This Data Processing Addendum (the "Addendum") forms part of the agreement between you and BuiltUp Technologies Ltd for use of the BuiltUp platform. It sets out the terms required by Article 28 of the UK GDPR where we process personal data on your behalf. If you need a signed copy for your records, section 16 tells you exactly how to get one.
1. Parties and Scope
This Addendum is between:
- The Customer ("you"), the organisation named on the BuiltUp account, acting as controller.
- BuiltUp Technologies Ltd, registered in England & Wales, Company No. 16100518, registered office 86-90 Paul Street, 3rd Floor, London EC2A 4NE ("BuiltUp", "we"), acting as processor.
It applies to all personal data that we process on your instructions through the platform. It does not apply to personal data where we are the controller in our own right, such as your billing contact details, your account administrator's login or our own marketing lists. That processing is covered by the Privacy Policy.
Your instruction to us is the ordinary use of the platform by you and your authorised users, together with any documented instruction you give us in writing. If we believe an instruction breaches data protection law, we will tell you and we may pause that processing until it is resolved.
2. Definitions
- Data Protection Law means the UK GDPR, the Data Protection Act 2018, and where applicable the EU GDPR, each as amended or replaced.
- Customer Personal Data means personal data contained in the content you and your users put into the platform.
- Controller, processor, data subject, personal data, processing and personal data breach have the meanings given to them in Data Protection Law.
- Sub-processor means a third party engaged by us to process Customer Personal Data.
3. Subject Matter and Duration
Subject matter. The provision of the BuiltUp construction management platform: estimating, take-off, project records, scheduling, quoting, invoicing, messaging and the client and subcontractor portals.
Duration. This Addendum runs for as long as we hold Customer Personal Data. That is the term of your subscription plus the deletion period set out in section 12. It survives termination of the main agreement for as long as any processing continues.
4. Nature and Purpose of Processing
We process Customer Personal Data only to deliver the platform to you. In practice that means:
- Storing, organising, retrieving and displaying your project records.
- Producing quotes, schedules of work, valuations and invoices, and issuing them to the recipients you choose.
- Analysing documents, drawings and voice notes you submit, using our AI provider, to return draft scopes, measurements and text.
- Sending transactional email on your behalf, such as a quote to your client or an invitation to a subcontractor.
- Carrying messages between you, your team, your clients and your subcontractors.
- Backing up, securing, supporting and maintaining the platform.
5. Types of Personal Data
- Identity and contact. Names, job titles, company names, email addresses, telephone numbers, site and postal addresses.
- Account. User identifiers, roles and permissions, authentication records, sign-in timestamps.
- Project content. Anything your team puts into a project: scopes, notes, measurements, valuations, correspondence, drawings, specifications and site photographs, which may show identifiable people.
- Voice. Audio recordings dictated on site and the transcripts produced from them.
- Commercial. Quote and invoice values, payment status, purchase order references.
- Technical. Device and browser information, IP addresses and application logs generated when your users access the platform.
Special category data
The platform is not designed for special category data as defined in Article 9, and we ask you not to put it in. Health, trade union membership, biometric or similar data should not be entered into project records, messages or file uploads. If your work requires it, contact us before you start so we can agree the terms in writing.
6. Categories of Data Subject
- Your employees, directors and other authorised users of the platform.
- Your clients and their representatives, including domestic clients and the contacts at commercial clients.
- Your subcontractors, labour-only operatives and their contacts.
- Suppliers, merchants, consultants and other professionals recorded against a project.
- Any individual who appears in a site photograph, a drawing, a message or a document you upload.
7. Our Obligations as Processor
In line with Article 28(3), we will:
- Process Customer Personal Data only on your documented instructions, including on transfers, unless we are required to do otherwise by law. Where the law requires it and does not prohibit us from telling you, we will tell you first.
- Make sure everyone authorised to process Customer Personal Data is under a duty of confidence, whether by contract of employment or by written agreement.
- Take the technical and organisational measures required by Article 32, as described in section 9.
- Respect the conditions on engaging sub-processors in section 8.
- Assist you, so far as is reasonable, with data subject requests as described in section 10.
- Assist you with your obligations under Articles 32 to 36, covering security, breach notification and data protection impact assessments, taking into account what we know and what is available to us.
- Delete or return Customer Personal Data at the end of the service as described in section 12.
- Make available the information needed to demonstrate compliance with Article 28 and allow for audits as described in section 13.
We will not sell Customer Personal Data, we will not use it for our own marketing, and we will not use it to train AI models.
8. Sub-processing
You give general written authorisation for us to engage sub-processors. The current list, with what each one does and where it processes, is published at builtup.io/sub-processors and forms part of this Addendum.
- Written terms. Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this Addendum.
- Our responsibility. Where a sub-processor fails to meet its data protection obligations, we remain fully liable to you for the performance of that sub-processor.
- Notice. We will give account owners at least 30 days' notice by email before a new sub-processor begins processing Customer Personal Data.
- Objection. You may object on reasonable data protection grounds within that 30-day period. If we cannot offer a workable alternative, you may terminate the affected part of the service without penalty for the remainder of the term, and we will refund fees paid in advance for the unused part.
The optional integrations listed on that page only process data if you connect them yourself. Where you push data into your own accounting or CRM system, that provider acts on your instructions, not ours.
9. Security Measures
We maintain appropriate technical and organisational measures under Article 32, having regard to the state of the art, the cost of implementation and the risk to individuals. In summary:
- Encryption in transit over TLS 1.2 or better on every connection.
- Encryption at rest on the database and on file storage, including backups.
- Salted, hashed password storage, signed session tokens with a limited lifetime, and optional Google or Apple sign-in.
- Logical tenant separation, so records are scoped to a workspace at the database layer and files are served through short-lived signed URLs.
- Role-based permissions enforced on the server, and least-privilege production access limited to a small number of named engineers.
- Daily encrypted backups with a rolling retention window.
- A published vulnerability disclosure route at security@builtup.io with a stated response window.
Please read this before you sign
These measures are contractual commitments, not certified controls. BuiltUp does not currently hold ISO 27001, SOC 2 or Cyber Essentials. A third-party penetration test and Cyber Essentials are under way, and SOC 2 and ISO 27001 are planned, but none of them is in place as at the date of this addendum, and you should sign on the basis of the commitments above rather than on a certificate that does not exist yet. Our security page carries the current status of each.
10. Assistance with Data Subject Rights
Most rights requests can be handled by you directly. Owners and admins can search, export, correct and delete records inside the workspace without needing us.
Where a request cannot be met with those tools, we will provide reasonable assistance by appropriate technical and organisational measures, taking into account the nature of the processing. That covers access, rectification, erasure, restriction, portability and objection.
- Email privacy@builtup.io with the workspace name and what is needed.
- We will acknowledge within 2 working days and respond substantively within 10 working days, so you can still meet your own one-month statutory deadline.
- If a data subject contacts us directly about your data, we will not respond on your behalf. We will pass the request to you promptly and tell the individual to approach you.
- Assistance is included at no charge for ordinary requests. If a request is repetitive or requires substantial engineering work, we will agree reasonable costs with you in advance.
11. Personal Data Breach
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. Notice goes to the account owner and to any security contact you have given us.
The notification will describe, to the extent known at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed to address it and to mitigate the effects.
- A contact point for further information.
Where we do not have all of that at first, we will send what we have and follow up in stages rather than waiting. Reporting to the Information Commissioner's Office and to affected individuals remains your decision as controller, and we will give you the information you need to make it.
12. Return and Deletion
- Export before you go. While the account is live you can export your project data and documents at any time from the platform.
- After termination. Your data stays available for 30 days so you can retrieve it. Write to us within that window if you want a full export supplied by us instead.
- Then deletion. At the end of that 30-day window we delete Customer Personal Data from live systems. Copies in encrypted backups are removed as those backups age out of the rolling retention window.
- What we keep. Only what the law requires, chiefly billing and accounting records for the statutory retention period. Those are kept for that purpose alone and are not used for anything else.
- Confirmation. We will confirm deletion in writing on request.
13. Audit and Information
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits and inspections conducted by you or an auditor you appoint.
- First step. A written security questionnaire or a request for documentation. We answer these free of charge and it will usually settle the matter.
- On-site or remote audit. Available on at least 30 days' written notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach.
- Conditions. Audits take place during business hours, must not unreasonably disrupt the service, must not extend to the data of any other customer, and are subject to confidentiality. Your auditor must not be a competitor of ours.
- Costs. You bear your own costs. We may charge our reasonable costs for time spent supporting an on-site audit, agreed in advance.
We have no third-party audit report to offer in place of this process. See section 9 and the security page.
14. International Transfers
Customer Personal Data is transferred outside the United Kingdom. Several of our sub-processors are based in the United States, and they are named on the sub-processors page. We do not offer UK-only data residency.
Every such transfer is made on the basis of an approved transfer mechanism:
- For transfers from the UK, the EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum (IDTA) issued under section 119A of the Data Protection Act 2018, or the IDTA in standalone form.
- For transfers from the EEA, the Standard Contractual Clauses adopted by the European Commission.
- Where a provider is certified under an adequacy decision that covers the transfer, that decision may be relied on instead.
By entering into this Addendum, the parties are taken to have entered into the applicable Clauses, with you as data exporter and BuiltUp as data importer where relevant, and with the details in sections 3 to 6 completing the required annexes. Technical measures supporting those transfers are described in section 9.
15. General
- Order of precedence. If this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum wins. Everything else in the Terms continues to apply.
- Liability. Each party's liability under this Addendum is subject to the limitations and exclusions in the Terms of Service.
- Your responsibilities. You confirm that you have a lawful basis for the personal data you put into the platform, that you have given the necessary privacy information to the individuals concerned, and that your instructions to us comply with Data Protection Law.
- Governing law. This Addendum is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except where the Standard Contractual Clauses require otherwise.
- Changes. We may update this Addendum to reflect a change in law, a supervisory authority decision or a change to our processing. Where a change materially reduces your protections we will give 30 days' notice by email.
16. How to Execute This Addendum
This Addendum applies automatically from the moment you start using the platform, so you are covered whether or not anything is signed. If your firm, your client or a main contractor needs a countersigned copy on file, here is the route:
- Email privacy@builtup.io with the subject line "DPA request".
- Tell us the full legal name of your organisation, its registered address and company number, the BuiltUp workspace it relates to, and the name and job title of the person signing.
- We prepare this Addendum as a PDF with those details completed, sign it, and send it back for signature. If you would rather use your own template, send it over and we will review it.
- You sign and return it. We countersign and send you the fully executed copy for your records. Allow up to 5 working days.
Data protection contact
privacy@builtup.ioProcessor details for the signature block
BuiltUp Technologies Ltd
Registered in England & Wales, Company No. 16100518
86-90 Paul Street, 3rd Floor
London, United Kingdom, EC2A 4NE
This Addendum is a contract document, not legal advice. If you are unsure how it sits with your own obligations, take advice on it.