Schedule 2 - Data Processing Agreement
Schedule 2 of the Customer Agreement: how Spanwise processes personal data on a customer's behalf.
This Schedule forms part of the Spanwise Customer Agreement between Spanwise Technologies Ltd and the Customer (the "Agreement"). Terms defined in the Agreement have the same meaning here.
1. Definitions and status
1.1 Terms used in this Schedule that are defined in UK data protection law ("controller", "processor", "personal data", "processing", "personal data breach", "data subject", "supervisory authority") have the meanings given there.
1.2 "UK Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any successor or amending legislation.
1.3 "Customer Personal Data" means personal data contained in Customer Data or otherwise processed by Spanwise on the Customer's behalf under the Agreement.
1.4 "Sub-processor List" means the list of sub-processors published at https://spanwise.co.uk/sub-processors and maintained by Spanwise under paragraph 6.
1.5 The Customer is the controller and Spanwise is the processor in respect of Customer Personal Data. This Schedule is made under Article 28(3) of the UK GDPR.
1.6 The controller and processor split. Spanwise acts as controller in respect of Authorised User account records, authentication data and billing contacts held to administer the Agreement, and its privacy notice at https://spanwise.co.uk/privacy applies to those. Spanwise acts as processor in respect of the same individuals' personal data where it appears in, or is derived from, a submitted document. This Schedule applies only to the processor role.
2. Subject matter and duration
2.1 The subject matter is the automated screening of structural calculation packages submitted to the Customer for building control purposes, as described in Schedule 1 to the Agreement.
2.2 Processing lasts for the term of the Agreement and, thereafter, only for as long as the retention periods in paragraph 7 require.
3. Nature and purpose of the processing
3.1 Spanwise processes Customer Personal Data in order to:
(a) receive and store an uploaded document; (b) extract its text, including by reading images of individual pages where a page cannot be read as text, which covers scanned and handwritten material; (c) screen the document using artificial intelligence, which involves sending the document's text and images of its pages to the third party AI providers named in the Sub-processor List; (d) produce a screening report and make it available in the application; (e) email that report to the submitting Authorised User; (f) produce the reduced-identification copies described in paragraph 8, for the quality-assurance purpose stated there; (g) operate, secure, monitor and support the Service; (h) delete data in accordance with paragraph 7.
3.2 Automated decision-making. The Service does not take a decision about any data subject; it produces information on which the Customer's officers decide. In any event, it produces no decision having a legal or similarly significant effect on a data subject within the meaning of Article 22 of the UK GDPR.
4. Types of personal data and categories of data subject
4.1 Categories of data subject:
(a) applicants for building control approval, and property owners and occupiers; (b) structural engineers, architects, designers and their staff; (c) the Customer's officers who use the Service.
4.2 Types of personal data. Spanwise does not choose what appears in a submitted document. In practice a structural calculation package may contain:
(a) names of individuals, including applicants, owners, engineers and checkers; (b) site and property addresses and postcodes; (c) contact details, including telephone numbers and email addresses; (d) professional details, including firm names, job titles, membership numbers and signatures; (e) planning and application reference numbers; (f) any other personal data the submitter has chosen to include.
4.3 For Authorised Users: username, work email address, password (stored only as a salted hash), session records, and a record of the Submissions they made.
4.4 Special category data. The Service is not designed to process special category personal data or criminal offence data. The Customer warrants that it will not knowingly submit a document containing such data, and shall tell Spanwise promptly if it becomes aware that it has. Spanwise shall then delete the document and shall request its deletion by any sub-processor to which it has been sent. The Customer acknowledges that Spanwise cannot inspect a document before it is processed, and that once a document has been sent to a sub-processor Spanwise cannot guarantee its deletion by that sub-processor within that sub-processor's own retention period (paragraph 9.5).
5. Spanwise's obligations
Spanwise shall:
5.1 process Customer Personal Data only on the Customer's documented instructions, including on transfers to a third country. The Agreement and this Schedule are the Customer's documented instructions, and an Authorised User uploading a document is an instruction to process it as described in paragraph 3. Spanwise shall tell the Customer if it believes an instruction infringes UK Data Protection Law, and may suspend the relevant processing until the instruction is confirmed or withdrawn;
5.2 where required by law to process other than on the Customer's instructions, inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest;
5.3 ensure that persons authorised to process Customer Personal Data are subject to a duty of confidence;
5.4 implement and maintain the technical and organisational measures in Annex A, and keep them appropriate to the risk, subject to clause 14.1 of the Agreement;
5.5 engage sub-processors only in accordance with paragraph 6;
5.6 taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise data subject rights under Chapter III of the UK GDPR;
5.7 assist the Customer in complying with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Spanwise;
5.8 at the Customer's choice, delete or return Customer Personal Data at the end of the Agreement, in accordance with paragraph 7 and clause 19 of the Agreement. The option to have data returned extends only to Customer Personal Data Spanwise still holds when the request is made. Raw documents are automatically deleted on the schedule in paragraph 7, which is processing on the Customer's own documented instruction under paragraph 5.1, and cannot be returned after deletion;
5.9 make available to the Customer the information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits under paragraph 11.
5A. Charges for assistance
5A.1 Spanwise shall provide the assistance in paragraphs 5.6 and 5.7 without charge for up to two requests in any 12 month period, and thereafter at the hourly rate stated in the Order Form, save where the need for assistance arises from Spanwise's own breach.
5A.2 Paragraph 5A.1 does not apply to paragraph 11.2, which is charged under paragraph 11.5.
6. Sub-processors
6.1 The Customer gives Spanwise general written authorisation to engage sub-processors for the processing described in paragraph 3.
6.2 The sub-processors engaged at the date of this Schedule are set out in the Sub-processor List. No sub-processor is named in the body of this Schedule, and a change to the Sub-processor List made in accordance with this paragraph is not a variation of the Agreement.
6.3 Spanwise shall impose on each sub-processor, by written contract, the data protection obligations set out in this Schedule, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
6.4 Notice of change.
(a) Where Spanwise chooses to engage a new sub-processor, it shall give the Customer at least 30 days' written notice before that sub-processor begins processing Customer Personal Data. (b) Where a change of sub-processor arises from a change made by an existing sub-processor, or by another third party on which the Service depends, Spanwise shall pass on notice of that change to the Customer within two working days of receiving it, together with the effective date notified to Spanwise. (c) Notice under this paragraph is given by email to the Customer's nominated contact and by updating the Sub-processor List.
6.5 Objection. The Customer may object to a new sub-processor on reasonable data protection grounds by written notice within the notice period under paragraph 6.4(a), or where paragraph 6.4(b) applies, at any time before the change takes effect. The parties shall discuss the objection in good faith. If it cannot be resolved, and Spanwise cannot provide the Service without the sub-processor, the Customer may terminate the Agreement on written notice and Spanwise shall refund fees for the unexpired period.
6.6 Spanwise may engage a replacement sub-processor immediately, without the notice in paragraph 6.4, where a change is necessary to address a security incident or to maintain the Service following the failure or withdrawal of an existing sub-processor. Spanwise shall tell the Customer as soon as practicable and paragraph 6.5 then applies.
7. Retention and deletion
7.1 Spanwise applies the following retention periods automatically, in software:
| Data | Retention |
|---|---|
| The raw uploaded document, as bytes and as extracted text | Deleted once a reduced-identification copy exists and the record is older than 30 days |
| Reduced-identification document text and redacted PDF (paragraph 8) | For the term of the Agreement |
| Processing job records, which may quote passages of a document | 24 hours |
| Documents held in a queue during a third party provider outage | 72 hours maximum |
| Text quoted inside a suppressed screening item | Scrubbed on the same 30-day window as the raw document |
| Login sessions and password reset tokens | 8-hour expiry for sessions; both stored only as SHA-256 hashes |
| Operational counters used for daily monitoring | 90 days; these contain no personal data by design |
| Screening results, outcome labels and account records | For the term of the Agreement |
| Application logs | Kept free of document content and personal data by design |
7.2 On termination, Spanwise shall delete Customer Personal Data, including the copies described in paragraph 8, within 30 days of the export period in clause 19.2 of the Agreement ending, save where retention is required by law. Deletion from backups occurs on the ordinary backup cycle and in any event within 90 days; until then the data remains subject to this Schedule.
7.3 Spanwise shall certify deletion in writing on request.
8. Reduced-identification copies and quality assurance
8.1 After a document has been screened, Spanwise runs an automated pass that identifies personal data in the extracted text and replaces it, producing a reduced-identification copy and a redacted PDF. The raw document is then deleted on the schedule in paragraph 7.
8.2 Spanwise's internal quality review of screening accuracy uses only those copies. The software provides no route from that review back to the raw document.
8.3 The process is automated and is not guaranteed to be complete. In particular, personal data written by hand, or appearing only inside an image of a page, may not be removed, because the process works on extracted text. Spanwise does not treat these copies as anonymous. They remain Customer Personal Data, remain subject to this Schedule, and are protected by the measures in Annex A.
8.4 The purpose of retaining them is to monitor and improve the accuracy of the Service. The Customer instructs that processing as part of the Service. They are not used to train, fine-tune or evaluate any machine learning model, and they are not disclosed to any third party.
9. International transfers
9.1 Customer Personal Data is transferred outside the United Kingdom on every screening. The Customer acknowledges this and instructs Spanwise to make those transfers as part of providing the Service.
9.2 The current sub-processors are all established in the United States, and Spanwise does not offer United Kingdom or European-only processing. What is transferred includes:
(a) the full text of a submitted document; (b) images of individual pages of a submitted document. These are how handwritten and scanned calculations are read. Personal data appearing on such a page, such as a site address, a firm's name or a signature, cannot be removed before the image is sent, because the redaction operates on extracted text and the image is the page itself; (c) the full text again, to a different provider, for the automated pass described in paragraph 8 that finds the personal data so it can be removed from the retained copies. Finding personal data requires reading it; (d) selected passages of the text, to a further provider, to pull out structured details such as member sizes for the report; (e) the contents of the screening report, which quotes passages of the document, for the purpose of delivering it by email; (f) everything stored by the Service, which is hosted outside the United Kingdom. Unlike the transfers above, this one is not transient: it lasts for as long as the Service holds the data under paragraph 7, which for the copies described in paragraph 8 is the term of the Agreement.
9.3 Each transfer is made under the European Commission's Standard Contractual Clauses as modified by the UK International Data Transfer Addendum, under the UK Extension to the EU-US Data Privacy Framework, or under another lawful transfer mechanism, in each case in force with the relevant sub-processor before any transfer is made. The Sub-processor List records the mechanism relied on for each sub-processor, and Spanwise shall supply evidence of it on request. Spanwise is completing the verification described on that page, and until it does the List describes the safeguard by category rather than naming the exact instrument.
9.4 Spanwise shall, before the commencement of processing under the Agreement, carry out and thereafter maintain a transfer risk assessment, and make it available to the Customer on request.
9.5 Retention by AI providers. The AI providers Spanwise uses are contractually prohibited from using Customer Personal Data to train or improve their models. They may retain it transiently for abuse monitoring, typically for no more than 30 days. Zero-retention processing is not currently in place, and Spanwise does not represent that it is.
10. Personal data breach
10.1 Spanwise shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. For this purpose Spanwise becomes aware when it has a reasonable degree of certainty that a security incident has led to personal data being compromised. An initial notification may be given with such information as is then available.
10.2 The notification shall describe, so far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, Spanwise shall provide it in phases without undue further delay.
10.3 Spanwise shall not notify a supervisory authority or any data subject about a breach affecting Customer Personal Data without the Customer's prior written consent, unless required by law.
10.4 Spanwise shall co-operate with the Customer and take the steps the Customer reasonably directs to assist in investigating, mitigating and remedying the breach.
11. Audit
11.1 Spanwise shall make available to the Customer, on reasonable written notice, the information reasonably necessary to demonstrate compliance with this Schedule, which may be satisfied by providing its security documentation, its record of processing activities and any current certification.
11.2 Where that information is not sufficient, the Customer or an independent auditor appointed by it may audit Spanwise's processing, on at least 30 days' written notice, no more than once in any 12 month period except following a personal data breach or at the direction of a supervisory authority.
11.3 Audits shall take place during business hours, shall not exceed one working day, shall not unreasonably disrupt Spanwise's business, shall be subject to confidentiality, and shall not extend to the data or systems of Spanwise's other customers.
11.4 The Customer bears its own costs.
11.5 The Customer shall reimburse Spanwise's reasonable costs of an audit under paragraph 11.2 at the hourly rate stated in the Order Form, save where the audit reveals a material breach by Spanwise of this Schedule.
12. The Customer's obligations
12.1 The Customer warrants that:
(a) it has a lawful basis for the processing it instructs, and where special category or criminal offence data is in fact processed, a condition under Article 9 or Article 10 of the UK GDPR and any accompanying policy document required by the Data Protection Act 2018; (b) it has provided the privacy information required by Articles 13 and 14 of the UK GDPR to the relevant data subjects, including in respect of the transfers described in paragraph 9; (c) its instructions comply with UK Data Protection Law.
12.2 The Customer is responsible for carrying out any data protection impact assessment required in respect of its use of the Service. Spanwise shall assist under paragraph 5.7.
13. General
13.1 This Schedule forms part of the Agreement. In the event of a conflict between this Schedule and the rest of the Agreement, this Schedule prevails in respect of the processing of Customer Personal Data.
13.2 Liability under this Schedule is subject to clause 17 of the Agreement, save that nothing in clause 17 limits a data subject's rights or either party's liability to a supervisory authority.
13.3 This Schedule is governed by the law of England and Wales.
13.4 Contact. Data protection notices, requests and queries under this Schedule should be sent to louie.milner@spanwise.co.uk, the data protection contact notified to the Information Commissioner on Spanwise's registration. Notice of a personal data breach under paragraph 10 will be given to the Customer's nominated contact in the Order Form.
13.5 Survival. Paragraphs 5.2, 7, 8.3, 9.5, 10, 11, 12 and 13 survive the end of the Agreement, for as long as Spanwise holds any Customer Personal Data.
Annex A - Technical and organisational measures
Access control
- Individual named accounts; passwords stored using PBKDF2-HMAC-SHA256 at 600,000 iterations
- Session and password reset tokens stored only as SHA-256 hashes; sessions expire after 8 hours
- Per-user isolation: an Authorised User can access only their own Submissions
- Separate, higher-privilege credentials for administrative functions, which are disabled until explicitly configured
- Anything capable of affecting screening behaviour is restricted to the owner account
Encryption
- TLS in transit
- Encrypted storage at rest, provided by the hosting platform
Minimisation and separation
- Automated removal of personal data from retained copies, and PDF redaction, before any internal quality review
- Internal quality review has access only to the reduced-identification copies; the software provides no fallback to the raw document
- No document content or personal data is written to application logs
Retention
- Automatic enforcement of the periods in paragraph 7, applied at start-up and on every upload
Availability and integrity
- Managed PostgreSQL with platform backups
- Queued handling of third party provider outages, with the queue itself purged after 72 hours
- Automated error alerting to the operator, with reports scrubbed of personal data
Application security
- Baseline security headers, rate limiting keyed on client IP, and per-account usage caps
- Restricted evaluation of any expression derived from a document, so that document content cannot cause code to run
- Dependency and vulnerability review
Organisational
- Spanwise is a small company. All personnel with access are bound by confidentiality
- A documented personal data breach procedure is maintained and available on request
- A record of processing activities is maintained and available on request