Legal

Data Processing Agreement

Build Assure Limited

Effective date: ⟦DATE⟧ · Version 0.5 · Draft for solicitor review

Draft pending legal review

This is a working draft giving BuildAssure an Article 28-aligned position for customer due-diligence conversations. It has not been reviewed by a solicitor and should not be issued in final form without qualified legal review.

Values shown as ⟦like this⟧ have not been settled yet. For an executable copy, or for a completed security questionnaire, write to buildassureapp@gmail.com.

This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable order form or subscription agreement ("Customer", "Controller") and Build Assure Limited (company number 16843792, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ) ("BuildAssure", "Processor"), and forms part of the agreement between the parties governing Customer's use of the BuildAssure platform (the "Agreement"). It applies whenever BuildAssure processes personal data on behalf of Customer in the course of providing the Service.

1. Definitions

"Data Protection Laws" means all laws relating to data protection and privacy applicable to the processing under the Agreement, including the UK GDPR, the Data Protection Act 2018 (each as amended, including by the Data (Use and Access) Act 2025) and the Privacy and Electronic Communications Regulations 2003. "UK GDPR", "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Sub-processor" means any processor engaged by BuildAssure to process personal data on Customer's behalf. "Service" means the BuildAssure platform and the modules of it made available to Customer under the applicable order form.

2. Subject matter and duration

BuildAssure will process personal data on behalf of Customer for the duration of the Agreement, for the purpose of providing the Service, and will cease processing (subject to Section 11) on termination or expiry of the Agreement.

3. Scope of processing

Details of the processing are set out in Annex 1. In summary, BuildAssure processes personal data that Customer or its authorised users submit into the Service, together with the account and technical data necessary to operate it, strictly to deliver the functionality of the Service.

4. Customer's instructions

BuildAssure will process personal data only on Customer's documented instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by UK law — in which case BuildAssure will inform Customer of that legal requirement before processing, unless prohibited from doing so. Customer instructs BuildAssure to process personal data as necessary to provide the Service in accordance with the Agreement and this DPA. If, in BuildAssure's opinion, an instruction infringes Data Protection Laws, it will inform Customer.

5. Confidentiality

BuildAssure will ensure that any person authorised to process personal data, including employees and contractors, is subject to an appropriate obligation of confidentiality.

6. Security measures

BuildAssure will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to Article 32 of the UK GDPR and the nature of construction compliance and audit data. The measures in place as at the effective date are set out in Annex 2.

7. Sub-processors

Customer provides general authorisation for BuildAssure to engage sub-processors, provided BuildAssure imposes data protection terms on each sub-processor that are no less protective than this DPA and remains fully liable to Customer for each sub-processor's performance. Current sub-processors are listed in Annex 3. BuildAssure will give Customer at least 30 days' advance notice of any intended addition or replacement of a sub-processor, allowing Customer to object on reasonable data-protection grounds; if the objection cannot be resolved in good faith, Customer may terminate the affected part of the Service as its exclusive remedy.

8. Data subject rights

Taking into account the nature of the processing, BuildAssure will provide reasonable assistance to Customer, insofar as this is possible, to enable Customer to respond to requests from data subjects exercising their rights under UK GDPR. Where BuildAssure receives a data subject request relating directly to Customer's data, it will promptly notify Customer and will not respond directly except as instructed or required by law.

9. Personal data breach notification

BuildAssure will notify Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer's personal data, and will provide reasonably available information to assist Customer in meeting its own notification obligations to the ICO and to affected data subjects.

10. Data protection impact assessments

BuildAssure will provide reasonable assistance to Customer with any data protection impact assessment, and any prior consultation with the ICO, which Customer reasonably considers necessary in relation to the processing carried out under this DPA, taking into account the nature of processing and the information available to BuildAssure.

11. Return and deletion of data

On termination or expiry of the Agreement, BuildAssure will, at Customer's election, delete or return all personal data processed on Customer's behalf and delete existing copies, unless UK law requires continued storage. Customer may request a standard export of its tenant's data for 30 days after termination. BuildAssure will then delete or anonymise personal data from active systems within 60 days, after which residual copies persist only in encrypted backups until overwritten in the ordinary backup cycle.

12. Audit rights

BuildAssure will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable notice, confidentiality, and no more than once per year absent a substantiated concern or a personal data breach.

13. International transfers

BuildAssure's primary infrastructure is hosted in the UK (AWS eu-west-2, London). Where a sub-processor processes personal data outside the UK, BuildAssure will ensure an appropriate safeguard is in place — UK adequacy ("data bridge") regulations where applicable, or the UK International Data Transfer Agreement or the International Data Transfer Addendum to the EU Standard Contractual Clauses — supported by a transfer risk assessment applying the test as reworded by the Data (Use and Access) Act 2025.

14. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement, including any separately agreed higher liability cap for data protection claims.

15. Order of precedence

In the event of a conflict between this DPA and the Agreement in relation to the processing of personal data, this DPA prevails.

16. Notices

Notices to BuildAssure under this DPA should be sent to buildassureapp@gmail.com and, where a postal notice is required, to Build Assure Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Annex 1 — Details of processing

Subject matter
Provision of the BuildAssure construction delivery and assurance platform to Customer.
Duration
The term of the Agreement, plus the post-termination export and deletion periods in Section 11.
Nature and purpose
Hosting, storage and processing of the site, audit, inspection, risk and compliance records submitted by Customer's authorised users, so that Customer can manage construction quality, safety and compliance workflows, including AI-assisted features where enabled.
Categories of data subjects
Customer's employees, subcontractors, consultants and other project personnel who are named or referenced in records held in the Service; Customer's authorised users and administrators.
Categories of personal data
Identity and role data (name, work email address, job title, employer, site or project association, permission group); authentication data (hashed credentials, session and access logs); content data submitted by authorised users, which may include free-text entries and mentions naming individuals, photographs and uploaded documents, timestamps and geotags, and digital signatures captured for sign-off workflows; technical data (IP address, device and browser information, product event logs).
Processing operations
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to Customer's other authorised users, transmission to sub-processors listed in Annex 3, restriction, erasure and destruction.
Special category data
Not intentionally processed. Where incidentally present in Customer-submitted content — for example health information within an incident or accident report — it is processed only as instructed by Customer.
Criminal offence data
Not intentionally processed.
Frequency
Continuous for the duration of the Agreement.

Note on records covered: the record types held in the Service include daily site logs and diary entries, audit and inspection findings, corrective and preventive actions, inspection and test plans, quality checklists, trade handovers, risk register entries, lessons-learnt and knowledge-share entries, notifications and delay notices. Personal data arises in these records where they name or identify an individual.

Annex 2 — Technical and organisational security measures

Part A — Measures in place as at the effective date

These are the measures BuildAssure warrants under Section 6.

  • Tenant isolation. Multi-tenant architecture enforced by database-level Row Level Security, logically isolating each Customer's data, with server-side authorisation checks on every request.
  • Encryption. Data encrypted in transit using TLS 1.2 or higher, and encrypted at rest.
  • Data residency. Customer data stored at rest in the United Kingdom (AWS eu-west-2, London).
  • Access control. Role- and permission-based access control within each tenant, restricting visibility by user group; least-privilege administration, with access reviewed and revoked promptly on leaver or role change.
  • Credential handling. Passwords stored using industry-standard one-way hashing; plain-text credentials are never stored.
  • Environment separation. Production separated from development and demonstration environments; live Customer personal data is not used in development or demos.
  • Change control. Changes managed through version control, peer review and controlled deployment, with automated dependency and vulnerability scanning.
  • Incident response. A documented process covering detection, containment, recovery, customer notification and lessons-learnt review.
  • Sub-processor governance. A maintained sub-processor register and written data-processing terms with material suppliers.
  • Backups. Backups managed through the hosting platform, supplemented by Customer-available data exports.

Part B — Planned enhancements

These are not yet implemented and are stated for transparency only. They are not warranted under Section 6 and Customer should not rely on them. BuildAssure will update this Annex as each is completed.

  • Enforcement of multi-factor authentication across administrative and end-user accounts.
  • An independent penetration test, before Tier 1 production rollout.
  • A documented backup restore test, after which BuildAssure will publish contractual recovery point and recovery time objectives. Until that test is complete, BuildAssure makes no contractual recovery commitment.
  • Expanded logging, monitoring and alerting, with a defined retention and review cadence.
  • Cyber Essentials certification.

Part C — Certification position

BuildAssure does not itself hold ISO 27001 or SOC 2 certification and does not claim it. Its principal infrastructure sub-processors are independently certified: Supabase (database, authentication and file storage) holds ISO 27001 and SOC 2 Type II, and Vercel (application hosting) holds ISO 27001 and SOC 2 Type II. Those certifications attest to the providers' own control environments only. They do not extend to BuildAssure's application logic, tenant access rules, administrative practices or internal processes, and BuildAssure does not rely on them as evidence of its own certification. Current attestation reports and certificates are available directly from each provider's trust centre.

Annex 3 — Authorised sub-processors

The following sub-processors are authorised to process Customer personal data. This list is kept current and made available to Customer on request, together with advance notice of any proposed change under Section 7.

Authorised sub-processors
Sub-processorService providedProcessing locationTransfer safeguard
SupabaseDatabase, authentication and file storage underlying the platformAWS eu-west-2 (London, UK)UK-hosted; no restricted transfer
VercelApplication hosting and content deliveryLondon region where configuredUK-hosted where configured; IDTA or Addendum for any processing outside the UK
ResendTransactional and system email deliveryEU/UK region where configuredIDTA or Addendum, plus transfer risk assessment, for any processing outside the UK
AnthropicAI-assisted features (Claude API)United StatesIDTA or Addendum, plus Anthropic's data processing terms
GoogleAI-assisted features (Gemini API)United States, or the Google Cloud region configured for the endpoint in useIDTA or Addendum, plus Google's Cloud Data Processing Addendum

Customer data submitted to either AI provider is processed only to return the requested output for the relevant feature, is limited to the data needed for that feature, and is not used to train the providers' models under their applicable commercial terms. AI output assists a human user and is not used to make final safety-critical or statutory decisions.

No monitoring, analytics or payment sub-processor is currently engaged. Any such engagement will be added to this Annex with advance notice under Section 7.

Known gap — disclosed, not yet in Annex 3

The platform contains a drawing-analysis capability which sends a whole uploaded CAD drawing file and its filename to a separate extraction service. That service is not yet named in Annex 3 of our Data Processing Agreement. Section 7 of that agreement requires us to give Customers at least 30 days' advance notice before adding a sub-processor, and adding this one is subject to that notice.