cbcivil.buildersA5DOpen A5D

LEGAL · VERSION 2026.07.23-r2

Data Processing Addendum

1. Application and roles

This DPA forms part of the Terms or Order when A5D processes Customer Personal Data for an organisation. Customer is controller or business; A5D is processor or service provider for documented instructions needed to provide, secure, support and lawfully operate the Service.

2. Processing

Processing covers hosted project controls, collaboration, validation, export, optional AI, support and security for the subscription plus export/deletion periods. Data may include identities, roles, activity records, project content, comments, AI prompts/responses and support material. Sensitive data is not authorised without a separate written agreement.

3. Confidentiality, security and subprocessors

A5D limits access to personnel under confidentiality and maintains the Security and Retention controls. Customer generally authorises the current Subprocessor List. Where practicable, material new processors receive 30 days' notice and reasonable data-protection objections are addressed.

4. Assistance and breach

A5D reasonably assists with data-subject requests, security assessments, legally required breach duties and regulator enquiries. A5D notifies Customer without undue delay after confirming a notifiable breach, with available nature, impact and mitigation information.

5. Return, deletion and transfers

Supported exports remain available during the term. Closure makes the workspace read-only for export; verified deletion requests are processed through the application and support workflow, and provider recovery backups currently expire after seven days, subject to law and documented holds. EEA/UK regulated transfers are not activated by this DPA; required clauses, representative and counsel-reviewed details must be completed first.

6. Audit, US terms and precedence

A5D provides reasonable annual documentary compliance information; constrained on-site audit is available only when legally required and documents are insufficient. Applicable US processor restrictions apply. This DPA prevails for Customer Personal Data; the Terms' liability terms otherwise apply.