Data Processing Addendum
Draft — legal review required — not yet effective. This document has been drafted to reflect ConditionVault's actual product, data processing, and technology stack. It is a draft and is not legally binding. It must be completed with verified company information, approved by the authorised business owner, reviewed by a qualified UK solicitor, and explicitly published before it becomes effective.
1. Parties and incorporation
This Data Processing Addendum ("DPA") is incorporated into the ConditionVault Terms of Service. It applies where ConditionVault processes personal data on behalf of a Customer organisation. The Customer is the data controller and ConditionVault is the data processor.
2. Definitions
Terms used in this DPA have the meanings given in the UK GDPR, the Terms of Service, and this DPA. "Customer Personal Data" means personal data processed by ConditionVault on behalf of the Customer under the Terms.
3. Roles
ConditionVault acts as a processor for customer-directed processing of property data, inspection content, photos, signatures, ConditionSign feedback, ConditionView sharing, and ConditionAI analysis. ConditionVault acts as an independent controller for its own account administration, billing, security, and audit records.
4. Documented instructions
ConditionVault processes Customer Personal Data only on documented instructions from the Customer, as provided through the Service interface. The Customer warrants that its instructions are lawful and that it has the necessary authority and consents to process the personal data uploaded.
5. Security measures
ConditionVault implements the technical and organisational measures set out in Schedule 2. These measures are subject to review and improvement. We do not claim specific security certifications unless verified.
6. Subprocessors
ConditionVault uses the subprocessors listed in Schedule 3. The Customer authorises the use of these subprocessors. We will provide notice of material changes to the subprocessor list. The Customer may object to a new subprocessor by contacting us. Subprocessor objection contact: [privacy contact to be confirmed].
7. Data-subject rights assistance
ConditionVault will assist the Customer in responding to data-subject requests, taking into account the nature of the processing. The Customer is responsible for identity verification and direct communication with data subjects.
8. Security incident assistance
ConditionVault will notify the Customer of a personal data breach without undue delay after becoming aware of it. We will provide information to help the Customer meet its breach-notification obligations.
9. Deletion or return
Upon termination, ConditionVault will delete or return Customer Personal Data according to the Customer's configured retention settings. Data may be retained in backups for the platform-managed backup retention period, after which it is permanently deleted.
10. International transfers
International transfers are described in Schedule 4. We will not state that a specific transfer mechanism is in place until it has been verified.
Schedule 1 — Processing details
Subject matter: Property inspection, reporting, and evidence management.
Duration: For the term of the Customer's subscription plus the configured retention period.
Nature and purpose: Storing, displaying, organising, and sharing inspection content including photos, condition ratings, compliance answers, signatures, and meter readings as directed by the Customer.
Data-subject categories: Customer users, landlords, tenants, prospective tenants, agents, property managers, inventory clerks, contractors, guarantors, ConditionSign recipients, ConditionView recipients, stakeholders, and occupants.
Personal-data categories: Identity data, contact data, property association, tenancy information, photographs, signatures, inspection comments, communications, meter and utility information, keys and access information, audit records.
Special-category data: ConditionVault is not designed for unnecessary special-category data. Customers must not upload it unless necessary, lawful, and within documented instructions. We cannot guarantee that special-category data will never appear in free-text or photographs. If special-category data is identified, it will be handled with appropriate care and flagged for review.
Retention: See retention schedule below.
Schedule 2 — Security measures
- Organisation-scoped access controls (RLS) — data is isolated by organisation
- Role-based permissions (organisation owner, admin, inspector, viewer)
- Authentication via Base44 platform with optional Google OAuth — ConditionVault does not receive passwords, password hashes, tokens, or provider credentials
- Token hashing for ConditionSign and ConditionView public links (SHA-256)
- Expiring and revocable sharing tokens
- Immutable finalised report snapshots with SHA-256 integrity hashing
- Audit event trails for property, report, and billing actions
- Rate limiting on registration, data-protection requests, and API operations
- Idempotency controls to prevent duplicate operations
- Operation locks to prevent concurrent modification conflicts
- Backend-authoritative writes for sensitive operations (billing, report finalisation, token management)
- Offline data partitioned by user and organisation in IndexedDB, cleared on sign-out
- Service worker for app-shell caching (no personal data cached)
We do not claim SOC 2, ISO 27001, Cyber Essentials, penetration testing, or other certifications unless and until verified evidence exists.
Schedule 3 — Subprocessors
The following providers are used by ConditionVault. No provider is published as a confirmed subprocessor until evidence of the contracting legal entity, DPA, and transfer mechanism is available. Providers marked "verification_required" are pending evidence and must not be treated as confirmed subprocessors.
| Provider | Contracting entity | Service | Processor status | Data | Location | Transfer | DPA status | Verification |
|---|---|---|---|---|---|---|---|---|
| Base44 | Not confirmed | Platform infrastructure, authentication, database, serverless functions, file storage | subprocessor | Account data, authentication tokens, organisation data, report data, photos, audit logs | Not confirmed | Not confirmed | verification_required | verification_required |
| Google (authentication) | Not confirmed | OAuth authentication provider (via Base44) | independent_controller | Email address, full name, Google profile data provided during sign-up | United States / Google Cloud regions | Not confirmed | verification_required | verification_required |
| Stripe | Not confirmed | Payment processing (currently test/sandbox mode) | independent_controller | Billing email, billing name, company name, billing address, payment method metadata | United States / Stripe regional infrastructure | Not confirmed | verification_required | verification_required |
| Resend | Not confirmed | Email delivery | subprocessor | Recipient email addresses, email content, delivery status metadata | United States | Not confirmed | verification_required | verification_required |
| AI provider (via Base44 InvokeLLM) | Not confirmed | AI/LLM processing for ConditionAI | subprocessor | Sanitised item photos, item name, room name — sent for AI analysis when user triggers ConditionAI. Private notes, tenant/landlord names, contact details, property addresses, signatures, and access codes are excluded by the sanitiser. | Not confirmed | Not confirmed | verification_required | verification_required |
ConditionAI data flow: When a user triggers ConditionAI, the following data is sent to the AI provider: sanitised item photos (up to 5), item name, room name, and report type label. The AI input sanitiser excludes by default: tenant names, landlord names, contact details, property addresses, signatures, keys/access codes, private notes, public-link tokens, authentication data, and unrelated photographs. The AI provider's identity, retention policy, training-use policy, processing location, and international transfer mechanism are to be confirmed. ConditionAI remains in testing status until these terms are verified.
Schedule 4 — International transfers
The following international transfers of personal data have been identified. No transfer mechanism is confirmed until evidence is available. All transfers are marked "verification_required".
- Google (authentication) — Destination: United States. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Contracting entity: not confirmed.
- Stripe (payments — sandbox) — Destination: United States. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Contracting entity: not confirmed.
- Resend (email delivery) — Destination: United States. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Contracting entity: not confirmed.
- AI provider (via Base44 InvokeLLM) — Destination: not confirmed. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Provider identity: not confirmed.
- Base44 (platform infrastructure) — Destination: not confirmed. Transfer mechanism: verification_required. Contracting entity: not confirmed.
Transfer risk assessments and UK IDTA or UK Addendum arrangements have not yet been confirmed. This is a publication blocker — no transfer mechanism is stated as in place until verified. Backup retention periods (platform-managed by Base44) are also not confirmed and are a publication blocker.
Contact us
For questions about this document, please contact us at [privacy contact to be confirmed]