EA
EstatesAI
Legal

Data Processing Agreement

Version 1.0 · Effective June 2026 · UK GDPR Article 28

By using the EstatesAI service you agree to this DPA. Enterprise customers requiring a countersigned DPA should contact legal@estatesai.uk.

Introduction

This Data Processing Agreement ("DPA") sets out how EstatesAI Ltd ("Processor") processes personal data on behalf of customers ("Controller") in the course of providing the EstatesAI platform.


This DPA is incorporated into and subject to the EstatesAI Terms of Service. If you require a separately executed DPA for procurement purposes, contact legal@estatesai.uk.

Article 1 — Roles

The Customer is the **Controller** — you determine the purposes and means of processing personal data uploaded to the platform.


EstatesAI is the **Processor** — we process personal data only on your documented instructions, for the purpose of providing the service.

Article 2 — Subject Matter

What we process: Names and email addresses of your users; IP addresses; any personal data contained within asset registers or compliance records you upload.


Why: To provide the EstatesAI platform services as described in the Terms of Service.


Duration: For the term of your subscription, plus the data retention period described in Article 6.


Nature: Storage, retrieval, AI enrichment (non-personal data only — see Article 5), display, export, and deletion.

Article 3 — Your Responsibilities

As Controller, you are responsible for:


— Ensuring you have a lawful basis for processing personal data and for instructing us to process it

— Informing data subjects about the processing in accordance with UK GDPR Articles 13–14

— The accuracy and legality of all personal data provided to us

— Limiting uploads to data that is necessary for the service

Article 4 — Our Obligations

EstatesAI, as Processor, will:


— Process personal data only on documented instructions from you

— Not process personal data for any purpose other than providing the service

— Notify you promptly if we believe any instruction infringes UK GDPR

— Ensure all personnel with access to personal data are bound by appropriate confidentiality obligations

— Implement and maintain appropriate technical and organisational security measures

Article 5 — AI Processing

When we send asset data to our AI provider for enrichment, **only non-personal asset data is transmitted** — asset names, building types, disciplines, and technical parameters.


Personal data — including user names, email addresses, and IP addresses — is **never transmitted** to AI systems.


This is by design. The AI enrichment process operates on technical building data, not on information about individuals.

Article 6 — Sub-Processors

We engage the following sub-processors:


Microsoft Azure (UK): Cloud hosting and database storage — data remains in the United Kingdom.

Anthropic (USA): AI enrichment of non-personal asset data — subject to UK IDTA/SCCs.

Postmark (USA/EU): Transactional email delivery — subject to SCCs.


We will notify you of any proposed changes to this list with at least **14 days' notice**. You may object to a new sub-processor on reasonable data protection grounds within that period.

Article 7 — Security

We implement and maintain appropriate technical and organisational measures including:


— Encryption in transit (TLS 1.2+) and at rest (AES-256)

— Role-based access control with least-privilege principles

— Password hashing (bcrypt with appropriate cost factor)

— Full audit logging of user actions

— Regular security reviews and testing


For details see our Security page at www.estatesai.uk/security.

Article 8 — Data Subject Rights

We will assist you in fulfilling data subject rights requests (access, rectification, erasure, restriction, portability, objection) using appropriate technical measures.


Where a data subject submits a rights request directly to us, we will promptly forward it to you for action.

Article 9 — Data Breaches

We will notify you **without undue delay and within 48 hours** of becoming aware of a personal data breach affecting your data.


Notification will include: the nature of the breach, the categories and approximate number of data subjects and records affected, our Data Protection contact details, the likely consequences of the breach, and the measures we have taken or propose to take.


You are responsible for assessing whether to notify the ICO (within 72 hours) and affected data subjects.

Article 10 — Data Return & Deletion

On termination of the service, we will:


1. Provide a data export in CSV format within 10 business days of your request

2. Delete all personal data within 90 days of termination

3. Provide written confirmation of deletion on request


Sub-processors are also required to delete data within this period.

Article 11 — International Transfers

We will not transfer personal data outside the United Kingdom except to the sub-processors listed in Article 6, which are subject to appropriate transfer safeguards (UK IDTA or Standard Contractual Clauses as applicable).

Article 12 — Audits

We will make available all information reasonably necessary to demonstrate compliance with this DPA and will support audits conducted by you or a mandated auditor, subject to reasonable prior notice (at least 30 days), audits during normal business hours, no more than once per year unless there are reasonable grounds to suspect non-compliance, and you bearing the reasonable costs of any audit.

Article 13 — Governing Law

This DPA is governed by the laws of England and Wales. Any disputes are subject to the exclusive jurisdiction of the English courts.

EstatesAI Ltd · Data Processing Agreement v1.0 · Registered in England and Wales