Legal
Data Processing Addendum
Last updated: 1 June 2026 · UK GDPR Article 28 Compliant
Enterprise / Regulated Customers
If you require a countersigned DPA for your own compliance records, or if you require the DPA to be incorporated into a separate master services agreement, please contact legal@measuredeck.com. We will provide a signed copy within 5 business days.
1. Introduction
This Data Processing Addendum (“DPA”) forms part of the agreement between MeasureDeck Ltd (“MeasureDeck,” “Processor”) and the customer (“Controller”) for the use of the MeasureDeck Services as defined in the Terms of Service. This DPA applies where the Controller processes personal data of individuals (including their employees, project personnel, supply chain contacts, or subcontractor contacts) by uploading or storing such data in the Services.
This DPA is intended to comply with the requirements of Article 28 of UK GDPR and Article 28 of EU GDPR where applicable, which require that processing by a processor be governed by a binding contract or other legal act.
In the event of any conflict between this DPA and the Terms of Service, the DPA shall take precedence in relation to the processing of personal data.
2. Definitions
- “Controller” means the customer who determines the purposes and means of processing personal data in the Services;
- “Processor” means MeasureDeck Ltd, which processes personal data on behalf of the Controller;
- “Data Subject” means the natural person to whom personal data relates;
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined in UK GDPR;
- “Processing” has the meaning given in UK GDPR;
- “Sub-processor” means any third party engaged by MeasureDeck to process personal data on its behalf in the delivery of the Services;
- “UK GDPR” means the UK General Data Protection Regulation as it forms part of retained EU law in the United Kingdom;
- “EU GDPR” means Regulation (EU) 2016/679;
- “SCCs” means the UK International Data Transfer Addendum (IDTA) to the EU Commission's Standard Contractual Clauses, as published by the ICO.
3. Nature, Purpose, and Subject Matter of Processing
3.1 Subject Matter
The subject matter of the processing is the provision of the MeasureDeck commercial management platform, including storage, retrieval, and processing of data uploaded by the Controller.
3.2 Duration
Processing shall continue for the term of the Controller's subscription to the Services and for the data retention periods set out in the Privacy Policy and this DPA following termination.
3.3 Nature and Purpose
Processing activities include storing, organising, retrieving, displaying, indexing, and deleting personal data uploaded by the Controller in connection with construction project commercial management, including but not limited to: contact information of project personnel, supplier and subcontractor contacts, names and details in change registers and payment applications, and employee data in team and user management features.
3.4 Types of Personal Data
The types of personal data processed may include:
- Contact details (name, email address, telephone number, job title, company name) of project personnel, subcontractors, and suppliers;
- User account data (name, email address, role) of the Controller's team members;
- Any personal data contained in documents, photographs, correspondence, or notes uploaded by the Controller to the Services.
3.5 Categories of Data Subjects
Categories of data subjects may include:
- Employees and contractors of the Controller;
- Employees and representatives of subcontractors, suppliers, and clients;
- Site personnel featured in photographs or site records.
4. Obligations of the Processor
MeasureDeck (as Processor) agrees to:
- Process personal data only on documented instructions from the Controller, including transfers of personal data to a third country, unless required to do so by applicable law (in which case MeasureDeck will notify the Controller before processing, unless prohibited by law);
- Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement and maintain appropriate technical and organisational security measures as described in this DPA;
- Not engage sub-processors without the Controller's prior general authorisation (as described in Section 6);
- Assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under UK GDPR, by making available to the Controller the personal data we hold and providing reasonable technical assistance;
- Assist the Controller in ensuring compliance with security obligations, breach notification, data protection impact assessments, and prior consultation under Articles 32–36 of UK GDPR, taking into account the nature of processing and information available to MeasureDeck;
- At the choice of the Controller, delete or return all personal data at the end of the provision of Services, and delete existing copies unless storage is required by applicable law;
- Make available to the Controller all information necessary to demonstrate compliance with the obligations in Article 28 of UK GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.
5. Security Measures
MeasureDeck implements and maintains the following technical and organisational security measures appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing:
5.1 Encryption
- AES-256 encryption of all personal data at rest;
- TLS 1.3 encryption of all personal data in transit;
- Hardware Security Module (HSM) backed key management with automated annual key rotation.
5.2 Access Controls
- Role-based access control (RBAC) at application level;
- Row-level security (RLS) enforced at database level to ensure users can only access data within their authorised workspace;
- Multi-factor authentication (MFA) available and recommended for all users;
- Principle of least privilege applied to all internal staff access;
- Regular access reviews for internal staff with access to production systems.
5.3 Availability and Resilience
- Automated database backups with point-in-time recovery;
- Redundant infrastructure across multiple availability zones;
- Business continuity and disaster recovery plan maintained and tested annually.
5.4 Monitoring and Testing
- Comprehensive audit logging of all access and processing activities;
- Annual third-party penetration testing with findings remediated on a risk-based timeline;
- Automated vulnerability scanning in CI/CD pipeline;
- Security incident response procedures.
6. Sub-processors
6.1 General Authorisation
The Controller provides general authorisation for MeasureDeck to engage the sub-processors listed at measuredeck.com/subprocessors. MeasureDeck will provide at least 30 days' notice before adding or replacing any sub-processor, giving the Controller the opportunity to object to such changes.
6.2 Sub-processor Obligations
MeasureDeck imposes data protection obligations on all sub-processors equivalent to those set out in this DPA by way of contractual terms. MeasureDeck remains liable to the Controller for the performance of its sub-processors' obligations.
6.3 International Transfers
Where sub-processors are located outside the UK or EEA (including Stripe, OpenAI, Resend, and Cloudflare in the USA), MeasureDeck ensures appropriate safeguards are in place, including the UK IDTA (International Data Transfer Addendum) or equivalent UK-approved transfer mechanism incorporating the EU Standard Contractual Clauses.
7. Personal Data Breach Notification
In the event of a personal data breach affecting Controller personal data processed by MeasureDeck, MeasureDeck will:
- Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach;
- Provide the Controller with sufficient information to meet its own notification obligations under Article 33 of UK GDPR, including the nature of the breach, the categories and approximate number of data subjects and personal data records affected, likely consequences, and measures taken or proposed to address the breach;
- Cooperate with the Controller and take reasonable steps to mitigate and remediate the breach.
8. Data Subject Rights Assistance
MeasureDeck will provide reasonable technical and organisational assistance to the Controller to respond to requests from data subjects exercising their rights under UK GDPR (Articles 15–22). The Controller remains responsible for responding to data subject requests within the statutory timeframe.
MeasureDeck will notify the Controller promptly if it receives a request directly from a data subject relating to personal data for which the Controller is the controller, without responding to that request unless instructed to do so.
9. Audit Rights
The Controller has the right to audit MeasureDeck's compliance with this DPA, subject to: (a) providing at least 30 days' prior written notice; (b) limiting audits to once per calendar year unless required by a regulatory authority; (c) conducting audits during normal business hours; (d) minimising disruption to MeasureDeck's operations; and (e) entering into a reasonable confidentiality agreement covering information learned during the audit.
MeasureDeck may provide audit reports or certifications from independent third parties in lieu of on-site audits where these demonstrate compliance with the relevant requirements.
10. Governing Law
This DPA is governed by the law of England and Wales. Any disputes arising under this DPA are subject to the exclusive jurisdiction of the courts of England and Wales.
11. Contact
For DPA enquiries, to request a countersigned copy, or for any data protection matters:
- Email: legal@measuredeck.com
- DPO: dpo@measuredeck.com
- Post: MeasureDeck Ltd, Data Protection Officer, 1 Commercial Street, London, EC1A 1AA