Back to Home

Data Processing Agreement (DPA)

Version 1.0 — Effective: May 13, 2026

BuildFlow Pro — Enterprise Data Processing Addendum

This DPA is available to Enterprise plan subscribers and governs our processing of personal data on your behalf under applicable data protection laws.

1. Definitions

  • "Controller" means you, the customer, who determines the purposes and means of the processing of personal data.
  • "Processor" means BuildFlow Pro, which processes personal data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person provided to or collected by the Platform.
  • "Sub-processor" means any third party engaged by BuildFlow Pro to assist in processing personal data.
  • "Data Subject" means any identified or identifiable natural person whose personal data is processed.
  • "Processing" means any operation performed on personal data, whether automated or manual.

2. Scope & Purpose

This DPA applies to all personal data processed by BuildFlow Pro on behalf of the Controller. Processing is performed solely to provide the BuildFlow Pro service, including:

  • Storing and managing project data, client information, and team member details
  • Generating estimates, contracts, change orders, and financial documents
  • Facilitating payment processing through Stripe
  • Synchronizing accounting data with QuickBooks
  • Sending transactional emails and notifications
  • Providing client portals, subcontractor portals, and collaboration features

3. Obligations of the Processor

BuildFlow Pro shall:

  • Process personal data only on documented instructions from the Controller, unless required by law
  • Ensure that persons authorized to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (see Section 5)
  • Not engage additional sub-processors without prior specific or general written authorization
  • Assist the Controller in responding to data subject requests (access, rectification, erasure, portability)
  • Assist the Controller in ensuring compliance with security, breach notification, and impact assessment obligations
  • Delete or return all personal data upon termination of service, unless retention is required by law
  • Make available all information necessary to demonstrate compliance and allow for audits

4. Obligations of the Controller

The Controller shall:

  • Ensure that the processing of personal data has a valid legal basis
  • Provide data subjects with required notices regarding the processing
  • Ensure that instructions for processing are lawful and consistent with applicable data protection law
  • Promptly notify BuildFlow Pro of any changes in processing requirements
  • Obtain proper consent from clients, subcontractors, and homeowners before uploading their personal data

5. Security Measures

BuildFlow Pro implements the following technical and organizational measures:

  • Encryption in transit: TLS 1.2+ / HTTPS for all data transmission
  • Encryption at rest: AES-256 encryption for stored data
  • Access controls: Role-based access control (RBAC) with least-privilege principle
  • Authentication: Secure session management with automatic timeout
  • Monitoring: Continuous logging of access and changes (audit trails)
  • Incident response: Documented breach notification procedures (see Breach Notification Policy)
  • Backup: Regular automated backups with tested restoration procedures
  • Vendor security: Sub-processors are vetted for security compliance

6. Sub-processors

BuildFlow Pro currently uses the following sub-processors:

Sub-processorPurposeLocation
Stripe, Inc.Payment processingUnited States
Intuit (QuickBooks)Accounting syncUnited States
ResendEmail deliveryUnited States
Cloud hosting providerInfrastructure & storageUnited States

The Controller will be notified at least 30 days in advance of any changes to the sub-processor list. The Controller may object to a new sub-processor within 14 days of notification.

7. Data Subject Rights

BuildFlow Pro will assist the Controller in fulfilling data subject requests under GDPR, CCPA, and other applicable laws, including requests for:

  • Access to personal data
  • Rectification or correction of personal data
  • Erasure ("right to be forgotten")
  • Restriction of processing
  • Data portability (export in machine-readable format)
  • Objection to processing

Requests will be processed within 30 days. Complex requests may require an additional 30-day extension with notice.

8. Data Breach Notification

In the event of a personal data breach, BuildFlow Pro will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:

  • Nature of the breach, including categories and approximate number of data subjects affected
  • Contact information for the BuildFlow Pro data protection contact
  • Description of likely consequences of the breach
  • Measures taken or proposed to address and mitigate the breach

For full details, see our Breach Notification Policy.

9. International Transfers

Personal data is processed and stored primarily in the United States. For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland, BuildFlow Pro relies on Standard Contractual Clauses (SCCs) as approved by the European Commission.

10. Data Retention & Deletion

Upon termination of the service agreement:

  • The Controller may request a full data export within 30 days
  • BuildFlow Pro will delete all personal data within 90 days of confirmed termination, unless retention is required by law
  • Consent records and audit logs may be retained for compliance purposes

11. Audit Rights

The Controller may audit BuildFlow Pro's compliance with this DPA once per calendar year, with 30 days' prior written notice. Audits shall be conducted during business hours and shall not unreasonably interfere with operations. BuildFlow Pro may provide SOC 2 Type II reports or equivalent certifications to satisfy audit requirements.

12. Liability & Indemnification

Each party's liability under this DPA is subject to the limitations of liability set forth in the main service agreement (Terms & Conditions). Both parties agree to indemnify the other for damages arising from the indemnifying party's breach of this DPA.

13. Term & Termination

This DPA is effective as long as BuildFlow Pro processes personal data on behalf of the Controller. It terminates automatically when the underlying service agreement ends. Obligations regarding data deletion, retention, and confidentiality survive termination.

14. Contact

For DPA-related inquiries, data protection requests, or to request a signed copy:

Enterprise customers may request a fully executed, countersigned copy of this DPA.