Back

Data Processing Addendum

Last updated: 07/21/2026

1. Introduction and Applicability

This Data Processing Addendum ("DPA") forms part of the agreement between RemoteAmbition, LLC ("Company", "we", "us") and the customer identified in the applicable account or order ("Customer") under the Exayard Terms of Service or other written agreement between the parties (the "Agreement"). This DPA applies automatically, without signature, to the extent the Company processes Personal Data contained in Customer Content on behalf of a business Customer and that processing is subject to Data Protection Laws. In the event of a conflict between this DPA and the Agreement with respect to its subject matter, this DPA controls. Customers who require a countersigned copy of this DPA may request one at [email protected].

2. Definitions

"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").

"Personal Data" means information relating to an identified or identifiable natural person that is contained in Customer Content and processed by the Company on the Customer's behalf. "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR. "Service Provider" has the meaning given in the CCPA. "Subprocessor" means a third party engaged by the Company to process Personal Data on the Customer's behalf. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914. "Customer Content" has the meaning given to "Content" in the Agreement.

3. Roles and Scope of Processing

As between the parties, Customer is the Controller (or, where Customer acts on behalf of a third-party controller, a Processor) of Personal Data in Customer Content, and the Company is a Processor (or Subprocessor) and, for CCPA purposes, a Service Provider. The subject matter, duration, nature and purpose of processing, categories of Personal Data, and categories of Data Subjects are described in Annex I. This DPA does not apply to personal data for which the Company is an independent controller (such as Customer account, billing, and usage data), which is described in the Company's Privacy Policy.

4. Processing on Documented Instructions

The Company will process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case the Company will inform the Customer of that legal requirement before processing, unless the law prohibits it). The parties agree that the Agreement, this DPA, and the Customer's use and configuration of the Service constitute the Customer's complete documented instructions, comprising: (a) processing to provide, maintain, secure, and support the Service; (b) processing to improve and develop the Service and the Company's products, including the machine-learning uses described in the Content section of the Terms of Service, except where the Customer has an arrangement with the Company excluding its Content from model training, and provided that the Company will de-identify Personal Data where reasonably practicable before such use; and (c) processing initiated by Customer users in their use of the Service. The Company will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.

CCPA. The Company will not sell or share Personal Data, will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement or outside the direct business relationship between the parties, and will not combine Personal Data with personal information it receives from other sources except as permitted for Service Providers. The Company certifies that it understands and will comply with these restrictions.

5. Confidentiality

The Company ensures that persons authorized to process Personal Data (including personnel and contractors performing labeling and quality review) are bound by contractual or statutory obligations of confidentiality.

6. Security

Taking into account the state of the art and the nature of the processing, the Company implements and maintains appropriate technical and organizational measures to protect Personal Data, as described in Annex II and on the Company's Security page. The Company may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.

7. Subprocessors

Customer provides a general authorization for the Company to engage Subprocessors to process Personal Data. The Company's current list of Subprocessors that handle Customer Content is published on the Security page. The Company will provide notice (via the Security page and, for material additions, via email or in-product notice) before adding a new Subprocessor that handles Customer Content. If the Customer reasonably objects to a new Subprocessor on data protection grounds within thirty (30) days of notice and the parties cannot resolve the objection, the Customer may terminate the affected services and receive a pro-rata refund of prepaid fees for the unused remainder of the term for those services. The Company imposes data protection obligations on its Subprocessors consistent with this DPA and remains liable for their performance.

8. Data Subject Requests

Taking into account the nature of the processing, the Company will assist the Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling the Customer's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If a Data Subject contacts the Company directly regarding Personal Data in Customer Content, the Company will, where the Customer is identifiable, direct the Data Subject to the Customer.

9. Personal Data Breach

The Company will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data, and will provide information reasonably available to the Company to assist the Customer in meeting its breach notification obligations, supplemented as further information becomes available.

10. Assistance

Taking into account the nature of the processing and the information available to it, the Company will provide reasonable assistance to the Customer with data protection impact assessments, consultations with supervisory authorities, and the Customer's obligations under Articles 32 to 36 of the GDPR.

11. Deletion and Return

Upon termination of the Agreement, or upon the Customer's deletion of Customer Content through the Service, the Company will delete Personal Data in Customer Content, except that (a) residual copies in backups are deleted on the Company's standard backup cycle (currently within thirty (30) days), and (b) the Company may retain Personal Data to the extent required by applicable law. The Customer can export Customer Content through the Service prior to termination. Trained models, model weights, statistical aggregates, and de-identified derivative datasets are not Personal Data returned or deleted under this section, as described in the Agreement.

12. Audits

The Company will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable written security questionnaires and copies of relevant security documentation. Where Data Protection Laws grant the Customer an audit right that cannot be satisfied by the foregoing, the Customer may conduct an audit through an independent third party bound by confidentiality, no more than once per twelve (12) months, on at least thirty (30) days' notice, during business hours, at the Customer's expense, and without access to other customers' data or the Company's proprietary systems beyond what is necessary.

13. International Transfers

The Company processes Personal Data in the United States. Where Personal Data protected by the GDPR, UK GDPR, or Swiss law is transferred to the Company in the United States or another country not recognized as providing adequate protection, the parties enter into the SCCs, which are incorporated into this DPA by reference as follows: Module Two (Controller to Processor) applies (or Module Three where the Customer is a Processor); the Company is the data importer and the Customer is the data exporter; Clause 7 (docking) is included; under Clause 9, Option 2 (general authorization) applies with the notice period in Section 7 of this DPA; under Clause 11, the optional language is not included; under Clauses 17 and 18, the governing law and forum are Ireland; Annexes I and II to the SCCs are completed with the information in Annexes I and II of this DPA. For UK transfers, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the UK Information Commissioner, and for Swiss transfers, as adapted for Swiss law (references to the GDPR read as references to the Swiss FADP, and the competent authority is the Swiss FDPIC).

14. Liability

Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Agreement, except where Data Protection Laws do not permit such limitation.

15. Term

This DPA remains in effect for as long as the Company processes Personal Data in Customer Content on the Customer's behalf under the Agreement.

Annex I: Details of Processing

Subject matter and nature: hosting, storage, analysis, and AI-assisted processing of construction plans, drawings, and related documents and data uploaded by the Customer; generation of takeoffs, estimates, and related outputs; collaboration, export, and support features; and service improvement and development as described in Section 4.

Duration: the term of the Agreement plus the deletion periods described in Section 11.

Categories of Data Subjects: the Customer's personnel and users; and third parties whose information appears in Customer Content, such as architects, engineers, consultants, property owners, and other project participants.

Categories of Personal Data: identification and contact data (names, email addresses, phone numbers, addresses); professional data (titles, roles, employers, professional seals and license numbers); project information relating to identifiable persons; and any other Personal Data the Customer chooses to include in Customer Content. The Service is not intended for special categories of data, and the Customer agrees not to submit them.

Frequency: continuous, as determined by the Customer's use of the Service.

Annex II: Technical and Organizational Measures

Encryption of data in transit (TLS 1.3) and at rest (AES-256); identity management with support for multi-factor authentication and SSO; role-based access control enforced server-side; scoped API keys and OAuth with least-privilege defaults; audit logging with per-request identifiers; HMAC-signed webhooks; logical separation of customer data; infrastructure hosted with providers maintaining SOC 2 Type II certifications; personnel and contractor confidentiality obligations and least-privilege access; backup and disaster recovery with a thirty (30) day backup retention window; and a vulnerability disclosure program ([email protected]). Further detail: https://exayard.com/security.

Contact

Questions about this DPA: [email protected].