Last updated: 9 September 2026
The Article 28 GDPR terms under which Buildinghost processes personal data on behalf of your company.
Controller is your company (“the Customer”). Processor is Buildinghost.
The distinction matters in practice. For your own account data (name, email, billing) Buildinghost is the controller and the Privacy Policy applies. For the personal data you enter into the system — workers, subcontractors, suppliers, contact persons — you remain the controller, and Buildinghost acts solely on your instructions.
No special categories of data under Article 9 GDPR are processed. The Customer undertakes not to enter such data into free-text fields.
Buildinghost processes personal data only on the Customer’s documented instructions, including as regards transfers to third countries, unless required to do so by EU or Member State law. In such a case Buildinghost informs the Customer before processing, unless that law prohibits it on important grounds of public interest. Use of the platform in accordance with its documentation constitutes a documented instruction.
All persons to whom Buildinghost grants access to personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is limited to staff for whom it is necessary to maintain the service.
Measures applied under Article 32 GDPR:
The Customer gives general authorisation for the use of sub-processors. The current list is published on the Sub-processorspage. Changes are announced at least 30 days in advance and the Customer has the right to object. Buildinghost imposes on each sub-processor data protection obligations no less onerous than those undertaken in this document, and remains fully liable for their performance.
The platform gives the Customer self-service means of fulfilling data subject requests: export in a machine-readable format, editing and deletion of records, and account erasure.
Where a request reaches Buildinghost directly, it is forwarded to the Customer without undue delay and without a substantive reply of our own.
In the event of a personal data breach, Buildinghost notifies the Customer without undue delay and no later than 48 hours after becoming aware of it, describing the nature of the breach, the categories affected and the measures taken. That deadline is shorter than the 72 hours under Article 33 so that the Customer retains time to make its own notification.
Retention periods:
On termination of the service the Customer can download a complete export from the “Privacy and data” screen. Thereafter, at the Customer’s choice, the data is erased or returned, unless EU or Member State law requires its retention.
Buildinghost makes available to the Customer all information necessary to demonstrate compliance with the obligations under Article 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits take place during business hours, on 30 days’ written notice, and no more than once a year, except where there are indications of a breach.
This document is accepted automatically on registration and forms an integral part of the Terms of Use. If you need a signed copy for your own records, write to privacy@buildinghost.eu.