Data Processing Addendum

Last updated: June 10, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Buildficient, Inc. ("Buildficient") and the customer identified in the applicable order or account ("Customer") governing Customer's use of the Buildficient service (the "Agreement"). This DPA applies to the extent Buildficient processes Personal Data on Customer's behalf that is subject to the EU or UK GDPR, the CCPA/CPRA, or similar data protection laws ("Data Protection Laws"). Terms such as "Personal Data," "Controller," "Processor," "Data Subject," and "Processing" have the meanings given in Data Protection Laws.

1. Scope and Roles

For Personal Data contained in Customer Content, Customer is the Controller (or a Processor acting for another Controller) and Buildficient is the Processor. Customer is responsible for the accuracy and lawfulness of the Personal Data it submits, for providing required notices, and for obtaining any consents needed from Data Subjects, including individuals whose voices or images appear in recordings and jobsite photos.

2. Details of Processing

3. Processor Obligations

Buildficient will:

4. Security Measures

Buildficient maintains appropriate technical and organizational measures, including: encryption of data in transit (TLS) and at rest; logical tenant isolation enforced through row-level security; role-based access controls and least-privilege access for personnel; multi-factor authentication for administrative access; logging, monitoring, and alerting; secure software development practices and dependency review; regular backups with tested restoration; and vendor security assessment for all subprocessors.

5. Data Subject Requests

If Buildficient receives a request from a Data Subject relating to Personal Data processed for Customer, Buildficient will promptly forward the request to Customer and will not respond directly except to direct the Data Subject to Customer or as required by law. The service includes self-serve tools for access, correction, export, and deletion that Customer can use to fulfill most requests.

6. Subprocessors

Customer provides general authorization for Buildficient to engage the following subprocessors: Supabase (database, authentication, storage), Vercel (hosting), Stripe (payments), Deepgram (speech-to-text), Anthropic (AI processing), Resend (transactional email), Google Workspace (business email), Upstash (caching), Sentry (error monitoring), PostHog (product analytics), and Inngest (background jobs). Buildficient will give Customer at least 30 days' advance notice of any new or replacement subprocessor. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected services and receive a pro rata refund of prepaid fees. Buildficient remains responsible for its subprocessors' performance and will impose data protection obligations on them that are no less protective than this DPA.

7. Audits

Upon written request no more than once per year, Buildficient will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and certifications (including SOC 2 reports when available) and responses to reasonable security questionnaires. Where Data Protection Laws require more, Customer may conduct an audit at its own expense, on reasonable notice, during business hours, no more than once per year, and subject to Buildficient's confidentiality and security requirements.

8. International Transfers

Where Personal Data subject to the EU GDPR is transferred to Buildficient in the United States or to subprocessors outside the European Economic Area, the parties rely on the European Commission's Standard Contractual Clauses (Module Two, Controller to Processor, and Module Three, Processor to Processor, as applicable), which are incorporated into this DPA by reference. For transfers subject to UK law, the UK International Data Transfer Addendum applies. For transfers subject to Swiss law, the clauses are adapted as required by the Swiss Federal Data Protection and Information Commissioner.

9. CCPA/CPRA

To the extent Buildficient processes Personal Data subject to the CCPA/CPRA, Buildficient acts as a service provider, will not sell or share that Personal Data, will not retain, use, or disclose it for any purpose other than providing the services, and certifies that it understands and will comply with these restrictions.

10. Deletion and Return

During the term, Customer may export Customer Content using the tools provided in the service. Following termination or expiration of the Agreement, Buildficient will retain Customer Content for 90 days to permit export, after which Buildficient will delete Personal Data from active systems, with deletion from encrypted backups occurring on the normal rotation cycle of up to 35 days, except where retention is required by law.

11. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and references in the Agreement to a party's liability mean the aggregate liability of that party under the Agreement and this DPA together.

12. Precedence

In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.

13. Contact

Questions about this DPA or requests for a countersigned copy: support@buildficient.com. Security and breach reports: security@buildficient.com.