Data Processing Agreement (DPA)

Effective from 1 August 2026 (version 1.0)

This Data Processing Agreement ("DPA") forms an integral part of the Construction Team Terms of Use (the "Terms"). It governs the processing of personal data by Two Men Code EOOD, UIC 208910446 (the "Provider"), on behalf of the Customer in the provision of the Service, in accordance with Art. 28 of Regulation (EU) 2016/679 ("GDPR"). Capitalised terms not defined here have the meaning given to them in the Terms.

1. Acceptance and Scope

  • This DPA is concluded in electronic form and accepted by the Customer together with the Terms - upon registration, upon ticking the consent to the Terms, or through continued use of the Platform. The electronic form satisfies the requirement of Art. 28(9) GDPR.
  • This DPA applies to the extent the Provider processes personal data contained in the Customer Data on behalf of the Customer (the "Personal Data").
  • This DPA does not apply to data the Provider processes as an independent controller - account registration and management data, billing and payments, Platform security, communication with the Customer and website statistics. These are described in the Privacy Policy.
  • Where the Customer is a natural person using the Platform for purely personal or household purposes, GDPR may not apply (Art. 2(2)(c) GDPR). In that case this DPA applies to the extent applicable.
  • In case of conflict between this DPA and the Terms on matters of personal data protection, this DPA prevails.

2. Roles and Responsibilities of the Parties

  • The Customer is the controller and the Provider is the processor of the Personal Data. Where the Customer processes personal data on behalf of a third party, the Customer warrants that it has obtained the authorisation of the relevant controller, and the Provider acts as a sub-processor.
  • The Customer is responsible for the lawfulness of the processing: the existence of a legal basis, informing data subjects, the accuracy of the data and the lawfulness of the instructions it gives.
  • The Customer warrants that its instructions and the Personal Data it provides do not infringe applicable law or the rights of third parties.

3. Customer Instructions

  • The Provider processes the Personal Data only on documented instructions from the Customer, including with regard to transfers of data to third countries, unless required to process them by Union or Member State law. In that case the Provider informs the Customer unless the law prohibits it.
  • The Customer's documented instructions are: the Terms, this DPA, the use and settings of the Platform by the Customer and its Users, and any additional written instructions agreed by both parties.
  • The Customer instructs that the Personal Data be processed for the provision, maintenance, security, troubleshooting, testing and improvement of the Service, including by creating derived data (for example, vector embeddings for search), to the extent necessary for these purposes and subject to the confidentiality and security of the data.
  • The Provider immediately informs the Customer if, in its opinion, an instruction infringes GDPR or other applicable data protection law. The Provider is not required to perform a legal review of the Customer's instructions.
  • Instructions beyond the scope of the Service are carried out only if the Provider agrees to them and may be charged separately.

4. Confidentiality

  • The Provider ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Access to the Personal Data is granted only to persons who need it to perform their duties.

5. Security of Processing

  • The Provider implements technical and organisational measures in accordance with Art. 32 GDPR, described in Annex 2, taking into account the state of the art, the costs, the nature, scope, context and purposes of the processing and the risks to the rights of data subjects.
  • The Provider may update the measures, provided that the overall level of protection is not reduced.
  • The Customer is responsible for security within its own sphere, including protecting passwords, correctly assigning User permissions, protecting its devices and promptly revoking access for persons who should no longer have it.

6. Sub-processors

  • The Customer gives the Provider general written authorisation to engage the sub-processors listed in Annex 3, as well as new sub-processors under the conditions of this section.
  • The Provider notifies the Customer of any intended addition or replacement of a sub-processor at least 14 days in advance, by updating Annex 3 and notifying the Account Administrator by email or via an in-Platform notification.
  • Within that period, the Customer may object in writing on reasonable grounds relating to data protection. The parties discuss the objection in good faith. If no solution is reached, the Customer's sole right is to terminate the agreement by written notice before the change takes effect. Termination is governed by Section 15 of the Terms and does not give rise to a refund of amounts paid.
  • Where a replacement is required because a sub-processor discontinues its service, because of a security incident or another urgent reason, the Provider may carry it out without prior notice and informs the Customer as soon as possible.
  • The Provider imposes on each sub-processor data protection obligations that are substantially equivalent to those under this DPA and remains liable to the Customer for their performance in accordance with Art. 28(4) GDPR, subject to the limitations in Section 13 of the Terms.
  • Where the Customer uses its own keys or accounts for third-party services (for example, Google Cloud or OpenAI) or connects the Platform to its bank, those third parties process the data under their agreement with the Customer and are not sub-processors of the Provider.

7. Transfers Outside the EEA

  • The Provider transfers Personal Data outside the European Economic Area only in compliance with Chapter V GDPR - on the basis of a European Commission adequacy decision (including the EU-US Data Privacy Framework for certified recipients), standard contractual clauses adopted by the European Commission, or another appropriate safeguard.
  • By accepting this DPA, the Customer instructs and authorises the transfers listed in Annex 3.

8. Data Subject Rights

  • The Platform provides functions that allow the Customer to handle data subject requests itself, including requests for access, rectification, erasure and export of data.
  • If the Provider receives a request directly from a data subject, it forwards the request to the Customer or refers the data subject to the Customer and does not respond on the merits, unless authorised by the Customer or required by law.
  • Taking into account the nature of the processing, the Provider provides reasonable assistance to the Customer in responding to such requests. Assistance beyond the available functions of the Platform may be charged at reasonable cost.

9. Personal Data Breaches

  • The Provider notifies the Customer without undue delay after becoming aware of a security breach affecting the Personal Data.
  • The notification contains the information available at the time under Art. 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The information may be provided in phases.
  • The Provider takes reasonable measures to mitigate the consequences of the breach.
  • Notifying the supervisory authority and data subjects is the obligation of the Customer as controller. The Provider provides reasonable assistance with the information available to it.
  • The Provider's notification or assistance does not constitute an acknowledgement of fault or liability.

10. Assistance with Impact Assessments

Taking into account the nature of the processing and the information available to it, the Provider provides reasonable assistance to the Customer with data protection impact assessments and prior consultation of the supervisory authority (Art. 35 and 36 GDPR), primarily by providing documentation about the Service. Assistance beyond the available documentation may be charged at reasonable cost.

11. Return and Deletion of Data

  • During the agreement, the Customer may export the Personal Data using the available export functions. This is the means of returning the data under Art. 28(3)(g) GDPR.
  • After termination of the agreement, the Customer has 30 days to export the data in accordance with Section 15.5 of the Terms. After that period, the Provider deletes the Personal Data from its active systems within a reasonable time.
  • Copies in backups and in maintenance and testing environments are deleted or overwritten in the course of their normal refresh cycle. Until then they remain protected under this DPA and are not actively processed.
  • The deletion obligation does not apply to data the Provider is required to retain under Union or Member State law.

12. Information and Audits

  • Upon reasonable written request, the Provider makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR, including this DPA, the description of measures in Annex 2, the list of sub-processors and the available certifications or audit reports of the sub-processors.
  • If that information is insufficient or an audit is required by a supervisory authority, the Customer may carry out an audit itself or through an independent auditor bound by confidentiality, under the following conditions: written request at least 30 days in advance; no more than once every 12 months, except in case of a security breach or at the request of a supervisory authority; during business hours and without disrupting the Provider's operations; without access to other customers' data or to the source code; in compliance with the Provider's security rules.
  • The costs of the audit are borne by the Customer, including reasonable compensation for the time spent by the Provider.
  • Audits of sub-processors are carried out by providing their certifications, audit reports or other documentation.

13. Liability

  • The parties' liability under this DPA is governed by Section 13 of the Terms, unless mandatory law provides otherwise. This DPA does not limit the rights of data subjects under Art. 82 GDPR.
  • The Customer indemnifies the Provider against damages, penalties and costs arising from the Customer's instructions or from Personal Data it provides in breach of applicable law, including where there is no legal basis for the processing.

14. Term and Final Provisions

  • This DPA remains in force for the term of the Terms and for as long as the Provider processes Personal Data on behalf of the Customer.
  • The Provider may amend this DPA in accordance with Section 20 of the Terms. Amendments required by changes in legislation or by guidance of a supervisory authority may take effect upon publication.
  • This DPA is governed by Bulgarian law. Disputes are resolved in accordance with Section 19 of the Terms.

Annex 1. Description of the Processing

  • Subject matter: processing of Personal Data in the provision of the Service - a cloud platform for managing construction projects.
  • Duration: for the term of the agreement and until deletion of the data in accordance with Section 11.
  • Nature and purposes: storage and hosting; organising, structuring, searching and displaying; calculations and document generation; AI processing (text recognition, data extraction, matching and vector embeddings for search); sending notifications and documents by email at the Users' initiative; maintenance, security, troubleshooting, testing and improvement of the Service.
  • Categories of data subjects: the Customer's Users (employees and representatives); the Customer's counterparties and their representatives and contact persons (clients, suppliers, subcontractors, designers, supervisors); workers and other persons on construction sites; other natural persons whose data is contained in documents and files uploaded by the Customer.
  • Categories of personal data: identification data (names, position, signature, image in photos); contact data (email, phone, address); professional data (company, role, qualification); financial and commercial data in documents (invoices, contracts, bank accounts, amounts), including of sole traders; data on hours worked, attendance and tasks; photos and files from construction sites; technical data on use of the Platform (audit log entries, IP address, time of actions); other personal data the Customer chooses to enter.
  • Special categories of data: the Platform is not intended for processing special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions and offences (Art. 10 GDPR). The Customer does not enter such data unless necessary and lawful, and bears full responsibility for doing so.
  • Frequency: continuous, for the term of the agreement.

Annex 2. Technical and Organisational Measures

The Provider applies at least the following measures:

  • Encryption in transit: all traffic to the Platform is transmitted over the secure HTTPS protocol (TLS).
  • Encryption at rest: the database and file storage are encrypted at rest by the hosting providers. Keys for external services entered by the Customer are additionally stored encrypted at application level (AES-256-GCM).
  • Isolation between customers: logical record-level isolation - every record is linked to the Customer's company and access is automatically restricted to it, with automated code checks enforcing this rule.
  • Access control: individual accounts, roles and permissions managed by the Account Administrator; passwords are stored only in hashed form (bcrypt).
  • Abuse protection: rate limiting of requests and protection against automated registrations.
  • Traceability: an audit log of the creation, modification and deletion of records.
  • Availability: regular database backups and monitoring of errors and Platform availability.
  • Location: the database and application runtime are hosted in the EU (Ireland); text recognition, IFC model processing and error monitoring are also performed in the EU.
  • Organisational measures: staff access to Personal Data only on a need-to-know basis, confidentiality obligations, and automated checks of code changes before release.

Annex 3. Sub-processors

As of the last update, the Provider uses the following sub-processors:

  • Vercel Inc.

    Activity
    Application hosting and runtime
    Location
    EU (Ireland); possible access from the US
    Transfer mechanism
    EU-US Data Privacy Framework and/or standard contractual clauses
  • Supabase Inc.

    Activity
    Database hosting
    Location
    EU (Ireland); possible access from the US
    Transfer mechanism
    Standard contractual clauses
  • Cloudflare, Inc.

    Activity
    File storage
    Location
    Europe; possible access from the US
    Transfer mechanism
    EU-US Data Privacy Framework and/or standard contractual clauses
  • Upstash, Inc.

    Activity
    Caching and request rate limiting
    Location
    EU or US
    Transfer mechanism
    EU-US Data Privacy Framework and/or standard contractual clauses
  • Railsware Products Studio LLC (Mailtrap)

    Activity
    Sending emails
    Location
    US
    Transfer mechanism
    EU-US Data Privacy Framework and/or standard contractual clauses
  • Functional Software, Inc. (Sentry)

    Activity
    Error monitoring
    Location
    EU (Germany); possible access from the US
    Transfer mechanism
    EU-US Data Privacy Framework and/or standard contractual clauses
  • OpenAI

    Activity
    AI features: recognition and extraction of data from documents, intelligent search and matching
    Location
    US
    Transfer mechanism
    Standard contractual clauses
  • Google Cloud EMEA Limited

    Activity
    Text recognition in documents (Cloud Vision) and IFC model processing (Cloud Run)
    Location
    EU; possible access from outside the EU
    Transfer mechanism
    EU-US Data Privacy Framework and/or standard contractual clauses
  • CompanyBook (companybook.bg)

    Activity
    Company lookups by UIC
    Location
    Bulgaria (EU)
    Transfer mechanism
    Not required

The Provider also uses services for which it acts as an independent controller - for example, Stripe for subscription payments, Google Analytics, Google Ads and Vercel Analytics for statistics and advertising, and Cloudflare Turnstile for registration protection. These are described in the Privacy Policy and the Cookie Policy and are not sub-processors under this DPA.

We use cookies to keep the platform working properly and to improve your experience. Even if you decline, we only collect anonymous, non-identifying measurement data (without cookies). Learn more about cookies