CivilQuants — Customer Data Processing Addendum (DPA)
Effective date: On the Customer's countersignature (see §13)
Version: v1 (aligned with Terms of Service v1.2 + Privacy Policy v1.2)
Last updated: 2026-05-22
Preamble
This Data Processing Addendum (the "DPA") is entered into between:
(1) Customer: [Customer legal name], of [Customer registered office address] (the "Customer" or "Controller"); and
(2) Processor: Ember Forge Pte Ltd, a private limited company incorporated in Singapore (UEN 202617538C), with its registered office at 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051 (the "Company", "we", "Processor", or "CivilQuants"),
(each a "Party", together the "Parties").
This DPA supplements and forms part of the CivilQuants Terms of Service ("ToS", available at civilquants.com/legal/terms) and the CivilQuants Privacy Policy ("Privacy Policy", available at civilquants.com/legal/privacy-policy) agreed between the Parties (together, the "Principal Agreement"). This DPA applies in addition to, and where required by data-protection law in priority to, the Principal Agreement, in respect of Personal Data that Customer uploads to or otherwise causes to be processed by the Service where that Personal Data relates to third parties (e.g., the Customer's employees, contractors, clients, or project participants identifiable in project files).
By countersigning this DPA, Customer authorises Ember Forge Pte Ltd to process Personal Data as a processor / service provider on Customer's documented instructions, including the specific anonymisation instruction set out in §5.
Ember Forge Pte Ltd's appointed Data Protection Representatives. Because Ember Forge Pte Ltd is established outside the European Union and the United Kingdom, it has appointed Data Protection Representatives in both regions under Article 27 of the UK GDPR and Article 27 of the EU GDPR. Customer and Customer's affected data subjects may contact the relevant Representative in their region as an alternative to contacting Ember Forge Pte Ltd's DPO in Singapore:
- EU Representative: Data Protection Representative Limited (trading as DataRep), The Cube, Monahan Road, Cork T12 H1XY, Ireland — datarequest@datarep.com with "CivilQuants" in the subject line (or web form at www.datarep.com/data-request). DataRep maintains additional contact addresses across all 27 EU/EEA member states; see DataRep's contact-locations document or contact via the email/web form above for local-country addresses.
- UK Representative: Data Protection Representative Limited (trading as DataRep), 107-111 Fleet Street, London EC4A 2AB, United Kingdom — datarequest@datarep.com with "CivilQuants" in the subject line (or web form at www.datarep.com/data-request).
1. Definitions
In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given in the Principal Agreement.
- "Applicable Data Protection Law" means, in respect of any given processing of Personal Data, all laws and regulations applicable to that processing, including (without limitation): the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018; the EU General Data Protection Regulation (Regulation 2016/679, EU GDPR) and EU member-state implementing laws; the EU ePrivacy Directive 2002/58/EC (as amended) and member-state implementing laws (including UK PECR); the Singapore Personal Data Protection Act 2012 (PDPA); the Australian Privacy Act 1988 (incorporating the Australian Privacy Principles); the New Zealand Privacy Act 2020; the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial equivalents (including Quebec Loi 25); and the Malaysian Personal Data Protection Act 2010.
- "Controller", "Processor", "Sub-Processor", "Personal Data", "Data Subject", "Process" / "Processing", "Personal Data Breach", and "Supervisory Authority" each have the meanings given in the UK GDPR / EU GDPR (or equivalent terms under other Applicable Data Protection Law in the relevant jurisdiction).
- "Customer Data" means Personal Data that Customer uploads to or otherwise causes to be processed by the Service in connection with Customer's use of the Service under the Principal Agreement, where that Personal Data relates to third parties (e.g., Customer's employees, contractors, clients, project participants identifiable in project files).
- "Service" has the meaning given in the ToS (the CivilQuants quantity take-off and parametric estimating service, including its REST API, MCP server, Python client SDK, and CLI).
- "Standard Contractual Clauses" or "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914 of 4 June 2021, as may be amended or replaced from time to time.
- "UK Addendum" means the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018, version B1.0 in force on 21 March 2022 (or any subsequent superseding version).
- "UK IDTA" means the UK International Data Transfer Agreement issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018.
2. Scope and application
2.1 When this DPA applies
This DPA applies to the extent that Customer Data is Processed by Ember Forge Pte Ltd as a Processor / service provider in connection with Customer's use of the Service. Where Customer's use of the Service does not involve Personal Data about third parties (for example, where Customer's project inputs are purely numerical geometry and material specifications with no personal identifiers), this DPA has no operational effect, but it remains executed so that the safeguards apply as and when Customer Data becomes part of any subsequent Processing.
2.2 Relationship to the Principal Agreement
In the event of any conflict between this DPA and the Principal Agreement in respect of any matter governed by Applicable Data Protection Law, this DPA prevails to the extent of the conflict and only in respect of that matter. The remainder of the Principal Agreement (commercial terms, intellectual property, warranty disclaimer, limitation of liability, dispute resolution) continues to apply unmodified, subject only to §12 below.
2.3 Capacity of the Parties
For the purposes of this DPA and in respect of Customer Data:
- Customer is the Controller and determines the purposes and means of Processing of Customer Data.
- Ember Forge Pte Ltd is the Processor acting on Customer's documented instructions in accordance with this DPA, the Principal Agreement, and any written instructions Customer issues to
dpo@emberforge.sg.
For the avoidance of doubt, this DPA does not change Ember Forge Pte Ltd's role as Controller for Personal Data processed in its own right under the Privacy Policy (including account data, billing data, security and access audit logs, the computational audit log of paid renders, marketing communications, and aggregate analytics derived from Ember Forge Pte Ltd's own use of the Service).
3. Customer's role, instructions, and warranties
3.1 Documented instructions
Customer instructs Ember Forge Pte Ltd to Process Customer Data in accordance with:
- (a) the Principal Agreement (Terms of Service + Privacy Policy);
- (b) this DPA, including the specific anonymisation instruction set out in §5;
- (c) any written instructions Customer subsequently issues to
dpo@emberforge.sg, provided those instructions are consistent with Applicable Data Protection Law and the technical and contractual scope of the Service.
These together constitute Customer's "documented instructions" for the purposes of Article 28(3)(a) of the UK / EU GDPR (and equivalent provisions under other Applicable Data Protection Law).
3.2 Customer's lawful basis warranty
Customer warrants that, in respect of all Customer Data it uploads to or causes to be Processed by the Service:
- (a) Customer has a valid lawful basis under Applicable Data Protection Law for processing the Personal Data and for instructing Ember Forge Pte Ltd to Process it on Customer's behalf;
- (b) Customer has provided all required transparency notices to the relevant Data Subjects;
- (c) Customer has obtained all required consents (where consent is the lawful basis) and has not been notified that any Data Subject has objected, withdrawn consent, or exercised any other right that would render the Processing unlawful;
- (d) where the Personal Data includes special categories of personal data (UK / EU GDPR Article 9) or criminal-offence data (Article 10), Customer has identified a valid Article 9 / Article 10 condition and has satisfied any applicable additional requirements under Applicable Data Protection Law;
- (e) where Applicable Data Protection Law requires the Customer to have conducted a Data Protection Impact Assessment (DPIA) before Processing, Customer has done so and has identified appropriate safeguards.
3.3 No instructions inconsistent with this DPA or Applicable Data Protection Law
If Customer issues an instruction to Ember Forge Pte Ltd which Ember Forge Pte Ltd reasonably believes is inconsistent with Applicable Data Protection Law, Ember Forge Pte Ltd will notify Customer in writing without undue delay and may suspend Processing of the instruction pending resolution.
4. Ember Forge Pte Ltd's obligations as Processor
In respect of Customer Data, and consistent with Article 28(3) of the UK / EU GDPR (and equivalent provisions under other Applicable Data Protection Law), Ember Forge Pte Ltd will:
4.1 Process only on documented instructions (Art 28(3)(a))
Process Customer Data only on Customer's documented instructions (per §3.1), including with regard to transfers of Customer Data to a third country or to an international organisation, unless required to do so by law to which Ember Forge Pte Ltd is subject (in which case Ember Forge Pte Ltd will inform Customer of that legal requirement before Processing, unless that law prohibits such notification on important grounds of public interest).
4.2 Confidentiality of personnel (Art 28(3)(b))
Ensure that persons authorised to Process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Current production-systems access is restricted to a named individual (Dave Irvine in his capacity as Director + DPO) and any future engineering function, each subject to written confidentiality obligations and the access-control measures set out in Annex 2.
4.3 Security measures (Art 28(3)(c))
Implement the technical and organisational measures set out in Annex 2 (Technical and Organisational Measures) to ensure a level of security appropriate to the risk, as required by Article 32 of the UK / EU GDPR (and equivalent provisions under other Applicable Data Protection Law). The measures in Annex 2 may evolve over time; where any change materially reduces the level of protection of Customer Data, Ember Forge Pte Ltd will notify Customer in advance.
4.4 Sub-Processors (Art 28(3)(d))
Engage Sub-Processors only in accordance with §6 below.
4.5 Assistance with Data Subject requests (Art 28(3)(e))
Taking into account the nature of the Processing, assist Customer by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of Customer's obligation to respond to requests for exercising the Data Subject's rights under Applicable Data Protection Law (including the rights of access, rectification, erasure, restriction, portability, and objection). The specific operational mechanism is set out in §8 below.
4.6 Assistance with breach notification, DPIAs, and prior consultations (Art 28(3)(f))
Assist Customer in ensuring compliance with the obligations under Articles 32 to 36 of the UK / EU GDPR (security of processing, notification of Personal Data Breaches to Supervisory Authorities and Data Subjects, Data Protection Impact Assessments, prior consultations), taking into account the nature of Processing and the information available to Ember Forge Pte Ltd. The specific operational mechanism for breach notification is set out in §9 below.
4.7 Return or deletion on termination (Art 28(3)(g))
At the choice of Customer, delete or return all Customer Data to Customer at the end of the provision of services under the Principal Agreement, and delete existing copies unless Applicable Data Protection Law requires storage of the Personal Data. The specific operational mechanism is set out in §11 below, including the explicit interaction with Ember Forge Pte Ltd's legitimate-interest retention of the computational audit log under §11.3.
4.8 Audit cooperation (Art 28(3)(h))
Make available to Customer all information necessary to demonstrate compliance with the obligations set out in this §4 and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, in accordance with §10 below.
5. Specific Processing instruction — anonymisation of Customer Data into aggregate statistics
5.1 The instruction (Customer's documented Article 28(3)(a) instruction)
Customer instructs Ember Forge Pte Ltd to anonymise Customer Data, where Ember Forge Pte Ltd in its sole reasonable discretion considers it useful for the purpose of producing aggregate, statistical, and non-identifiable insights about how the Service is used (for example: "the average number of assemblies per project", "the most common drainage standard chosen across all Customers", "the distribution of project sizes among Studio-tier accounts"). Such anonymisation may be carried out at any time during the term of the Principal Agreement.
5.2 Anonymisation standard
The anonymisation Ember Forge Pte Ltd performs in reliance on this instruction will be irreversible, meaning the resulting aggregate data cannot reasonably be re-identified using any means reasonably likely to be used (including by reference to additional data) to identify the Data Subject directly or indirectly. Ember Forge Pte Ltd will perform anonymisation by reference to:
- (a) the UK Information Commissioner's Office (ICO) Anonymisation Code of Practice (as in force at the time of Processing);
- (b) the European Data Protection Board (EDPB) Opinion 05/2014 on Anonymisation Techniques (as endorsed by the EDPB and as may be updated from time to time);
- (c) the Singapore PDPC Guide to Basic Anonymisation (as in force at the time of Processing);
- (d) any further guidance from a Supervisory Authority that materially affects the standard for anonymisation under Applicable Data Protection Law.
5.3 Effect of anonymisation
Upon irreversible anonymisation, the resulting aggregate data is no longer Personal Data within the meaning of Applicable Data Protection Law, and Ember Forge Pte Ltd may use that aggregate data for its own product analytics, Service improvement, and public communication purposes without further restriction under this DPA.
5.4 Withdrawal of the instruction
Customer may withdraw this anonymisation instruction at any time, on written notice to dpo@emberforge.sg. Withdrawal takes effect prospectively: Ember Forge Pte Ltd will exclude Customer's Customer Data from any future aggregation runs from the effective date of the withdrawal, and will replace prior aggregate snapshots that included Customer's data at the next scheduled rebuild. Aggregate data already disseminated to third parties prior to the withdrawal cannot be recalled.
5.5 Why this clause exists
This §5 is the documented controller instruction required to allow Ember Forge Pte Ltd to perform the anonymisation step described in Privacy Policy §1.1 and §2.3 as a processor activity (under Article 28(3)(a) of the UK / EU GDPR) rather than as a unilateral act on its own legitimate-interest basis (which would risk recharacterising Ember Forge Pte Ltd as an independent controller in breach of Article 28). Customer's countersignature of this DPA constitutes the documented instruction.
6. Sub-Processors
6.1 General authorisation
Customer grants Ember Forge Pte Ltd general authorisation to engage the Sub-Processors listed in Annex 3 (Sub-Processors) for the Processing of Customer Data, in accordance with the regions, roles, and transfer mechanisms set out there.
6.2 Change notice
Where Ember Forge Pte Ltd intends to:
- (a) add a new Sub-Processor to Annex 3, or
- (b) change the region of Processing or role of an existing Sub-Processor in a manner that materially affects the protection of Customer Data,
Ember Forge Pte Ltd will provide Customer with at least 30 days' prior written notice by email to Customer's account-administrator address. The notice will identify the proposed change, the Sub-Processor concerned, the categories of Customer Data affected, and the applicable transfer mechanism.
6.3 Right to object
Customer may object to the proposed change on reasonable data-protection grounds within 14 days of receipt of the notice, by email to dpo@emberforge.sg. The Parties will use good-faith efforts to resolve the objection. If the Parties cannot resolve the objection within a reasonable time, Customer may terminate the Principal Agreement (so far as it relates to the affected Service component) with effect from the proposed change date and receive a pro-rata refund of pre-paid fees for the period after termination.
6.4 Sub-Processor obligations
Ember Forge Pte Ltd will enter into a written contract with each Sub-Processor imposing data-protection obligations substantially equivalent to those in this DPA, including (without limitation) Sub-Processor's obligations to (i) Process Customer Data only on Customer's documented instructions (as transmitted through Ember Forge Pte Ltd), (ii) implement appropriate technical and organisational measures, (iii) comply with international-transfer requirements, and (iv) assist with Data Subject rights and Personal Data Breach notification.
6.5 Ember Forge Pte Ltd's liability for Sub-Processors
Ember Forge Pte Ltd remains liable to Customer for the performance of each Sub-Processor's data-protection obligations as if they were Ember Forge Pte Ltd's own, except where the failure is caused by Customer's own breach or where the limitation provisions of §12 apply.
7. International transfers
7.1 Where Customer is in the UK / EU and Ember Forge Pte Ltd Processes Customer Data in Singapore
Where Customer Data is Personal Data of UK or EU Data Subjects and is transferred from Customer (or Customer's data sources) in the UK or EU to Ember Forge Pte Ltd in Singapore for Processing under this DPA, the Parties incorporate by reference:
- (a) the EU Standard Contractual Clauses Module 2 (Controller-to-Processor) for EU-Data-Subject Personal Data, with the docking clause activated and the following selections made in respect of the optional provisions and Annexes:
- Clause 7 (docking) — Optional clause enabled.
- Clause 9 (use of sub-processors) — Option 2 (general written authorisation) per §6 above; 30 days' prior notice.
- Clause 11(a) (redress) — Optional independent dispute resolution clause not selected.
- Clause 17 (governing law) — Law of the Republic of Ireland.
- Clause 18 (choice of forum and jurisdiction) — Courts of Ireland.
- Annex I.A (parties) — As set out in the Preamble above.
- Annex I.B (description of transfer) — As set out in Annex 1 below.
- Annex I.C (competent Supervisory Authority) — The Supervisory Authority of the Member State in which the EU-based exporter is established (typically the Irish Data Protection Commission where Ireland is the applicable forum under Clause 18, or as otherwise determined under Clause 13).
- Annex II (technical and organisational measures) — As set out in Annex 2 below.
- Annex III (list of sub-processors) — As set out in Annex 3 below.
- (b) the UK Addendum for UK-Data-Subject Personal Data, with Tables 1, 2, 3, and 4 of the UK Addendum populated by reference to this DPA and the EU SCCs as incorporated above, with the following Table 4 selection: neither Party may end the UK Addendum as set out in section 19 of the UK Addendum.
The text of the EU SCCs (as published by the European Commission in Decision 2021/914) and the UK Addendum (as published by the UK ICO) are incorporated into this DPA in full, by reference. Where this DPA is silent on a matter governed by the EU SCCs or the UK Addendum, those instruments prevail.
7.2 Onward transfers to Sub-Processors outside the UK / EU
Where Ember Forge Pte Ltd's Sub-Processors Process Customer Data in jurisdictions outside the UK or EU, Ember Forge Pte Ltd ensures appropriate safeguards for those onward transfers, including (as applicable):
- (a) Sub-Processor adequacy under UK or EU adequacy decisions;
- (b) The Sub-Processor's own SCC-based contractual framework or the UK IDTA / UK Addendum, where the Sub-Processor accepts SCC obligations;
- (c) Supplementary measures (encryption in transit and at rest, access controls, transfer impact assessments) as appropriate;
as further described in Annex 3 in the "Transfer mechanism" column.
7.3 Singapore PDPA transfer obligations
Where Customer is in Singapore and the transfer to Ember Forge Pte Ltd is governed by Singapore PDPA, Ember Forge Pte Ltd's status as a Singapore-incorporated entity means PDPA Section 26 (transfer limitation) does not require additional safeguards for the transfer from Customer to Ember Forge Pte Ltd itself; PDPA Section 26 applies to Ember Forge Pte Ltd's onward transfers to Sub-Processors outside Singapore, which Ember Forge Pte Ltd governs under (a)–(c) above.
7.4 Country-specific notes
The country-specific transfer provisions set out in Privacy Policy §5.4 (Australia APP 8, New Zealand IPP 12, Canada PIPEDA Accountability principle, Malaysia PDPA Section 129) apply to Customer Data transferred under this DPA in the corresponding circumstances.
8. Data Subject rights
8.1 Customer's primary responsibility
As Controller, Customer is primarily responsible for responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law.
8.2 Ember Forge Pte Ltd's assistance
Where a Data Subject contacts Ember Forge Pte Ltd directly to exercise a right in respect of Customer Data, Ember Forge Pte Ltd will:
- (a) within a reasonable time, refer the Data Subject to Customer as the appropriate contact for that request;
- (b) without undue delay, notify Customer of the request, including the identity of the Data Subject (to the extent provided by them), the nature of the request, and the date received;
- (c) not respond to the request itself, except (i) to confirm receipt and refer the Data Subject to Customer, or (ii) where Ember Forge Pte Ltd is legally required to respond directly (in which case Ember Forge Pte Ltd will notify Customer in advance unless legally prohibited).
8.3 Technical assistance
Taking into account the nature of the Processing, Ember Forge Pte Ltd will assist Customer with appropriate technical and organisational measures in responding to Data Subject requests, including (where reasonably practicable):
- (a) providing Customer with the technical means to retrieve, export, rectify, or delete specific Personal Data within Customer Data;
- (b) providing copies of Customer Data in a structured, commonly used, machine-readable format;
- (c) confirming the retention status of specific Personal Data within Customer Data.
8.4 Customer's costs
Ember Forge Pte Ltd's assistance under this §8 is provided at no additional cost where it can reasonably be delivered through the Service's standard interfaces. Where assistance requires Ember Forge Pte Ltd to perform manual, non-standard, or repeated operations, Ember Forge Pte Ltd may charge Customer a reasonable fee, notified to Customer in advance, based on Ember Forge Pte Ltd's reasonable costs.
8.5 EU and UK Data Subjects — alternative Representative contact channel
Where a Data Subject within the scope of Customer Data is located in the European Union / EEA or the United Kingdom, that Data Subject (or Customer on their behalf) may contact Ember Forge Pte Ltd's appointed Data Protection Representative in the relevant region as an alternative to contacting Ember Forge Pte Ltd's DPO in Singapore. Contact details for the EU and UK Representatives are set out in the Preamble to this DPA above. The Representative will route the request to Ember Forge Pte Ltd's DPO and ensure that statutory response timelines are met.
9. Personal Data Breach notification
9.1 Notification by Ember Forge Pte Ltd
Ember Forge Pte Ltd will notify Customer without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Data. (This notification window is shorter than the statutory 72-hour Supervisory-Authority notification window applicable to Customer as Controller, in order to leave Customer reasonable time to meet its own notification obligations.)
9.2 Notification contents
The notification will include, to the extent then known and consistent with the level of detail reasonably available at the time:
- (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
- (b) the name and contact details of Ember Forge Pte Ltd's Data Protection Officer (
dpo@emberforge.sg); - (c) the likely consequences of the Personal Data Breach;
- (d) the measures taken or proposed by Ember Forge Pte Ltd to address the Personal Data Breach, including measures to mitigate its possible adverse effects.
Where it is not possible to provide all of the above at the time of initial notification, Ember Forge Pte Ltd will provide the available information at notification and supplement it as further information becomes available, without undue further delay.
9.3 Assistance with Customer's notification obligations
Ember Forge Pte Ltd will assist Customer with Customer's notification obligations to its Supervisory Authority under Article 33 of the UK / EU GDPR and, where applicable, communication of the Personal Data Breach to affected Data Subjects under Article 34, including by providing such further information and cooperation as is reasonable in the circumstances.
9.4 No admission of liability
Notification of a Personal Data Breach by Ember Forge Pte Ltd does not constitute an admission of fault or liability by Ember Forge Pte Ltd or any Sub-Processor.
10. Audit rights
10.1 Information rights
Ember Forge Pte Ltd will, on reasonable written request, make available to Customer:
- (a) a current copy of this DPA and the security exhibit (Annex 2);
- (b) the current Sub-Processor list (Annex 3);
- (c) any third-party audit or certification reports Ember Forge Pte Ltd has obtained (for example, SOC 2 Type II, ISO 27001) — if and when such reports are produced.
10.2 On-site audit
Customer is entitled to conduct, or to mandate an independent third-party auditor (subject to reasonable confidentiality obligations) to conduct, an audit of Ember Forge Pte Ltd's compliance with this DPA, on the following conditions:
- (a) Notice: not less than 30 days' prior written notice, except in the case of an audit triggered by a Personal Data Breach affecting Customer Data, in which case 5 business days' notice is sufficient;
- (b) Frequency: not more than once per 12-month period, except in the case of an audit triggered by a Personal Data Breach;
- (c) Scope: limited to the scope reasonably necessary to verify compliance with this DPA and Applicable Data Protection Law in respect of Customer Data;
- (d) Conduct: during normal business hours; without disrupting Ember Forge Pte Ltd's ordinary operations or the privacy or security of other customers; subject to reasonable security and confidentiality controls; auditor not a competitor of Ember Forge Pte Ltd;
- (e) Cost: at Customer's cost, unless the audit reveals a material breach of this DPA by Ember Forge Pte Ltd, in which case Ember Forge Pte Ltd will bear its own costs and reimburse Customer's reasonable audit costs.
10.3 Audit reports — option to satisfy
Where Ember Forge Pte Ltd has obtained a third-party audit or certification report (for example, SOC 2 Type II or ISO 27001) covering the scope of Customer's intended audit, Ember Forge Pte Ltd may satisfy Customer's audit right by providing that report instead of permitting an on-site audit, provided that the report is sufficiently current (issued within the preceding 12 months) and substantively addresses Customer's reasonable audit concerns.
11. Return and deletion
11.1 On termination
On termination of the Principal Agreement (for any reason), Ember Forge Pte Ltd will, at Customer's written choice notified to dpo@emberforge.sg within 30 days of termination:
- (a) delete all Customer Data Processed under this DPA, including from operational systems and from backups (subject to §11.2), and confirm such deletion in writing; or
- (b) return all Customer Data to Customer in a commercially reasonable structured format, and then delete in accordance with (a).
If Customer does not notify Ember Forge Pte Ltd of a choice within 30 days of termination, Ember Forge Pte Ltd will default to deletion under (a) and confirm in writing.
11.2 Backups
Customer Data held in routine system backups will be deleted in accordance with Ember Forge Pte Ltd's standard backup-rotation schedule, which is currently a maximum retention of 30 days for incremental backups and 90 days for full backups (with backups encrypted at rest per Annex 2). During the backup-retention window, Customer Data in backups will not be Processed for any purpose other than disaster-recovery integrity.
11.3 Legal-retention exceptions
The deletion and return obligations under §11.1 do not apply to the extent that Ember Forge Pte Ltd is required to retain Customer Data, or specific elements of Customer Data, under Applicable Data Protection Law or other applicable law. Specifically:
- (a) Tax and accounting records are retained for 7 years from the relevant tax year, per HMRC / IRAS / EU member-state requirements (Privacy Policy §6);
- (b) The Computational Audit Log of paid renders is retained for 7 years from render date, on the basis of legitimate interest in the establishment, exercise, or defence of legal claims (UK / EU GDPR Article 6(1)(f) and the retention exemption from the right of erasure under Article 17(3)(e); equivalent provisions in PDPA, PIPEDA, APP, Privacy Act 2020, PDPA Malaysia). The Computational Audit Log records the parameters submitted, output hash, engine version, software version, warranty-policy version in force, warranty-acknowledgment timestamp, account/API-token identity, and render timestamp for each paid render (see ToS §8.4 and Privacy Policy §6 and §8). On account erasure, identifying Personal Data is removed from the log within 90 days; the technical render record (parameters_used after scrubbing of identifying free-text fields, hash, engine_version, software_version, warranty_policy_version, render timestamp, surface, assembly_slug, standard_code) is retained for the full 7-year window in a form not linked to identifying Personal Data outside the period necessary to substantiate the legal-claims basis;
- (c) Security and access audit logs are retained for 24 months (Privacy Policy §6).
Customer Data subject to retention under (a)–(c) above will be Processed only for the corresponding retention purpose and will be subject to the technical and organisational measures in Annex 2 throughout the retention period. At the end of each retention period, Ember Forge Pte Ltd will delete the relevant Customer Data without further notice.
12. Liability
12.1 Interaction with the Principal Agreement
This DPA does not modify the limitation of liability provisions of the Principal Agreement (ToS §10 — Limitation of liability, including the §10.3 aggregate cap, the §10.4 Category A uncapped carve-outs and Category B super-cap, and the §10.5 risk-allocation provisions) except as required by Applicable Data Protection Law (including Article 82 of the UK / EU GDPR and equivalent provisions under other Applicable Data Protection Law).
12.2 Statutory liability
Where Applicable Data Protection Law confers on a Data Subject a right of compensation that cannot be excluded or limited by contract, that right applies notwithstanding the Principal Agreement and this DPA. As between the Parties, liability for damages arising from a Party's breach of Applicable Data Protection Law in respect of Customer Data is allocated in accordance with each Party's respective fault and responsibility for the breach, consistent with Article 82(4) of the UK / EU GDPR (where the EU GDPR applies).
12.3 Indemnification
Each Party will indemnify the other Party against losses, damages, costs (including reasonable legal fees), and Supervisory Authority fines arising from that Party's breach of its obligations under this DPA, subject to the limitations of liability in the Principal Agreement (subject to §12.1 and §12.2 above).
13. Term and termination
This DPA takes effect on the date Customer countersigns it and continues for so long as Ember Forge Pte Ltd Processes Customer Data on Customer's behalf under the Principal Agreement. Termination of the Principal Agreement terminates this DPA, except that §10 (Audit rights — for a reasonable period not exceeding 2 years from termination), §11 (Return and deletion — until completion), and §12 (Liability — for the duration of any applicable statutory limitation period) survive termination.
14. Governing law and jurisdiction
This DPA is governed by the law and jurisdiction set out for the Principal Agreement (ToS §18 — Dispute resolution), namely:
- B2B (Business) Customers: the laws of Singapore, with disputes resolved by arbitration administered by the Singapore International Arbitration Centre (SIAC) in accordance with the SIAC Rules in force at the time of commencement of the arbitration (per ToS §18.1);
- Consumer Customers: the laws of the consumer's country of habitual residence and the courts of that country, in accordance with ToS §18.2.
Notwithstanding the above, where the EU SCCs are incorporated under §7.1(a), Clause 17 (governing law) and Clause 18 (jurisdiction) of the EU SCCs prevail over this §14 for matters within the scope of the EU SCCs (with governing law being the law of Ireland and jurisdiction being the courts of Ireland, per §7.1(a)).
15. Counterparts and execution
This DPA may be executed in counterparts (including by electronic signature, scanned PDF exchange, or DocuSign), each of which when so executed and delivered will be an original, and all counterparts together will constitute one and the same agreement. Delivery of an executed counterpart by email is sufficient to bind the executing Party.
ANNEX 1 — Description of Processing
| Item | Detail |
|---|---|
| Subject matter of Processing | Provision of the CivilQuants quantity take-off and parametric estimating Service to Customer (per the Principal Agreement). |
| Duration of Processing | The term of the Principal Agreement, plus any retention period set out in §11.3 of this DPA (notably 7 years for the Computational Audit Log and tax records, 24 months for security and access audit logs). |
| Nature and purpose of Processing | Hosting, storage, retrieval, transmission, analysis, anonymisation (per §5), and deletion of Customer Data for the purpose of (i) generating Bills of Quantities and related deliverables from Customer's project inputs, (ii) maintaining Customer's account and access controls, (iii) providing technical support, (iv) maintaining the Computational Audit Log for evidentiary purposes (per ToS §8.4 and Privacy Policy §6), and (v) producing aggregate Service-improvement statistics on Customer's documented instruction (per §5). |
| Types of Personal Data | (a) Identifiers of third parties incidentally present in Customer-uploaded project files (e.g., employee names in a project file, contractor names in a tender pack, names of project participants); (b) any other Personal Data Customer chooses to include in project inputs; (c) the metadata associated with Customer Data within the Service (file name, upload timestamp, account identifier). |
| Categories of Data Subjects | The natural persons identifiable in the Customer Data, typically: Customer's employees, contractors, sub-consultants, clients, project participants, and other third parties whom Customer chooses to identify in project files. |
| Special categories of Personal Data | Not normally Processed. If Customer Data includes special categories of personal data (UK / EU GDPR Article 9) or criminal-offence data (Article 10), Customer warrants per §3.2 that it has identified a valid Article 9 / Article 10 condition. |
| Frequency of transfer | Continuous, on-demand, for the duration of the Principal Agreement. |
| Location(s) of Processing | Primarily Singapore (Ember Forge Pte Ltd) + London (Fly.io LHR region for hosting infrastructure). Sub-Processor Processing locations per Annex 3. |
ANNEX 2 — Technical and Organisational Measures (TOMs)
Ember Forge Pte Ltd implements the following technical and organisational measures to ensure a level of security appropriate to the risk of the Processing under this DPA, consistent with Article 32 of the UK / EU GDPR.
1. Encryption
- Encryption in transit: TLS 1.3 for all data in transit between Customer (or Customer's data sources) and the Service, between the Service and its Sub-Processors, and between internal system components.
- Encryption at rest: AES-256-equivalent encryption at rest for the primary database (Fly Postgres) and object storage (Cloudflare R2). Encryption keys managed by the respective infrastructure providers; access to keys restricted to the same access-control regime as production-systems access.
2. Access controls
- Principle of least privilege: production-systems access restricted to a named individual (Dave Irvine in his capacity as Director + DPO) and any future engineering function added under written confidentiality obligations.
- Multi-factor authentication (MFA) required on all production-access accounts (Fly.io, Cloudflare, Stripe, Clerk admin, Sentry, PostHog admin, GitHub, AWS where applicable to Sub-Processor access).
- Role-based access control for the operator-side admin dashboard (when shipped per launch spec § 3.6).
- Session timeouts on production-admin sessions.
- Audit logging of significant production actions retained for 24 months (Privacy Policy §6).
3. Network and infrastructure security
- Cloudflare as the perimeter network — DDoS protection, Web Application Firewall (WAF), rate limiting at the edge, country-level egress controls where appropriate.
- Fly.io as the application and database host — single-tenant container isolation; private networking between application and database; no public Postgres exposure.
- R2 (Cloudflare object storage) signed-URL access for artefact retrieval; no public-read buckets for Customer Data.
- Regular dependency scanning for known vulnerabilities (CI pipeline + Renovate/Dependabot).
4. Software development and operational security
- Secure development: code review by a second party (or a second LLM reviewer in cross-vendor adversarial mode) on all changes to security-sensitive code paths (authentication, payment, data persistence, Personal Data handling, MCP serving).
- Pre-commit security review: security-reviewer agent + cross-vendor adversarial pass (currently Codex for adversarial review) on every high-risk merge.
- CI gates: static analysis (ruff, mypy --strict, tsc), test coverage, OPSEC regression tests preventing leakage of identifying substrings.
- No secrets in source control: all secrets via environment variables or secrets-store; rotation on any exposure event.
5. Backups and recovery
- Encrypted backups rotated per the schedule set out in §11.2 of this DPA.
- Backup integrity testing at reasonable intervals.
- Disaster recovery posture: target RPO (recovery point objective) ≤ 24 hours for Customer Data Processed in the preceding 7 days.
6. Personnel measures
- Confidentiality obligations in writing for all personnel with access to Customer Data.
- Need-to-know access for engineering staff.
- Security awareness training for any future personnel addition.
- Off-boarding revokes access within 24 hours of role end.
7. Sub-Processor management
- Written DPA in place with each Sub-Processor before Customer Data is shared.
- Periodic review of Sub-Processor security posture (annual, or upon material change in Sub-Processor status).
- Right to terminate Sub-Processor engagement on material data-protection failure.
8. Incident response
- Incident response playbook with notification timelines that meet UK GDPR (≤72 hours to ICO + affected individuals where likely high-risk), EU GDPR (≤72 hours to lead Supervisory Authority), and PDPA (≤72 hours to PDPC for "notifiable" breaches).
- Customer notification within 48 hours of Ember Forge Pte Ltd becoming aware of a Personal Data Breach affecting Customer Data, per §9.1 of this DPA.
- Post-incident review to identify and remediate root cause.
9. Physical security
- No physical premises under Ember Forge Pte Ltd's control hosting Customer Data; all hosting via Sub-Processors with their own physical security controls (Fly.io data centres, Cloudflare edge network, US/EU/SG cloud provider facilities). Sub-Processors' physical security is verified by their published certifications (SOC 2, ISO 27001 where applicable).
10. Continual improvement
- These measures are reviewed at least annually and updated to reflect (i) changes in the threat landscape, (ii) changes in Applicable Data Protection Law or Supervisory Authority guidance, and (iii) Sub-Processor capability changes. Where any change materially reduces the level of protection of Customer Data, Ember Forge Pte Ltd will notify Customer in advance per §4.3 of this DPA.
ANNEX 3 — Sub-Processors
Current list of Sub-Processors authorised under §6.1 of this DPA. Updated per the change-notice mechanism in §6.2.
| Sub-Processor | Role | Categories of Customer Data Processed | Region of Processing | Transfer mechanism (for UK / EU Customer Data) | DPA signing date |
|---|---|---|---|---|---|
| Stripe Payments Europe / Stripe Inc. | Payment processing, billing data, tax calculation, fraud screening | Customer billing information (not normally containing third-party Personal Data; Customer Data per this DPA is not normally shared with Stripe) | Global (Stripe has UK/EU/SG entities) | Stripe's own SCC framework + adequacy where available | Pending — to be confirmed |
| Resend | Sending transactional and (with consent) marketing email | Customer's account email address and recipient email addresses; Customer Data not normally Processed by Resend | US (EU region pending GA) | UK ICO IDTA + EU SCCs + supplementary measures | Pending — to be confirmed |
| Clerk | Authentication (account email, password hash, auth session, MFA factors) | Customer authentication data only; Customer Data not Processed by Clerk | US | UK ICO IDTA + EU SCCs + supplementary measures | Pending — to be confirmed |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, R2 object storage, edge logs | All Customer Data may transit Cloudflare's edge network; R2 stores artefacts derived from Customer Data | Global edge network; R2 storage region TBD per deployment | UK ICO IDTA + EU SCCs (for any data egress to US backbones) | Pending — to be confirmed |
| Sentry | Error monitoring (error events, stack traces, hashed user identifier) | Error context that may incidentally include identifiers; Customer Data redacted from error payloads per Annex 2 §4 secure-development controls | EU region (configured + verified at deployment per Privacy §4) | None required for EU-to-EU; SCC fallback if any Sub-Processor of Sentry is outside EU | Pending — to be confirmed |
| PostHog | Product analytics (usage events, page views, session metadata, IP, anonymised user identifier) — consent-gated | Usage event metadata; Customer Data not Processed by PostHog | EU region (configured + verified at deployment per Privacy §4) | None required for EU-to-UK and EU-to-EU; SCC fallback if any Sub-Processor of PostHog is outside EU | Pending — to be confirmed |
| Fly.io | Hosting infrastructure (application servers + Postgres database) | All Customer Data Processed by the application is hosted on Fly.io infrastructure | London (LHR) region for v1 | None required for LHR-to-UK and LHR-to-EU; SCC fallback if Fly's US control-plane Processes any Customer Data | Pending — to be confirmed |
Signature block
For Ember Forge Pte Ltd:
Signed: ___________________________
Name: Dave Irvine
Title: Director and Data Protection Officer
Date: ___________________________
For Customer:
Signed: ___________________________
Name: [Customer signatory name]
Title: [Customer signatory title]
Date: ___________________________
Email of signatory (for service of notices under this DPA): [Customer signatory email]