Data Processing Agreement
Last updated 4 August 2026
When you use BuildTraq you put personal data into it — the names and contact details of the people who buy your units, and details of your own staff. For that data you are the controller and we act on your instructions as your processor. Article 28 of the GDPR requires that relationship to be set out in writing. This is that document.
1. When this applies
This agreement forms part of the Terms of Service and applies automatically from the moment you open an account. You do not need to sign or request it. If you need a countersigned copy for your own records, email privacy@buildtraq.com.
It is between you (“Controller”) and BuildTraq, Larnaca, Cyprus (“Processor”, “we”). Terms such as personal data, processing, controller, processor and personal data breach carry the meanings given in the GDPR.
Where the UK GDPR, Swiss law, or another comparable regime applies to your use, the equivalent provisions of that law apply and references here should be read accordingly.
2. What each of us is responsible for
You decide what personal data goes into BuildTraq, whose it is, why, and how long it stays. You confirm that:
- you have a lawful basis for every piece of personal data you enter, including the details of unit buyers and anyone appearing in a photograph;
- you have given those people whatever privacy information the law requires, and our being named as a processor is consistent with it;
- your instructions to us are lawful, and the data you enter is accurate and relevant.
We process that data only on your documented instructions. Using the product as intended is an instruction: when you create a report, upload a photo, invite a colleague or send an invoice reminder, that is your instruction to process the data involved. We also process where EU or member state law requires it, and if that happens we will tell you first unless the law forbids it.
We will tell you if, in our opinion, an instruction from you breaches data protection law. We are not obliged to review your instructions for lawfulness beyond that.
3. Confidentiality
Everyone we allow to access your data is bound by a duty of confidentiality, is given access only where they need it for the purpose, and is informed of the confidential nature of the data.
4. Security
We keep appropriate technical and organisational measures in place to protect personal data, taking into account the state of the art, the cost of implementation, and the risk to the people concerned. What we do today is listed in Annex 2.
Security measures change as technology and threats do. We may vary the measures in Annex 2 provided we do not materially reduce the overall level of protection.
5. Sub-processors
You give us general written authorisation to engage sub-processors. The ones we use today are listed in Annex 3, and the same list appears in our Privacy Policy.
Before adding or replacing a sub-processor we will give you at least 30 days’ notice by email to account administrators. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you in good faith to resolve it. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of any fees paid in advance for it. That is your sole remedy in this situation.
We impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain responsible to you for their performance.
6. International transfers
Your data is stored in the European Union. Some sub-processors in Annex 3 operate from outside it, as marked. Where we or a sub-processor transfer personal data outside the EEA, the UK or Switzerland, that transfer is made under the European Commission’s Standard Contractual Clauses, which are incorporated into this agreement by reference, or under another valid transfer mechanism such as the EU–US Data Privacy Framework where the recipient is certified.
7. Helping you meet your obligations
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with:
- Requests from individuals. The product already lets you find, correct, export and delete records yourself, and that is normally the fastest route. If someone contacts us directly about data in your workspace, we will not respond substantively — we will pass the request to you promptly, because it is yours to answer.
- Security, breach notification and impact assessments under Articles 32 to 36, so far as they relate to data we process for you.
This assistance is included at no charge for reasonable volumes. Where a request is repetitive, or requires effort disproportionate to the fees you pay, we may charge a reasonable fee based on time spent, after telling you in advance.
8. If there is a breach
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any event in time to let you meet your own notification duties.
The notification will describe what we know: the nature of the breach, the categories and approximate number of people and records involved so far as we can tell, the likely consequences, and the steps taken or proposed. Where we cannot provide everything at once, we will provide it in phases as it becomes available.
Notifying regulators and affected individuals is your responsibility as the controller. We will not do so on your behalf unless the law requires it of us directly. Our notifying you is not an admission of fault or liability.
9. Audits
We will make available the information reasonably necessary to demonstrate our compliance with this agreement.
You may audit us, or appoint an independent auditor who is not a competitor of ours, subject to the following, which exist so that audits stay proportionate to a service at this price:
- no more than once in any twelve-month period, unless a regulator requires more or there has been a confirmed breach affecting your data;
- on at least 30 days’ written notice;
- during business hours, without unreasonably disrupting the service;
- under a confidentiality undertaking, and never in a way that would expose another customer’s data;
- at your cost;
- satisfied in the first instance by documentation, questionnaires or third-party reports where those reasonably answer your questions.
10. Return and deletion
You can export your data at any time while your account is open. When it closes, we keep the data for 30 days so you can change your mind or export it, then delete it.
After that we retain only what the law requires us to keep — chiefly accounting and invoice records, which Cypriot law requires for six years — and use it for nothing else. Copies may persist briefly in our database provider’s snapshots before being overwritten; those are never used to restore an individual record.
11. Liability
Our liability under this agreement is subject to the limits and exclusions in the Terms of Service. Those limits apply to this agreement and the Terms taken together, not separately to each, so this document does not create a second, additional exposure.
Nothing here limits liability that cannot lawfully be limited, and nothing here affects any right an individual has directly against either of us under data protection law.
You will indemnify us against claims, fines and reasonable costs arising from your entering personal data without a lawful basis, from instructions that breach data protection law, or from your failure to give the people concerned the privacy information the law requires.
12. Duration and precedence
This agreement lasts as long as we process personal data for you. Where it conflicts with the Terms of Service on a data protection matter, this agreement wins. On everything else, the Terms win.
Annex 1 — What we process
Subject matter and duration
Providing the BuildTraq construction management service, for as long as your account is open, plus the retention described in clause 10.
Nature and purpose
Hosting, storing, organising, displaying, backing up and transmitting the records you create, so that you can run construction projects and share progress and billing with the buyers of your units.
Categories of data subjects
- Your staff and colleagues who hold accounts — administrators, managers and viewers.
- Buyers of your units, and their representatives, who you record against a unit or give portal access to.
- People who happen to appear in photographs taken on site, including workers, visitors and passers-by.
Types of personal data
- Account data — name, email address, an encrypted password, and two-factor authentication data where enabled.
- Contact data — buyers’ names, email addresses and mobile numbers.
- Work records — daily reports, issues, milestones, units and their status, attributed to the account that created them.
- Financial records — invoices, amounts, due dates, payment status, change orders and the name of whoever approved one.
- Photographs — site images, which may show people and may carry embedded capture time and location.
- Assistant data — questions typed or spoken to the in-app assistant, and voice recordings made while the microphone button is held, which are transcribed and not retained afterwards.
Special category data
BuildTraq is not designed for special category data as defined in Article 9, and you should not put it in. Photographs of identifiable people are not special category data unless used to identify someone uniquely, which the product does not do — we run no facial recognition or biometric processing of any kind.
Annex 2 — Security measures
These are the measures in place today.
Access control
- Data is scoped to a workspace and enforced in the database itself, so one customer’s records cannot be read from another’s account.
- Roles limit what each member sees. Billing is restricted to administrators and the buyer it concerns.
- Administrators can require two-factor authentication, and the service enforces the assurance level on sensitive operations.
- Passwords are hashed by our authentication provider and are never stored or visible in readable form.
Our own staff access
- Support access to a customer workspace is read-only by default.
- Write access must be raised deliberately, applies to one workspace, and expires automatically after 20 minutes.
- Every support access event is recorded in an audit log, and a workspace can be set to display a notice of when support last accessed it.
Protecting the data
- Encrypted in transit using TLS.
- Encrypted at rest by our hosting and storage providers.
- Deletions are recorded rather than silently erased, so a removed record leaves an audit trail showing who removed it and when.
- Photographs are private to the workspace unless explicitly marked visible to the buyer of a unit.
Resilience and monitoring
- Data is held on managed infrastructure offering 99.8–99.9% disk durability.
- Health checks on the API, with automatic restart on failure.
- Error monitoring configured not to attach personal identifiers to reports.
- Rate limiting on public endpoints to limit abuse and brute-force attempts.
Backups. We do not currently offer a contractual backup or point-in-time recovery guarantee, and you should not rely on us as your only copy. Export your records regularly and keep them somewhere you control — the app lets you export at any time. We will update this Annex if that changes.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, photo storage | Ireland (EU) |
| Render | Hosts the API | Germany (EU) |
| Resend | Sends transactional email | Ireland (EU) |
| Vercel | Hosts the website | Global edge network |
| Sentry | Error monitoring | United States |
| OpenRouter | In-app assistant | United States |
| OpenAI | Transcribes spoken questions | United States |
| Open-Meteo | Weather shown on daily reports | Germany (EU) |
Open-Meteo receives a project’s location and date only, and no personal data. It is listed for completeness.