PricingBlogSign inStart free trial

SiteWrite · Data Processing Addendum · v1.2

Data Processing Addendum

Version 1.2 · Effective from 15 June 2026

This Data Processing Addendum (the “DPA”) forms part of, and is subject to, the SiteWrite Terms of Service (the “Terms”) entered into between SiteWrite Ltd, a company incorporated in England and Wales with company number 17177709 whose registered office is at 91 Princess Street, Manchester, M1 4HT (the “Processor”, “we”, “us”, or “our”), and the Customer identified in the Order (the “Controller”, “you”, or “your”).

This DPA applies to our processing of Personal Data on the Controller’s behalf in connection with the Service. In the event of any conflict between the Terms and this DPA, this DPA prevails to the extent of the conflict in respect of the processing of Personal Data.

Capitalised terms used but not defined in this DPA have the meanings given to them in the Terms.

1. Definitions

1.1
In this DPA:
  • “Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “special category data” each have the meanings given in the UK GDPR.
  • “Controller Personal Data” means any Personal Data that the Processor processes on behalf of the Controller in connection with the Service.
  • “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other applicable laws relating to the processing of Personal Data, in each case as amended from time to time.
  • “International Transfer” means a transfer of Personal Data to a country, territory or international organisation outside the United Kingdom that is not the subject of an adequacy decision under UK GDPR.
  • “Restricted Transfer Mechanism” means the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or any other transfer mechanism recognised under UK GDPR for International Transfers.
  • “Sub-processor” means any third party engaged by the Processor to process Controller Personal Data in connection with the Service.
  • “UK GDPR” means the United Kingdom General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018.

2. Subject matter and scope

2.1
The parties acknowledge that:
  • the Controller is the controller and the Processor is the processor of the Controller Personal Data;
  • the Processor processes Controller Personal Data on behalf of the Controller in connection with the provision of the Service under the Terms; and
  • the subject matter, duration, nature and purpose of the processing, the categories of data subjects, and the types of Personal Data processed are described in Annex 1 to this DPA.
2.2
The Controller is responsible for ensuring that it has all necessary lawful bases, consents, notices and authorisations in place to permit the Processor to process the Controller Personal Data as contemplated by the Terms and this DPA.

3. Processor obligations

3.1
Processing only on documented instructions. The Processor will process Controller Personal Data only on the documented instructions of the Controller, including with regard to International Transfers, unless required to do so by law to which the Processor is subject. The Terms, this DPA, the Documentation, and the Controller’s configuration of the Service constitute the Controller’s documented instructions. If the Processor is required by law to process Personal Data otherwise than in accordance with the Controller’s instructions, it will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
3.2
Confidentiality. The Processor will ensure that all personnel authorised to process Controller Personal Data are bound by appropriate obligations of confidentiality, whether contractual or statutory, and have received appropriate data protection training.
3.3
Security measures. The Processor will implement and maintain the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk of the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of data subjects.
3.4
Assistance with data subject requests. Taking into account the nature of the processing, the Processor will assist the Controller, by appropriate technical and organisational measures and insofar as is reasonably possible, in fulfilling the Controller’s obligation to respond to requests from data subjects exercising their rights under Data Protection Laws. The Service provides Authorised Users with a self-service facility to access and export Controller Personal Data in a structured, machine-readable format. Correction and erasure of Controller Personal Data are available on request to the Processor, which the Processor will action without undue delay. Where the Controller requires assistance beyond these standard facilities, the Processor may charge reasonable additional fees for time and materials.
3.5
Assistance with compliance obligations. Taking into account the nature of the processing and the information available to it, the Processor will provide reasonable assistance to the Controller in respect of the Controller’s obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation).
3.6
Personal data breach notification. The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Controller Personal Data. That notification will include, to the extent then known to the Processor, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, and the measures taken or proposed to address the breach. The Processor will provide further information as it becomes available. The Processor will not delay notification while completing investigation; further information will follow as it is established.
3.7
Audit. The Processor will make available to the Controller, on reasonable request and subject to confidentiality undertakings, information sufficient to demonstrate compliance with this DPA, including a copy of any current third-party audit reports (such as SOC 2 or ISO 27001 reports of its sub-processors, where available). The Controller may, no more than once in any 12-month period and on at least 30 days’ written notice, conduct an audit of the Processor’s relevant policies and procedures during normal business hours, by itself or through an independent auditor that is not a competitor of the Processor and is bound by confidentiality obligations. The Controller will bear the costs of any such audit unless the audit reveals a material breach by the Processor of this DPA. Audits in response to a personal data breach affecting the Controller may be conducted on shorter notice and on a more frequent basis as reasonably required.
3.8
Return and deletion of data. On termination or expiry of the Terms, the Processor will, at the Controller’s choice, return or delete all Controller Personal Data in accordance with clauses 6.5 and 6.6 of the Terms, save where applicable law requires retention of some or all of that data. The Controller is responsible for downloading or exporting its photographs, generated Reports and other survey files within the 30-day period referred to in clause 6.5 of the Terms, as set out in clause 6.6 of the Terms. Where deletion is not immediately possible because Controller Personal Data persists in routine encrypted backups, the Processor will isolate that data from active processing and delete it on expiry of the applicable backup retention cycle, and in any event within 90 days of termination. Encrypted database backups are retained for 7 days; off-site file backups are deleted in accordance with the Processor’s backup lifecycle policy.

4. Sub-processing

4.1
The Controller grants the Processor general authorisation to engage Sub-processors to process Controller Personal Data, subject to this clause 4. A current list of Sub-processors is published at sitewrite.ai/subprocessors and the Controller is responsible for monitoring that list.
4.2
The Processor will:
  • enter into a written agreement with each Sub-processor that imposes on the Sub-processor data protection obligations equivalent in substance to those imposed on the Processor under this DPA;
  • remain liable to the Controller for the performance of the Sub-processor’s obligations to the same extent as if the relevant processing had been carried out by the Processor; and
  • give the Controller at least 14 days’ prior notice of any intended addition or replacement of a Sub-processor, by updating the list at sitewrite.ai/subprocessors and (if the Controller has subscribed to such notifications) by email to the Controller’s account administrator.
4.3
The Controller may object to a new Sub-processor on reasonable data protection grounds by written notice within 14 days of the notification described in clause 4.2(c). The parties will discuss the objection in good faith. If the Processor is unable to address the Controller’s objection by adopting alternative measures, the Controller may, as its sole and exclusive remedy, terminate the affected portion of the Service on written notice, and the Processor will refund any prepaid Fees for periods after the termination date. Continued use of the affected service after the 14-day notice period without objection constitutes acceptance of the new Sub-processor.

5. International transfers

5.1
The Processor may make International Transfers of Controller Personal Data, including to its Sub-processors, only where it has put in place a Restricted Transfer Mechanism appropriate to the transfer, and any supplementary measures reasonably necessary to ensure an essentially equivalent level of protection.
5.2
Where required, the Controller authorises the Processor to enter into Restricted Transfer Mechanisms with Sub-processors on the Controller’s behalf, provided that the terms of those mechanisms are no less protective than those set out in this DPA.
5.3
Details of the transfer mechanisms applicable to each Sub-processor are available on request to hello@sitewrite.ai.
5.4
Primary processing location. The primary database in which Controller Personal Data is stored is located within the European Economic Area, which benefits from UK adequacy and therefore does not require a Restricted Transfer Mechanism. Certain other processing — including application, email-delivery and document-generation functions — and certain Sub-processors operate outside the United Kingdom and the EEA, including in the United States. Such transfers are made under a Restricted Transfer Mechanism in accordance with this clause 5. The location of each Sub-processor is identified at sitewrite.ai/subprocessors.

6. Liability

6.1
The liability of each party under or in connection with this DPA (including any third-party claims under Article 82 UK GDPR) is governed by, and subject to, the limitations and exclusions of liability set out in clause 12 of the Terms.
6.2
Nothing in this DPA limits or excludes either party’s liability where the same cannot be limited or excluded under Data Protection Laws.

7. General

7.1
This DPA forms part of the Terms. Save as expressly amended by this DPA, all provisions of the Terms continue in full force and effect.
7.2
This DPA will be reviewed and updated from time to time to reflect changes in Data Protection Laws or in the Service. The Processor will give the Controller reasonable notice of any material change.
7.3
This DPA is governed by, and construed in accordance with, the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales for any dispute arising out of or in connection with it.

Annex 1 · Description of processing

A. Subject matter and duration of the processing

The processing concerns the Controller Personal Data uploaded to, generated within, or otherwise processed in connection with the Customer’s use of the SiteWrite multi-tenant software-as-a-service platform for the purposes of preparing professional inspection-based reports.

The processing will continue for the duration of the Subscription Term, and for any post-termination period during which the Processor retains Controller Personal Data in accordance with clause 3.8 of this DPA and clauses 6.5 and 6.6 of the Terms.

B. Nature and purpose of the processing

The Processor processes Controller Personal Data for the purpose of providing the Service, including:

  • hosting, storing, indexing, transmitting, displaying and backing up Controller Personal Data;
  • authenticating Authorised Users and applying tier-based access controls;
  • operating the field application, the firm administration application, the offline capture and synchronisation feature, and any related edge functions and APIs;
  • transmitting structured inputs to large language model providers in response to AI Write requests, and returning the resulting Output to the Authorised User for review. The Processor does not permit its model providers to use the inputs submitted to their interfaces to train their models; this position is secured through the model providers’ applicable commercial terms rather than through a technical zero-retention configuration within the Service;
  • logging operational and audit events including sign-in events, feature usage, AI prompt sources resolved, and administrative actions;
  • providing customer support, troubleshooting and incident response;
  • performing routine operational tasks such as billing, security monitoring, fraud and bot prevention, and compliance with legal obligations.

C. Categories of data subjects

The Controller Personal Data may relate to the following categories of data subjects:

  • the Controller’s Authorised Users (including surveyors, inspectors, assessors, administrators, and other Customer Personnel);
  • the Controller’s end-clients who commission Reports through the Controller (for example, prospective property purchasers, property owners, landlords, tenants, lenders, or their agents);
  • third parties whose details may incidentally appear in inspection records and Reports (for example, occupiers, contractors, vendors’ representatives, or named professionals).

D. Categories of Personal Data

The Controller Personal Data may include the following categories:

  • Authorised User identifiers and contact details: name, business email, role, professional qualifications, RICS or other regulator registration number, telephone number, signature image;
  • authentication and security data: hashed password, multi-factor authentication tokens, session and refresh tokens, IP addresses, device information, sign-in timestamps;
  • consent and acceptance records: the date and version of the Terms and related notices accepted, and the IP address from which acceptance was given (the IP address being obtained via a third-party IP-lookup service and visible to the Controller’s firm administrators);
  • end-client and instruction details: name, address, contact details, instruction reference, fee information;
  • property-related Personal Data: property address, occupancy details, photographs (which may incidentally include images of individuals or personal possessions);
  • Report content: condition observations, defect identifications, narrative descriptions, recommendations, advisories, risk and hazard determinations, and any associated AI-generated drafts;
  • AI call-log metadata: the prompt source resolved, a truncated snapshot of the inputs submitted for an AI Write request, and token-usage counts. The log does not retain the generated Output. The input snapshot may contain free-text entered by an Authorised User;
  • operational and audit metadata associated with the foregoing categories.

E. Special category data

The Service is not designed to deliberately record special category data, and its structured fields, phrase libraries and prompts do not solicit it. The Controller acknowledges, however, that special category data may incidentally be processed — for example, where photographs of occupied properties capture personal possessions, mobility aids, or religious or similar items, or where Authorised Users enter free-text or dictated observations. The Processor applies the following safeguards in respect of any such incidental processing: data-minimisation guidance in the Documentation, tenant isolation through row-level security, the retention and deletion controls described in this DPA, and the correction and erasure mechanisms in clause 3.4. The Controller must not knowingly upload special category data to the Service except where it has determined that such processing is lawful and proportionate under Data Protection Laws and has notified the Processor in writing of the categories of special category data being processed.

F. Frequency and duration of retention

Controller Personal Data is processed continuously throughout the Subscription Term. Retention periods within the Service are configured by the Controller, subject to operational minimums published in the Documentation. On termination, retention is governed by clause 3.8 of this DPA and clauses 6.5 and 6.6 of the Terms.


Annex 2 · Technical and organisational security measures

The Processor will implement and maintain the following technical and organisational measures, which it may update from time to time provided that the overall level of protection is not materially reduced.

A. Access control and tenant isolation

  • Multi-tenant architecture with strict tenant isolation enforced at the database layer through row-level security.
  • Tier-based access control distinguishing platform administrators, firm administrators, and field users. Each user has a unique account; account sharing is prohibited.
  • Multi-factor authentication required for administrative access to production systems.
  • Principle of least privilege applied to internal access; access to Controller Personal Data is granted only to personnel who need it for support, security, or operational purposes.

B. Encryption

  • Encryption of Controller Personal Data in transit using TLS 1.2 or higher between client devices, application servers, and database.
  • Encryption of Controller Personal Data at rest in the database and in object storage using industry-standard algorithms.

C. Network and infrastructure security

  • Production infrastructure hosted with enterprise-grade cloud providers operating recognised security frameworks (for example, SOC 2, ISO 27001).
  • Network segmentation, firewall rules and bot/abuse protection at the edge.
  • Regular patching of operating systems and dependencies.
  • Vulnerability scanning of application dependencies.

D. Application security

  • Secure software development lifecycle including code review for changes that affect access control or Personal Data handling.
  • Defence against common web application vulnerabilities (OWASP Top 10).
  • Server-side validation and authorisation enforced for every privileged action.
  • Secrets management using environment variables and managed secret stores; no secrets committed to source control.

E. Logging and monitoring

  • Audit logging of sign-in events, administrative actions, AI prompt source resolution, and significant configuration changes.
  • AI Write requests are logged as the prompt source resolved, a truncated snapshot of the inputs, and token-usage counts; the generated Output is not retained in the log.
  • Operational monitoring with alerts for anomalous activity.
  • Retention of logs for a period appropriate to security and audit purposes.

F. Backup and resilience

  • Regular automated backups of the production database, encrypted at rest, retained for 7 days, with continuous transaction-log archiving to support point-in-time recovery within that retention window.
  • A separate, encrypted off-site backup of file storage (including photographs and generated Reports), maintained on a routine schedule independent of the primary database backups, with deleted objects purged in accordance with the Processor’s backup lifecycle policy.
  • A documented business continuity and disaster recovery plan with a defined recovery time objective, tested periodically by performing a restore to a working copy.

G. Personnel

  • Confidentiality obligations imposed on all personnel by contract.
  • Data protection and security training appropriate to the role.
  • Background checks where lawful and proportionate to the role.

H. Incident response

  • Documented incident response procedure including triage, containment, investigation, notification, and remediation.
  • Designated point of contact for security and personal data breach matters.

I. Sub-processor management

  • Sub-processors selected on the basis of their ability to provide sufficient guarantees of compliance with Data Protection Laws.
  • Written agreements with Sub-processors imposing equivalent data protection obligations.
  • Periodic review of Sub-processor security posture and certifications.

Acceptance

This DPA is incorporated into the Terms and forms part of them. By accepting the Terms (whether by signing an Order, accepting electronically, or accessing or using the Service), the Controller is also accepting this DPA.

A signed counterpart of this DPA is available on request from hello@sitewrite.ai.

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Addendum
  • Sub-processors
  • Beta Programme Addendum
  • Account Deletion

SiteWrite Ltd is a company registered in England and Wales, number 17177709. Registered office: 91 Princess Street, Manchester, M1 4HT.

© 2026 SiteWrite Ltd. hello@sitewrite.ai