Privacy Notice
This Privacy Notice explains what personal information Recovery Console collects, why, who we share it with, and what rights you have to control it. Recovery Console is offered by Dorsey-Worx LLC (“Dorsey-Worx”), a US company. The Service is US-only and we do not knowingly market to or onboard organizations outside the United States.
1. Roles — controller vs. processor
For the personal information our customers (HVAC and trade-services businesses) ingest into the Service about their own end-customers, Dorsey-Worx is a service provider / processor acting on the customer’s instructions under our Terms of Service. The customer is the controller / business of record.
For account-holder personal information (the operator-side: your name, email, password hash, audit log of your activity in the console), Dorsey-Worx is the controller.
2. What we collect
From operators (account holders)
- Name, email address, hashed password, and (if enabled) MFA secrets / recovery codes.
- Company name, trade type, and service area as supplied at signup.
- Authentication and audit logs: login IP, user-agent, login outcomes, failed-login counts, security-relevant configuration changes.
- Billing information: handled by our payment processor; we receive only metadata (subscription tier, status, last-4 of the card).
From end-customers (the operator’s customers)
- Phone number, name, email address, service address, job history, and call / SMS interaction transcripts as ingested from the operator’s connected systems (e.g. ServiceTitan, telephony providers).
- Recordings and AI-generated summaries of inbound calls (see AI Disclosure).
3. Why we collect it
| Purpose | Lawful basis (operator data) |
|---|---|
| Provide and operate the Service | Contract |
| Authenticate users + secure accounts | Contract / legitimate interest |
| Detect abuse, fraud, and unauthorized access | Legitimate interest |
| Send transactional email (verification, security alerts) | Contract |
| Comply with legal obligations | Legal obligation |
End-customer data is processed on our customer’s instructions to operate the Service for them; we do not process end-customer data for any other purpose.
4. Who we share with
See the Data residency, retention & sub-processors page for the current list of sub-processors (AWS, Twilio, Resend, Anthropic, ServiceTitan, Sentry). We do not sell personal information and we do not share it for cross-context behavioral advertising.
5. How long we keep it
Per-table retention windows are listed on the Data Policy page. Highlights:
- Operational data (jobs, conversations, dispatch logs): retained for the life of the subscription plus 90 days after cancellation, then deleted.
- Authentication audit logs: retained for 365 days after the related account is closed, to support fraud / incident investigations.
- Backups: encrypted at rest, retained 30 days, then rotated.
6. Your rights
California (CCPA / CPRA)
If you are a California resident you have the right to:
- Know what personal information we hold about you and obtain a copy.
- Delete personal information, subject to the exceptions in Cal. Civ. Code § 1798.105(d) (e.g. fraud / security records, legal compliance).
- Correct inaccurate personal information.
- Opt out of sale / sharing — we do not sell or share for cross-context behavioral advertising, but the right is preserved here for completeness.
- Limit use of sensitive personal information to what is necessary to provide the Service.
- Non-discrimination for exercising any of the above rights.
Operators can self-serve a copy or deletion of their account from Settings → Privacy & data controls. End-customers should request these rights through their provider (the operator) since we are a processor on their behalf; if you are unsure who your provider is, email privacy@dorsey-worx.com and we will help you identify and contact them.
Other US states (Virginia, Colorado, Connecticut, Utah, etc.)
If you reside in a state with an in-force comprehensive privacy law, you generally have access, deletion, correction, and opt-out rights similar to those above. To exercise any of these rights, contact privacy@dorsey-worx.com with proof of residency. We will respond within 45 days.
7. How to exercise rights
Operators: use Settings → Privacy & data controls for self-serve export and deletion. Or email privacy@dorsey-worx.com. We will verify your identity using the email address on file and respond within 45 days (extendable once by an additional 45 days for complex requests).
8. Security
See the Security Policy page for details on how we secure the Service and how to report a vulnerability. In summary: encryption in transit and at rest, least-privilege IAM, multi-tenant isolation enforced at the database row level, and an audit log retained beyond account deletion to support investigations.
9. Children
Recovery Console is a B2B service intended for use by employees of trade-services businesses. We do not knowingly collect personal information from children under 16.
10. International users
Recovery Console is operated from the United States and all data is stored in AWS US East 1. We do not market or onboard customers outside the US, and we do not certify under any cross-border transfer mechanism (e.g. EU–US Data Privacy Framework). EU and UK residents should not use the Service.
11. Changes
We may update this Notice. Material changes will be announced via email to account owners at least 14 days before they take effect, with the new effective date reflected at the top of this page.
12. Contact
Dorsey-Worx LLC · privacy@dorsey-worx.com · legal@dorsey-worx.com