SiteWrite · Data Processing Addendum · v1.2
Data Processing Addendum
Version 1.2 · Effective from 15 June 2026
This Data Processing Addendum (the “DPA”) forms part of, and is subject to, the SiteWrite Terms of Service (the “Terms”) entered into between SiteWrite Ltd, a company incorporated in England and Wales with company number 17177709 whose registered office is at 91 Princess Street, Manchester, M1 4HT (the “Processor”, “we”, “us”, or “our”), and the Customer identified in the Order (the “Controller”, “you”, or “your”).
This DPA applies to our processing of Personal Data on the Controller’s behalf in connection with the Service. In the event of any conflict between the Terms and this DPA, this DPA prevails to the extent of the conflict in respect of the processing of Personal Data.
Capitalised terms used but not defined in this DPA have the meanings given to them in the Terms.
1. Definitions
- “Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “special category data” each have the meanings given in the UK GDPR.
- “Controller Personal Data” means any Personal Data that the Processor processes on behalf of the Controller in connection with the Service.
- “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other applicable laws relating to the processing of Personal Data, in each case as amended from time to time.
- “International Transfer” means a transfer of Personal Data to a country, territory or international organisation outside the United Kingdom that is not the subject of an adequacy decision under UK GDPR.
- “Restricted Transfer Mechanism” means the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or any other transfer mechanism recognised under UK GDPR for International Transfers.
- “Sub-processor” means any third party engaged by the Processor to process Controller Personal Data in connection with the Service.
- “UK GDPR” means the United Kingdom General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018.
2. Subject matter and scope
- the Controller is the controller and the Processor is the processor of the Controller Personal Data;
- the Processor processes Controller Personal Data on behalf of the Controller in connection with the provision of the Service under the Terms; and
- the subject matter, duration, nature and purpose of the processing, the categories of data subjects, and the types of Personal Data processed are described in Annex 1 to this DPA.
3. Processor obligations
4. Sub-processing
- enter into a written agreement with each Sub-processor that imposes on the Sub-processor data protection obligations equivalent in substance to those imposed on the Processor under this DPA;
- remain liable to the Controller for the performance of the Sub-processor’s obligations to the same extent as if the relevant processing had been carried out by the Processor; and
- give the Controller at least 14 days’ prior notice of any intended addition or replacement of a Sub-processor, by updating the list at sitewrite.ai/subprocessors and (if the Controller has subscribed to such notifications) by email to the Controller’s account administrator.
5. International transfers
6. Liability
7. General
Annex 1 · Description of processing
A. Subject matter and duration of the processing
The processing concerns the Controller Personal Data uploaded to, generated within, or otherwise processed in connection with the Customer’s use of the SiteWrite multi-tenant software-as-a-service platform for the purposes of preparing professional inspection-based reports.
The processing will continue for the duration of the Subscription Term, and for any post-termination period during which the Processor retains Controller Personal Data in accordance with clause 3.8 of this DPA and clauses 6.5 and 6.6 of the Terms.
B. Nature and purpose of the processing
The Processor processes Controller Personal Data for the purpose of providing the Service, including:
- hosting, storing, indexing, transmitting, displaying and backing up Controller Personal Data;
- authenticating Authorised Users and applying tier-based access controls;
- operating the field application, the firm administration application, the offline capture and synchronisation feature, and any related edge functions and APIs;
- transmitting structured inputs to large language model providers in response to AI Write requests, and returning the resulting Output to the Authorised User for review. The Processor does not permit its model providers to use the inputs submitted to their interfaces to train their models; this position is secured through the model providers’ applicable commercial terms rather than through a technical zero-retention configuration within the Service;
- logging operational and audit events including sign-in events, feature usage, AI prompt sources resolved, and administrative actions;
- providing customer support, troubleshooting and incident response;
- performing routine operational tasks such as billing, security monitoring, fraud and bot prevention, and compliance with legal obligations.
C. Categories of data subjects
The Controller Personal Data may relate to the following categories of data subjects:
- the Controller’s Authorised Users (including surveyors, inspectors, assessors, administrators, and other Customer Personnel);
- the Controller’s end-clients who commission Reports through the Controller (for example, prospective property purchasers, property owners, landlords, tenants, lenders, or their agents);
- third parties whose details may incidentally appear in inspection records and Reports (for example, occupiers, contractors, vendors’ representatives, or named professionals).
D. Categories of Personal Data
The Controller Personal Data may include the following categories:
- Authorised User identifiers and contact details: name, business email, role, professional qualifications, RICS or other regulator registration number, telephone number, signature image;
- authentication and security data: hashed password, multi-factor authentication tokens, session and refresh tokens, IP addresses, device information, sign-in timestamps;
- consent and acceptance records: the date and version of the Terms and related notices accepted, and the IP address from which acceptance was given (the IP address being obtained via a third-party IP-lookup service and visible to the Controller’s firm administrators);
- end-client and instruction details: name, address, contact details, instruction reference, fee information;
- property-related Personal Data: property address, occupancy details, photographs (which may incidentally include images of individuals or personal possessions);
- Report content: condition observations, defect identifications, narrative descriptions, recommendations, advisories, risk and hazard determinations, and any associated AI-generated drafts;
- AI call-log metadata: the prompt source resolved, a truncated snapshot of the inputs submitted for an AI Write request, and token-usage counts. The log does not retain the generated Output. The input snapshot may contain free-text entered by an Authorised User;
- operational and audit metadata associated with the foregoing categories.
E. Special category data
The Service is not designed to deliberately record special category data, and its structured fields, phrase libraries and prompts do not solicit it. The Controller acknowledges, however, that special category data may incidentally be processed — for example, where photographs of occupied properties capture personal possessions, mobility aids, or religious or similar items, or where Authorised Users enter free-text or dictated observations. The Processor applies the following safeguards in respect of any such incidental processing: data-minimisation guidance in the Documentation, tenant isolation through row-level security, the retention and deletion controls described in this DPA, and the correction and erasure mechanisms in clause 3.4. The Controller must not knowingly upload special category data to the Service except where it has determined that such processing is lawful and proportionate under Data Protection Laws and has notified the Processor in writing of the categories of special category data being processed.
F. Frequency and duration of retention
Controller Personal Data is processed continuously throughout the Subscription Term. Retention periods within the Service are configured by the Controller, subject to operational minimums published in the Documentation. On termination, retention is governed by clause 3.8 of this DPA and clauses 6.5 and 6.6 of the Terms.
Annex 2 · Technical and organisational security measures
The Processor will implement and maintain the following technical and organisational measures, which it may update from time to time provided that the overall level of protection is not materially reduced.
A. Access control and tenant isolation
- Multi-tenant architecture with strict tenant isolation enforced at the database layer through row-level security.
- Tier-based access control distinguishing platform administrators, firm administrators, and field users. Each user has a unique account; account sharing is prohibited.
- Multi-factor authentication required for administrative access to production systems.
- Principle of least privilege applied to internal access; access to Controller Personal Data is granted only to personnel who need it for support, security, or operational purposes.
B. Encryption
- Encryption of Controller Personal Data in transit using TLS 1.2 or higher between client devices, application servers, and database.
- Encryption of Controller Personal Data at rest in the database and in object storage using industry-standard algorithms.
C. Network and infrastructure security
- Production infrastructure hosted with enterprise-grade cloud providers operating recognised security frameworks (for example, SOC 2, ISO 27001).
- Network segmentation, firewall rules and bot/abuse protection at the edge.
- Regular patching of operating systems and dependencies.
- Vulnerability scanning of application dependencies.
D. Application security
- Secure software development lifecycle including code review for changes that affect access control or Personal Data handling.
- Defence against common web application vulnerabilities (OWASP Top 10).
- Server-side validation and authorisation enforced for every privileged action.
- Secrets management using environment variables and managed secret stores; no secrets committed to source control.
E. Logging and monitoring
- Audit logging of sign-in events, administrative actions, AI prompt source resolution, and significant configuration changes.
- AI Write requests are logged as the prompt source resolved, a truncated snapshot of the inputs, and token-usage counts; the generated Output is not retained in the log.
- Operational monitoring with alerts for anomalous activity.
- Retention of logs for a period appropriate to security and audit purposes.
F. Backup and resilience
- Regular automated backups of the production database, encrypted at rest, retained for 7 days, with continuous transaction-log archiving to support point-in-time recovery within that retention window.
- A separate, encrypted off-site backup of file storage (including photographs and generated Reports), maintained on a routine schedule independent of the primary database backups, with deleted objects purged in accordance with the Processor’s backup lifecycle policy.
- A documented business continuity and disaster recovery plan with a defined recovery time objective, tested periodically by performing a restore to a working copy.
G. Personnel
- Confidentiality obligations imposed on all personnel by contract.
- Data protection and security training appropriate to the role.
- Background checks where lawful and proportionate to the role.
H. Incident response
- Documented incident response procedure including triage, containment, investigation, notification, and remediation.
- Designated point of contact for security and personal data breach matters.
I. Sub-processor management
- Sub-processors selected on the basis of their ability to provide sufficient guarantees of compliance with Data Protection Laws.
- Written agreements with Sub-processors imposing equivalent data protection obligations.
- Periodic review of Sub-processor security posture and certifications.
Acceptance
This DPA is incorporated into the Terms and forms part of them. By accepting the Terms (whether by signing an Order, accepting electronically, or accessing or using the Service), the Controller is also accepting this DPA.
A signed counterpart of this DPA is available on request from hello@sitewrite.ai.