Legal document
Data Processing Addendum
The agreement that has to exist between a controller and a processor before real data goes into the system, and how your company gets a signed one.
Draft - pending legal review. This text was written by the product team, not by a lawyer, and it is published for comment while the company behind the product is being set up. It is not part of any contract until we say so in writing, and it will change after the legal review.
Square brackets mark a detail that is not decided yet. We would rather leave the gap visible than fill it with something that is not true.
1. What this document is for
When a construction company puts its people, its suppliers and its deliveries into our service, that company is the controller and we are the processor. Article 28 of the GDPR says the two sides need a written agreement, and it lists what has to be in it. That agreement is the Data Processing Addendum, or DPA. It sits on top of the Terms of Service and wins over them on anything about personal data.
Status. The DPA itself is with the legal review and is not published here yet. This page describes what it will contain so that a buyer can see whether it meets their requirements before asking for the draft.
2. What it covers
- Subject, duration, nature and purpose of the processing: running the delivery control service for the customer, for as long as the subscription runs.
- Types of personal data and categories of people: the customer's staff, foremen and receivers on site, supplier contacts, and whoever appears in the documents and photographs that the customer uploads.
- Instructions: we process only on the customer's documented instructions, and we say so if an instruction looks unlawful to us.
- Confidentiality: everyone with access is bound by it, in writing.
- Security: the measures required by Article 32, described concretely rather than as a promise to be careful.
- Help with people's requests: when someone asks the customer for access, correction or deletion, we give the customer the tools and the answers it needs.
- Help with Articles 32 to 36: breach notification, impact assessments, prior consultation.
- End of contract: deletion or return of the data, at the customer's choice, within a stated period.
- Audit: the information needed to demonstrate compliance, and the right to audit on reasonable notice.
3. Subprocessors
The DPA gives us general written authorisation to use the subprocessors listed on the Subprocessors page, and binds us to the same obligations towards them that we owe the customer. Before a new one starts, the customer gets at least thirty days notice and can object on reasonable data protection grounds. We stay fully responsible for what a subprocessor does with the data.
4. International transfers
Where data leaves the European Economic Area or the United Kingdom, the DPA includes the European Commission's standard contractual clauses, the UK addendum or an international data transfer agreement where the UK version applies, and a transfer risk assessment. Customers in Armenia get the clauses that the Armenian law on personal data requires for a transfer abroad.
5. United States
For customers doing business in California, the DPA includes service provider terms under the CCPA: we do not sell or share personal information, we do not keep, use or disclose it outside the direct business relationship, and we do not combine it with data from anywhere else.
6. How to get a signed one
Write to [to be completed before launch] with the legal name of your company, the address, and who will sign. We send the current version, take your redlines seriously, and sign electronically. For a paying customer this happens before the account goes live with real data.
Enterprise buyers who need their own paper instead of ours can send it. We would rather read a customer template than lose a month arguing about whose form to use.
7. What is not in the DPA
The DPA is about personal data. It does not set prices, uptime or support times - those are in the Terms of Service and, for Enterprise, in the separate agreement. A self-hosted installation on the customer's own server usually needs no DPA at all for the core system, because the data never reaches us; it is only needed if the AI features are switched on.
Version 1.0, 18 September 2026. This page always shows the current version; earlier versions are kept and sent on request.
Questions about this document: [to be completed before launch].
Other legal documents