Skip to main content
Legal

Data Processing Addendum

Version 1.0Draft prepared 13 July 2026 — not yet effective

Draft — legal review required — not yet effective. This document has been drafted to reflect ConditionVault's actual product, data processing, and technology stack. It is a draft and is not legally binding. It must be completed with verified company information, approved by the authorised business owner, reviewed by a qualified UK solicitor, and explicitly published before it becomes effective.

1. Parties and incorporation

This Data Processing Addendum ("DPA") is incorporated into the ConditionVault Terms of Service. It applies where ConditionVault processes personal data on behalf of a Customer organisation. The Customer is the data controller and ConditionVault is the data processor.

2. Definitions

Terms used in this DPA have the meanings given in the UK GDPR, the Terms of Service, and this DPA. "Customer Personal Data" means personal data processed by ConditionVault on behalf of the Customer under the Terms.

3. Roles

ConditionVault acts as a processor for customer-directed processing of property data, inspection content, photos, signatures, ConditionSign feedback, ConditionView sharing, and ConditionAI analysis. ConditionVault acts as an independent controller for its own account administration, billing, security, and audit records.

4. Documented instructions

ConditionVault processes Customer Personal Data only on documented instructions from the Customer, as provided through the Service interface. The Customer warrants that its instructions are lawful and that it has the necessary authority and consents to process the personal data uploaded.

5. Security measures

ConditionVault implements the technical and organisational measures set out in Schedule 2. These measures are subject to review and improvement. We do not claim specific security certifications unless verified.

6. Subprocessors

ConditionVault uses the subprocessors listed in Schedule 3. The Customer authorises the use of these subprocessors. We will provide notice of material changes to the subprocessor list. The Customer may object to a new subprocessor by contacting us. Subprocessor objection contact: [privacy contact to be confirmed].

7. Data-subject rights assistance

ConditionVault will assist the Customer in responding to data-subject requests, taking into account the nature of the processing. The Customer is responsible for identity verification and direct communication with data subjects.

8. Security incident assistance

ConditionVault will notify the Customer of a personal data breach without undue delay after becoming aware of it. We will provide information to help the Customer meet its breach-notification obligations.

9. Deletion or return

Upon termination, ConditionVault will delete or return Customer Personal Data according to the Customer's configured retention settings. Data may be retained in backups for the platform-managed backup retention period, after which it is permanently deleted.

10. International transfers

International transfers are described in Schedule 4. We will not state that a specific transfer mechanism is in place until it has been verified.

Schedule 1 — Processing details

Subject matter: Property inspection, reporting, and evidence management.

Duration: For the term of the Customer's subscription plus the configured retention period.

Nature and purpose: Storing, displaying, organising, and sharing inspection content including photos, condition ratings, compliance answers, signatures, and meter readings as directed by the Customer.

Data-subject categories: Customer users, landlords, tenants, prospective tenants, agents, property managers, inventory clerks, contractors, guarantors, ConditionSign recipients, ConditionView recipients, stakeholders, and occupants.

Personal-data categories: Identity data, contact data, property association, tenancy information, photographs, signatures, inspection comments, communications, meter and utility information, keys and access information, audit records.

Special-category data: ConditionVault is not designed for unnecessary special-category data. Customers must not upload it unless necessary, lawful, and within documented instructions. We cannot guarantee that special-category data will never appear in free-text or photographs. If special-category data is identified, it will be handled with appropriate care and flagged for review.

Retention: See retention schedule below.

Schedule 2 — Security measures

  • Organisation-scoped access controls (RLS) — data is isolated by organisation
  • Role-based permissions (organisation owner, admin, inspector, viewer)
  • Authentication via Base44 platform with optional Google OAuth — ConditionVault does not receive passwords, password hashes, tokens, or provider credentials
  • Token hashing for ConditionSign and ConditionView public links (SHA-256)
  • Expiring and revocable sharing tokens
  • Immutable finalised report snapshots with SHA-256 integrity hashing
  • Audit event trails for property, report, and billing actions
  • Rate limiting on registration, data-protection requests, and API operations
  • Idempotency controls to prevent duplicate operations
  • Operation locks to prevent concurrent modification conflicts
  • Backend-authoritative writes for sensitive operations (billing, report finalisation, token management)
  • Offline data partitioned by user and organisation in IndexedDB, cleared on sign-out
  • Service worker for app-shell caching (no personal data cached)

We do not claim SOC 2, ISO 27001, Cyber Essentials, penetration testing, or other certifications unless and until verified evidence exists.

Schedule 3 — Subprocessors

The following providers are used by ConditionVault. No provider is published as a confirmed subprocessor until evidence of the contracting legal entity, DPA, and transfer mechanism is available. Providers marked "verification_required" are pending evidence and must not be treated as confirmed subprocessors.

ProviderContracting entityServiceProcessor statusDataLocationTransferDPA statusVerification
Base44Not confirmedPlatform infrastructure, authentication, database, serverless functions, file storagesubprocessorAccount data, authentication tokens, organisation data, report data, photos, audit logsNot confirmedNot confirmedverification_requiredverification_required
Google (authentication)Not confirmedOAuth authentication provider (via Base44)independent_controllerEmail address, full name, Google profile data provided during sign-upUnited States / Google Cloud regionsNot confirmedverification_requiredverification_required
StripeNot confirmedPayment processing (currently test/sandbox mode)independent_controllerBilling email, billing name, company name, billing address, payment method metadataUnited States / Stripe regional infrastructureNot confirmedverification_requiredverification_required
ResendNot confirmedEmail deliverysubprocessorRecipient email addresses, email content, delivery status metadataUnited StatesNot confirmedverification_requiredverification_required
AI provider (via Base44 InvokeLLM)Not confirmedAI/LLM processing for ConditionAIsubprocessorSanitised item photos, item name, room name — sent for AI analysis when user triggers ConditionAI. Private notes, tenant/landlord names, contact details, property addresses, signatures, and access codes are excluded by the sanitiser.Not confirmedNot confirmedverification_requiredverification_required

ConditionAI data flow: When a user triggers ConditionAI, the following data is sent to the AI provider: sanitised item photos (up to 5), item name, room name, and report type label. The AI input sanitiser excludes by default: tenant names, landlord names, contact details, property addresses, signatures, keys/access codes, private notes, public-link tokens, authentication data, and unrelated photographs. The AI provider's identity, retention policy, training-use policy, processing location, and international transfer mechanism are to be confirmed. ConditionAI remains in testing status until these terms are verified.

Schedule 4 — International transfers

The following international transfers of personal data have been identified. No transfer mechanism is confirmed until evidence is available. All transfers are marked "verification_required".

  • Google (authentication) — Destination: United States. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Contracting entity: not confirmed.
  • Stripe (payments — sandbox) — Destination: United States. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Contracting entity: not confirmed.
  • Resend (email delivery) — Destination: United States. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Contracting entity: not confirmed.
  • AI provider (via Base44 InvokeLLM) — Destination: not confirmed. Transfer mechanism: verification_required. Supplementary measures: to be assessed. Provider identity: not confirmed.
  • Base44 (platform infrastructure) — Destination: not confirmed. Transfer mechanism: verification_required. Contracting entity: not confirmed.

Transfer risk assessments and UK IDTA or UK Addendum arrangements have not yet been confirmed. This is a publication blocker — no transfer mechanism is stated as in place until verified. Backup retention periods (platform-managed by Base44) are also not confirmed and are a publication blocker.

Contact us

For questions about this document, please contact us at [privacy contact to be confirmed]