Data Processing Addendum
Last updated: June 10, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Buildficient, Inc. ("Buildficient") and the customer identified in the applicable order or account ("Customer") governing Customer's use of the Buildficient service (the "Agreement"). This DPA applies to the extent Buildficient processes Personal Data on Customer's behalf that is subject to the EU or UK GDPR, the CCPA/CPRA, or similar data protection laws ("Data Protection Laws"). Terms such as "Personal Data," "Controller," "Processor," "Data Subject," and "Processing" have the meanings given in Data Protection Laws.
1. Scope and Roles
For Personal Data contained in Customer Content, Customer is the Controller (or a Processor acting for another Controller) and Buildficient is the Processor. Customer is responsible for the accuracy and lawfulness of the Personal Data it submits, for providing required notices, and for obtaining any consents needed from Data Subjects, including individuals whose voices or images appear in recordings and jobsite photos.
2. Details of Processing
- Subject matter. Provision of the Buildficient construction project management service, including voice transcription, AI-assisted scheduling, daily logs, photo analysis, and billing features.
- Duration. The term of the Agreement plus the 90-day post-termination retention period described in Section 10.
- Nature and purpose. Hosting, storage, transmission, transcription, AI-based analysis, display, and backup of Customer Content as needed to provide the service.
- Categories of Personal Data. Names, contact details, job titles and roles, voice recordings and transcripts, photographs and videos that may depict individuals, location data, schedule and task assignments, and communications content.
- Categories of Data Subjects. Customer's employees, contractors, and subcontractors; Customer's clients and their representatives; and other individuals appearing in Customer Content.
3. Processor Obligations
Buildficient will:
- Process Personal Data only on Customer's documented instructions, including as set out in the Agreement and this DPA, unless required otherwise by law (in which case Buildficient will notify Customer unless legally prohibited);
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations;
- Implement and maintain the technical and organizational measures described in Section 4;
- Assist Customer, taking into account the nature of the processing, in responding to Data Subject requests and in meeting Customer's obligations regarding security, breach notification, and data protection impact assessments;
- Notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer's Personal Data, and provide information reasonably required for Customer to meet its own notification obligations;
- Delete or return Personal Data at termination as described in Section 10.
4. Security Measures
Buildficient maintains appropriate technical and organizational measures, including: encryption of data in transit (TLS) and at rest; logical tenant isolation enforced through row-level security; role-based access controls and least-privilege access for personnel; multi-factor authentication for administrative access; logging, monitoring, and alerting; secure software development practices and dependency review; regular backups with tested restoration; and vendor security assessment for all subprocessors.
5. Data Subject Requests
If Buildficient receives a request from a Data Subject relating to Personal Data processed for Customer, Buildficient will promptly forward the request to Customer and will not respond directly except to direct the Data Subject to Customer or as required by law. The service includes self-serve tools for access, correction, export, and deletion that Customer can use to fulfill most requests.
6. Subprocessors
Customer provides general authorization for Buildficient to engage the following subprocessors: Supabase (database, authentication, storage), Vercel (hosting), Stripe (payments), Deepgram (speech-to-text), Anthropic (AI processing), Resend (transactional email), Google Workspace (business email), Upstash (caching), Sentry (error monitoring), PostHog (product analytics), and Inngest (background jobs). Buildficient will give Customer at least 30 days' advance notice of any new or replacement subprocessor. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected services and receive a pro rata refund of prepaid fees. Buildficient remains responsible for its subprocessors' performance and will impose data protection obligations on them that are no less protective than this DPA.
7. Audits
Upon written request no more than once per year, Buildficient will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and certifications (including SOC 2 reports when available) and responses to reasonable security questionnaires. Where Data Protection Laws require more, Customer may conduct an audit at its own expense, on reasonable notice, during business hours, no more than once per year, and subject to Buildficient's confidentiality and security requirements.
8. International Transfers
Where Personal Data subject to the EU GDPR is transferred to Buildficient in the United States or to subprocessors outside the European Economic Area, the parties rely on the European Commission's Standard Contractual Clauses (Module Two, Controller to Processor, and Module Three, Processor to Processor, as applicable), which are incorporated into this DPA by reference. For transfers subject to UK law, the UK International Data Transfer Addendum applies. For transfers subject to Swiss law, the clauses are adapted as required by the Swiss Federal Data Protection and Information Commissioner.
9. CCPA/CPRA
To the extent Buildficient processes Personal Data subject to the CCPA/CPRA, Buildficient acts as a service provider, will not sell or share that Personal Data, will not retain, use, or disclose it for any purpose other than providing the services, and certifies that it understands and will comply with these restrictions.
10. Deletion and Return
During the term, Customer may export Customer Content using the tools provided in the service. Following termination or expiration of the Agreement, Buildficient will retain Customer Content for 90 days to permit export, after which Buildficient will delete Personal Data from active systems, with deletion from encrypted backups occurring on the normal rotation cycle of up to 35 days, except where retention is required by law.
11. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and references in the Agreement to a party's liability mean the aggregate liability of that party under the Agreement and this DPA together.
12. Precedence
In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.
13. Contact
Questions about this DPA or requests for a countersigned copy: support@buildficient.com. Security and breach reports: security@buildficient.com.