Structure and incorporation
This Data Processing Addendum (“DPA”) forms part of the agreement between Gridline, Inc.(“Gridline”, “we”, “us”) and the customer (“Customer”, “you”) that has accepted Gridline’s Terms of Serviceor another written agreement governing use of the Service (the “Agreement”). It applies to the extent Gridline processes Personal Data on the Customer’s behalf in providing the Service.
Where this DPA conflicts with the rest of the Agreement, this DPA controls with respect to the processing of Personal Data. Terms not defined here have the meaning given in the Agreement.
Definitions
- Data Protection Lawsmeans all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018 (“UK GDPR”), and the California Consumer Privacy Act as amended (“CCPA”).
- Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach have the meanings given in the GDPR.
- Customer Personal Datameans Personal Data contained within Customer Data that Gridline processes on the Customer’s behalf under the Agreement.
- Subprocessor means a third party engaged by Gridline to process Customer Personal Data.
- Standard Contractual Clauses or SCCs means the clauses approved by the European Commission in Decision 2021/914, and, for UK transfers, the UK International Data Transfer Addendum.
Roles of the parties
For Customer Personal Data, the Customer is the Controller and Gridline is the Processor. Where the Customer is itself acting as a processor on behalf of a third-party controller, Gridline is a subprocessor; in that case the Customer warrants that it has the third party’s authority to engage Gridline on these terms.
Each party will comply with its obligations under Data Protection Laws in respect of the processing carried out under the Agreement. The Customer is responsible for the lawfulness of the Customer Personal Data and of its instructions to Gridline.
Scope and Customer instructions
Gridline will process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Agreement and this DPA and as needed to provide, secure, and support the Service. The Agreement, including the Customer’s use of the Service’s features and settings, constitutes the Customer’s complete and final instructions.
Gridline will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend processing of the affected instruction until it is amended or confirmed. Gridline will not process Customer Personal Data for any purpose other than providing the Service, and will not sell it or otherwise use it for its own purposes.
No training on Customer Personal Data
Gridline does not use Customer Personal Data, Customer Data, prompts, or generated Output to train, fine-tune, or improve any artificial intelligence or machine-learning foundation model, whether Gridline’s or a third party’s. Where the Service routes content to a third-party model provider to perform inference and return a result to the Customer, Gridline engages such providers on terms that prohibit training on the content and that apply zero or short retention where the provider offers it. This commitment is a material term of this DPA.
Confidentiality of personnel
Gridline will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations, are informed of the confidential nature of the data, and access it only on a need-to-know basis to perform their duties.
Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Gridline will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against a Personal Data Breach, as described in Annex II. Gridline may update these measures provided that they do not materially reduce the overall level of protection.
Subprocessors
The Customer provides general authorization for Gridline to engage Subprocessors to process Customer Personal Data. Gridline’s current Subprocessors are listed in Annex III.
- Gridline will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA.
- Gridline remains responsible for its Subprocessors’ performance of their obligations.
- Gridline will give the Customer notice of the addition or replacement of a Subprocessor with a reasonable opportunity to object on reasonable, data-protection grounds. If the parties cannot resolve a good-faith objection, the Customer may terminate the affected portion of the Service.
Data subject requests
The Service provides the Customer with controls to access, correct, delete, and export Customer Personal Data. Taking into account the nature of the processing, Gridline will assist the Customer with appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Laws. If Gridline receives such a request directly, it will, unless legally prohibited, promptly forward it to the Customer and will not respond except on the Customer’s instructions.
Assistance to the Customer
Taking into account the nature of processing and the information available to it, Gridline will provide reasonable assistance to the Customer with its obligations relating to the security of processing, data protection impact assessments, prior consultation with supervisory authorities, and Personal Data Breach notifications under Articles 32 to 36 of the GDPR.
Personal Data Breach notification
Gridline will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations. Gridline will take reasonable steps to contain and remediate the breach. Gridline’s notification is not an acknowledgment of fault or liability.
International transfers
Where Gridline processes Customer Personal Data subject to the GDPR or UK GDPR in a country that has not received an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA and apply to that transfer. For EU transfers, the Customer is the data exporter and Gridline the data importer; Module Two (Controller to Processor) applies, or Module Three (Processor to Processor) where the Customer acts as a processor. For UK transfers, the UK International Data Transfer Addendum applies to the SCCs. The Annexes to this DPA populate the corresponding annexes of the SCCs.
Return and deletion of data
On termination or expiry of the Agreement, Gridline will, at the Customer’s choice, make Customer Personal Data available for export for a limited period and then delete it from active systems, with residual copies removed from backups in the ordinary course, unless retention is required by law. The deletion provisions of this DPA prevail over any conflicting provision in the Agreement.
Audits and demonstrating compliance
Gridline will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Where the Customer reasonably requires further information, Gridline will respond to a reasonable number of written security questionnaires and, where required by Data Protection Laws, allow for and contribute to audits conducted by the Customer or an independent auditor it appoints, on reasonable prior notice, during business hours, no more than once per year (except following a Personal Data Breach), and subject to confidentiality.
California (CCPA) terms
To the extent the CCPA applies, Gridline acts as a “service provider” with respect to Customer Personal Data. Gridline will not sell or share such data, will not retain, use, or disclose it except as necessary to perform the Service or as permitted by the CCPA, and will not retain, use, or disclose it outside the direct business relationship with the Customer or combine it with data from other sources except as the CCPA permits. Gridline certifies that it understands and will comply with these restrictions.
Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a party’s liability means its aggregate liability under the Agreement and this DPA combined.
Annex I: Description of processing
Parties
Data exporter: the Customer (Controller, or processor where it acts on behalf of a third party). Data importer: Gridline, Inc. (Processor).
Subject matter and duration
Processing of Customer Personal Data to provide the Service for the duration of the Agreement and the return or deletion period described above.
Nature and purpose
Hosting, storage, transmission, retrieval, analysis, and generation of Output in connection with the Customer’s building models, drawing sets, project documents, and queries, including routing of content to model providers to perform inference.
Categories of Data Subjects
- the Customer’s Authorized Users (employees and contractors of the firm);
- individuals whose Personal Data may incidentally appear within Customer Data, such as names in project documents, correspondence, or drawing metadata.
Categories of Personal Data
- identification and contact data (name, work email, role, firm);
- account and authentication data;
- usage and log data;
- any Personal Data the Customer chooses to include in Customer Data.
Special categories
The Service is not intended for special categories of Personal Data, and the Customer should not submit them. Any such data present in Customer Data is processed only as incidental to the Service.
Frequency and retention
Continuous, for the duration of the Agreement, with retention as described in the Return and deletion section.
Annex II: Technical and organizational measures
Gridline maintains measures including:
- Encryption: Customer Personal Data is encrypted in transit (TLS) and at rest.
- Access control: authentication and single sign-on through a dedicated identity provider, role-based and least-privilege access, and unique credentials for personnel.
- Network and application security: segregation of environments, hardened cloud infrastructure, and protective controls at the network and application layers.
- Confidentiality and integrity: internal access to Customer Personal Data limited to what is needed to operate and support the Service, with logging of administrative access.
- Resilience: use of reputable cloud providers with backup and recovery capabilities.
- Governance: confidentiality obligations on personnel, vendor due diligence, and an internal security program that Gridline is maturing toward formal third-party certification.
Annex III: Subprocessors
Gridline engages the following categories of Subprocessors to process Customer Personal Data. A current, named list is available to customers on request, and changes are notified as described in the Subprocessors section.
- Cloud hosting and application delivery, for running the Site and Service (United States).
- Managed database, for storing application and project data (United States).
- Identity and authentication, for secure sign-in and single sign-on (United States).
- AI model inference, for generating Output, under terms that prohibit training on Customer content.
Contact
Questions about this DPA, requests to exercise audit rights, or a current subprocessor list can be directed to privacy@gridlineos.com. For security matters, contact security@gridlineos.com.