This Data Processing Agreement ("DPA") sets out the terms on which spanSense Ltd processes personal data on behalf of a Customer, in accordance with Article 28 of the UK GDPR. It supplements, and forms part of, the spanSense Terms & Conditions.
spanSense Ltd · Registered in England and Wales, company no. 17464577 · Registered office: 8 Howard Street, Reading, RG1 7XS
1.1This DPA is entered into between spanSense Ltd ("spanSense", the "Processor") and [CUSTOMER LEGAL NAME] (the "Customer", the "Controller"), together the "parties".
1.2This DPA applies whenever spanSense processes personal data on the Customer's behalf in connection with the Customer's use of the Service under the Terms & Conditions between the parties (the "Agreement"). In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.
2.1"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the UK GDPR.
2.2"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any other applicable law relating to the processing of personal data, each as amended or replaced from time to time.
2.3"Sub-processor" means any third party engaged by spanSense to process personal data on the Customer's behalf in providing the Service.
2.4"Customer Personal Data" means the personal data described in Annex 1, processed by spanSense on the Customer's behalf under the Agreement.
3.1spanSense will only process Customer Personal Data:
3.2spanSense will promptly inform the Customer if, in its opinion, an instruction from the Customer infringes the Data Protection Legislation.
3.3spanSense will ensure that persons authorised to process Customer Personal Data are subject to a duty of confidentiality.
4.1spanSense will implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, as described in spanSense's Data Security Policy and summarised in Annex 2.
5.1The Customer gives spanSense general authorisation to engage the Sub-processors listed in Annex 2 to support the Service.
5.2spanSense will impose data protection terms on any Sub-processor that are no less protective than those in this DPA, and will remain liable to the Customer for that Sub-processor's performance of its obligations.
5.3spanSense will give the Customer reasonable prior notice of any intended change to its Sub-processors, and will consider any reasonable objection raised by the Customer.
6.1Where Customer Personal Data is transferred outside the UK, spanSense will ensure the transfer is subject to appropriate safeguards under the Data Protection Legislation (for example, the UK's International Data Transfer Agreement, an adequacy decision, or the Sub-processor's equivalent standard contractual clauses).
7.1Taking into account the nature of the processing, spanSense will provide reasonable assistance to the Customer, at the Customer's cost where the assistance requires material additional effort, in relation to:
8.1spanSense will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide such information as the Customer reasonably requires to meet its own notification obligations under the Data Protection Legislation.
9.1spanSense will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable prior notice, reasonable frequency, and appropriate confidentiality protections.
10.1On termination of the Agreement, spanSense will, at the Customer's choice, delete or return all Customer Personal Data, and delete existing copies, except to the extent applicable law requires spanSense to retain it, consistent with clause 6.4 of the Terms & Conditions regarding export of Customer Data.
11.1Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
12.1This DPA takes effect on the date the Customer first accepts the Agreement and continues for as long as spanSense processes Customer Personal Data on the Customer's behalf.
13.1This DPA is governed by the laws of England and Wales, consistent with clause 20 of the Terms & Conditions.
13.2Except as amended by this DPA, the Agreement remains in full force and effect.
| Subject matter | Provision of the spanSense bridge and structure inspection management platform to the Customer |
|---|---|
| Duration | For the term of the Agreement, and thereafter as set out in clause 10 of this DPA |
| Nature and purpose | Hosting, storage, and processing of data submitted by the Customer's Authorised Users in order to provide the Service, including account management and support |
| Categories of Data Subjects | The Customer's Authorised Users (e.g. inspectors, engineers, administrators); individuals incidentally identifiable in site photographs uploaded to the Service |
| Types of Personal Data | Name, email address, role/job title, login and usage data; inspector names recorded against inspection records; individuals incidentally captured in site photographs |
| Special category data | Not intentionally collected or required by the Service |
| Sub-processor | Purpose |
|---|---|
| Render | Application hosting |
| Supabase | PostgreSQL database, and storage of uploaded photographs and files |
| Google (Gemini API) | AI-assisted extraction of structured data from uploaded inspection documents and drafting of conclusion text; document contents and inspector-entered comments are sent to this API for processing |
| CARTO / OpenStreetMap | Map tile imagery for the structure-location map; tile requests carry the requesting device's IP address |
See spanSense's Data Security Policy for full detail, which is incorporated into this Annex by reference and may be updated from time to time consistent with clause 4 of this DPA.