Data Processing Agreement
Last Updated: August 7, 2026
This Data Processing Agreement ("DPA") is entered into between the customer identified on the applicable Holy Estimate account ("Customer") and CST Group Inc., doing business as Holy Estimate ("Holy Estimate," "we," "us," or "our"), and forms part of, and is incorporated by reference into, the Terms of Service between Customer and Holy Estimate (the "Agreement"). This DPA applies automatically to the extent Customer submits Personal Data (defined below) to the Services on behalf of its own clients, employees, or other individuals. If your organization requires a separately countersigned copy of this DPA for procurement purposes, contact us using the information in Section 15 and we will provide one for execution.
1. Definitions
"Personal Data":means any information relating to an identified or identifiable individual that Holy Estimate processes on Customer's behalf in connection with the Services.
"Customer Data": has the meaning given in the Terms of Service, and includes Personal Data submitted to the Services by or on behalf of Customer.
"Process" or "Processing": means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
"Sub-processor": means a third party engaged by Holy Estimate to Process Personal Data in connection with providing the Services.
"Applicable Data Protection Laws": means U.S. federal and state laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and comparable state privacy laws.
"Security Incident": means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data transmitted, stored, or otherwise processed by Holy Estimate.
2. Roles of the Parties
As between the parties, Customer is the business that determines the purposes and means of processing Personal Data it submits to the Services, and Holy Estimate acts as a service provider/processor that processes Personal Data solely on Customer's behalf and for the purpose of providing the Services. Holy Estimate will not sell or share Personal Data processed under this DPA, and will not retain, use, or disclose it for any purpose other than providing the Services, as instructed by Customer, or as otherwise permitted by Applicable Data Protection Laws.
3. Details of Processing
The subject matter, duration, nature, purpose, and categories of Personal Data and data subjects are described below:
Subject Matter
Holy Estimate's provision of a cloud-based estimating software platform to Customer.
Duration
The term of Customer's subscription under the Agreement, plus any retention period described in Section 4 of our Privacy Policy or Section 10 of this DPA.
Nature and Purpose
Hosting, storage, and processing of Customer Data as necessary to provide, maintain, secure, and support the Services.
Categories of Personal Data
Names, addresses, phone numbers, and email addresses of Customer's clients and contacts; project and estimate details; photos and documents Customer uploads; and account information of Customer's authorized users.
Categories of Data Subjects
Customer's clients and business contacts whose information Customer enters into the Services, and Customer's own personnel who use the Services.
4. Processing Instructions
Holy Estimate will process Personal Data only in accordance with Customer's documented instructions, which include instructions given through Customer's configuration and use of the Services and instructions set out in the Agreement and this DPA, unless otherwise required by applicable law. If Holy Estimate is required by law to process Personal Data other than as instructed, Holy Estimate will notify Customer before doing so, unless the law prohibits such notice.
5. Confidentiality
Holy Estimate limits access to Customer Data to personnel and contractors who need such access to provide or support the Services, and requires such personnel to be subject to confidentiality obligations covering Customer Data.
6. Security Measures
Holy Estimate maintains administrative, technical, and physical safeguards designed to protect Customer Data, consistent with the measures described in our Security Overview. These measures are designed to reduce risk but, as with any technology, no method of transmission or storage can be guaranteed to be completely secure.
7. Sub-processors
Customer provides general authorization for Holy Estimate to engage Sub-processors to support the Services. As of the date above, our current Sub-processors are:
Vercel Inc.
Website and application hosting infrastructure.
Stripe, Inc.
Payment processing for subscription billing.
Each Sub-processor is bound by data protection obligations materially similar to those in this DPA. If Holy Estimate engages a new Sub-processor that will process Customer Data, we will provide reasonable advance notice (for example, by updating this page and revising the "Last Updated" date, or by direct notice for material changes). If Customer reasonably objects to a new Sub-processor on data protection grounds within ten (10) business days of notice, the parties will work in good faith to address the objection; if unresolved, Customer's sole remedy is to terminate the affected subscription in accordance with the Agreement.
8. Requests from Individuals
If Holy Estimate receives a request directly from an individual seeking to exercise rights regarding Personal Data that Holy Estimate processes on Customer's behalf (such as a request for access, correction, or deletion), Holy Estimate will promptly notify Customer and will not respond directly other than to acknowledge receipt and direct the individual to Customer, unless legally required to do otherwise. Holy Estimate will provide reasonable assistance to help Customer respond to such requests, including through account functionality that allows Customer to access, correct, export, or delete Customer Data directly.
9. Security Incident Notification
If Holy Estimate becomes aware of a confirmed Security Incident affecting Customer Data, we will notify Customer without undue delay, and in any event within five (5) business days of confirming the incident, and will provide information reasonably available to us to help Customer meet its own notification obligations under Applicable Data Protection Laws.
10. Return or Deletion of Customer Data
Upon termination or expiration of Customer's subscription, Holy Estimate will make Customer Data available for export for a reasonable period, and will thereafter delete or anonymize Customer Data within our standard retention and backup cycles, except where retention is required by law or for legitimate business purposes such as billing records, dispute resolution, or fraud prevention.
11. Audits and Assessments
Upon reasonable written request, no more than once per twelve-month period, Holy Estimate will make available information reasonably necessary to demonstrate compliance with this DPA, such as a summary of our security practices. On-site audits are not offered as a standard practice; if Customer has a specific compliance need requiring one, contact us to discuss options.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service.
13. Term
This DPA remains in effect for as long as Holy Estimate processes Personal Data on Customer's behalf under the Agreement.
14. Governing Law
This DPA is governed by the laws of the State of New York, consistent with the governing law provision of the Terms of Service.
15. Contact Us
Questions about this DPA, or requests for a countersigned copy, can be directed to:
CST Group Inc., d/b/a Holy Estimate
14923 State Route 30, PO Box 848
Malone, NY 12953
Phone: 518-483-4100 (NY) | 941-249-3520 (FL) | Toll-Free: 877-954-4100
Email: support@cstsupport.com