arrangement.
Depending on the applicable legal framework and processing relationship, a DPA may address matters such as:
- subject matter and duration of processing;
- nature and purpose of processing;
- categories of personal data;
- categories of data subjects;
- documented Customer instructions;
- confidentiality;
- security measures;
- subprocessors;
- international transfers;
- data-subject rights assistance;
- personal data breaches;
- compliance assistance;
- deletion or return;
- audit and compliance information;
- other legally required processor obligations.
The executed DPA, rather than this public information page, establishes binding Customer-specific processor obligations.
Customers that require a DPA should contact SPRINGS-C during the commercial or procurement process at [email protected].
43. Order of Precedence
If there is a conflict relating specifically to Customer Personal Data processing, the applicable documents generally operate according to their subject matter.
Unless the relevant agreement states otherwise:
- a negotiated agreement signed by SPRINGS-C LLC and the Customer controls according to its terms;
- an executed Data Processing Agreement controls for matters specifically concerning processing of Customer Personal Data;
- the applicable Order Form controls for Customer-specific commercial scope;
- the Terms of Service apply generally to the Services;
- this Data Processing Information page provides public informational context.
This page does not override a binding Customer agreement.
44. Changes to This Page
SPRINGS-C may update this Data Processing Information page to reflect changes in the Services, processing practices, providers, legal requirements, security practices, or business operations.
The current version will be published with an updated "Last updated" date.
A change to this informational page does not by itself amend an executed Customer DPA unless the applicable agreement expressly provides otherwise.
Contact
45. Contact
Questions about SPRINGS-C data-processing practices or requests for procurement or DPA information may be directed to:
SPRINGS-C has not designated a public Data Protection Officer on this page.
Related Policies and Information
Last updated: August 12, 2026