Legal

Data Processing Addendum

Last updated June 22, 2026

This Data Processing Addendum (“DPA”) supplements the Terms of Service and applies where faircompanies.build processes personal data on your behalf — for example, when you (a business or Enterprise customer) upload data about your clients, team, or projects.

This is a template DPA for review, not yet a finalized contract. Enterprise customers who require a countersigned DPA (with the data tables and any regional terms completed) should contact [email protected]. Bracketed items are placeholders to be finalized with counsel.

1. Roles and scope

For personal data you submit through the Service (“Customer Personal Data”), you act as the controller and faircompanies.build ([legal entity — to be finalized]) acts as the processor, processing only on your documented instructions (which include your use of the Service’s features) and as needed to provide the Service.

2. Nature and purpose of processing

We process Customer Personal Data to host, operate, secure, and support the Service — the land-to-build workflow described in the Terms. The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are described in [Annex I — to be completed].

3. Confidentiality

We ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.

4. Security

We maintain technical and organizational measures appropriate to the risk, including encryption in transit, access controls, virus scanning of uploads, and audit logging. A summary of measures is set out in [Annex II — to be completed].

5. Subprocessors

You authorize us to engage subprocessors to provide the Service (for example: cloud hosting and storage, automated/AI inference, payment processing, email delivery, and analytics). We impose data-protection terms on each subprocessor consistent with this DPA and remain responsible for their performance. The current list is available on request; we will give reasonable notice of changes so you may object on reasonable data-protection grounds.

6. Data subject requests

Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from data subjects to exercise their rights (access, correction, deletion, portability, objection) under applicable law.

7. International transfers

Where Customer Personal Data is transferred across borders, the parties will rely on a lawful transfer mechanism — for example, the European Commission’s Standard Contractual Clauses and the UK Addendum where applicable — which are incorporated by reference when required.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your notification obligations.

9. Return and deletion

On termination, and at your choice, we will delete or return Customer Personal Data within a reasonable period, except where retention is required by law.

10. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable confidentiality, scope, and frequency limits.

11. Contact

Data-protection questions or DPA requests: [email protected].