This Data Processing Agreement forms part of the Terms of Service and is the Article 28 agreement your compliance team will ask for. It is between:
- the Customer — the organisation subscribing to Tool & Plant, acting as controller; and
- Construkta — Construkta Technologies Limited, registered in England and Wales, company number 17408270, registered office 66 Paul Street, London, EC2A 4NA, United Kingdom, acting as processor.
It applies to personal data inside Customer content. It does not apply to account, billing or security data, where Construkta is the controller in its own right — see the Privacy Policy.
No signature is needed: it takes effect when you accept the Terms. If your procurement process needs a countersigned copy, email info@construkta.co.uk.
1. Roles
| Data | Controller | Processor |
|---|---|---|
| Names, emails, roles of Tool & Plant users | Construkta | — |
| Billing and subscription data | Construkta | — |
| Security logs, usage analytics | Construkta | — |
| Machines, certificates, projects, inspections, photographs | Customer | Construkta |
| Personal data about the Customer's staff, operatives, examiners and contractors inside those records | Customer | Construkta |
The Customer confirms it has a lawful basis for the personal data it puts into Tool & Plant, and has told the people concerned as UK GDPR requires — including where a certificate names an examiner who is not one of its own staff.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Tool & Plant equipment and inspection-certificate record service.
Duration: for as long as the subscription runs, plus the wind-down period in section 10.
Nature and purpose: hosting, storage, retrieval, indexing, optical/AI extraction of fields from uploaded images and PDFs, generation of PDF compliance packs, display of limited fields on the public QR portal, and delivery of reminder emails and SMS.
3. Categories of data subject
- The Customer's employees, workers and authorised users
- Operatives and site staff named in inspection or defect records
- Competent persons and examiners named on certificates
- Contacts at the Customer's suppliers, hire companies and main contractors
- Anyone incidentally captured in a photograph taken through the app
4. Categories of personal data
- Identification and contact data: name, work email, phone, employer, job role
- Employment context: which projects and machines a person is associated with
- Signatures and sign-off names on weekly inspection checklists
- Examiner name, employer and report number on certificates
- Images: photographs of machines, data plates, certificates and dockets, and any personal data visible in them
- Scan and access events: who viewed or scanned which machine, and when
No special category data is required by the service. The Customer must not upload it.
5. Construkta's obligations
Construkta will:
- Process personal data only on the Customer's documented instructions — using the service is such an instruction — unless required otherwise by law, in which case it will tell the Customer first unless prohibited.
- Ensure anyone authorised to process the data is under a duty of confidence.
- Implement the technical and organisational measures in section 8.
- Not engage a sub-processor except as set out in section 6.
- Assist the Customer, taking account of the nature of processing, in responding to data subject rights requests.
- Assist the Customer with security, breach notification and data protection impact assessments under Articles 32 to 36.
- Delete or return personal data at the end of the agreement, as set out in section 10.
- Make available the information needed to demonstrate compliance, and allow audits under section 11.
- Immediately tell the Customer if it thinks an instruction breaches data protection law.
6. Sub-processors
The Customer gives general authorisation for the sub-processors listed below. Construkta imposes data protection terms on each of them no less protective than this DPA, and remains liable for their performance.
Construkta will give at least 30 days' notice before adding or replacing a sub-processor, by email to account admins. If the Customer reasonably objects on data protection grounds within that period and it cannot be resolved, the Customer may terminate the affected part of the service without penalty for the remainder of the term.
Current sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Supabase / AWS | Database, file storage, authentication | eu-west-2 (London) |
| Cloudflare | Content delivery, application hosting, bot protection | Global edge, UK/EU points of presence |
| Stripe Payments Europe | Subscription billing and payments | EU, with UK/US transfers under SCCs + UK Addendum |
| Lovable Emails | Reminder and transactional email delivery | UK/EU, via the Lovable platform |
| Twilio | SMS reminders, where enabled by the Customer (off by default) | EU/US, SCCs + UK Addendum |
| OpenAI (via the Lovable AI Gateway) | Reading fields from uploaded photographs and PDFs | US, SCCs + UK Addendum |
| Google Maps Platform | Project location lookup and map display | EU/US, SCCs + UK Addendum |
7. International transfers
Personal data is held at rest in eu-west-2 (London). Where a sub-processor processes data outside the UK, the transfer is covered by UK adequacy regulations, or by the EU Standard Contractual Clauses together with the ICO's International Data Transfer Addendum, plus a transfer risk assessment and supplementary measures where needed.
8. Security measures
- Encryption in transit (TLS 1.2+) and at rest
- Row-level access control in the database, so an organisation's data is isolated from every other organisation
- Role-based permissions: admin, manager, collaborator, and project-scoped access
- Optional multi-factor authentication for user accounts
- Signed, expiring links for document downloads rather than public file URLs
- Rate limiting and abuse protection on the public QR portal
- Audit trail of record changes, with who changed what and when
- Automated daily backups, retained for a limited period in line with our hosting provider's schedule
- Access to Customer content is controlled entirely by the Customer's own admins and managers through role-based permissions enforced at the database row level. Construkta staff do not have routine access to customer records. Any privileged access required for support or account erasure uses a separate service key and is recorded in the audit trail
9. Personal data breaches
Construkta will notify the Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer content, with the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken. The Customer, as controller, is responsible for deciding whether to notify the ICO or data subjects.
10. Deletion and return
On termination, Customer content is deleted from live systems at the Customer's request, or after a 30-day export window if no request is made sooner. Where Customer content includes records the Customer is legally required to retain — for example reports of thorough examination under LOLER — Construkta will not erase those records until the Customer confirms they have been exported to the duty holder. Backups containing deleted data are retained for a limited period in line with our hosting provider's schedule, then permanently deleted. Construkta confirms deletion in writing on request, with an erasure record. It may retain data where the law requires, in which case this DPA continues to apply to it.
11. Audit
Construkta will respond to a reasonable security questionnaire once per year at no cost. Where that is genuinely insufficient, the Customer may audit once per year on 30 days' notice, during business hours, without disrupting the service, subject to confidentiality, and at the Customer's cost unless material non-compliance is found.
12. Liability
Liability under this DPA is subject to the limitations in the Terms of Service.
13. Conflicts
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins.