Data Processing Agreement
Last updated: 19 June 2026
1. Roles and scope
For personal data contained in the content you enter into Condit, you are the controller and we are the processor. We process that personal data only to provide the service and only on your documented instructions, including those set out in this DPA and the Terms of Service.
2. Our obligations as processor
- Process personal data only on your documented instructions, unless required by law (in which case we will tell you, unless the law prohibits it).
- Ensure that people authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see section 5).
- Engage sub-processors only as set out in section 4.
- Assist you, taking into account the nature of processing, in responding to data subject rights requests.
- Assist you with security, breach notification, and data protection impact assessments.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- On termination, delete or return your personal data as set out in section 6.
- Make available information needed to demonstrate compliance, and allow for and contribute to audits as set out in section 7.
3. Your obligations as controller
You are responsible for the lawfulness of the personal data you provide and the instructions you give, for having a valid legal basis for the processing, and for the accuracy of the data.
4. Sub-processors
You give general authorisation for us to engage the sub-processors listed in Annex B to deliver the service. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give you reasonable notice of any new sub-processor and an opportunity to object on reasonable data protection grounds.
5. Security
We maintain measures appropriate to the risk, including encryption in transit, encrypted password storage, access controls, and database row-level security isolating each organisation's data. We review these measures periodically.
6. Return and deletion
By design, Condit holds as little personal data as possible: it is a working tool, not a long-term archive. Finished reports are exported as PDFs that you store on your own systems and which remain your definitive record; we do not keep a database of your finished reports. Drafts and tasks are working data, intended to be kept only while a report or job is in progress; when deleted they are moved to a recycle bin and then automatically and permanently erased shortly afterwards (currently within around 48 hours). On termination, we will delete the personal data we hold within 30 days, except where retention is required by law; residual copies in encrypted backups are deleted on the normal backup cycle.
7. Audits
On reasonable written request, and no more than once per year unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance with this DPA.
8. International transfers
Where personal data is transferred outside the UK, we rely on a recognised transfer mechanism such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum.
9. Liability and term
This DPA is subject to the liability provisions of the Terms of Service and remains in force for as long as we process personal data on your behalf.
Annex A - Details of processing
- Subject matter: provision of the Condit condition reporting and workflow service.
- Duration: the term of the subscription.
- Nature and purpose: hosting, storing, organising and displaying content so you can create and manage condition reports and tasks.
- Types of personal data: names and contact details of your staff; and any personal data you include in report content (for example examiner names, and client or collector details), comments, photographs and signatures.
- Categories of data subjects: your staff and users; and individuals referenced in your report content, such as clients, owners, examiners and contacts.
Annex B - Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | European Union (Ireland, AWS eu-west-1) |
| Resend | Transactional email (invitations, password resets) | United States (under appropriate safeguards) |