The short version
- You are the controller of the personal data in your workspace; we process it only on your instructions.
- We keep it confidential and secure, use vetted subprocessors, help you answer privacy requests, and tell you promptly about a breach.
- We do not sell it, share it for advertising, or use it for our own purposes.
This summary is for convenience. The full text below is what applies.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ConstructorIQ Inc. (“PMT1”) and Customer, and applies whenever PMT1 processes Personal Data on Customer’s behalf. It is effective automatically; no signature is needed. Customers who need a countersigned copy may request one at privacy@pmt1.com. If this DPA conflicts with the Terms on the subject of data protection, this DPA controls.
1. Definitions
“Data Protection Laws” means the privacy and data-protection laws that apply to the processing of Personal Data under the Terms, including U.S. state privacy laws such as the California Consumer Privacy Act (“CCPA”) and, where applicable, the EU and UK General Data Protection Regulations (“GDPR”). “Personal Data” means information in Customer Data that relates to an identified or identifiable person. “Subprocessor” means a third party PMT1 engages to process Personal Data. “Controller”, “processor”, “business”, “service provider”, “sell” and “share” have the meanings given in the applicable Data Protection Laws.
2. Roles and scope
Customer is the controller (or business) and PMT1 is the processor (or service provider) of Personal Data in Customer Data. Each party will comply with the Data Protection Laws that apply to it. This DPA does not apply to data for which PMT1 is a controller, such as account, billing and website data, which is covered by our Privacy Policy.
3. Details of the processing
| Subject matter and purpose | Providing, securing and supporting the PMT1 service under the Terms. |
|---|---|
| Duration | The subscription term, plus the export and deletion periods in the Terms. |
| Nature of processing | Hosting, storage, retrieval, display, transmission, backup, and automated processing by the AI assistant when a user invokes it. |
| Categories of data subjects | Customer’s users, employees and crew members; contacts at owners, general contractors, design firms, suppliers, subcontractors and inspection agencies; visitors and others named or pictured in project records. |
| Types of Personal Data | Names, employers, job titles and classifications, phone numbers, email addresses, training and certification records, hours worked where recorded, signatures, photographs, comments, and any other Personal Data Customer chooses to enter. |
| Sensitive data | None intended. The Acceptable Use Policy prohibits government identifiers, financial account numbers, health information and children’s data. Incident records may incidentally describe injuries; Customer decides whether to record such details. |
4. Processing on instructions
PMT1 will process Personal Data only on Customer’s documented instructions — which are the Terms, this DPA, and Customer’s and its users’ use of the service’s features — unless the law requires otherwise, in which case PMT1 will tell Customer first where the law allows. PMT1 will tell Customer if it believes an instruction violates Data Protection Laws.
5. U.S. state privacy law terms
PMT1 will not: (a) sell or share Personal Data; (b) retain, use or disclose Personal Data for any purpose other than the business purposes specified in the Terms and this DPA, including for any commercial purpose other than providing the service; (c) retain, use or disclose Personal Data outside the direct business relationship with Customer; or (d) combine Personal Data with personal data it receives from other sources, except as the CCPA permits service providers to do. PMT1 certifies that it understands and will comply with these restrictions, will provide the level of privacy protection the CCPA requires, will notify Customer if it determines it can no longer meet its obligations, and grants Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
6. Confidentiality
PMT1 ensures that everyone it authorizes to process Personal Data is bound by a duty of confidentiality, and limits staff access to what is needed for support, security and operations. Staff access to customer workspaces requires two-step sign-in and is logged.
7. Security
PMT1 maintains technical and organizational measures appropriate to the risk, including those described on our Security page: encryption in transit and at rest, database-level tenant isolation, access controls, logging, backups and secure development practices. PMT1 may update these measures but will not materially reduce the overall level of protection.
8. Subprocessors
Customer gives general authorization for PMT1 to engage the Subprocessors listed at pmt1.com/subprocessors. PMT1 will (a) impose data-protection obligations on each Subprocessor that are no less protective than this DPA, (b) remain responsible for their performance, and (c) update that page at least 30 days before a new Subprocessor begins processing Personal Data. Customer may object on reasonable data-protection grounds within that period by writing to privacy@pmt1.com; if the parties cannot resolve the objection, Customer may cancel the affected service and receive a pro-rated refund of prepaid fees.
9. Helping with individuals’ requests
The service lets Customer access, correct, export and delete Personal Data itself. If PMT1 receives a request from an individual about Personal Data in Customer’s workspace, it will not respond on the merits but will refer the person to Customer and, where it can identify the Customer, pass the request on. PMT1 will give reasonable help with requests Customer cannot fulfill through the service.
10. Personal data breaches
PMT1 will notify Customer without undue delay, and in any case within 72 hours, after confirming a breach of security that led to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data. The notice will describe what is known about the nature of the breach, the data and individuals affected, the likely consequences and the steps taken, and will be updated as more is learned. Notification is not an admission of fault.
11. Assessments and regulators
Taking into account the nature of the processing and the information available, PMT1 will give reasonable assistance with data-protection impact assessments and consultations with regulators that Data Protection Laws require of Customer.
12. Return and deletion
Customer can export its data at any time during the term and for 30 days afterwards. After that, PMT1 deletes Personal Data from active systems, and copies in backups age out within about 35 days, unless the law requires longer retention — in which case PMT1 will keep it confidential and process it no further.
13. Information and audits
PMT1 will make available the information reasonably needed to demonstrate compliance with this DPA, including written responses to security questionnaires and summaries of relevant third-party reports held by its hosting providers. Where Data Protection Laws give Customer an audit right that this information does not satisfy, Customer may audit once a year on 30 days’ written notice, during business hours, under confidentiality obligations, at its own cost, and without access to other customers’ data.
14. International transfers
PMT1 hosts Customer Data in the United States. Where Customer transfers Personal Data that is subject to the GDPR, UK GDPR or Swiss law to PMT1, the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), with the UK Addendum or Swiss amendments where relevant, are incorporated by reference. For the Clauses: Customer is the data exporter and PMT1 the importer; the details of processing are in “Details of the processing”; the security measures are in “Security”; the option for general written authorization of Subprocessors applies; and the governing law and courts are those of Ireland (or England and Wales for the UK Addendum).
15. Liability
Each party’s liability under this DPA is subject to the limits of liability in the Terms.
Questions about this page: privacy@pmt1.com