BUILDFLOW CRM — DATA PROCESSING AGREEMENT (DPA) Version 1.0 — July 2026 Buildflow (buildflow.builders), United Kingdom This Data Processing Agreement ("DPA") forms part of the Buildflow Terms of Service between Buildflow ("Processor", "we") and the customer identified in the subscription ("Controller", "you"). It applies to Processing of Personal Data carried out by us on your behalf under UK GDPR and, where applicable, EU GDPR. 1. DEFINITIONS Terms such as "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor" and "Personal Data Breach" have the meanings given in UK GDPR. 2. ROLES 2.1 You are the Controller of the client, project and staff data you enter into your workspace. We are the Processor of that data. 2.2 We are an independent Controller of your account administration, billing and security log data. 3. SUBJECT MATTER, DURATION, NATURE AND PURPOSE 3.1 Subject matter: provision of the Buildflow CRM service. 3.2 Duration: for the term of your subscription and the retention period set out in clause 10. 3.3 Nature and purpose: hosting, storage, retrieval, transmission, organisation and analysis of workspace records so you can run enquiries, quotations, projects and handover. 3.4 Types of Personal Data: names, postal and site addresses, email addresses, telephone numbers, correspondence, photographs of works, quotation and payment information, and staff role assignments. 3.5 Categories of Data Subject: your prospective and actual clients, their representatives, your staff and your subcontractors. 4. PROCESSOR OBLIGATIONS We shall: (a) Process Personal Data only on your documented instructions, including the instructions given through your use of the service, unless required by law (in which case we will inform you unless the law forbids it); (b) ensure persons authorised to Process Personal Data are bound by confidentiality; (c) implement the technical and organisational measures in Annex A; (d) respect the conditions in clause 6 for engaging Sub-processors; (e) assist you, taking into account the nature of Processing, in responding to Data Subject requests; (f) assist you with data protection impact assessments and with your obligations under Articles 32 to 36 UK GDPR; (g) at your choice delete or return Personal Data at the end of the service in accordance with clause 10; (h) make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits under clause 8. 5. CONTROLLER OBLIGATIONS You warrant that you have a lawful basis for the Personal Data you enter, that you provide the required privacy information to your Data Subjects, and that you manage workspace membership, roles and leavers promptly. 6. SUB-PROCESSORS 6.1 You give general written authorisation for us to engage the Sub-processors published at https://www.buildflow.builders/subprocessors. 6.2 We will update that versioned list before appointing a new Sub-processor and will notify you by email on request. You may object on reasonable data protection grounds within 14 days; if we cannot resolve the objection you may terminate the affected service without penalty for the remainder of the paid term. 6.3 We remain liable to you for the acts and omissions of our Sub-processors. 7. INTERNATIONAL TRANSFERS Where a Sub-processor Processes Personal Data outside the UK or EEA, the transfer is made under the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses, together with any supplementary measures required by a transfer risk assessment. 8. AUDIT On no more than one occasion in any twelve-month period, and on 30 days' written notice, we will respond to a reasonable written security questionnaire and provide available evidence of the measures in Annex A. On-site audit is available where a supervisory authority requires it, subject to confidentiality and reasonable cost recovery. 9. PERSONAL DATA BREACH We will notify you without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting your workspace, and will provide the information reasonably available to allow you to meet your own notification duties. 10. RETENTION, RETURN AND DELETION Workspace content is retained for the term of your subscription. After termination you may export your data for 30 days, after which the workspace and its contents are deleted. Backups age out on the hosting provider's standard cycle. Security and billing records may be retained for up to six years where required by law. 11. LIABILITY AND ORDER OF PRECEDENCE Liability under this DPA is subject to the limitations in the Terms of Service. In the event of conflict, this DPA prevails over the Terms of Service in respect of Processing of Personal Data. ANNEX A — TECHNICAL AND ORGANISATIONAL MEASURES * Encryption of Personal Data in transit (HTTPS only, HSTS enforced) and at rest by the hosting provider. * Row-level database access policies enforcing workspace isolation on every table holding leads, quotations, costs, contracts and client documents. * Role-based access control with roles stored separately from user profiles and enforced at the database layer. * Private file storage; documents served only via short-lived signed links. * Minimum 12-character passwords, strength checking, sign-in rate limiting, optional two-factor authentication and automatic session expiry. * Recorded security events, portal access history and exportable audit logs. * Scheduled automated security, dependency-vulnerability and data-integrity checks with alerting to workspace admins. * Managed automated database backups. * Documented vulnerability reporting route with acknowledgement within one working day. ANNEX B — SUB-PROCESSORS The current versioned list is published at https://www.buildflow.builders/subprocessors. To execute a signed copy of this DPA, email privacy@buildflow.builders quoting your workspace name.