DPA
Data Processing Addendum
Last updated: 2026-06-06. This Data Processing Addendum ("DPA") forms part of the agreement between BuildingHQ ("Processor") and the customer ("Controller") that has accepted the BuildingHQ Terms of Service. It applies when Processor processes Personal Data on behalf of Controller to provide the Service.
1. Definitions
Capitalised terms not defined here have the meanings given in the Terms of Service. "Personal Data" means information about an identifiable person that Controller submits to the Service. "Applicable Data Protection Law" means the data-protection or privacy laws applicable to the parties' processing of Personal Data in the jurisdictions where each party operates.
2. Subject matter and duration
The subject matter of the processing is Personal Data submitted to the Service by or on behalf of Controller. The processing will continue for the duration of the Agreement and any additional period during which Processor retains Personal Data as expressly permitted by the Terms of Service or this DPA.
3. Nature, purpose, and categories
Processor processes Personal Data only for the purpose of providing, securing, and supporting the Service for Controller, and as otherwise instructed in writing by Controller (including instructions in the Service's user interface).
Categories of data subjects: Controller's board members, contractors, vendors, residents, tenants, and other people whose information is added to the Service by Controller or its users.
Categories of Personal Data: identification data (name, email, phone), authentication identifiers, content submitted to the Service (log entries, attachments, voice notes), inbound email content from senders Controller has allow-listed, technical / log data (IP, user-agent, timestamps), and any other Personal Data Controller chooses to submit.
4. Roles
For Personal Data submitted by Controller (and on which Controller decides means and purposes), Controller is the Controller and Processor is the Processor. For data Processor collects as an independent controller — for example, account data Processor collects to manage its relationship with Controller's administrators — Processor processes that data under its Privacy Policy as a separate controller.
5. Processor obligations
Processor will:
- process Personal Data only on documented instructions from Controller, except where Applicable Data Protection Law requires otherwise;
- ensure that personnel authorised to process Personal Data have committed to confidentiality;
- implement the technical and organisational measures set out at /security;
- notify Controller without undue delay after becoming aware of a confirmed security incident affecting Controller's Personal Data, and cooperate reasonably with Controller's response;
- provide reasonable assistance to Controller, taking the nature of the processing into account, with responding to requests from individuals about their Personal Data;
- at Controller's choice, delete or return Personal Data on termination, unless Applicable Data Protection Law requires further storage.
6. Controller obligations
Controller represents that it has all rights, consents, and authority required to submit Personal Data to the Service and to instruct Processor's processing under this DPA. Controller is solely responsible for the legality, accuracy, and quality of Personal Data submitted, and for providing any required notice to the individuals whose information it submits.
7. Subprocessors
Controller authorises Processor to engage subprocessors. The current subprocessor list is published at /subprocessors. Processor will:
- give Controller at least 30 days' notice before adding or replacing a subprocessor (by updating the published list and emailing notification subscribers);
- impose contractual obligations on each subprocessor that are no less protective than those in this DPA; and
- remain liable to Controller for the acts and omissions of subprocessors processing Personal Data on Processor's behalf.
If Controller reasonably objects to a new subprocessor on data-protection grounds, Controller may terminate the affected portion of the Service and receive a pro-rata refund of pre-paid fees for the unused period.
8. Security and information requests
Processor will make available, on Controller's written request and subject to confidentiality, current information about the security and operational measures applied to the Service that is reasonably necessary for Controller to evaluate Processor's performance under this DPA.
9. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations of liability in the Terms of Service.
10. Conflicts and order of precedence
If there is a conflict between this DPA and the Terms of Service relating to processing of Personal Data, this DPA controls.
How to execute this DPA
This DPA is effective on the date Controller accepts the Terms of Service. If you require a counter-signed copy for your records, email support@buildinghq.app with the Controller's legal name, address, and signatory.
For enterprise contracts with bespoke clauses, contact support@buildinghq.app.