Data Processing Agreement (DPA)
Version 1.0 | Effective Date: June 15, 2026
Data Processing Agreement entered into pursuant to Article 28 GDPR
1. Parties and purpose
This Data Processing Agreement ("DPA") is entered into between:
- DiasporaBuild [LEGAL FORM TO BE COMPLETED], registered under no. [TO BE COMPLETED], registered office [ADDRESS TO BE COMPLETED] (the "Processor" or "DiasporaBuild"); and
- Any business customer using the DiasporaBuild platform in the course of its activity — contractor, supplier, inspector, architect or company (the "Controller" or "Business Customer").
This DPA forms an integral part of the Terms of Service and the Master Services Agreement (MSA). It applies whenever DiasporaBuild processes personal data on behalf of the Business Customer (e.g. data of its own clients, prospects, employees or subcontractors entered into the Platform — quotes, contracts, contacts, sites, teams).
For processing carried out by DiasporaBuild for its own purposes (account management, billing, security, service improvement, Directory), DiasporaBuild acts as a controller; such processing is described in the Privacy Policy.
2. Description of processing
| Element | Description |
|---|---|
| Subject matter | Provision of the DiasporaBuild platform (construction project management, quotes, contracts, teams, site monitoring, milestone payments, design tools) |
| Duration | Duration of the Business Customer's use of the Platform |
| Nature | Collection, recording, structuring, storage, consultation, disclosure to project participants, erasure |
| Purpose | Enabling the Business Customer to manage its construction projects and client relationships through the Platform |
| Data categories | Identity and contact details (end clients, prospects, team members, workers), project and site data (addresses, photos, plans), contractual and billing data, messaging exchanges |
| Data subjects | End clients and prospects of the Business Customer, its team members, subcontractors and site workers |
| Sensitive data | No special-category data (Art. 9 GDPR) is required by the Platform; the Business Customer undertakes not to enter any |
3. Obligations of DiasporaBuild (processor)
DiasporaBuild undertakes to:
- Process personal data only on documented instructions from the Business Customer (evidenced by its use and configuration of the Platform), unless required by law — in which case DiasporaBuild informs the Customer before processing, unless legally prohibited;
- Ensure that persons authorised to process the data are bound by an obligation of confidentiality;
- Implement the technical and organisational measures described in Annex 1 (Art. 32 GDPR);
- Comply with the conditions for engaging sub-processors (Section 4);
- Assist the Business Customer, insofar as possible and taking into account the nature of the processing, in responding to data-subject requests (access, rectification, erasure, portability, objection, restriction);
- Assist the Business Customer in complying with its obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments);
- Notify the Business Customer of any personal data breach without undue delay and no later than 48 hours after becoming aware of it, providing the information needed for notification to the supervisory authority;
- At the Business Customer's choice, delete or return all personal data at the end of the contractual relationship (export available from the Platform; deletion within 90 days, unless retention is required by law);
- Make available the information necessary to demonstrate compliance with this DPA and allow reasonable audits (at most once per year, with 30 days' notice, during business hours, without access to other customers' data; primarily on a documentary basis).
4. Sub-processors
4.1 The Business Customer gives general authorisation for the sub-processors listed in Annex 2.
4.2 DiasporaBuild informs the Business Customer of any addition or replacement of a sub-processor (Platform notification or email) at least 15 days in advance, allowing reasonable objections. If an objection cannot be resolved, the Business Customer may terminate the affected services.
4.3 DiasporaBuild imposes on each sub-processor, by contract, obligations equivalent to those in this DPA and remains fully liable to the Business Customer for their performance.
5. International transfers
Data may be transferred outside the EU/EEA (in particular to the United States and to the African countries where construction sites are located). Such transfers are governed by: the Standard Contractual Clauses (Decision 2021/914), applicable adequacy decisions (including the EU-US Data Privacy Framework), and supplementary measures (encryption in transit, minimisation). Details per sub-processor are in Annex 2.
6. Obligations of the Business Customer
The Business Customer warrants that it: has a valid legal basis for the processing entrusted; informs data subjects in accordance with Articles 13 and 14 GDPR; does not enter any sensitive or unnecessary data into the Platform; and properly configures its team's access rights.
7. Liability and term
Each party's liability under this DPA is governed by the liability provisions of the MSA. This DPA takes effect upon the Business Customer's acceptance of the Terms and remains in force for as long as DiasporaBuild processes data on its behalf.
Annex 1 — Technical and organisational measures
- Encryption: TLS 1.2+ for all communications; encryption at rest for stored files;
- Authentication: hashed passwords (bcrypt), secure httpOnly cookie sessions, optional OAuth;
- Access control: role-based access (RBAC), least-privilege principle, per-account data segregation;
- Environments: strict separation of production and development environments (separate databases);
- Backups: regular backups and restoration procedures;
- Logging: structured, timestamped logs retained for 12 months;
- Payments: no card data stored; PCI-DSS certified providers;
- Vulnerability management: security patches, code reviews, application audits;
- Organisation: staff awareness, confidentiality undertakings, incident-management procedure and breach register.
Annex 2 — List of sub-processors
| Sub-processor | Service | Location | Transfer safeguards |
|---|---|---|---|
| Stripe, Inc. | Card payments | EU / United States | SCCs + DPF |
| pawaPay Ltd | Mobile-money payments | United Kingdom / Africa | SCCs |
| Resend (Plus Five Five, Inc.) | Email delivery | United States | SCCs + DPF |
| Cloudflare, Inc. (R2) | File storage | EU / United States | SCCs + DPF |
| MongoDB, Inc. | Database | EU / United States | SCCs + DPF |
| OpenAI, LLC | AI features | United States | SCCs + DPF |
| Google LLC (Gemini, OAuth) | AI and authentication | EU / United States | SCCs + DPF |
| [HOSTING PROVIDER TO BE COMPLETED] | Application hosting | [TO BE COMPLETED] | [TO BE COMPLETED] |
Contact: privacy@diasporabuild.com
Related documents: Terms of Service · Privacy Policy · MSA