Legal
Data Processing Information
This page provides general information about how Vertex Commercial ("Vertex Commercial," "we," "us," or "our") approaches the processing of personal information in connection with the Vertex Commercial CRM and operations platform.
Vertex Commercial provides business software to cleaning companies and related organizations. Customers may use the platform to process information concerning their own customers, employees, cleaners, contractors, applicants, suppliers, contacts, service locations, and other business relationships.
Depending on the processing activity, Vertex Commercial may act as a controller, processor, service provider, or equivalent role under applicable privacy law.
This page is provided for transparency and customer due diligence. It is not itself a Data Processing Agreement ("DPA") and does not replace any binding DPA, Order Form, subscription agreement, or other contract between Vertex Commercial and a Customer.
Where a binding DPA is required by applicable law or agreed as part of a Customer's commercial relationship, the executed DPA governs the applicable processing and takes precedence over this informational page in the event of a conflict.
- Last updated
- August 12, 2026
- Applies to
- vertexcommercial.io
- Provided by
- Vertex Commercial
This page is provided for transparency and customer due diligence. It is not itself a Data Processing Agreement and does not replace any binding agreement between Vertex Commercial and a Customer.
Data-Processing Roles
1. Vertex Commercial
The Vertex Commercial Services are provided by:
- Legal entity
- Vertex Commercial
- Entity ID
- 0008102431
- Address
- 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States
- [email protected]
- Phone
- +1 (505) 298-3585
- Website
- https://vertexcommercial.io
2. Understanding Our Data-Processing Roles
Privacy laws assign different responsibilities depending on who determines why and how personal information is processed.
The applicable role therefore depends on the specific processing activity rather than on a single label applied to the entire Vertex Commercial relationship.
3. When Vertex Commercial Acts as a Controller
Vertex Commercial generally acts as a controller or equivalent responsible business when Vertex Commercial determines the purposes of processing for its own business operations.
Examples may include processing relating to:
- website visitors;
- Contact submissions;
- Demo requests;
- Solution Quiz submissions;
- prospective customers;
- commercial communications;
- Customer account administration;
- Customer administrative contacts;
- subscription management;
- invoicing;
- billing;
- payment administration;
- refund administration;
- fraud prevention;
- security monitoring;
- Vertex Commercial support records;
- legal and compliance activities;
- Vertex Commercial's own business records.
For these activities, Vertex Commercial determines the purposes of processing and handles the information according to its Privacy Policy and applicable law.
4. When Vertex Commercial Acts as a Processor or Service Provider
A Customer may enter personal information into the Vertex Commercial platform as part of the Customer's own business operations.
Where Vertex Commercial processes that information on behalf of the Customer and according to the Customer's documented instructions, Vertex Commercial may act as a processor, service provider, or equivalent role under applicable privacy law.
In this context, the Customer generally determines the purposes for which the Customer Data is processed.
The exact legal role depends on the processing activity, applicable privacy law, and the applicable contractual arrangement.
Vertex Commercial does not become the owner of Customer Data merely because the information is processed through the Vertex Commercial Services.
Customer Instructions
5. Customer Responsibilities as Controller
Where the Customer acts as the controller or equivalent responsible business, the Customer is responsible for determining that its use of personal information through Vertex Commercial is lawful.
Depending on applicable law, Customer responsibilities may include:
- determining lawful purposes for processing;
- establishing an appropriate legal basis;
- providing required privacy notices;
- obtaining required consents;
- responding to privacy rights;
- limiting collection to appropriate information;
- maintaining accurate information;
- determining appropriate retention;
- managing Authorized Users;
- configuring permissions;
- determining whether sensitive information should be processed;
- evaluating integrations;
- complying with employment and workplace privacy requirements;
- complying with laws applicable to the Customer's own customers, employees, contractors, and other individuals.
Vertex Commercial does not determine the Customer's legal basis for collecting information about its own customers, employees, contractors, or other data subjects.
6. Processing Under Customer Instructions
Where Vertex Commercial acts as a processor or service provider, Vertex Commercial processes Customer Personal Data to provide, secure, maintain, support, and improve the contracted Services according to the applicable agreement and the Customer's documented instructions.
Documented instructions may include:
- the applicable commercial agreement;
- Order Form;
- Data Processing Agreement;
- product configuration;
- Authorized User actions;
- API instructions;
- integration configuration;
- support requests;
- other documented directions permitted by the applicable agreement.
Vertex Commercial may determine technical and organizational methods reasonably necessary to operate the Services while remaining within the scope of the Customer's instructions and applicable law.
If Vertex Commercial believes that an instruction would violate applicable data-protection law, Vertex Commercial may inform the Customer and may suspend the affected processing to the extent reasonably necessary while the issue is reviewed.
Processing Details
7. Subject Matter of Processing
The subject matter of processing is the provision of the Vertex Commercial CRM and operations platform and any related implementation, configuration, support, integration, maintenance, and other Services purchased by the Customer.
8. Duration of Processing
The duration of processing generally corresponds to the Customer's use of the applicable Vertex Commercial Services, subject to any additional retention required or permitted by the applicable agreement or law.
Some information may continue to be processed after termination for a limited period where reasonably necessary for:
- data export;
- account closure;
- backup lifecycle;
- billing;
- fraud prevention;
- security;
- dispute resolution;
- legal compliance;
- enforcement of agreements;
- other legitimate obligations.
Specific contractual retention or deletion commitments may be stated in the applicable DPA or other Customer agreement.
9. Nature and Purpose of Customer Data Processing
Depending on the Customer's use of Vertex Commercial, processing may include:
- collection;
- recording;
- organization;
- structuring;
- storage;
- retrieval;
- consultation;
- display;
- transmission;
- synchronization;
- modification;
- analysis;
- reporting;
- export;
- deletion;
- other processing necessary to provide configured Services.
Processing may support purposes such as:
- customer relationship management;
- lead management;
- service-location management;
- job scheduling;
- workforce coordination;
- employee administration;
- time-related operational records;
- customer communications;
- operational finance;
- invoicing records;
- inventory;
- equipment;
- quality control;
- inspections;
- reporting;
- document management;
- workflow management;
- integrations;
- AI-assisted functions;
- other Customer-configured business processes.
10. Categories of Data Subjects
Depending on the Customer's use of Vertex Commercial, Customer Personal Data may concern individuals such as:
- Customer employees;
- cleaners;
- contractors;
- temporary workers;
- job applicants;
- Customer administrators;
- Authorized Users;
- Customer customers;
- prospective customers;
- customer contacts;
- property or service-location contacts;
- suppliers;
- vendors;
- business partners;
- other individuals whose information the Customer lawfully processes through the Services.
Customer Data
11. Categories of Customer Personal Data
Depending on Customer configuration, Customer Personal Data may include:
- Identification and contact data
- Names; business and personal contact details where entered; telephone numbers; email addresses; addresses; job titles; roles.
- Employment and workforce information
- Employee records; contractor records; work assignments; schedules; availability; time-related records; operational performance records; training or qualification information where entered.
- Customer and service information
- Customer contact information; service locations; service requirements; schedules; communications; notes; job history; quality-control information.
- Operational information
- Tasks; work orders; checklists; inspection records; documents; inventory-related records; equipment assignments; internal operational notes.
- Commercial and financial information
- Invoice information; payment status; expenses; pricing records; operational financial information; other Customer-entered commercial records.
- Technical information
- User identifiers; account information; authentication-related information; permission information; logs and operational records.
The exact categories depend on the features selected and information entered by the Customer.
12. Sensitive and Regulated Information
Customers should avoid entering sensitive or specially regulated personal information unless it is reasonably necessary for an authorized business purpose and the Customer has determined that appropriate legal, technical, and contractual safeguards are in place.
Sensitive information may include, depending on applicable law:
- government identification numbers;
- health information;
- biometric information;
- genetic information;
- financial-account credentials;
- information revealing racial or ethnic origin;
- religious or philosophical beliefs;
- trade-union membership;
- sexual orientation;
- highly sensitive employment information;
- other specially protected categories.
Vertex Commercial does not represent through this page that the platform is approved for every category of regulated information.
Organizations that require HIPAA-regulated processing must complete a separate legal, technical, and contractual review before using Vertex Commercial for protected health information.
13. Payment Data and Customer CRM Data
Payment information relating to a Customer's purchase of Vertex Commercial Services is generally processed as part of Vertex Commercial's own commercial, billing, fraud-prevention, and accounting activities rather than as Customer CRM Data processed solely on behalf of the Customer.
Customer-entered payment-status information or financial records concerning the Customer's own business may instead form part of Customer Data.
The classification therefore depends on the relevant processing activity.
Additional information about subscription and payment processing is available in the Privacy Policy and Billing, Cancellation & Refund Policy.
Security and Confidentiality
14. Confidentiality
Vertex Commercial restricts access to Customer Personal Data according to role, authorization, operational need, and applicable security controls.
Personnel or other individuals authorized to process Customer Personal Data are expected to be subject to appropriate confidentiality obligations or equivalent duties.
Vertex Commercial does not authorize personnel to access Customer Personal Data merely because the information is technically accessible through infrastructure.
Access should be limited to purposes reasonably necessary to operate, secure, maintain, support, or otherwise provide the applicable Services.
15. Access Control
Vertex Commercial uses organization-level and role-based access controls designed to restrict access to authorized information and functionality.
Customers are responsible for:
- assigning appropriate roles;
- limiting administrator access;
- reviewing Authorized Users;
- disabling accounts that are no longer required;
- protecting authentication credentials;
- configuring Customer-side permissions appropriately.
Vertex Commercial may apply additional controls to administrative or operational access according to the relevant system and security requirements.
16. Security Measures
Vertex Commercial maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure.
Measures may include, as applicable to the configured systems:
- authentication controls;
- role-based authorization;
- least-privilege practices;
- organization-level access restrictions;
- transport security;
- infrastructure security controls;
- separation of development and production environments;
- controlled change management;
- input validation;
- selected authentication, administrative, security, and operational logging;
- availability and error monitoring;
- backup and recovery processes;
- secure development practices;
- incident-management processes.
The precise measures may depend on the Services, infrastructure, providers, Customer configuration, and applicable agreement.
Vertex Commercial does not claim through this page that any security system eliminates all risk.
17. Encryption
Data transmitted between supported Vertex Commercial interfaces and configured production services is protected using transport-security mechanisms appropriate to the relevant connection.
Production databases, file storage, backups, and other stored information are protected using the security controls available in the configured infrastructure and service environment.
Subprocessors
18. Subprocessors and Service Providers
Vertex Commercial may engage third-party service providers to assist in providing the Services.
Where a provider processes Customer Personal Data on behalf of Vertex Commercial in a processor role, that provider may constitute a subprocessor under applicable privacy law.
Subprocessor categories may include providers supporting:
- hosting;
- infrastructure;
- databases;
- storage;
- authentication;
- communications;
- email;
- security;
- monitoring;
- customer support;
- AI functionality;
- integrations;
- other technical operations required to provide the Services.
The actual providers used may depend on the Services, Customer configuration, region, and technical environment.
Where a binding DPA applies, subprocessor authorization, notification, objection, and contractual requirements will be governed by that DPA and applicable law.
Vertex Commercial does not publish an invented or incomplete list of subprocessors on this page.
Customers conducting formal procurement or privacy review may request current information about relevant subprocessors through the applicable contracting or due-diligence process at [email protected].
19. Subprocessor Obligations
Where Vertex Commercial engages a subprocessor to process Customer Personal Data on behalf of a Customer, Vertex Commercial seeks to impose data-protection obligations appropriate to the processing and applicable contractual requirements.
The applicable obligations may address matters such as:
- confidentiality;
- security;
- processing scope;
- use of information;
- incident handling;
- assistance;
- deletion or return;
- international transfers;
- other obligations required by applicable law or Customer agreement.
The precise obligations depend on the provider relationship and applicable DPA.
International Transfers
20. International Data Processing
Vertex Commercial is established in the United States.
Customer Personal Data may therefore be processed in the United States or in other jurisdictions where Vertex Commercial or its approved service providers operate.
The location of processing may depend on the configured infrastructure, providers, integrations, Customer requirements, and commercial arrangement.
Vertex Commercial does not represent on this page that all Customer Personal Data remains in a single country.
21. International Transfer Safeguards
Where applicable law requires a legal safeguard for an international transfer of Customer Personal Data, Vertex Commercial evaluates appropriate transfer mechanisms based on the relevant jurisdictions, provider, processing activity, Customer agreement, and applicable law.
Depending on the circumstances, an appropriate mechanism may include:
- an adequacy mechanism recognized by applicable law;
- approved standard contractual clauses;
- another recognized contractual transfer mechanism;
- another lawful transfer basis available under applicable law.
The transfer mechanism applicable to a particular Customer should be confirmed in the relevant DPA or commercial documentation.
Vertex Commercial does not state that Standard Contractual Clauses apply to every transfer.
Vertex Commercial does not claim participation in the EU-U.S. Data Privacy Framework unless that participation is separately verified and current.
22. Customer Instructions Concerning Location
Where a Customer requires specific data-location, residency, or international-transfer conditions, those requirements must be reviewed during the commercial and technical process.
A specific data-residency commitment applies only if expressly included in the Customer's applicable written agreement.
The public website does not itself create a data-residency guarantee.
Data-Subject Rights
23. Data-Subject Rights Assistance
Where Vertex Commercial acts as a processor or service provider, the Customer generally remains responsible for responding to requests from individuals concerning Customer Personal Data.
Depending on the Services, applicable law, and DPA, Vertex Commercial may provide reasonable assistance to help the Customer respond to requests involving:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection;
- other applicable privacy rights.
Where an individual contacts Vertex Commercial directly about Customer Personal Data controlled by a Customer, Vertex Commercial may direct the individual to the relevant Customer or otherwise handle the request according to the applicable contractual and legal requirements.
Retention, Export and Deletion
24. Customer Data Access and Export
Vertex Commercial may provide product functionality or reasonable operational processes that allow authorized Customers to access or export Customer Data.
Available export formats, scope, and functionality may depend on the relevant product module and Customer configuration.
Customers are responsible for protecting information after exporting it from Vertex Commercial.
Any additional contractual data-export commitments are governed by the applicable commercial agreement or DPA.
25. Correction and Deletion
Authorized Customers may be able to correct or delete Customer Data through available product functionality.
Where direct functionality is not available or appropriate, Vertex Commercial may assist with reasonable correction or deletion requests according to the applicable Customer agreement.
Deletion from active systems may not cause information to disappear immediately from every backup or security record.
Residual information may remain for a limited period according to backup lifecycle, security, technical, contractual, or legal requirements.
26. Return or Deletion After Termination
After termination or expiration of the relevant Services, Customer Data will be handled according to the applicable commercial agreement, DPA, product functionality, and applicable law.
Depending on the agreement, the Customer may have an opportunity to export relevant Customer Data before final account closure.
Where Vertex Commercial acts as a processor and applicable law or the DPA requires deletion or return of Customer Personal Data after the Services end, Vertex Commercial will handle the data according to those requirements, subject to any lawful retention obligation.
Any specific export window, deletion period, backup lifecycle, or return procedure should be stated in the applicable binding agreement rather than on this public page.
27. Retention
Vertex Commercial does not apply one universal retention period to every category of Customer Data.
Retention depends on factors including:
- Customer instructions;
- duration of the Services;
- Customer configuration;
- data type;
- account status;
- backup lifecycle;
- security requirements;
- contractual obligations;
- dispute-resolution needs;
- legal requirements.
Where Vertex Commercial processes Customer Personal Data solely as a processor, Customer instructions and the applicable DPA are important factors in determining retention.
Where Vertex Commercial processes information for its own controller purposes, retention is governed by the Vertex Commercial Privacy Policy and applicable law.
Security Incidents
28. Personal Data Breaches and Security Incidents
Vertex Commercial maintains processes intended to identify, investigate, contain, and respond to security incidents affecting the Services.
Where Vertex Commercial becomes aware of a personal data breach affecting Customer Personal Data for which a Customer has applicable notification rights, Vertex Commercial will handle notification and cooperation according to applicable law and the relevant DPA or Customer agreement.
Information provided may depend on the nature of the incident and information reasonably available at the time.
Vertex Commercial may continue to provide relevant updates as additional material information becomes available where required by the applicable agreement or law.
29. Customer Incident Responsibilities
Customers are responsible for promptly notifying Vertex Commercial when they become aware of suspected unauthorized use of their Vertex Commercial accounts or credentials.
Customers are also responsible for:
- maintaining appropriate internal access controls;
- protecting credentials;
- managing Authorized Users;
- reviewing access after personnel changes;
- protecting exported Customer Data;
- securing Customer-managed integrations;
- maintaining security for systems outside Vertex Commercial's control.
Compliance Assistance
30. Assistance With Compliance Obligations
Where Vertex Commercial acts as a processor and applicable law or a binding DPA requires assistance, Vertex Commercial may provide reasonable cooperation concerning relevant Customer compliance obligations.
Depending on the circumstances, this may include assistance relating to:
- data-subject requests;
- security;
- personal data breaches;
- data-protection impact assessments;
- regulator inquiries concerning Vertex Commercial processing;
- information reasonably necessary to demonstrate processor compliance.
The scope and method of assistance depend on the processing, Services, applicable law, and Customer agreement.
31. Data Protection Impact Assessments
The Customer is generally responsible for determining whether its use of Vertex Commercial requires a data-protection impact assessment or similar privacy-risk assessment.
Where Vertex Commercial acts as a processor and reasonable information about Vertex Commercial's processing is necessary for that assessment, Vertex Commercial may provide relevant information according to the applicable DPA, Customer agreement, confidentiality requirements, and security considerations.
32. Regulatory Cooperation
Vertex Commercial may cooperate with competent privacy, regulatory, law-enforcement, judicial, or governmental authorities where legally required.
Where a regulatory inquiry concerns processing performed on behalf of a Customer, Vertex Commercial may coordinate with the Customer where legally permitted and appropriate.
Nothing on this page requires Vertex Commercial to disclose privileged information, confidential security information, another Customer's information, or information that Vertex Commercial is legally prohibited from disclosing.
33. Government and Legal Requests
Vertex Commercial may receive legal demands for information, such as subpoenas, court orders, warrants, or other lawful governmental requests.
Vertex Commercial evaluates such requests according to applicable law and may seek clarification, limitation, or other appropriate protection where reasonably available.
Where legally permitted and appropriate, Vertex Commercial may notify an affected Customer of a request concerning that Customer's data.
Vertex Commercial will not intentionally provide Customer Personal Data to a governmental authority merely because an informal request is made where lawful process is required.
34. Audit and Compliance Information
Customers conducting reasonable privacy, security, procurement, or vendor due diligence may request information concerning Vertex Commercial's processing practices.
Where a binding DPA creates audit or information rights, Vertex Commercial will address those rights according to the DPA and applicable law.
The method of demonstrating compliance may take into account:
- confidentiality;
- security;
- protection of other Customers;
- system integrity;
- the scope and sensitivity of the requested information;
- available documentation;
- reasonable operational burden.
This public page does not create an unrestricted right to access Vertex Commercial systems, source code, infrastructure, offices, credentials, or other Customers' information.
35. Security and Due-Diligence Requests
Vertex Commercial may provide appropriate information during a legitimate Customer, procurement, enterprise, or payment-service-provider due-diligence review.
Certain information may be provided only under confidentiality restrictions or through an appropriate review process because public disclosure could create security or privacy risk.
Requests may be sent to [email protected].
AI and Integrations
36. AI Processing
Some Vertex Commercial functionality may use AI-assisted services.
Where Customer Personal Data is processed through an AI-assisted feature, the applicable processing depends on:
- the feature used;
- Customer permissions;
- Customer instructions;
- product configuration;
- configured provider;
- provider terms;
- applicable Customer agreement;
- applicable privacy law.
Vertex Commercial does not state on this page that Customer Personal Data is never retained or used for model improvement by every possible AI provider unless that statement has been verified for the actual configured provider and contractual arrangement.
Where AI providers process Customer Personal Data on behalf of Vertex Commercial, their role will be addressed according to applicable contractual and subprocessor requirements.
37. Automated Actions and Human Control
Vertex Commercial may provide AI-assisted recommendations, summaries, drafts, search functionality, or workflow assistance.
Customers remain responsible for determining how such functionality is used in their business.
Where configured product functionality requires confirmation for critical actions, the relevant Authorized User remains responsible for reviewing the action before confirmation.
Customers should apply appropriate human review when using AI-assisted functionality for employment, financial, legal, safety, customer-facing, or other material decisions.
38. Customer-Authorized Integrations
Customers may authorize integrations between Vertex Commercial and third-party services.
Where an integration is enabled, Customer Data may be transmitted to or received from the third-party service as necessary to provide the integration.
The Customer is responsible for ensuring that it has authority to enable the integration and disclose relevant information.
A third-party integration provider may act independently under its own terms and privacy obligations.
Vertex Commercial does not control the independent processing of a third-party service after information has been lawfully transmitted to that service at the Customer's direction.
39. Data Minimization
Customers should configure Vertex Commercial and enter Customer Personal Data in a manner appropriate to their legitimate business needs.
Customers should avoid collecting or storing personal information that is unnecessary for the intended business process.
Vertex Commercial may design product fields, permissions, and workflows to support structured data use, but the Customer remains responsible for determining which Customer Personal Data it chooses to process.
40. Accuracy of Customer Data
Customers are responsible for the accuracy and quality of Customer Data they submit to the Services.
Vertex Commercial does not independently verify the factual accuracy of ordinary Customer-entered CRM records unless verification is part of a separately agreed Service.
41. Privacy by Configuration
Vertex Commercial may provide configuration options relating to roles, permissions, workflows, integrations, and other processing features.
Customers should review their configuration based on the sensitivity of their data and their own privacy obligations.
The availability of a technical feature does not by itself determine whether the Customer's use of that feature is lawful in every jurisdiction.
Data Processing Agreement
42. Data Processing Agreement
A binding Data Processing Agreement may be entered into where required by applicable privacy law or the Customer's commercial arrangement.
Depending on the applicable legal framework and processing relationship, a DPA may address matters such as:
- subject matter and duration of processing;
- nature and purpose of processing;
- categories of personal data;
- categories of data subjects;
- documented Customer instructions;
- confidentiality;
- security measures;
- subprocessors;
- international transfers;
- data-subject rights assistance;
- personal data breaches;
- compliance assistance;
- deletion or return;
- audit and compliance information;
- other legally required processor obligations.
The executed DPA, rather than this public information page, establishes binding Customer-specific processor obligations.
Customers that require a DPA should contact Vertex Commercial during the commercial or procurement process at [email protected].
43. Order of Precedence
If there is a conflict relating specifically to Customer Personal Data processing, the applicable documents generally operate according to their subject matter.
Unless the relevant agreement states otherwise:
- a negotiated agreement signed by Vertex Commercial and the Customer controls according to its terms;
- an executed Data Processing Agreement controls for matters specifically concerning processing of Customer Personal Data;
- the applicable Order Form controls for Customer-specific commercial scope;
- the Terms of Service apply generally to the Services;
- this Data Processing Information page provides public informational context.
This page does not override a binding Customer agreement.
44. Changes to This Page
Vertex Commercial may update this Data Processing Information page to reflect changes in the Services, processing practices, providers, legal requirements, security practices, or business operations.
The current version will be published with an updated "Last updated" date.
A change to this informational page does not by itself amend an executed Customer DPA unless the applicable agreement expressly provides otherwise.
Contact
45. Contact
Questions about Vertex Commercial data-processing practices or requests for procurement or DPA information may be directed to:
Vertex Commercial has not designated a public Data Protection Officer on this page.
Related Policies and Information
Last updated: August 12, 2026