Legal
Data Processing Addendum
Last updated June 22, 2026
This Data Processing Addendum (“DPA”) supplements the Terms of Service and applies where faircompanies.build processes personal data on your behalf — for example, when you (a business or Enterprise customer) upload data about your clients, team, or projects.
1. Roles and scope
For personal data you submit through the Service (“Customer Personal Data”), you act as the controller and faircompanies.build ([legal entity — to be finalized]) acts as the processor, processing only on your documented instructions (which include your use of the Service’s features) and as needed to provide the Service.
2. Nature and purpose of processing
We process Customer Personal Data to host, operate, secure, and support the Service — the land-to-build workflow described in the Terms. The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are described in [Annex I — to be completed].
3. Confidentiality
We ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
4. Security
We maintain technical and organizational measures appropriate to the risk, including encryption in transit, access controls, virus scanning of uploads, and audit logging. A summary of measures is set out in [Annex II — to be completed].
5. Subprocessors
You authorize us to engage subprocessors to provide the Service (for example: cloud hosting and storage, automated/AI inference, payment processing, email delivery, and analytics). We impose data-protection terms on each subprocessor consistent with this DPA and remain responsible for their performance. The current list is available on request; we will give reasonable notice of changes so you may object on reasonable data-protection grounds.
6. Data subject requests
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from data subjects to exercise their rights (access, correction, deletion, portability, objection) under applicable law.
7. International transfers
Where Customer Personal Data is transferred across borders, the parties will rely on a lawful transfer mechanism — for example, the European Commission’s Standard Contractual Clauses and the UK Addendum where applicable — which are incorporated by reference when required.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your notification obligations.
9. Return and deletion
On termination, and at your choice, we will delete or return Customer Personal Data within a reasonable period, except where retention is required by law.
10. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable confidentiality, scope, and frequency limits.
11. Contact
Data-protection questions or DPA requests: [email protected].