1
Introduction and Scope
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the CivCore Terms of Service or other written agreement between CivCore Inc. (“CivCore”) and the customer identified in that agreement (“Customer”) governing Customer’s use of the Services (the “Agreement”). This DPA applies to CivCore’s Processing of Personal Information contained in Customer Data on Customer’s behalf. In the event of a conflict between this DPA and the Agreement with respect to such Processing, this DPA controls.
2
Definitions
“Personal Information” means information that identifies, relates to, or could reasonably be linked with an identified or identifiable natural person, to the extent such information is protected as “personal information,” “personal data,” or a similar term under applicable Data Protection Laws.
“Data Protection Laws” means all privacy and data protection laws applicable to the Processing of Personal Information under the Agreement, which may include the California Consumer Privacy Act as amended (“CCPA”), other U.S. state privacy laws, and Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), in each case only to the extent applicable to the Processing at issue.
“Processing” means any operation performed on Personal Information, such as collection, storage, use, disclosure, or deletion (“Process” and “Processing” have corresponding meanings).
“Customer Data” means the documents, files, and data Customer or its users upload to or connect with the Services, as defined in the Agreement.
“Subprocessor” means a third party engaged by CivCore to Process Personal Information in Customer Data on CivCore’s behalf.
3
Roles and Processing Instructions
As between the parties, Customer is the controller (or business) of Personal Information in Customer Data, and CivCore Processes such Personal Information as Customer’s processor (or service provider). CivCore will Process Personal Information in Customer Data only: (a) to provide, maintain, secure, and support the Services in accordance with the Agreement, including to debug, troubleshoot, respond to Customer support requests, and test and improve the Services (with personnel access on a need-to-know basis, controlled and logged, and excluding use of Customer Data to train machine-learning models except as expressly permitted by the Agreement); (b) in accordance with Customer’s documented instructions, including instructions given through Customer’s configuration and use of the Services; and (c) as required by applicable law, in which case CivCore will notify Customer unless legally prohibited. The Agreement and this DPA constitute Customer’s complete instructions as of the effective date. The subject matter, duration, nature, and purpose of the Processing, and the categories of Personal Information and of individuals concerned, are described in Annex A.
CivCore will notify Customer if, in its opinion, an instruction violates applicable Data Protection Laws, and may suspend the affected Processing until instructions are revised.
4
CCPA Service Provider Terms
To the extent the CCPA applies, CivCore acts as Customer’s “service provider.” CivCore will not: (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than the business purposes specified in the Agreement and this DPA, or outside the direct business relationship with Customer; or (c) combine Personal Information received from Customer with personal information from other sources, except as permitted by the CCPA (including for security, de-identification as permitted by the Agreement, or as otherwise permitted for service providers). CivCore certifies that it understands and will comply with these restrictions, and will notify Customer if it determines it can no longer meet its obligations under the CCPA.
5
Confidentiality
CivCore will ensure that personnel authorized to Process Personal Information are bound by written or statutory confidentiality obligations and Process Personal Information only as needed to provide the Services.
6
Security
CivCore will implement and maintain administrative, technical, and organizational measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex B. CivCore may update these measures from time to time, provided the updates do not materially reduce the overall protection of Personal Information.
7
Subprocessors
Customer provides general authorization for CivCore to engage Subprocessors, including the entities listed at security.civcore.com. CivCore will: (a) impose data protection obligations on Subprocessors that are no less protective than those in this DPA, to the extent applicable to the services they provide; (b) remain responsible for Subprocessors’ performance; and (c) provide at least thirty (30) days’ notice (by updating the list at the URL above and/or by email) before adding or replacing a Subprocessor that Processes Personal Information in Customer Data. If Customer reasonably objects on data protection grounds within the notice period, the parties will work in good faith to resolve the objection; if it cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid unused fees.
8
AI Provider Processing
Customer acknowledges and instructs that, as part of the Services, Customer Data submitted for AI-assisted analysis is transmitted to the AI model providers identified at security.civcore.com (currently Amazon Web Services (including Bedrock), Google Cloud, and OpenAI) to generate outputs. CivCore has configured its accounts with such providers so that Customer Data is not used to train the providers’ models. Such providers may temporarily retain submitted data in accordance with their standard enterprise/API terms (for example, for abuse monitoring). CivCore will not enable training on Customer Data by any AI provider without Customer’s prior written consent.
9
Assistance
Taking into account the nature of the Processing, CivCore will provide reasonable assistance to Customer in: (a) responding to requests from individuals to exercise privacy rights (access, correction, deletion, and similar rights) with respect to Personal Information in Customer Data - if CivCore receives such a request directly, it will promptly forward it to Customer and not respond except to direct the individual to Customer; (b) conducting data protection or privacy impact assessments where required; and (c) meeting Customer’s security and breach notification obligations, in each case at Customer’s reasonable expense where assistance is material.
10
Security Incident Notification
CivCore will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information in Customer Data (a “Security Incident”). The notification will describe, to the extent known, the nature of the Security Incident, the categories and approximate volume of affected data, measures taken or planned, and a contact point. CivCore will take reasonable steps to contain and remediate the Security Incident. CivCore’s notification is not an admission of fault.
11
Deletion and Return
Upon Customer’s request, made at any time during or after the term of the Agreement, CivCore will (a) return Customer Data in a commonly used format and/or (b) delete Customer Data, in each case within ninety (90) days of the request, except for: (i) data retained in routine backups until the backup cycle completes (not to exceed ninety (90) days after deletion from production systems), which remains protected under this DPA until deleted; and (ii) data CivCore must retain under applicable law. Absent a deletion request, following termination or expiration of the Agreement CivCore may retain Customer Data to permit Customer to reactivate its account, and all such retained Customer Data remains subject to the protections of this DPA for as long as it is retained; CivCore may also delete Customer Data in its discretion at any time more than ninety (90) days after termination. De-identified data that no longer constitutes Personal Information is not subject to this Section.
12
Audits and Security Reviews
Upon Customer’s reasonable written request (no more than once per 12-month period, absent a Security Incident), CivCore will make available: (a) its then-current security documentation; and (b) once completed, its SOC 2 Type II report or comparable third-party attestation, subject to confidentiality; additional information is available at CivCore’s trust center, security.civcore.com. The parties agree that such documentation and attestations satisfy Customer’s audit and verification rights under applicable Data Protection Laws to the fullest extent permitted; where an on-site audit is required by law, the parties will agree on reasonable scope, timing, duration, and confidentiality protections, at Customer’s expense.
13
Data Location
CivCore Processes Customer Data in the United States, and Customer authorizes such Processing and the transfers it entails. Customer is responsible for ensuring that its provision of Personal Information to CivCore for Processing in the United States complies with Data Protection Laws applicable to Customer, and CivCore will reasonably cooperate, including by executing additional transfer documentation where legally required and mutually agreed.
14
Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, and references in the Agreement to a party’s liability mean aggregate liability under the Agreement and this DPA together.
15
Term
This DPA remains in effect for as long as CivCore Processes Personal Information in Customer Data.
A
Annex A — Details of Processing
Subject matter: Customer Data uploaded to or connected with the Services, including project documents, proposals, bids, RFPs, cost data, and related files.
Duration: the term of the Agreement plus the deletion periods in Section 11.
Nature and purpose: hosting, storage, organization, analysis (including AI-assisted analysis), display, transmission, and deletion, to provide the construction intelligence Services described in the Agreement.
Categories of Personal Information: names, business contact details, job titles, and other personal information that Customer chooses to include in Customer Data (e.g., project personnel, subcontractor, and counterparty information).
Categories of individuals: Customer’s personnel, contractors, subcontractors, business contacts, and other individuals whose information Customer includes in Customer Data.
Sensitive information: Customer is not authorized to upload, and CivCore does not intend to Process, government identifiers, health information, financial account credentials, or other sensitive personal information, except as strictly incidental to project documents.
B
Annex B — Technical and Organizational Measures
CivCore’s security program is further described at its trust center, security.civcore.com; the measures below are the contractual baseline.
•
Encryption of data in transit (TLS 1.2+) and at rest.
•
Role-based access controls; unique credentials; multi-factor authentication for production access.
•
Multi-tenant architecture with application-level authorization controls restricting each customer organization’s access to its own data.
•
Logging and monitoring of production systems; error and anomaly alerting (Sentry). Customer document content does not appear in monitoring telemetry.
•
Vulnerability management and dependency patching processes; third-party penetration testing scheduled.
•
Employee background/security screening as permitted by law and security awareness training.
•
Vendor security review for Subprocessors.
•
Backup and disaster recovery procedures.
•
Incident response plan with defined roles and escalation.
•
SOC 2 Type II examination in progress with Oneleet. Trust center: security.civcore.com.