Parties
1. Parties and status
This Data Processing Agreement (DPA) is entered into between the customer identified in the applicable order form or services agreement (Customer) and the Oporo contracting entity identified in that agreement (Oporo). It forms part of the agreement under which Oporo supplies the services (Main Agreement).
For Customer Personal Data, Customer is the Controller and Oporo is the Processor. Each party will comply with the Data Protection Laws applicable to it. Where Customer is itself a Processor, Oporo acts as Customer's subprocessor and references to Controller obligations mean the obligations Customer must pass through on behalf of the relevant Controller.
Definitions
2. Defined terms
Customer Personal Data means Personal Data processed by Oporo on behalf of Customer through the services. Data Protection Laws means the UK GDPR, the Data Protection Act 2018, and other data-protection or e-privacy law applicable to the processing. UK GDPR has the meaning given in section 3(10), supplemented by section 205(4), of the Data Protection Act 2018.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, processing, and Supervisory Authority have the meanings given by applicable Data Protection Laws. Subprocessor means another processor engaged by Oporo to process Customer Personal Data.
Application
3. Scope, duration, and precedence
This DPA applies while Oporo processes Customer Personal Data under the Main Agreement. The subject matter, nature, purpose, data types, Data Subjects, and duration are described in Schedule 1 and the Main Agreement.
If this DPA conflicts with the Main Agreement on the protection or processing of Customer Personal Data, this DPA prevails. Any applicable UK international-transfer terms prevail over both for the relevant restricted transfer.
Article 28(3)(a)
4. Documented instructions and compliance
Oporo will process Customer Personal Data only on Customer's documented instructions, including instructions concerning international transfers, unless UK or other applicable law requires processing. In that case, Oporo will inform Customer of the legal requirement before processing unless the law prohibits that notice for important public-interest reasons.
The Main Agreement, this DPA, Customer's authorised use and configuration of the services, support requests, and written instructions consistent with the Main Agreement constitute documented instructions. Oporo will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws and may suspend the affected processing until the parties resolve the issue.
Customer is responsible for the lawfulness, fairness, accuracy, and transparency of Customer Personal Data and instructions; establishing a lawful basis; issuing required notices; obtaining required consents; and ensuring that it does not instruct Oporo to process data in breach of Data Protection Laws.
Article 28(3)(b)
5. Confidentiality
Oporo will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality, receive access only as needed for their role, and process the data only as permitted by this DPA.
Articles 28(3)(c) and 32
6. Security of processing
Taking account of the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as risks to individuals, Oporo will maintain appropriate technical and organisational measures designed to provide a level of security appropriate to risk. Current measures are described in Schedule 2.
Oporo may update the measures as technologies and risks change, provided that the overall protection of Customer Personal Data is not materially reduced. Customer is responsible for configuring permissions appropriately, protecting credentials, maintaining secure user devices, and using the available controls consistently with its risks.
Articles 28(2) and 28(4)
7. Subprocessors
Customer gives Oporo general written authorisation to use the Subprocessors listed in Schedule 3. The online Sub-Processor Register provides the current detailed service, data-category, location, and usage information and distinguishes those Subprocessors from other external integrations. Oporo will impose data-protection obligations on each Subprocessor that provide materially equivalent protection for Customer Personal Data as required by Article 28. Oporo remains responsible to Customer for a Subprocessor's performance of those obligations.
Oporo will give at least 30 days' prior notice of a new or replacement Subprocessor where reasonably practicable. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate only the affected service without penalty, subject to payment for services already supplied.
Article 28(3)(e)
8. Data Subject rights
Taking account of the nature of the processing, Oporo will assist Customer through appropriate technical and organisational measures, insofar as possible, to fulfil requests to exercise Data Subject rights. If Oporo receives a request relating to Customer Personal Data, it will notify Customer and will not respond except on Customer's documented instructions or as required by law.
Customer remains responsible for verifying requests, deciding how to respond, and meeting statutory deadlines. Any material assistance outside normal service functionality may be charged at the rates agreed in the Main Agreement unless the request results from Oporo's breach.
Articles 28(3)(f) and 32-36
9. Compliance assistance
Taking account of the nature of processing and information available to it, Oporo will provide reasonable assistance with Customer's obligations concerning security, breach notifications, communications to Data Subjects, data protection impact assessments, and prior consultation with a Supervisory Authority.
Oporo will provide information reasonably required for that assistance but is not responsible for Customer's legal assessment, notices, filings, or decisions. Additional assistance may be chargeable where permitted by the Main Agreement unless required because of Oporo's breach.
Article 28(3)(f)
10. Personal Data Breaches
Oporo will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include available information about the nature of the breach, affected data and people, likely consequences, measures taken or proposed, and a contact point. Oporo may provide information in phases as it becomes available.
Oporo will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably cooperate with Customer. Notification is not an admission of fault or liability. Customer is responsible for notifying regulators and Data Subjects unless the parties agree otherwise in writing.
Article 28(3)(g)
11. Return and deletion
During the service term, Customer may export Customer Personal Data using available service functionality. On termination or expiry, and at Customer's choice notified before termination, Oporo will return or delete Customer Personal Data and delete existing copies, unless applicable law requires continued storage.
Unless the Main Agreement states otherwise, Oporo may retain Customer Personal Data for up to 90 days after termination to permit an orderly export or deletion. Data in isolated backups may remain for up to 35 additional days and will not be restored except for disaster recovery or legal need; if restored, it remains protected by this DPA and will be deleted again under the normal cycle. Oporo may retain records required by law or necessary to establish, exercise, or defend legal claims, subject to restricted access and no further incompatible processing.
Article 28(3)(h)
12. Information and audits
Oporo will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA. Customer may request relevant policies, summaries, questionnaires, certifications, or independent audit reports where available.
If that information is insufficient, Customer may conduct one audit in any 12-month period on at least 30 days' written notice, and more often following a confirmed breach or regulator request. Audits must occur during normal business hours, avoid unreasonable disruption, protect other customers' information, and be performed by qualified persons who are not Oporo competitors and are bound by confidentiality. Customer bears its audit costs unless the audit identifies a material breach by Oporo. Oporo will contribute to and allow audits and inspections by a competent Supervisory Authority as required by law.
International transfers
13. Restricted transfers
Oporo will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless it is authorised by Customer's instructions and permitted by Data Protection Laws. Oporo will rely on UK adequacy regulations or put an appropriate safeguard in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised mechanism, and complete any required transfer risk assessment.
Deployment regions and any customer-specific residency commitment must be recorded in the Order Form or service documentation. Where required for a transfer under this DPA, the parties agree to execute or incorporate the applicable approved transfer terms.
General
14. Liability, notices, and law
The liability exclusions and limits in the Main Agreement apply to this DPA to the maximum extent permitted by law. Nothing in this DPA limits a person's rights or either party's liability where it cannot lawfully be limited.
Notices under this DPA must be sent using the notice method in the Main Agreement, with privacy notices to contact@oporo.net. The governing law and jurisdiction provisions in the Main Agreement apply. If no Main Agreement provision applies, the laws of England and Wales govern this DPA and the courts of England and Wales have exclusive jurisdiction.
Schedule 1
Details of processing
- Subject matter
- Provision, support, security, and maintenance of the Oporo construction information SaaS platform and related services.
- Duration
- The term of the Main Agreement plus the return, deletion, backup, legal-hold, and statutory retention periods described in this DPA.
- Nature and operations
- Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, making available to authorised users, validation, comparison, analysis, support, backup, restriction, export, archive, and deletion.
- Purposes
- Providing customer workspaces; managing users and permissions; hosting and processing project documents, models, specifications, assets, issues, comments, reviews, approvals, transmittals, and notifications; customer support; service security; and customer-authorised AI assistance where enabled.
- Data Subjects
- Customer personnel; project owners, consultants, contractors, suppliers, operators, occupants, and stakeholders; authorised platform users; invitees; document authors, reviewers, assignees, issue participants, and people identified in Customer Content.
- Personal Data
- Names, work contact details, organisation and role; account, identity, permission, and membership data; internal and federated identity identifiers; project-directory records; authorship, assignment, approval, comment, issue, notification, audit, and activity data; IP addresses and technical identifiers; and personal data contained in documents, images, BIM/IFC models, free text, and other Customer Content.
- Special category data
- Not intentionally required. Customer must not submit special category or criminal-offence data unless expressly agreed, lawful, necessary, and supported by appropriate safeguards and documented instructions.
- Frequency
- Continuous or as initiated by Customer and authorised users during the service term.
- Controller instructions
- The Main Agreement, this DPA, Order Forms, authorised service configuration and use, support requests, and other documented instructions accepted under clause 4.
Schedule 2
Technical and organisational measures
The measures below describe the current control framework. They are applied as appropriate to the service, deployment, processing risk, and Customer configuration.
- Governance
- Documented security responsibilities, confidentiality obligations, access reviews, incident procedures, supplier oversight, and privacy-by-design controls proportionate to the processing risk.
- Identity and access
- Authenticated access; role-based and project-scoped permissions; least-privilege administration; account status and membership controls; short-lived access tokens; hashed refresh tokens; HTTP-only session cookies; and federated identity authentication where configured.
- Encryption and secrets
- HTTPS/TLS for data in transit; encryption at rest provided by applicable managed cloud services; password hashing; and production credentials held in protected service configuration or an approved secret store rather than source control.
- Application security
- Server-side authorisation for protected resources, restricted file-download routes, input validation, dependency maintenance, environment separation, and controlled deployment procedures.
- Logging and monitoring
- Audit records for relevant user and workflow actions, application telemetry, diagnostic logging, service-health monitoring, and operational alerting. Access to logs is restricted according to operational need.
- Availability and recovery
- Managed cloud infrastructure, backups appropriate to the service, incident triage and recovery procedures, and periodic restoration testing. Customer-specific recovery commitments apply only where stated in the Main Agreement.
- Data lifecycle
- Customer-authorised deletion functions, retention controls, account closure procedures, and isolated backups that expire under the applicable backup schedule.
- Personnel and suppliers
- Access limited to authorised personnel and suppliers subject to confidentiality and data-protection obligations, with access removed when no longer required.
Schedule 3
Authorised Subprocessors
The online Sub-Processor Register, as published on the effective date of this DPA, is incorporated into and forms Schedule 3. It identifies each authorised Subprocessor, the service and purpose, relevant data categories and Data Subjects, processing locations, and whether use is core, optional, or customer-specific.
The register also identifies other service providers and external integrations for transparency. A provider listed only in those separate categories is not an authorised Subprocessor under this Schedule unless the register or an applicable Order Form expressly classifies it as one.
Changes to authorised Subprocessors are governed by clause 7, including advance notice and Customer's right to object on reasonable, documented data-protection grounds. Oporo will retain a record of the register version applicable to the Customer where required to evidence the authorisation in effect.
Execution
Agreement details
This DPA may be executed with the Main Agreement, by counterparts or electronic signature, or incorporated by reference into an Order Form that identifies this version.
Customer
Legal name: ____________________
Name and title: ____________________
Signature: ____________________
Date: ____________________
Oporo contracting entity
Legal name: ____________________
Name and title: ____________________
Signature: ____________________
Date: ____________________
