Legal

Data Processing Agreement

1. Background and Scope

1.1 This Data Processing Agreement ("DPA") forms part of the agreement between Kirby Digital Ltd (company number 17309006, registered office 106 Poynter House, Holland Park, London, W11 4TB), trading as Kirby Projects ("Kirby", the "Processor") and the Customer (the "Controller") for the provision of the Kirby Projects platform (the "Service"). The DPA is incorporated into, and accepted together with, the Kirby Projects Terms of Service when the Customer registers an account or subscribes (together, the "Agreement").

1.2 This DPA applies where and to the extent Kirby processes Personal Data on behalf of the Customer in providing the Service ("Customer Personal Data").

1.3 Terms such as "Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in UK data protection law, meaning the UK GDPR and the Data Protection Act 2018 ("Data Protection Law").

1.4 The subject matter, duration, nature and purpose of processing, the types of Personal Data, and the categories of data subjects are set out in Annex 1.

2. Roles and Compliance

2.1 The parties agree that for Customer Personal Data the Customer is the controller and Kirby is the processor. Each party will comply with its obligations under Data Protection Law.

2.2 The Customer warrants that it has a lawful basis for the processing instructed under the Agreement, that it has provided any required notices to data subjects, and that its instructions to Kirby comply with Data Protection Law. The Customer will not submit special category data to the Service except where necessary, and where it does so it warrants that an appropriate condition under Article 9 UK GDPR (and, where relevant, Schedule 1 of the Data Protection Act 2018) applies.

2.3 Kirby processes personal data relating to its own account administration, billing and business contacts as an independent controller; such processing is described in the Kirby Privacy Policy and is outside the scope of this DPA.

3. Kirby's Processing Obligations

3.1 Kirby will process Customer Personal Data only on the Customer's documented instructions (which include the Agreement and the Customer's use of the Service's features), unless required to do otherwise by law, in which case Kirby will inform the Customer of that legal requirement before processing unless the law prohibits this.

3.2 Kirby will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

3.3 Kirby will ensure that persons authorised to process Customer Personal Data are subject to obligations of confidentiality.

4. Security

4.1 Kirby will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. The current measures are described in Annex 2.

4.2 The Annex 2 measures are minimum controls; Kirby may update or enhance them from time to time provided the updates do not materially reduce the overall level of protection.

4.3 The Customer is responsible for its own configuration and use of the Service, including user and permission management, project visibility and sharing settings, and the strength and confidentiality of its Users' credentials. Kirby is not responsible for incidents arising from the Customer's configuration choices or credential management.

5. Assistance to the Customer

5.1 Taking into account the nature of the processing, Kirby will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Data Protection Law. If a data subject contacts Kirby directly about Customer Personal Data, Kirby will (where the requester is identifiable as relating to the Customer) refer them to the Customer without undue delay.

5.2 Kirby will assist the Customer, insofar as reasonably possible and taking into account the information available to Kirby, with the Customer's obligations regarding security, personal data breach notification, data protection impact assessments, and prior consultation with the Information Commissioner's Office ("ICO").

5.3 Assistance under this clause 5 beyond that strictly required of a processor by Data Protection Law, or that is extensive, repeated or unrelated to any actual or suspected breach by Kirby, is chargeable at Kirby's reasonable rates.

6. Sub-processors

6.1 The Customer gives general written authorisation for Kirby to engage the sub-processors listed in Annex 3 and to replace or add sub-processors in accordance with this clause.

6.2 Kirby will give the Customer at least 30 days' notice of the addition or replacement of a sub-processor (by email or in-Service notice). The Customer may object within that period on documented, reasonable data-protection grounds specific to the proposed sub-processor's processing of Customer Personal Data (and not, for example, a general preference against a particular provider); if the parties cannot resolve the objection, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period.

6.3 Kirby will impose data protection obligations on each sub-processor that are materially equivalent to those in this DPA, and remains liable to the Customer for the performance of its sub-processors' obligations.

7. Personal Data Breach

7.1 Kirby will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and ordinarily within 72 hours of becoming aware where sufficient information is available.

7.2 The notification will, so far as known, describe the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed. Kirby may provide information in phases as it becomes available.

7.3 Kirby will take reasonable steps to mitigate the effects of the breach and will cooperate with the Customer's reasonable requests in connection with it. Kirby's notification is not an admission of fault.

8. Deletion and Return

8.1 On termination or expiry of the Agreement, Kirby will, at the Customer's written election made within 30 days: (a) make Customer Personal Data available for export in one or more common machine-readable formats (such as CSV or JSON for structured data, and original file formats for uploaded documents); and/or (b) delete Customer Personal Data, and will in any event delete Customer Personal Data remaining in the Service within 90 days of termination, save to the extent retention is required by law and except for backup copies which are deleted in the ordinary course of Kirby's backup cycle.

9. International Transfers

9.1 Kirby will not transfer Customer Personal Data outside the UK or the European Economic Area except: (a) to a country covered by UK adequacy regulations; or (b) subject to appropriate safeguards under Data Protection Law, including the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, which are incorporated by reference where required.

9.2 The primary hosting locations for the Service are set out in Annex 3.

10. Audit

10.1 Kirby will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, which Kirby will in the first instance satisfy by providing security documentation, completed questionnaires, and summaries of any third-party audits or certifications held by Kirby or its sub-processors.

10.2 Where the Customer reasonably considers this information insufficient, the Customer (or an independent auditor bound by confidentiality, not a competitor of Kirby) may audit Kirby's compliance no more than once in any 12-month period, on at least 30 days' notice, during business hours, without disruption to Kirby's operations, and at the Customer's cost. Audits of sub-processors are satisfied by the sub-processors' own audit reports and certifications. The Customer must not conduct penetration testing, vulnerability scanning or any other intrusive or destructive testing of the Service without Kirby's prior written consent.

10.3 All information, documentation and findings provided or produced under this clause 10 are Kirby's Confidential Information and may be used only to assess compliance with this DPA.

11. Liability and General

11.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service, save to the extent that liability cannot lawfully be limited.

11.2 If there is a conflict between this DPA and the rest of the Agreement in respect of the processing of Customer Personal Data, this DPA prevails.

11.3 This DPA is governed by the laws of England and Wales and terminates automatically with the Agreement, save for provisions that by their nature survive.

Annex 1 — Description of Processing

Item Description
Subject matter Provision of the Kirby Projects platform: cloud-based project, quality, document, procurement, and health & safety record management for construction and engineering.
Duration The term of the Agreement, plus the post-termination retention/export windows in clause 8.
Nature and purpose Hosting, storage, organisation, retrieval, display, transmission, backup and deletion of data submitted to the Service, to provide the Service to the Customer.
Categories of data subjects The Customer's personnel and Users; personnel of the Customer's clients, contractors, subcontractors and suppliers appearing in project records; other individuals named in documents or records the Customer uploads.
Types of Personal Data Names, job titles, employers, business contact details (email, phone), user account data, signatures, photographs incidentally containing individuals, permit and training references, and any personal data contained in documents or records the Customer chooses to upload.
Special category data Not intended to be processed. Limited health-related information may appear incidentally in health & safety records the Customer creates (e.g. accident or incident records); the Customer is responsible for its lawful basis for recording it.

Annex 2 — Technical and Organisational Measures

Kirby maintains, as a minimum, the following measures (as updated from time to time under clause 4.2):

Area Measures
Access control Unique user accounts; role- and project-scoped access enforced in the application layer; least-privilege administrative access; multi-factor authentication on Kirby's administrative and infrastructure accounts.
Encryption Encryption in transit (TLS) for all Service traffic; encryption at rest for databases and file storage as provided by the hosting sub-processors.
Tenant separation Logical separation of customer data through per-organisation and per-project scoping enforced by the application.
Backups & resilience Automated database backups on a regular cycle with documented restore procedures; hosting on established cloud infrastructure providers.
Secure development Version-controlled codebase; type-checked builds; review and testing before production deployment; dependency vulnerability monitoring.
Email & webhook security Authenticated transactional email (SPF, DKIM, DMARC); signed and replay-protected inbound webhooks.
Organisational Confidentiality obligations on personnel; access limited to those who need it; security incidents triaged and documented; sub-processors selected with regard to their security posture.

Annex 3 — Approved Sub-processors

Sub-processor Role Location / hosting region
Supabase, Inc. Database, authentication and file storage for the Service EU — Central EU (Frankfurt), AWS eu-central-1
Vercel, Inc. Application hosting and delivery EU — Frankfurt (fra1 / eu-central-1) for serverless functions; global edge network for static content delivery
Cloudflare, Inc. DNS, content delivery, security services (and, if adopted, object storage for documents) Global network (DNS, CDN, security). Object storage, if adopted for documents, to be configured to an EU/UK region
Resend, Inc. Transactional email delivery (via Amazon SES) EU (eu-west-1, Ireland) sending region
Google LLC (Google Workspace) Business email and correspondence handling incidental to support UK/EU data region

Payment processing is performed by Stripe Payments UK Ltd / Stripe, Inc. acting as an independent controller of cardholder data; Stripe is therefore not a sub-processor under this DPA.