Data Processing Agreement
Effective: 28 September 2026
This Data Processing Agreement ("DPA") applies where you use Auro to process personal data for which you are the controller, such as your clients' names, contacts or site addresses. It forms part of, and is subject to, our Terms of Service. In it, "you" are the controller and Auro Online Limited ("Auro", "we", "us", "our") is the processor. Words defined in UK data protection law (the UK GDPR and the Data Protection Act 2018) have the same meaning here.
1. What we process, and why
- Subject matter and duration: our processing of your personal data for as long as you have an account or organisation (called a workspace in the app) on Auro, plus any short wind-down period.
- Nature and purpose: to provide the Auro service to you, as described in our Terms.
- Types of personal data: whatever you or your team put into Auro, typically names, email addresses, contractor contact details, and the contact and site details within your projects, cost plans, tenders and files.
- Categories of data subject: your staff, and the people in your projects such as clients, site contacts, and the contractor contacts you invite to tenders.
2. Our obligations
We will:
- process your personal data only on your documented instructions (which include your use of the Service, these terms, the sharing of tender content with the organisations you exchange tenders with, and the creation of aggregated and anonymised statistics and data as described in our Terms), unless the law requires otherwise, in which case we will tell you first where we are allowed to;
- make sure the people authorised to process the data are under a duty of confidentiality;
- put in place appropriate technical and organisational security measures (as required by Article 32 UK GDPR), including encryption in transit, access controls, and keeping each customer's data separated;
- assist you (taking into account the nature of the processing and the information available to us) to respond to requests from individuals exercising their rights, and to meet your own obligations on security, breach notification and data protection impact assessments;
- notify you without undue delay if we become aware of a personal data breach affecting your data;
- at the end of the service, delete or return your personal data at your choice, and delete existing copies unless the law requires us to keep them;
- make available the information you reasonably need to show compliance with this DPA, and allow for and contribute to audits; and
- tell you if, in our opinion, an instruction from you infringes data protection law.
3. Sub-processors
You give us general authorisation to engage other companies ("sub-processors") to help provide the Service, such as cloud hosting, authentication, AI processing, PDF generation, email delivery, error monitoring and analytics. We remain responsible for their compliance and put terms in place with each that meet the requirements of this DPA.
We keep the current list of our sub-processors on our Sub-Processors page. Before we add or replace a sub-processor, we will update that page and notify organisation administrators, for example by email or a notice in the Service. If you have a reasonable data protection objection, you can raise it with us; if we cannot resolve it, you may stop using the affected part of the Service.
4. International transfers
Some sub-processors are outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on a recognised safeguard, such as the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge"), or the UK International Data Transfer Agreement / the UK Addendum to the EU Standard Contractual Clauses.
5. General
This DPA is governed by the law of England and Wales. If anything in it conflicts with the rest of our Terms on the subject of data protection, this DPA takes precedence. For any data protection question, contact us at hello@auro.build.