Legal
Data Processing Addendum
Effective August 15, 2026
1. Definitions
Terms such as Personal Data, Processing, Controller, Processor, Data Subject, Supervisory Authority, and Personal Data Breach have the meanings given in the GDPR. Service Provider, Business, Sell, and Share have the meanings given in the California Consumer Privacy Act as amended ("CCPA"). Data Protection Laws means all privacy and data protection laws applicable to the processing under this DPA.
2. Roles
Customer is the Controller (or Business) of Personal Data contained in Customer Data. RTI is the Processor (or Service Provider) and processes that Personal Data only on Customer's documented instructions.
RTI is an independent Controller for Account Data described in its Privacy Policy — the identity and contact details of the individuals who administer the account, billing information, and security logs. This DPA does not govern that processing.
Where Customer is itself a processor for another party (for example, a subcontractor recording inspections on behalf of a general contractor), Customer warrants it has authority to give the instructions in this DPA, and RTI is a subprocessor.
3. Scope and instructions
RTI will process Personal Data only:
a) to provide, secure, maintain, and support the Service under the Terms; b) as further instructed by Customer in writing, where those instructions are consistent with the Terms; and c) as required by applicable law, in which case RTI will inform Customer of the requirement before processing unless the law prohibits it.
RTI will notify Customer if, in its opinion, an instruction infringes Data Protection Laws.
RTI will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than performing the Service; retain, use, or disclose it outside the direct business relationship between the parties; combine it with personal information from other sources except as permitted for a service provider; or use it to train machine-learning or artificial-intelligence models.
RTI certifies that it understands and will comply with these restrictions.
The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in Annex A.
4. Confidentiality
RTI will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations, are informed of the confidential nature of the data, and receive appropriate training. Access is limited to personnel who need it to provide or support the Service.
5. Security
RTI will implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Those measures are set out in Annex B.
RTI may update the measures over time provided the level of protection is not materially reduced.
6. Subprocessors
Customer gives RTI general authorization to engage subprocessors. The subprocessors engaged as at the effective date are listed in Annex C.
RTI will:
- impose data protection obligations on each subprocessor no less protective than those in this DPA;
- remain fully liable to Customer for each subprocessor's performance; and
- give Customer at least 30 days' notice before adding or replacing a subprocessor that processes Customer Data, by email to the account administrator and by publishing an updated Annex C.
Customer may object to a new subprocessor on reasonable data protection grounds within that notice period. The parties will discuss in good faith. If the objection cannot be resolved, Customer may terminate the affected part of the Service without penalty and receive a pro-rated refund of prepaid fees.
7. Data Subject requests
RTI will, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise a right in respect of Customer Data. RTI will not respond to such a request itself except to direct the Data Subject to Customer.
Taking into account the nature of the processing, RTI will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond. The Service provides self-service functionality for Customer to access, correct, export, and delete Customer Data, which the parties agree constitutes substantial assistance.
8. Personal Data Breach
RTI will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification will describe, to the extent known:
- the nature of the breach, including categories and approximate numbers of Data Subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address it and mitigate its effects; and
- a contact point for further information.
RTI will provide reasonable cooperation and information to assist Customer in meeting its own notification obligations. RTI will not make a public statement identifying Customer without Customer's prior written consent, unless legally required.
9. Data Protection Impact Assessments
RTI will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the processing and the information available to RTI.
10. Deletion and return
On termination or expiry of the Terms, Customer may export Customer Data through the Service during the export window stated in the Terms.
After that window, RTI will delete Customer Data within 90 days, except:
- where retention is required by applicable law, in which case RTI will inform Customer and will continue to protect the data and process it only as required for that purpose; and
- copies held in routine backups, which are overwritten in the ordinary backup cycle within 30 days and are not restored except for disaster recovery.
On written request, RTI will certify deletion.
Note on the activity log. The Service's activity log is append-only and chained cryptographically; selectively deleting entries would break the chain that makes the record tamper-evident. Deletion is performed at workspace level, removing the log as a whole. Customer acknowledges this design.
11. Audits
RTI will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written security questionnaires no more than once per year.
Customer may, on at least 30 days' written notice, no more than once per year (and additionally following a Personal Data Breach affecting Customer Data), conduct an audit of RTI's compliance. Audits will take place during business hours, must not unreasonably disrupt RTI's operations, are subject to confidentiality, and must not require RTI to disclose another customer's data. Customer bears its own costs and RTI's reasonable costs where the audit exceeds one business day.
12. International transfers
RTI processes Personal Data in the United States. Where Customer transfers Personal Data subject to GDPR or UK GDPR to RTI, the parties agree that:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), are incorporated by reference and apply, with Customer as data exporter and RTI as data importer;
- the UK International Data Transfer Addendum applies to transfers subject to UK GDPR;
- Annexes A, B, and C of this DPA populate Annexes I, II, and III of the Standard Contractual Clauses;
- the governing law and forum are those specified in the Terms where permitted, and otherwise the Republic of Ireland; and
- the optional docking clause applies.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.
14. Term
This DPA takes effect on the effective date and continues until RTI ceases all processing of Customer Data.
Annex A — Details of processing
Subject matter. Provision of the Ready-to-Inspect construction quality assurance and quality control platform.
Duration. For the term of the Terms, plus the export and deletion windows.
Nature and purpose. Hosting, storage, retrieval, transmission, display, backup, and deletion of inspection records so that Customer can document, review, approve, and hand over construction work.
Categories of Data Subjects
- Customer's employees and contractors who use the Service (administrators, QA/QC managers, trade partners)
- Individuals appearing in inspection photographs — typically site workers, and occasionally passers-by
- Customer's clients and project owners granted portal access
- Individuals named in inspection observations or notes
Categories of Personal Data
| Category | Detail |
|---|---|
| Identity and contact | Name, email address, phone number |
| Employment | Job title, trade, role, permissions, company affiliation |
| Images | Profile photographs; inspection photographs that may depict identifiable individuals |
| Location | GPS coordinates embedded into inspection photographs where the device permits, associating an individual with a place and time |
| Signature | Drawn signature image, typed name, role at signing, timestamp, hashed IP address |
| Technical | IP address, browser user-agent, session timestamps |
| Free text | Observations, notes, and comments that may name or describe individuals |
Special categories of data. None are requested or required. Customer must not enter special-category data into free-text fields. Customer is responsible if it does.
Frequency. Continuous, for the duration of the Terms.
Annex B — Technical and organizational measures
Access control and tenant isolation
- Row-level security in the database scopes every record to a single workspace; isolation is enforced at the data layer, not only in application code.
- Role-based access control (administrator, QA/QC manager, trade partner, client portal).
- Individual named accounts; shared credentials prohibited by the Terms.
- Password strength enforcement and new-device verification.
- Optional federated sign-in via Google.
Encryption
- TLS for all data in transit.
- Encryption at rest provided by the infrastructure provider.
- Photographs and signature images served through short-lived signed URLs; no public object links.
- Passwords stored as one-way hashes; signer IP addresses stored as one-way hashes.
Integrity
- Activity log entries are chained using SHA-256, each record binding the hash of the record before it, so alteration of a historical entry is detectable.
- Server-side enforcement of documentation requirements before a submission is accepted.
- Submission records are independently hashed.
Availability and resilience
- Managed database with automated backups provided by the infrastructure provider.
- Offline capture with device-local queueing and automatic sync.
- Self-service export of all Customer Data in CSV and PDF form at any time.
Operational
- Access to production data limited to personnel who require it.
- Confidentiality obligations on all personnel with access.
- Change management through version-controlled deployments.
- Written subprocessor agreements.
Annex C — Subprocessors
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase, via Lovable Cloud | Database, object storage, authentication | All Customer Data including photographs and signatures | United States |
| Stripe, Inc. | Payment and subscription processing | Billing contact and payment data (Account Data) | United States |
| Resend | Transactional email delivery | Recipient name, email address, message content | United States |
| Cloudflare, Inc. | DNS, CDN, video delivery | Network request metadata | Global edge network |
| Google LLC | Optional federated sign-in | Email address and name, where the user selects this method | United States |
Customer-enabled integrations. Where Customer connects an optional integration (for example Smartsheet), that provider is not an RTI subprocessor. Data is transmitted at Customer's direction under Customer's own agreement with that provider.
Current version maintained at readytoinspect.io/subprocessors.