Montes Software LLC
FittingsOS Data Processing Agreement
Version 2026.09.21-1 · Effective September 21, 2026
This Data Processing Agreement (this “DPA”) is entered into by and between Montes Software LLC, a California limited liability company doing business as FittingsOS (“Provider”), and the Customer organization on whose behalf the Software is used, together with each Authorized User to the extent that user is authorized to bind Customer or is otherwise using the Software (“Customer”).
This DPA forms part of the FittingsOS Terms of Service (the “Terms”). In case of conflict regarding Personal Data processing or information security, this DPA controls over the Terms. An executed Master Software License and Services Agreement (“MSA”) and any DPA attached to that MSA, if any, control as between Provider and that Customer legal entity to the extent of conflict with this public DPA.
By checking the agreement box at sign-in, executing the click-wrap, or continuing to use the Software after a published version of this DPA that you have accepted, you agree to this DPA. If you lack authority to bind the Customer organization, you are still bound in your personal capacity as an Authorized User with respect to your own use, and you will not submit Personal Data you are not authorized to submit.
Provider is not SOC 2, ISO 27001, or HITRUST certified. This DPA is not an attestation report and does not claim AS9100, Nadcap, or ISO certification of any shop.
Effective date: September 21, 2026. DPA version: 2026.09.21-1. Related Privacy Policy version: 2026.09.21-1.
1. Definitions
“Applicable Data Protection Law” means privacy and data protection laws applicable to the processing of Personal Data under the Terms, including as applicable the California Consumer Privacy Act as amended by the CPRA (“CCPA”), other U.S. state privacy laws, and, if applicable, the EU/UK GDPR.
“Personal Data” means any Customer Data relating to an identified or identifiable natural person that Provider processes on behalf of Customer in connection with the Software.
“Process” / “Processing” means any operation performed on Personal Data, whether or not by automated means.
“Security Incident” means confirmed unauthorized access to, or acquisition of, Personal Data or Customer Data in Provider’s possession or control that compromises the confidentiality of such data, excluding unsuccessful attempts (for example, pings and port scans) and incidents solely within Customer-controlled infrastructure with no Provider involvement.
“Subprocessor” means a third party engaged by Provider to Process Personal Data on behalf of Customer.
Other capitalized terms have the meanings in the Terms.
2. Roles of the parties
Customer as controller / business. Customer determines the purposes and means of Processing Personal Data that Customer stores in the Software. Customer is responsible for the accuracy of Personal Data, for providing notices, and for obtaining consents where required, including as an employer.
Provider as processor / service provider. Provider Processes Personal Data only: (a) to provide the Software and related support; (b) as documented in the Terms and this DPA; (c) as further reasonably instructed by Customer in writing, provided the instructions are consistent with the Terms; and (d) as required by law (in which case Provider will notify Customer unless legally prohibited).
CCPA service provider. To the extent CCPA applies, Provider is a “service provider.” Provider shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data outside the business relationship or for any purpose other than the business purposes specified in the Terms and this DPA; or (c) combine Personal Data with personal information from other sources except as permitted by CCPA for service providers. Provider certifies it understands these restrictions.
Customer-hosted / hybrid deployments. Where Software components run in Customer’s environment and Provider does not host Production Customer Data, Provider’s Processing of Personal Data is limited to incidental access during support (for example, screen shares or log snippets Customer chooses to provide). Customer remains primarily responsible for securing its environment.
Website inquiries. Personal information submitted on the public marketing form is collected by Provider as a business (see the Privacy Policy), not as a processor of Customer Data. That inquiry is not Customer Data in the Software until a Customer account stores it.
3. Nature, purpose, and duration of processing
Subject matter: provision of FittingsOS Software and support.
Duration: the term of Customer’s access under the Terms or MSA, plus limited transition, backup, and legal-hold retention as described herein.
Nature: storage, retrieval, transmission, structuring, backup (if hosted), support access, and security logging.
Purpose: enable the Customer’s ERP, QMS, calibration, and related shop operations as configured by Customer.
Categories of data subjects: Customer employees, contractors, and Authorized Users; potentially suppliers’ or customers’ contact persons if Customer stores such data.
Categories of Personal Data: names, usernames, work email and phone, role and training records, audit-trail identifiers; optionally other HR-related fields Customer configures.
Sensitive data: not required for core ERP. Customer shall not submit government ID numbers, health data, or similar unless a written amendment and additional controls are agreed.
Export-controlled data: may appear in job or quality records Customer stores; classification and lawful handling are Customer’s responsibility. Provider is not the Empowered Official. Export-controlled technical data, gold NC, and machine tapes are intended to remain on the Customer/shop origin and off the public cloud.
4. Provider obligations
Provider shall Process Personal Data only on documented instructions from Customer, including the Terms, this DPA, and Customer’s configuration of the Software.
Provider shall ensure persons authorized to Process Personal Data are bound by confidentiality obligations.
Provider shall implement the security measures described in Section 9 and on /security. Those descriptions are posture, not a certification.
Provider shall not engage Subprocessors except as provided in Section 6.
Taking into account the nature of Processing, Provider shall assist Customer by appropriate technical and organizational measures, insofar as possible, for Customer’s obligations to respond to data-subject requests. Provider will not respond directly to data subjects about Customer Data except to redirect them to Customer, unless legally required.
Provider shall assist Customer with data-protection impact assessments and consultations with supervisory authorities, upon reasonable written request. Material effort may be charged at then-current professional-services rates if an MSA so provides; otherwise, Provider will provide commercially reasonable assistance.
Upon termination, Provider shall delete or return Personal Data in Provider’s hosted possession as set forth in Section 10, except for archival copies retained under legal hold or as required by law.
Provider shall make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as set forth in Section 8.
Provider shall inform Customer if, in Provider’s opinion, an instruction infringes Applicable Data Protection Law, without obligation to provide legal advice.
5. Customer obligations
Customer shall not instruct Provider to Process Personal Data in violation of Applicable Data Protection Law.
Customer shall not upload export-controlled technical data, gold NC programs, or classified information to a public form or to a hosted surface that is not designated for that data.
Customer is solely responsible for its quality system, certificates, Empowered Official function, and employee notices (including biometric notices if Customer enables those features).
Customer shall configure roles and seats so that only Authorized Users have access, and shall promptly disable accounts of persons who leave.
Customer shall not submit another person’s biometric identifiers without a lawful basis.
6. Subprocessors
Customer authorizes Provider to engage Subprocessors to deliver the Software. The current list is published at /security and includes, as applicable: Vercel (shop UI hosting), Cloudflare (DNS, WAF, API tunneling, Turnstile), GitHub (source control and CI), Tailscale (remote access as applicable), and Resend (transactional email when outbound email is enabled).
Provider shall impose written confidentiality and data-protection terms on Subprocessors no less protective of Personal Data than this DPA in all material respects, given the service each performs.
Provider remains responsible for Subprocessor performance as to Personal Data Processor obligations under this DPA.
Provider will keep the public /security list current. Continued use of the Software after a posted Subprocessor update constitutes authorization of that Subprocessor. If Customer objects to a new Subprocessor on reasonable data-protection grounds in writing within fifteen (15) days of posting, the parties will discuss a commercially reasonable alternative; if none exists, Customer’s sole remedy is to stop using the affected feature or terminate the affected hosted service under the Terms.
7. Security incidents
Provider shall notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data Provider hosts, and in any event within seventy-two (72) hours of confirmed awareness, unless a shorter period is required by law. Notification will describe, to the extent known: the nature of the incident, the categories of data and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
Provider shall reasonably cooperate with Customer’s incident-response and notification obligations. Provider’s notification is not an admission of fault.
Customer is responsible for incidents originating in Customer-controlled infrastructure, shop-origin systems, or user credentials Customer failed to protect.
8. Audits
Upon written request not more than once per twelve (12) months (unless a Security Incident or regulator requires more), Provider shall make available a written summary of relevant security controls. Because Provider is not currently SOC 2 certified, Provider does not promise an SOC 2 Type I or Type II report.
If Applicable Data Protection Law requires a further audit, Customer may conduct a remote audit of Provider’s relevant policies on reasonable notice, during business hours, subject to confidentiality, and without unreasonably disrupting operations. On-site audits, if required by law and not reasonably satisfied remotely, are at Customer’s expense and require a mutually agreed scope.
Provider may satisfy audit requests by providing current public posture information at /security plus confidential summaries under NDA.
9. Security measures
Provider maintains measures designed to protect Personal Data, including as applicable: TLS for public traffic; security headers and CSP on hosted surfaces; httpOnly session cookies on hosted sign-in; tenant isolation by organization identifier with row-level security on org-scoped tables; rate limiting and abuse controls; and architectural separation intended to keep export-controlled technical data and gold NC off the public cloud.
These measures are described on /security. They may change as the product evolves, provided the overall level of protection is not materially reduced without notice via a DPA / TERMS_VERSION update where the change is material to Personal Data.
No measure guarantees absolute security. Customer remains responsible for endpoint security, account hygiene, and shop-origin systems.
10. Return and deletion
Upon termination of hosted access, Customer may export Customer Data then available through the Software’s ordinary export features, if any, during a commercially reasonable wind-down not to exceed thirty (30) days unless an MSA provides otherwise.
Thereafter Provider shall delete hosted Customer Data from production systems within a commercially reasonable period, except: (a) backup copies that expire on the backup rotation; (b) records Provider must retain by law; (c) Terms-acceptance and security logs Provider holds as a business; and (d) data on Customer-controlled shop-origin systems, which Customer deletes itself.
Provider is not obligated to delete data it does not host.
11. International transfers
The Software is operated from the United States. Customer instructs Provider to Process Personal Data in the United States. If GDPR applies to a transfer, the parties will execute standard contractual clauses or another lawful transfer mechanism upon reasonable request. Until then, Customer is responsible for assessing whether its use of a U.S. hosted service is lawful for its data.
12. Liability
Each party’s liability under this DPA is subject to the limitation of liability, warranty disclaimer, and indemnity in the Terms, except to the extent Applicable Data Protection Law prohibits that limitation as to a particular claim.
Provider’s processing of Customer Data does not make Provider the employer, the quality manager, or the Empowered Official.
13. Updates; re-agreement; agreement by use
Provider may update this DPA. Material changes will be published at /dpa with a new DPA version and will bump TERMS_VERSION. Authorized Users must re-execute the click-wrap before further use of the Software.
Continued use of the Software after you have accepted a given DPA version constitutes ongoing assent to that version until a new version requires re-execution.
If you do not agree to an updated DPA, do not sign in and do not use the Software. Refusal means you may not use the Software.
14. Contact
Data-protection contact: security@fittingsos.com. Security reports: security@fittingsos.com. Provider: Montes Software LLC, Los Angeles County, California, operating fittingsos.com.
Do not send export-controlled technical data, prints, or NC programs to those mailboxes.
This DPA is the processing contract for Customer Data. It is not legal advice to Customer.
