HomeData processing agreement

Data processing agreement

Last updated: 9 September 2026

The Article 28 GDPR terms under which Buildinghost processes personal data on behalf of your company.

1. Roles of the parties

Controller is your company (“the Customer”). Processor is Buildinghost.

The distinction matters in practice. For your own account data (name, email, billing) Buildinghost is the controller and the Privacy Policy applies. For the personal data you enter into the system — workers, subcontractors, suppliers, contact persons — you remain the controller, and Buildinghost acts solely on your instructions.

2. Subject matter, duration and nature of the processing

  • Subject matter: provision of the Buildinghost platform for construction project management.
  • Duration: for the term of the subscription, plus the retention periods in section 8.
  • Nature and purpose: storing, organising, querying and displaying the data entered by the Customer.
  • Categories of data subjects: the Customer’s employees, workers, and representatives of subcontractors and suppliers.
  • Categories of data: names, job titles, phone numbers, emails, pay rates, days worked, attached documents.

No special categories of data under Article 9 GDPR are processed. The Customer undertakes not to enter such data into free-text fields.

3. Processing on documented instructions

Buildinghost processes personal data only on the Customer’s documented instructions, including as regards transfers to third countries, unless required to do so by EU or Member State law. In such a case Buildinghost informs the Customer before processing, unless that law prohibits it on important grounds of public interest. Use of the platform in accordance with its documentation constitutes a documented instruction.

4. Confidentiality

All persons to whom Buildinghost grants access to personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is limited to staff for whom it is necessary to maintain the service.

5. Technical and organisational measures

Measures applied under Article 32 GDPR:

  • Encryption in transit (TLS) and at rest.
  • Tenant isolation enforced at the database level (Row Level Security), not only in the application.
  • Role-based access within the company — administrator, manager, accountant, supervisor.
  • An audit log of every creation, edit and deletion, retained for 24 months.
  • A strict Content Security Policy limiting outbound connections to approved origins.
  • Automatic database backups at the hosting provider.

6. Sub-processors

The Customer gives general authorisation for the use of sub-processors. The current list is published on the Sub-processorspage. Changes are announced at least 30 days in advance and the Customer has the right to object. Buildinghost imposes on each sub-processor data protection obligations no less onerous than those undertaken in this document, and remains fully liable for their performance.

7. Assistance with data subject rights

The platform gives the Customer self-service means of fulfilling data subject requests: export in a machine-readable format, editing and deletion of records, and account erasure.

Where a request reaches Buildinghost directly, it is forwarded to the Customer without undue delay and without a substantive reply of our own.

8. Security breaches and retention periods

In the event of a personal data breach, Buildinghost notifies the Customer without undue delay and no later than 48 hours after becoming aware of it, describing the nature of the breach, the categories affected and the measures taken. That deadline is shorter than the 72 hours under Article 33 so that the Customer retains time to make its own notification.

Retention periods:

  • Account data — until the subscription ends.
  • Grace period after a requested deletion — 30 days, after which erasure is final.
  • Audit log — 24 months.
  • Invitations never accepted — 90 days after they expire.
  • Accounting records — as required by applicable tax law.

9. Return and erasure of data

On termination of the service the Customer can download a complete export from the “Privacy and data” screen. Thereafter, at the Customer’s choice, the data is erased or returned, unless EU or Member State law requires its retention.

10. Audits and demonstrating compliance

Buildinghost makes available to the Customer all information necessary to demonstrate compliance with the obligations under Article 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits take place during business hours, on 30 days’ written notice, and no more than once a year, except where there are indications of a breach.

11. Acceptance

This document is accepted automatically on registration and forms an integral part of the Terms of Use. If you need a signed copy for your own records, write to privacy@buildinghost.eu.