Data Processing Agreement
Last updated: July 13, 2026
Purpose and Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between you (the “Customer”) and Elite Tech Global, LLC, the company behind LogStead (“LogStead,” “we,” or “us”), governing how we process personal data on your behalf when you use the LogStead service available at logstead.app. It supplements our Privacy Policy and Terms of Service. Where this DPA conflicts with those documents on the subject of processing personal data on your behalf, this DPA controls.
This DPA applies to the workplace incident records you enter into LogStead. It does not apply to your account data — your name, email, company details, and billing status — for which we act as the business deciding how the data is used and which our Privacy Policy governs directly.
Roles of the Parties
For the workplace incident records you enter, you are the party that decides what is collected and why — the controller (and, under laws such as the California Consumer Privacy Act, the business). LogStead processes that data only on your behalf and on your instructions — the processor (and CCPA service provider). You are responsible for having the authority and a lawful basis to enter the incident data, including any information about your employees.
Nature and Purpose of Processing
We process the incident data you enter for the sole purpose of providing the LogStead service: generating OSHA Forms 300, 300A, and 301; calculating DART and TRIR rates; producing PDF and CSV exports and electronic-submission files; sending deadline reminders; and otherwise operating the features you use. We do not use your incident data for our own purposes, and we will never use it for advertising or sell, rent, or share it with third parties for marketing.
Categories of Data and Data Subjects
Types of personal data: employee names and job titles, dates of injury or illness, descriptions of what happened and the resulting injury or illness, treatment and outcome information, and days away from work or on restricted duty — the details required to complete OSHA injury and illness records.
Categories of data subjects: your employees and, where applicable, other workers whose workplace injuries or illnesses your organization is required to record.
Our Obligations
We will:
- process the incident data only on your documented instructions, including as set out in this DPA and reflected in your use of the Service, unless we are required to do otherwise by law (in which case we will inform you where legally permitted);
- ensure that personnel authorized to process the data are bound by appropriate obligations of confidentiality;
- implement and maintain the technical and organizational security measures described below;
- assist you, taking into account the nature of the processing, in responding to requests from data subjects and in meeting your own security, breach-notification, and consultation obligations; and
- make available the information reasonably necessary to demonstrate our compliance with this DPA.
Subprocessors
You authorize us to engage the subprocessors below to help provide the Service. Each is bound by data-protection obligations no less protective than those in this DPA, and we remain responsible to you for their performance.
- Supabase — database hosting and authentication. Incident data is stored in a PostgreSQL database with row-level security policies that isolate each organization's data.
- Vercel — application hosting and aggregated usage analytics.
- Lemon Squeezy — subscription payment processing. Lemon Squeezy does not receive your incident data.
- Resend — delivery of transactional emails such as team invitations and deadline reminders.
- Sentry — error monitoring. Error reports may include technical context such as browser type and URL, but not incident content.
If we add or replace a subprocessor that processes incident data, we will update this page. You may object to a new subprocessor for reasonable data-protection grounds by contacting us at the address below; if we cannot accommodate the objection, you may stop using the affected feature or terminate your subscription.
Security Measures
All data transmitted between your browser and LogStead is encrypted using TLS (HTTPS). Our database enforces row-level security (RLS) policies so that each organization can only access its own data. Authentication tokens are managed by Supabase Auth and stored in secure, HTTP-only cookies. OSHA writes flow through authenticated, role-checked server routes rather than direct client access. We review and update these measures as the Service evolves.
Personal Data Breaches
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to incident data we process on your behalf, we will notify you without undue delay and provide the information reasonably available to help you meet any obligation to notify regulators or affected individuals.
Data Subject Requests
If we receive a request from one of your employees or another individual to exercise rights over incident data (such as access, correction, or deletion), we will, unless legally prohibited, direct that request to you, since you are the party responsible for those records. Taking into account the nature of the processing, we will provide reasonable assistance to help you respond.
Location of Processing
LogStead and its subprocessors store and process data in the United States. If you or your data subjects are located elsewhere, you are responsible for ensuring you have a lawful basis for transferring the incident data to us for processing in the United States.
Retention, Return, and Deletion
OSHA requires employers to retain injury and illness records for five years following the year they cover, and LogStead is built to preserve that record of authority — for that reason there is no permanent-purge feature for finalized logs. On termination of your subscription, and subject to that retention requirement and any other legal obligation, we will delete or return the incident data at your request. Where you delete your account, we will remove your personal information within 30 days, though we may retain anonymized or aggregated data that cannot identify you.
Demonstrating Compliance
On reasonable written request, and no more than once per year unless required by a regulator or following a security incident, we will provide the information reasonably necessary to demonstrate our compliance with this DPA. Any such review is subject to confidentiality obligations and must not disrupt the Service or the data of our other customers.
Term
This DPA takes effect when you begin using LogStead to process incident data and remains in force for as long as we process that data on your behalf. Provisions that by their nature should survive termination — including those on retention, deletion, and confidentiality — will continue to apply.
Changes to This DPA
We may update this DPA from time to time. If we make material changes, we will notify you by email or by posting a notice within the application. Your continued use of LogStead after changes take effect constitutes acceptance of the updated DPA.
Contact
Questions about this DPA or how we process data on your behalf? Email us at support@logstead.app, or write to us at the address below.
Elite Tech Global, LLC
7533 S Center View Ct # 5188
West Jordan, Utah 84084
United States