Legal
Data Processing Addendum
Controller-to-processor terms, US state service provider terms and international transfer mechanisms.
This Data Processing Addendum ("DPA") forms part of the Master Services Agreement between Build Intelligence Group, LLC ("Build IG", "Processor") and the Client identified in the Order Confirmation ("Client", "Controller"). It applies where Build IG processes personal data on Client's behalf. On the processing of personal data, this DPA prevails over the Agreement.
1. Definitions and scope
1.1 "Data Protection Laws" means all laws applicable to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended ("CCPA"), and the comprehensive privacy laws of other US states.
1.2 "Subprocessor" means any processor engaged by Build IG to process Personal Data on Client's behalf. Capitalised terms not defined in this DPA have the meanings given in the Agreement, including "Client Data", "Output" and "Platform".
1.3 "Personal Data" means personal data, personal information or equivalent within Client Data. Terms such as controller, processor, data subject, business, service provider and sale have the meanings given in the applicable Data Protection Laws.
1.4 Roles. For Personal Data within Client Data, Client is the controller (or a processor acting for a third-party controller) and Build IG is the processor. For account, billing and marketing data, Build IG is a controller; that processing is outside the scope of this DPA and is described in Build IG's Privacy Policy, which is a notice and not part of the Agreement.
2. Details of processing (GDPR Article 28(3))
| Item | Detail |
|---|---|
| Subject matter | Provision of the Build IG platform — automated extraction of quantities from construction documents supplied by Client, and generation of preliminary estimates, schedules and reports. |
| Duration | From the effective date of the Agreement until deletion or return under clause 11 of this DPA. Personal Data is deleted from active systems no later than 90 days after termination or expiry of the Agreement; routine encrypted backups may persist only as permitted by clause 11.3. |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, automated analysis, consultation, use, transmission to Client, erasure and destruction. |
| Purpose of the processing | Providing the Platform to Client; providing technical support and troubleshooting at Client's request; maintaining, securing, testing and evaluating the quality, reliability and performance of the Platform, provided that Personal Data is not used as training data for any machine learning model and is not retained in or derivable from any model; generating Derived Data under clause 9.4 of the Agreement, which contains no Personal Data; and complying with law. No other purpose. |
| Types of Personal Data | Names, business and personal contact details, job titles and professional credentials of Client's personnel and Users; and any personal data contained in documents Client uploads, which may include names, property addresses and contact details of property owners, occupants, design professionals, contractors and other project stakeholders. Client controls what it uploads. |
| Categories of data subjects | Client's personnel and Users; property owners and occupants; design professionals named in uploaded documents; contractors, subcontractors and other project stakeholders. |
| Special category data | None is sought or expected. Client must not upload special category data within the meaning of GDPR Article 9, or sensitive personal information under US state laws, without first agreeing additional measures with Build IG in writing. |
| Controller obligations and rights | Client determines the purposes and means of the processing; is responsible for the lawfulness of the Personal Data it uploads and for having a lawful basis; must provide any notices and obtain any consents required; and has the rights set out in this DPA, including the rights of instruction, audit and deletion. |
3. Processing on documented instructions
3.1 Build IG will process Personal Data only on Client's documented instructions, including in relation to transfers to a third country or an international organisation. The Agreement, this DPA, and Client's use of the Platform's features constitute Client's complete documented instructions.
3.2 Where Union, Member State or other applicable law requires Build IG to process Personal Data other than on Client's instructions, Build IG will inform Client of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
3.3 Build IG will immediately inform Client if, in its opinion, an instruction infringes Data Protection Laws. Build IG may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
3.4 No training on Personal Data. Build IG will not use Personal Data as training data to train, fine-tune or otherwise develop any machine learning model, and will not permit any Subprocessor to do so. No Personal Data will be retained in, or be derivable from, any model. This prohibition is absolute and is not subject to any election, consent or opt-in.
3.5 Testing and evaluation. Processing that transiently reads Personal Data in order to test or measure the accuracy, quality or performance of the Platform is operation of the Platform under clause 2 and is not model training, provided that the Personal Data is not used as training data, is not retained in any model, and is not retained in any evaluation artefact beyond the test run and its result record.
3.6 Non-personal Client Data. Build IG's use of Client Data that is not Personal Data is governed by clauses 9.3 to 9.6 of the Agreement and is outside the scope of this DPA.
4. Confidentiality of personnel
4.1 Build IG will ensure that every person it authorises to process Personal Data has committed themselves to confidentiality or is under an appropriate statutory obligation of confidentiality, has been trained on their obligations, and has access only to the Personal Data necessary for their role.
5. Security (GDPR Article 32)
5.1 Build IG will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: encryption of Personal Data in transit and at rest; measures to ensure ongoing confidentiality, integrity, availability and resilience; the ability to restore availability and access in a timely manner after an incident; role-based access control and least-privilege administration; audit logging; documented incident response; and a process for regularly testing and evaluating the effectiveness of those measures.
5.2 Build IG will not materially decrease the overall security of the Platform during the term.
6. Subprocessors (GDPR Articles 28(2) and 28(4))
6.1 General authorisation. Client gives Build IG general written authorisation to engage subprocessors. The current list, with each subprocessor's name, function and processing location, is published at buildig.ai/subprocessors.
6.2 Notice of changes. Build IG will give Client at least thirty (30) days' notice before adding or replacing a subprocessor, by email to the address on Client's account and by updating the list. Client may subscribe to change notifications on that page.
6.3 Right to object. Client may object to a new subprocessor on reasonable data protection grounds by written notice within the 30-day period. The parties will discuss the objection in good faith. If it cannot be resolved, Client may terminate the affected part of the Agreement on written notice and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
6.4 Flow-down. Build IG will impose on each subprocessor, by written contract, data protection obligations that are the same as those in this DPA, in particular providing sufficient guarantees of appropriate technical and organisational measures.
6.5 Liability. Where a subprocessor fails to fulfil its data protection obligations, Build IG remains fully liable to Client for the performance of that subprocessor's obligations.
7. Assistance with data subject rights (GDPR Articles 12–23)
7.1 Build IG will provide self-service functionality enabling Client to access, correct, export and delete Personal Data within the Platform.
7.2 Taking into account the nature of the processing, Build IG will assist Client by appropriate technical and organisational measures, insofar as possible, to fulfil Client's obligation to respond to requests to exercise data subject rights.
7.3 Build IG will not respond directly to a data subject in relation to Personal Data processed for Client, except to confirm that the request has been passed to Client. Build IG will notify Client without undue delay of any such request it receives.
8. Assistance with Articles 32 to 36
8.1 Taking into account the nature of the processing and the information available to it, Build IG will assist Client in ensuring compliance with its obligations under GDPR Articles 32 to 36, including security of processing, personal data breach notification to a supervisory authority and to data subjects, data protection impact assessments, and prior consultation with a supervisory authority.
8.2 Build IG will make available the information reasonably necessary for Client to complete a data protection impact assessment relating to the Platform.
9. Personal data breach
9.1 Build IG will notify Client without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Personal Data processed for Client.
9.2 The notification will describe, to the extent known: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it, including to mitigate adverse effects; and a contact point for further information. Where the information is not all available at once, Build IG will provide it in phases without undue further delay.
9.3 Build IG will cooperate with Client and take the reasonable steps Client directs to assist in investigating and remedying the breach. Build IG will not make any public statement identifying Client in relation to a breach without Client's prior written consent unless required by law.
10. Audit and information (GDPR Article 28(3)(h))
10.1 Build IG will make available to Client all information necessary to demonstrate compliance with Article 28 and this DPA, including its current security documentation and, where available, third-party audit reports and certifications.
10.2 Build IG will allow for and contribute to audits, including inspections, conducted by Client or by another auditor mandated by Client. Audits may be conducted once in any twelve-month period on at least thirty (30) days' written notice, during business hours, without unreasonably disrupting Build IG's operations, and subject to confidentiality obligations. Additional audits may be conducted following a personal data breach or where required by a supervisory authority, without regard to that frequency limit.
10.3 Client bears its own costs of an audit and Build IG's reasonable costs of supporting one, except where the audit reveals material non-compliance, in which case Build IG bears both. Build IG's support costs will not be charged at more than its reasonable internal cost and will not be so set as to make the exercise of this right impracticable.
11. Deletion or return (GDPR Article 28(3)(g))
11.1 At Client's choice, Build IG will delete or return all Personal Data to Client after the end of the provision of services relating to processing, and will delete existing copies.
11.2 Client may make that choice at any time and must do so within sixty (60) days of termination or expiry, which is the same window as the export period in clause 9.9 of the Agreement. If Client makes no choice, Build IG will delete. Where Client elects return, Build IG will make the Personal Data available and will not delete it before the end of that sixty-day window. Deletion will be completed within thirty (30) days after the choice is given effect or after that window expires, whichever is later.
11.3 Exceptions. Build IG may retain Personal Data after that point only where and to the extent storage is required by Union, Member State or other applicable law. In that case Build IG will inform Client of the requirement, retain only what the law requires for only as long as it requires, isolate it from active processing, and continue to protect it under this DPA. Personal Data residing in routine encrypted backups is put beyond use immediately on deletion from active systems and is overwritten on the ordinary backup cycle, which does not exceed a further ninety (90) days.
11.4 Build IG will certify deletion in writing on Client's request.
12. International transfers
12.1 Standard Contractual Clauses. Where Personal Data protected by the GDPR is transferred from the EEA to a country without an adequacy decision, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and are executed by the parties by entering into the Agreement, on the following basis:
- (a) Module Two (controller to processor) applies where Client is a controller; Module Three (processor to processor) applies where Client is itself a processor;
- (b) Clause 7 (docking) applies; in Clause 9, Option 2 (general written authorisation) applies with the notice period in clause 6.2 of this DPA; in Clause 11, the optional independent dispute-resolution paragraph does not apply; in Clause 17, the governing law is that of Ireland; in Clause 18(b) the forum is the courts of Ireland;
- (c) Annex I.A (parties) is populated by the identities, roles and contact details in the Agreement and the Order Confirmation, with Client as data exporter and controller (or processor) and Build IG as data importer and processor (or sub-processor); Annex I.B (description of transfer) by clause 2 of this DPA, with the frequency of transfer being continuous for the duration of the Agreement; Annex I.C (competent supervisory authority) being the authority of the Member State in which Client is established, or where Client is not established in the EEA, the supervisory authority of Ireland; Annex II (technical and organisational measures) by clause 5 of this DPA; and Annex III (sub-processors) by the list at buildig.ai/subprocessors. Entering into the Agreement constitutes signature of the Clauses and their Annexes by both parties.
12.2 United Kingdom. For transfers subject to the UK GDPR, the ICO International Data Transfer Addendum to the EU SCCs applies to the clauses in clause 12.1, with Tables 1 to 4 completed by reference to this DPA, and the parties elect that section 18 of the Addendum applies so that it updates automatically when the ICO revises it. For Switzerland, references to the GDPR are to the FADP and the competent authority is the FDPIC.
12.3 Data Privacy Framework. Where Build IG is certified under the EU–US Data Privacy Framework or its UK extension, it will comply with its principles. The parties do not rely on that certification alone; the clauses in 12.1 and 12.2 apply independently and continue to apply regardless of the status of the Framework.
12.4 Transfer impact assessment. Build IG has conducted and will maintain a transfer impact assessment and will make it available to Client on request.
12.5 Successor clauses. If the European Commission or the ICO adopts a further or replacement set of clauses applicable to the transfers under this DPA, those clauses will apply automatically in place of the clauses in 12.1 or 12.2 from the date they take effect, and the parties will cooperate to complete any required annexes.
13. US state law — service provider terms
13.1 For Personal Data subject to the CCPA, Client is the business and Build IG is a service provider (and, where Personal Data is made available to it rather than processed on Client's instruction, a contractor). Build IG:
- (a) will not sell or share Personal Data;
- (b) will not retain, use or disclose Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement, including not for its own commercial purposes, and not outside the direct business relationship with Client — save that Build IG may use Personal Data internally to build and improve the quality of its services as permitted by 11 CCR §7050(a)(4) and clause 3.5 of this DPA, and which does not include using Personal Data as training data for any model;
- (c) will not combine Personal Data with personal information it receives from or on behalf of another person, or collects from its own interactions, except as permitted by 11 CCR §7050(b);
- (d) will comply with the applicable obligations of the CCPA and will provide the same level of privacy protection as the CCPA requires of a business;
- (e) certifies that it understands the restrictions in paragraphs (a) to (d) and will comply with them;
- (f) will notify Client promptly if it determines it can no longer meet its obligations under the CCPA;
- (g) grants Client the right to take reasonable and appropriate steps to ensure that Build IG uses Personal Data in a manner consistent with Client's obligations under the CCPA, including through the audit rights in clause 10; and
- (h) grants Client the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Personal Data.
13.2 Build IG will assist Client in responding to consumer requests, including requests to know, delete, correct, and opt out of sale or sharing, and will implement any opt-out signal Client passes to it.
13.3 The equivalent terms apply, and Build IG accepts the equivalent obligations as a processor or service provider, under the comprehensive privacy laws of other US states, including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware and Minnesota.
14. General
14.1 Records. Build IG maintains a record of processing activities carried out on behalf of Client, as required by GDPR Article 30(2), and will make it available to Client or a supervisory authority on request.
14.2 Liability. Each party's liability under this DPA is subject to clause 14 of the Agreement, except where Data Protection Laws prohibit such limitation. Nothing in this DPA limits a data subject's rights under Data Protection Laws.
14.3 Governing law. This DPA is governed by the law of the Agreement, except that clause 12 is governed as stated in the Standard Contractual Clauses. Clause 16 of the Agreement (arbitration) does not apply to any claim brought under the Standard Contractual Clauses, which are subject to their own dispute resolution and forum provisions.
14.4 Conflict. Where this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those Clauses prevail.
14.5 Changes. Build IG may update this DPA on thirty (30) days' notice only where the update is required to reflect a change in Data Protection Laws, a decision of a supervisory authority or court, or the adoption of successor transfer clauses, and provided the update does not reduce the protections afforded to Personal Data or Client's rights under this DPA. Any other change requires Client's affirmative electronic acceptance in the Platform or another written agreement between the parties. Where Client reasonably objects to an update, it may terminate the Agreement under clause 6.3 of this DPA.