Effective August 17, 2026
This Data Processing Agreement (”DPA”) is incorporated into and forms part of the Master Subscription Agreement, Order Form(s), or other written agreement governing Constructor's provision of the Services to Customer (the “Principal Agreement”) by and between Constructor.io Corporation, a Delaware corporation, with offices at 268 Bush Street #4450, San Francisco, CA 94104-3503 (“Constructor”) and the customer identified in the applicable Principal Agreement, Proof Schedule, account registration, web form submission, or online acceptance flow (“Customer”) (each a “Party” and together, the “Parties”); and applies to any and all provision of Services by Constructor to Customer, including as part of a pre-contractual “Proof Schedule” arrangement (or similar proof of concept offering). This DPA becomes binding on the date Customer executes or accepts the Principal Agreement, begins to send Constructor Personal Data to facilitate a Proof Schedule (or similar proof of concept offering), or first accesses or uses the Services, whichever occurs first (the “Effective Date”). Capitalized terms not defined herein shall have the meanings set forth in the Principal Agreement.
1.1.
“Applicable European Law” means any law of the EU (or the law of one or more of the Member States of the EU), which is applicable to one or more of the Parties.
1.2.
“Customer Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of Customer pursuant to or in connection with the Principal Agreement, including Personal Data provided as Customer Data as defined in the Principal Agreement.
1.3.
“Contracted Processor” means Constructor and any Subprocessor.
1.4.
“Data Controller” means the entity which determines the purposes and means of the Processing of Personal Data, including as a “Business” as defined in the CCPA.
1.5.
“Data Processor” means the entity which Processes Personal Data on behalf of the Data Controller, including as applicable as a “Service Provider” as that term is defined by the CCPA.
1.6.
“Data Protection Laws” means all data protection legislation and regulations applicable to the processing of the Customer Personal Data under this DPA and the Principal Agreement, including without limitation Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (“GDPR”) and supplementing national legislation, in each case as may be amended, repealed, consolidated, or replaced from time to time, and the UK GDPR, as well as laws and regulations of Switzerland, and the United states and its states, including the California Consumer Privacy Act of 2018 (Title 1.81.5, §1798.100 et. seq., and its implementing regulations, as amended by the California Privacy Rights Act) (the “CCPA”), to the extent any of the foregoing is applicable to either: (i) Constructor in its role as service provider Processing data under the Principal Agreement or (ii) Customer and its Affiliates, as the case may be. For the avoidance of doubt, each party is only responsible for the local, state, national and/or foreign law, treaties, and/or regulations applicable to it.
1.7.
“Data Subject” means the individual to whom Personal Data relates and includes any “Consumer” as defined under the CCPA. Any Data Subject Rights, as described in Section 7 of this DPA, apply to Consumer rights.
1.8.
“Data Transfer” means:
1.8.1.
a transfer of Customer Personal Data from the Customer to Constructor; or
1.8.2.
an onward transfer of Customer Personal Data from Constructor to a Subprocessor.
1.9.
“Personal Data” means any information relating to an identified or identifiable person that has been provided by or for Customer to the Services or collected and Processed by or for Customer through the Services.
1.10.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alternation, unauthorized disclosure of, or access to, Customer Personal Data.
1.11.
“Processing” means any operation or set of operations which is performed upon Customer Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.
1.12.
“Services” means the services the Customer is provided pursuant to the Principal Agreement.
1.13.
“Standard Contractual Clauses” or “SCCs” means: (i) where the GDPR or Swiss Federal Act on Data Protection applies, the contractual clauses issued pursuant to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, completed as described in Annex 4 hereto (‘EU SCCs’); and (ii) where the UK GDPR applies, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner pursuant to S119A(1) of the UK Data Protection Act 2018 and completed as described in Annex 4 hereto (‘UK SCCs’).
1.14.
“Subprocessor” means any Data Processor engaged by Constructor to process Customer Personal Data.
1.15.
“UK GDPR” means the GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018.
2.
Scope; Roles and Regulatory Compliance.
2.1.
This DPA applies to the Customer Personal Data that Constructor receives from Customer, or otherwise Processes on Customer’s behalf, in connection with the Services provided by Constructor to Customer pursuant to the Principal Agreement, or with a Proof Schedule of the Services performed by Constructor for Customer (where applicable).
2.2.
With respect to the Processing Customer Personal Data governed by the GDPR, the Parties acknowledge and agree that Constructor is a processor of the Customer Personal Data, Customer is a controller of the Customer Personal Data, and each Party will comply with the obligations applicable to it in such role with respect to the Processing of Customer Personal Data.
2.3.
Customer shall, in its use of the Services, Process Customer Personal Data in accordance with the requirements of Data Protection Laws. For the avoidance of doubt, Customer’s instructions for the Processing of Personal Data shall comply with Data Protection Laws, including any applicable requirement to provide notice to Data Subjects of the use of Constructor as Data Processor. Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data. Customer shall ensure that the Customer is entitled to transfer the relevant Personal Data to Constructor so that Constructor and its Sub-processors may lawfully use, process and transfer the Personal Data in accordance with this DPA and the Principal Agreement on Customer’s and its Affiliates’ behalf.
2.4.
Constructor will notify Customer upon Constructor’s receipt of any legally binding request for disclosure of Customer Personal Data from a government agency or law enforcement authority, including judicial authorities (each, a ‘Public Authority’) unless otherwise legally prohibited. To the extent Constructor is prohibited by law from providing such notification, Constructor shall use commercially reasonable efforts to obtain a waiver of the prohibition to enable Constructor to communicate as much information as possible, as soon as possible. Further, Constructor shall challenge the request if there are reasonable grounds to consider that the request is unlawful. When challenging a request, Constructor shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits and shall not disclose the Customer Personal Data requested until required to do so under the applicable procedural rules. Constructor agrees it will provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request. Constructor shall promptly notify Customer if Constructor becomes aware of any direct access by a Public Authority to Customer Personal Data and provide information available to Constructor in this respect, to the extent permitted by law. For the avoidance of doubt, this DPA shall not require Constructor to pursue action or inaction that could result in civil or criminal penalty for Constructor such as contempt of court.
2.5.
The Parties acknowledge that Constructor acts as an independent data controller with respect to certain personal data collected directly from Customer's authorized users of the Constructor dashboard and through Constructor's support channels, for Constructor's own legitimate business purposes, including account management, service improvement, product analytics, customer success operations, and support quality management, as further described in Constructor's Privacy Policy at
https://constructor.com/privacy-policy. Such processing is not governed by this DPA, and Constructor shall process such data in accordance with applicable Data Protection Laws and its Privacy Policy.
3.
Processing of Customer Personal Data.
3.1.
Constructor, as Data Processor:
3.1.1.
shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data;
3.1.2.
shall not Process Customer Personal Data other than on the relevant Customer’s documented instructions, including but not limited to the Principal Agreement and this DPA, unless required by Applicable European Law, in which case, Constructor shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
3.1.3.
shall immediately inform the Customer if Constructor reasonably believes that documented instructions provided by the Customer are unlawful or infringe applicable Data Protection Laws.
3.2.
By entering into the Principal Agreement, Customer instructs Constructor to Process Personal Data for the following purposes: (i) Processing in accordance with the Principal Agreement and applicable Order Form, which includes updating the Service and preventing or addressing service or technical issues; (ii) Processing initiated by Customer’s users in their use of the Service; (iii) Processing for a legitimate interest, which includes for security purposes; and (iv) Processing to comply with other reasonable documented instructions provided by Customer (e.g., via email or support channels) where such instructions are consistent with the terms of the Principal Agreement.
4.
Data Processor Personnel. Constructor shall ensure that any employee, agent, or contractor of Constructor, who may have access to the Customer Personal Data, are subject to confidentiality undertakings or statutory obligations of confidentiality equally as protective of Customer Personal Data as this DPA, ensuring in each case that access is limited to those individuals who need to know or access the relevant Customer Personal Data, as necessary for the purposes of the Principal Agreement. For purposes of this DPA, the acts or omissions of Constructor, its employees, and its affiliates, agents, contractors, and their employees constitute Constructor’s acts or omissions.
5.
Security. Taking into account (a) the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing, (b) the size, scope and type of Constructor’s business, (c) the amount of resources available to Constructor, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Constructor shall in relation to the Customer Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures listed in Articles 32 to 34 (inclusive) of the GDPR.
6.1.
The Customer provides its general authorisation to Constructor to engage Subprocessors to Process Customer Personal Data in connection with the provision of the Service. The Customer authorizes Constructor to appoint (and permit each Subprocessor appointed in accordance with this Section 6 to appoint) Subprocessors in accordance with this Section 6 and any restrictions in the Principal Agreement. Constructor may continue to use those Subprocessors already engaged by Constructor as at the date of this DPA, as such are listed in Annex 3 to this DPA, for the purposes of Processing Customer Personal Data pursuant to this DPA.
6.2.
If Constructor engages a new Subprocessor, Constructor shall inform the Customer of the engagement at least thirty (30) days prior to the date on which it commences Processing Personal Data, by sending an email notification to the Customer, and the Customer may object to the engagement of such new Subprocessor by notifying Constructor within ten (10) days of Constructor’s email, provided that such notification must explain the reasonable grounds for the objection. If the Customer does not object within the specified time period, the engagement of the new Subprocessor shall be deemed accepted by the Customer. If the Customer does object, then Constructor will do one of the following:
6.2.1.
Provide additional information to Customer such that Customer withdraws its objection;
6.2.2.
Continue providing the Services to Customer without the use of such Subprocessor; or
6.2.3.
Select a different Subprocessor for whom Customer raises no objection.
6.3.
If Constructor is unable to provide one of the foregoing options within thirty (30) days of Customer’s objection, then Customer may terminate the applicable Order Form with respect only to those Services which cannot be provided by Constructor without the use of the objected-to new Subprocessor by providing written notice to Constructor. Upon such termination Customer will receive a pro-rata refund of any prepaid unused fees as of the termination date with respect to such terminated Services.
6.4.
With respect to each Subprocessor (which, for the purposes of this Section 6.4 includes new Subprocessors engaged in accordance with Section 6), Constructor shall ensure that the arrangement between Constructor and the relevant Subprocessor is governed by a written contract including terms that offer at least the same level of protection for Customer Personal Data as those set out in this DPA and meet the requirements of applicable Data Protection Laws. Constructor shall be liable for the acts and omissions of its Subprocessors to the same extent Constructor would be liable if performing the services of each Subprocessor directly under the terms of this DPA and the Principal Agreement.
7.1.
Taking into account the nature of the Processing, Constructor shall assist the Customer by implementing reasonable and appropriate physical, technical, and organizational measures, for the fulfillment of the Customer’s obligations, as reasonably understood by Customer, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
7.2.
Constructor shall, to the extent legally permitted:
7.2.1.
promptly notify Customer if it receives a request from a Data Subject under any Data Protection Law in respect of Customer Personal Data; and
7.2.2.
ensure that it does not respond to that request except on the documented instructions of Customer or as required by applicable laws to which Constructor is subject, in which case Constructor shall to the extent permitted by applicable laws inform Customer of that legal requirement before Constructor responds to the request.
8.
Personal Data Breach and Notification.
8.1.
Constructor shall notify Customer without undue delay upon Constructor becoming aware of a Personal Data Breach, but in no case more than forty-eight (48) hours after becoming aware of such Personal Data Breach. Such notice will, as permitted and required by applicable Data Protection Laws, provide Customer with details of the Personal Data breach to the extent such information is reasonably available to Constructor.
8.2.
Constructor shall reasonably cooperate with the Customer and take commercially reasonable steps to assist Customer in complying with its obligations under the applicable Data Protection Laws. Except as required by applicable Data Protection Laws, the obligations herein shall not apply to Personal Data Breaches that are caused by the Customer or its users.
9.
Data Protection Impact Assessment and Prior Consultation. Upon request, Constructor shall provide reasonable assistance to the Customer with any data protection impact assessments, and prior consultations with Supervisory Authorities or other competent data privacy authorities, which Customer reasonably considers to be required by Articles 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Customer Personal Data by, and taking into account the nature of the processing and information available to, the Contracted Processors.
10.
Deletion or Return of Customer Personal Data. Constructor shall promptly and in any event within 90 days of the date of cessation of any Services involving the Processing of Customer Personal Data, delete and procure the deletion of all copies of the Customer Personal Data or return all Customer Personal Data to the Customer, at the Customer’s election, unless Applicable European Law requires storage of Customer Personal Data or to fulfil a legitimate interest. Constructor may retain and use data derived from Personal Data that has been anonymized or aggregated in compliance with applicable law, such that it no longer identifies or relates to an identifiable natural person, for the purposes of improving its services, including for model improvement and analytics.
11.1.
Constructor uses external auditors to verify the adequacy of its security measures with respect to its processing of Personal Data. Such audits are performed at least once annually at Constructor’s expense by independent third-party security professionals appointed at Constructor’s discretion. This audit will result in the generation of an audit report attesting that Constructor’s security controls achieve recognized industry standards, including Service Organization Controls (‘SOC 2’), ISO 27001, or such other alternative standards that are substantially equivalent. A description of Constructor’s certifications and standards for audit can be found at
https://constructor.com/security-and-compliance.
11.2.
No more than once per year during the term of the Principal Agreement, upon reasonable written request, Constructor shall make available to the Customer its most recent SOC 2 audit report (or substantially equivalent or replacement standard). Such an audit report will be deemed Confidential Information as per the confidentiality terms of the Principal Agreement. Unless otherwise provided under Section 11.3 of this DPA, the Customer agrees that any audit rights granted by Data Protection Laws will be satisfied by this audit report.
11.3.
If the information made available to the Customer pursuant to Section 11.2 of this DPA is insufficient to demonstrate Constructor’s compliance with its obligations under Article 28 EU GDPR (and the Standard Contractual Clauses, if applicable), then Constructor shall enable Customer to request one onsite audit per annual period during the term of the Principal Agreement to verify Constructor’s compliance with its obligations under Article 28 EU GDPR (and the Standard Contractual Clauses, if applicable) as follows: (a) Customer may only mandate an auditor for the purposes of this Section 11.3 if the auditor is reasonably agreed to by Constructor; (b) Customer shall give Constructor at least thirty (30) days advance notice of any audit or inspection to be conducted under Section 11.3; and Customer shall make (and ensure that each of its mandated auditors makes) reasonable endeavors to avoid causing (or, if it cannot avoid, to minimize) any damage, injury, or disruption to Constructor’s premises, equipment, personnel, and business operations while its personnel are on those premises in the course of such an audit or inspection, (d) any audit will be subject to the confidentiality obligations set forth in the Principal Agreement, or as otherwise agreed in writing by the parties; and (e) the Customer shall reimburse Constructor for any time expended for any such on-site audit at Constructor’s then-current professional services rates, which shall be made available to the Customer upon request, provided that all reimbursement rates shall be reasonable, taking into account the resources expended by Constructor. Constructor need not give access to its premises for the purposes of such an audit or inspection:
11.3.1.
to any individual unless he or she produces reasonable evidence of identity and authority;
11.3.2.
outside normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis and Customer undertaking an audit has given notice to Constructor that this is the case before attendance outside those hours begins;
11.3.3.
for the purposes of more than one audit or inspection, in respect of Constructor, in any calendar year, except for any additional audits or inspections which:
11.3.3.1.
Customer reasonably considers necessary because of genuine concerns as to Constructor’s compliance with this DPA; or
11.3.3.2.
Customer is required to carry out by Data Protection Law, a Supervisory Authority, or any similar regulatory authority responsible for the enforcement of Data Protection Laws in any country or territory, where the Customer has identified its concerns or the relevant requirement or request in its notice to Constructor of the audit or inspection; or
11.3.4.
to a third party who is performing the audit on behalf of the Customer, unless such third-party auditor executes a confidentiality agreement acceptable to Constructor before the audit.
11.4.
Before commencement of any such on-site audit; Customer and Constructor shall mutually agree on the scope, timing, and duration of the audit in addition to the reimbursement rate for which the Customer shall be responsible. Customer shall promptly notify Constructor with information regarding any non-compliance during the course of an audit.
11.5.
The Customer must provide Constructor with any audit reports generated in connection with any audit at no charge unless prohibited by applicable law. The Customer may use audit reports only for the purposes of meeting its audit requirements under the Data Protection laws and/or confirming compliance with the requirements of this DPA. The audit reports shall be confidential.
11.6.
Nothing in this Section 11 shall require Constructor to breach any confidentiality owed to any of its clients, employees, or Subprocessors.
11.7.
Nothing in this Section 11 shall restrict or modify the auditing provisions under the Standard Contractual Clauses.
12.1.
The Customer understands and agrees that Constructor and its Subprocessors may Process Personal Data in jurisdictions that are outside of the European Economic Area (‘EEA’), Switzerland and the United Kingdom (‘UK’) (collectively the ‘European Territories’).
12.2.
Transfer Mechanisms for Cross Border Data Transfers.
12.2.1.
If Customer Personal Data is transferred from the European Territories to outside the European Territories, then such transfer will only take place if: (i) the recipient is recognized by the European Commission as providing an adequate level of protection for personal data (as described in the EU GDPR); or (ii) the transfer is covered by a suitable framework or transfer mechanism recognized by the relevant authorities or courts as providing an adequate level of protection for Personal Data, including but not limited to the Standard Contractual Clauses or Binding Corporate Rules for Processors.
12.2.2.
The terms and conditions of Annex 4 of this DPA (‘Transfer Mechanism’) shall apply when Constructor processes Customer Personal Data outside of the European Territories that is protected by the EU GDPR or the UK GDPR.
12.2.3.
In the event the Services are covered by more than one transfer mechanism, the transfer of Personal Data will be subject to a single transfer mechanism in accordance with the following order of precedence: (i) if applicable, the applicable Standard Contractual Clauses as set forth in Annex 4 of this DPA; or (ii) other applicable data transfer mechanisms permitted under Data Protection Laws.
13.
Additional Terms for California
These additional terms set out in Section 13 of this DPA shall only apply to “Personal Information” of a “Consumer” that Constructor Processes in the course of providing Customer the Services under the Principal Agreement (referred to hereafter as “Customer Personal Information”). Capitalized terms identified in this Section 13 shall have the same meaning as defined in the CCPA, unless otherwise noted.
13.1.
The Customer or its Affiliate is a Business subject to the CCPA. Customer has the exclusive authority to determine the purposes for and means of Processing the Customer Personal Information. Customer will provide Customer Personal Information to Constructor solely for the purpose of Constructor performing the Services, and will collect and provide the Customer Personal Information to Constructor solely in compliance with the CCPA.
13.2.
Constructor is a Service Provider that provides certain services to the Customer or its Affiliate(s) pursuant to the Principal Agreement. For clarity, Constructor is not a Third Party as described in the CCPA.
13.3.
Constructor will comply with CCPA in the provision of the Services to Customer. Constructor will collect, retain, use, share, disclose or otherwise Process Customer Personal Information only as necessary to perform the Services specified in the Principal Agreement or as otherwise expressly permitted in the Principal Agreement. Without limiting the foregoing, Constructor will not Sell the Customer Personal Information. Constructor will notify Customer if Constructor determines it can no longer meet Constructor’s obligations under CCPA. Upon notice by Customer, where Customer has determined Constructor is not Processing Customer Personal Information in accordance with the Principal Agreement and this DPA, Customer may take reasonable and appropriate steps to stop and remediate such unauthorized Processing.
13.4.
If Constructor receives a request submitted by a Consumer to exercise a right it has under the CCPA in relation to that Consumer’s Customer Personal Information, it will provide a copy of the request to the Customer. The Customer will be responsible for handling and communicating with Consumers in relation to such requests.
13.5.
Constructor certifies that it understands its restrictions and obligations set forth in this Section 13 and will comply with them.
14.1.
Notices. All notices and communications given under this DPA shall be made in accordance with the Principal Agreement.
14.2.
Liability. This DPA shall be subject to the limitations of liability agreed between the parties under the Principal Agreement (and any reference to the liability of a party means that party and its Affiliates in aggregate). In the event that the Principal Agreement does not contain an applicable liability cap, Constructor’s total liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, shall not exceed five thousand U.S. dollars ($5,000 USD).
14.3.
Order of Precedence. With regard to the subject matter of this DPA, in the event of inconsistencies between the provisions of this DPA and any other agreements between the Parties, including the Principal Agreement and agreements entered into or purported to be entered into after the date of this DPA, the provisions of this DPA shall prevail with regard to the parties’ data protection obligations, except where the parties expressly agree otherwise in a written agreement signed or otherwise accepted by both parties. The Principal Agreement, as amended and modified by this DPA, otherwise remains in full force and effect. In the event of any conflict or inconsistency between this DPA and the Standard Contractual Clauses set forth in Annex 4 or the UK SCC’s, as applicable, the Standard Contractual Clauses or the UK SCC’s, as applicable, shall prevail. This DPA will control over any different or additional online data processing agreements or addenda (even where such terms are referred to in an ordering document entered into subsequent to this DPA), and any such additional data processing agreements or addenda are hereby rejected, and shall be void and have no effect, and this DPA shall govern without modification or addition.
14.4.
Term and Termination. The term of this DPA shall commence on the Effective Date and shall be coterminous with the Principal Agreement.
14.5.
Amendment. Constructor may update this DPA from time to time by posting an updated version on its website or otherwise making the updated version available to Customer, provided that Constructor will give Customer reasonable prior notice of any material updates unless the update is required by Data Protection Laws or does not materially reduce the protections for Customer Personal Data. The updated DPA will become effective on the date the new version is posted. Any amendment signed or otherwise accepted by both Parties will control over a conflicting online update solely for the applicable Customer.
14.6.
Choice of Law. This DPA will be governed by and construed in accordance with governing law and jurisdiction provisions of Delaware, United States, unless required otherwise by Data Protection Laws and Standard Contractual Clauses (where applicable).
14.7.
Severability. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.
ANNEX I
A. LIST OF PARTIES
Data exporter(s): Customer, as identified in the applicable Principal Agreement, account registration, web form submission, or other online acceptance flow. Customer's contact details, and where applicable the contact details of its data protection officer and/or representative in the European Union, will be provided by Customer through Constructor's web forms, dashboard, account records, or other commercially reasonable means and maintained by Constructor in its account records. Customer may update its contact details through the Constructor dashboard or by contacting Constructor.
- Company name: Customer, as identified in the applicable Principal Agreement, account registration, web form submission, or other online acceptance flow.
- Address: as provided by Customer through the applicable Principal Agreement, account registration, web form submission, Constructor dashboard, or other online account records maintained by Constructor.
- Contact person’s name, position and/or email: as provided by Customer through Constructor's web forms, dashboard, account records, or other commercially reasonable means and maintained by Constructor in its account records.
- Role (controller/processor): The parties acknowledge and agree that with regard to the processing of Personal Data, the Customer is acting as the Data Controller (Module 2).
Data importer(s): [Identity and contact details of the data importer(s), including any contact person with responsibility for data protection]
- Company name: Constructor.io Corporation
- Address: 268 Bush Street #4450, San Francisco, CA 94104 United States
- Contact person’s name, position and contact details: Dan McCormick, CISO, privacy@constructor.io
- Role (controller/processor): The parties acknowledge and agree that with regard to the processing of Personal Data, Constructor is acting as a Data Processor (Module 2).
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred
Customer may submit Customer Personal Data to Constructor for the provision of the Services, which may include, but is not limited to Customer Personal Data relating to the following categories of data subjects:
- Customer employees with access to the Constructor dashboard and/or support channels
- Visitors to Customer Properties utilizing Constructor’s Service
Categories of personal data transferred
Customer may submit (or Constructor may collect at Customer’s direction) Customer Personal Data to Constructor for the provision of the Services, the extent of which is determined by Customer in its sole discretion, which may include the following categories of Customer Personal Data:
- For Customer employees and contractors with access to the Constructor dashboard and/or support channels:
- Email address (and other contact information that may be provided by such users from time to time)
- IP Address
- For visitors to Customer Properties utilizing Constructor’s Services:
- IP Address
- Other non-sensitive personal data that may be provided by Customer to Constructor from time to time.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
N/A
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous, for the duration of the Principal Agreement.
Nature of the processing
For Constructor to provide Services in accordance with the Principal Agreement.
Purpose(s) of the data transfer and further processing
Customer Personal Data is transferred for the purpose of provision of the Services by Constructor to Customer pursuant to the Principal Agreement.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Customer Personal Data will be retained in accordance with Section 10 of this DPA (Deletion or Return of Customer Personal Data)
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
The subject matter, nature and duration of the processing shall be as specified in the Sub-processor List.
C. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with Clause 13
In respect of the EU SCCs, means the competent supervisory authority determined in accordance with Clause 13 of the EU SCCs. In respect of the UK SCCs, means the UK Information Commissioner's Office.
ANNEX II – TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
The technical and organizational security measures are based on Constructor’s Security Terms and Conditions applicable to the Services and may be modified from time to time, however any update will not materially reduce the overall protections provided herein.
Measures of pseudonymisation and encryption of personal data:
Constructor maintains Customer Data in an encrypted format at rest using AES-256 or equivalent and in transit over public networks using industry standard HTTPS/TLS (1.2 or higher).
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services:
Constructor’s customer agreements contain strict confidentiality obligations. Constructor’s personnel and subcontractors authorized to Process Personal Data are subject to confidentiality obligations substantially equivalent with the ones Constructor committed to in the Principal Agreement or are under an appropriate statutory obligation of confidentiality. Constructor has a business continuity plan designed to maintain service and/or recovery from reasonably foreseeable emergency situations or disaster. Customer Data is securely backed up on a regular basis. Constructor infrastructure spans multiple fault-independent availability zones on its hosting provider and is supported by various tools and processes designed to maintain availability and resiliency of Services.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident:
Constructor performs regular backups and live replicas of Customer Data, which is hosted in third-party cloud provider data centers. Backups are retained redundantly across multiple availability zones and encrypted in transit and at rest.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing:
Constructor maintains a comprehensive information security program, including administrative, organizational, technical, and physical safeguards reasonably designed to protect the Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. As set out in Section 5 of the DPA, Constructor’s security program is intended to be appropriate to the nature of the Services and the size and complexity of Constructor’s business operations. Constructor has a separate and dedicated security team that manages the Constructor security program. This team facilitates and supports independent audits and assessments performed by third parties to provide independent feedback on the operating effectiveness of the information security program.
Measures for user identification and authorisation:
Constructor personnel are required to use unique user access credentials and multi-factor authentication for authorization related to Customer Data. Constructor follows the principles of least privilege through role-based access models when provisioning service or system access. Constructor personnel are authorized to access Customer Data based on their job function, role and responsibilities. Access is promptly removed upon termination.
Measures for the protection of data during transmission:
Customer Data is encrypted when in transit over public networks using industry standard HTTPS/TLS (TLS 1.2 or higher).
Measures for the protection of data during storage:
Customer Data is encrypted at rest using Advanced Encryption Standard (AES-256) or equivalent.
Measures for ensuring physical security of locations at which personal data are processed:
Constructor is a fully distributed organization with no physical premise to secure. Constructor maintains user access policies and procedures which are documented, approved and implemented for maintaining logical access in accordance with least privileges and need to know.
The Constructor Services hosted on data servers owned by third party cloud provider(s) are protected by the security and environmental controls of such cloud provider(s). Our third party cloud provider(s) is SOC 1,2,3, ISO 27001/27017/27018, and PCI-DSS compliant.
Measures for ensuring events logging:
Constructor monitors access to applicable Constructor applications, tools, and resources that process or store Customer Data as follows:
- Logs recording privileged user access activities, authorized and unauthorized access attempts, system exceptions, and information security events are retained, complying with applicable laws and regulations.
- Logs are reviewed regularly and network intrusion detection (IDS) tools implemented to help facilitate timely detection.
- Physical and logical user access to log files are restricted to authorized personnel.
Measures for ensuring system configuration, including default configuration:
Constructor maintains programmatic configuration baselines for Constructor systems supporting the production data processing environment. Changes to these baselines are restricted to a small number of authorized Constructor personnel, and are required to adhere to internal change control processes.
Measures for internal IT and IT security governance and management:
Constructor maintains internal policies on the acceptable use of IT systems and general information security. Constructor has implemented and will maintain a security team responsible for ensuring the management of Constructor’s security program. All Constructor personnel with access to Customer Data must complete new hire security awareness training, as well as annual refreshers, that includes the protection of such information.
Measures for certification/assurance of processes and products:
Constructor has a separate and dedicated security team that manages Constructor’s security program, by holding regular independent third-party audits to attest of Constructor’s security-related certifications, including SOC 2 and ISO 27001 certification, and regular application penetration testing.
Measures for ensuring data minimization:
When using Constructor Services, the Customer may submit personal data into the Services and/or Constructor may use its beacon placed on Customer Properties to collect personal data. The Customer determines the personal data that is being inputted into the Services. Constructor truncates the IP addresses of visitors to Customer Properties by removing the last octet shortly after collection. Constructor stores raw logs containing the full IP address, but only the truncated version is used for general service uses (e.g. behavioral tracking).
Measures for ensuring data quality:
As part of Constructor’s security program, Constructor conducts system audits, event logging, and related monitoring procedures to proactively record user access and system activity for routine review. When Constructor's dedicated Security Team becomes aware of an incident, Constructor’s incident response plan guides Constructor’s investigation, response to, and mitigation of any problem related to its Services and information assets.
Measures for ensuring limited data retention:
Upon termination or expiration of the Principal Agreement, Constructor will delete or destroy all copies of Personal Data in Constructor’s systems or otherwise in Constructor’s possession or control, unless legally prohibited or to fulfill a legitimate interest.
Customers can access, update, delete, or correct their account information via the Constructor dashboard or by contacting their Customer Success representative.
Measures for ensuring accountability:
Constructor has implemented and has adopted internal policies and implemented measures across its organization based on the principles of data protection by design and data protection by default. For more detailed information, please refer to Constructor Privacy Policy.
Measures for allowing data portability and ensuring erasure:
The Customer is responsible for responding to requests from their users to exercise their rights under applicable Data Protection Laws, including the right to access, rectification, restriction of Processing, erasure (“right to be forgotten”), data portability, objection to the Processing, or to not be subject to an automated individual decision making. Customers can contact us at privacy@constructor.io to address such requests from the Data Subject. If the Customer, in its use of the Services, does not have the ability to address such request from its Data Subject, Constructor shall, upon Customer’s request, provide commercially reasonable efforts to assist Customer in responding to such Data Subject request, to the extent Constructor is legally permitted to do so and the response to such Data Subject request is required under applicable Data Protection Laws and Regulations.
For transfers to Subprocessors, also describe the specific technical and organisational measures to be taken by the Subprocessor to be able to provide assistance to the controller and, for transfers from a processor to a subprocessor, to the data exporter
When Constructor engages a subprocessor under this DPA, Constructor and the subprocessor enter into an agreement with data protection terms substantially equivalent to those contained herein
ANNEX III – APPROVED SUBPROCESSORS
| Service |
Purpose |
Entity Country |
| Processors of Service data |
| Amazon Web Services, Inc. |
Cloud infrastructure, hosting, storage, networking, backup, and related infrastructure services |
United States (with additional data centers in Germany, Singapore, and Australia) |
| Databricks Inc. |
Service data processing and machine learning supporting the Services |
United States |
| Wiz, Inc. |
Cloud security services, monitoring, vulnerability detection, and risk remediation |
United States |
| Anthropic, PBC |
AI-assisted software development and debugging; processing of engineering inputs and logs |
United States |
| OpenAI OpCo, LLC |
AI-assisted software development and debugging; processing of engineering inputs and logs |
United States |
| Processors of only Constructor dashboard user and customer support data (i.e. Customer’s internal users) |
| Thena (Pivoting Owl Inc.) |
Support ticketing and support workflow management |
United States |
| Sentry (Functional Software, Inc.) |
Error tracking, crash reporting, and application monitoring for service delivery, debugging, and support |
United States |
| FullStory, Inc. |
Dashboard session replay for service delivery, debugging, and support |
United States |
| MS Teams (Microsoft Corporation) |
Support communications for service delivery and customer support |
United States |
| Slack Technologies, LLC |
Support communications for service delivery and customer support |
United States |
ANNEX IV - CROSS BORDER DATA TRANSFER MECHANISM
1.
Application of the EU Standard Contractual Clauses.
1.1 When Constructor in the provision of the Services is a recipient of Personal Data subject to the GDPR, then Constructor will process such Personal Data outside of the European Economic Area (EEA) or Switzerland. The parties agree that the EU SCCs will apply to Personal Data that is transferred via the Services from the European Economic Area or Switzerland, either directly or via onward transfer, to any country or recipient outside the European Economic Area or Switzerland that is: (a) not recognized by the European Commission (or, in the case of transfers from Switzerland, the competent authority for Switzerland) as providing an adequate level of protection for personal data and (b) not covered by a suitable framework recognized by the relevant authorities or courts as providing an adequate level of protection for personal data, including but not limited to Binding Corporate Rules for Processors.
1.2 For data transfers from the EEA or Switzerland that are subject to the EU SCCs, the EU SCCs will be deemed entered into (and incorporated into this DPA by this reference) and completed as follows:
(i) Where Customer acts as a Data Controller and Constructor acts as Customer’s Data Processor with respect to Personal Data subject to the EU SCCs, Module 2 (Controller to Processor) will apply;
(ii) in Clause 7, the optional docking clause will not apply;
(iii) in Clause 9, option 2 will apply, and the time period for prior notice of Sub-Processor changes shall be as set out in Section 6 (Subprocessing) of this DPA. In Clause 9(c), where confidentiality restrictions prohibit Constructor from providing a copy of a Sub-Processor agreement to Customer, Constructor shall (on a confidential basis) provide all information that it reasonably can in connection with such Sub-Processor Agreement to Customer;
(iv) in Clause 11, the optional language will not apply;
(v) in Clause 12, any claims brought under the EU SCCs shall be subject to the terms and conditions set forth in the Principal Agreement to the extent possible;
(vi) in Clause 13, the supervisory authority shall be as follows:
(a) Where the Customer is established in an EU Member State: the supervisory authority with responsibility for ensuring compliance by Customer with the GDPR as regards the data transfer shall act as competent supervisory authority;
(b) Where the Customer is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with Article 3(2) and has appointed a representative pursuant to Article 27(1) of the GDPR, the supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of the GDPR is established shall act as competent supervisory authority;
(c) Where the Customer is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of the GDPR, the Irish Data Protection Commission shall act as competent supervisory authority.
(d) Where the Customer is established in the United Kingdom, the Information Commissioner’s Office shall act as competent supervisory authority.
(vii) in Clause 17, option 1 will apply, and the EU SCCs will be governed by Irish law;
(viii) in Clause 18(b), disputes shall be resolved before the courts of Dublin, Ireland;
(ix) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex 1 to this DPA;
(x) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex 2 to this DPA;
Nothing in this Section 1.2 is intended to conflict with either party’s rights or responsibilities under the EU SCCs and, in the event of any such conflict, the EU SCCs shall prevail.
1.3 The EU Standard Contractual Clauses apply to (i) the legal entity that has executed the Standard Contractual Clauses as a Data Exporter and, (ii) all Affiliates of Customer established within the European Economic Area (EEA) and Switzerland that have purchased subscriptions to the Services on the basis of an Order Form. For the purpose of the EU SCCs and this Section 1.3, the aforementioned entities shall be deemed “Data Exporters”.
2.
Application of the UK Standard Contractual Clauses.
2.1 When Constructor in the provision of the Services is a recipient of Personal Data subject to the UK GDPR (and not the law in any EEA jurisdiction), then Constructor will process such Personal Data outside of the UK. The parties agree that the UK SCCs will apply to Personal Data that is subject to the UK GDPR and transferred via the Services from the UK, either directly or via onward transfer, to any country or recipient outside the European Territories that (a) is not recognized by the competent authority as providing an adequate level of protection for personal data, and (b) not covered by a suitable framework recognized by the relevant authorities or courts as providing an adequate level of protection for personal data, including but not limited to Binding Corporate Rules for Processors.
2.2 For data transfers from the UK that are subject to the UK SCCs, the UK SCCs will be deemed entered into (and incorporated into this DPA by this reference) and completed as follows:
(i) In Table 1 of the UK SCCs, the Parties’ details shall be the Parties and their Affiliates to the extent any of them is involved in such transfer, including those set forth in Annex 1, and the Key Contact shall be the contacts set forth in Annex 1.
(ii) In Table 2 of the UK SCCs, the Approved EU SCCs referenced in Table 2 shall be the EU SCCs as executed by the Parties pursuant to this DPA.
(iii) In Table 3 of the UK SCCs, Annex 1A, 1B, and II shall be as set forth in Annex 1.
(iv) In Table 4 of the UK SCCs, either party may end this DPA as set out in Section 19 of the UK SCCs.
(v) By entering into this DPA, the Parties are deemed to be signing the UK SCCs and their applicable Tables and Appendix Information.
3. Additional Safeguards for the Data Transfer and Processing of Customer Personal Data from the EEA, Switzerland, and the United Kingdom:
3.1
Constructor shall encrypt all transfers of the Customer Personal Data between Constructor and Customer to help prevent the acquisition of such data by third parties.
3.2
Constructor represents and warrants that: (1) as of the date of this DPA, it has not received any directive under Section 702 of the U.S. Foreign Intelligence Surveillance Act, codified at 50 U.S.C. § 1881a (“FISA Section 702”); and (2) no court has found Constructor to be the type of entity eligible to receive process issued under FISA Section 702: (i) an “electronic communication service provider” within the meaning of 50 U.S.C § 1881(b)(4) or (ii) a member of any of the categories of entities described within that definition; and (3) it is not the type of provider that is eligible to be subject to Upstream collection (“bulk” collection) pursuant to FISA Section 702.
3.3
Constructor will challenge any request under FISA Section 702 for bulk or upstream surveillance.
3.4
Constructor will use all reasonably available legal mechanisms to challenge any demands for data access through the national security process it receives, if any, as well as any non-disclosure provisions attached thereto.