NEWScaffEngine — the 3D builder. Model the scaffold before anyone leaves the yard

ScaffoldOptix

Legal

Data Processing Agreement

The Article 28 terms on which ScaffoldOptix processes personal data on your behalf — including what we have not yet built.

Version 1.0 · Last updated 23 September 2026

Background

This Data Processing Agreement forms part of the agreement between Optix Group, a business operating in England and Wales ("Processor", "we", "us") and the customer identified in the Order Form ("Controller", "you").

In providing the products, we process personal data on your behalf. This agreement sets out the terms required by Article 28(3) UK GDPR and applies to all such processing.

If any term of this agreement conflicts with any other part of our contract, this agreement prevails in respect of the processing of personal data.

1. Definitions

  • Applicable Data Protection Law — UK GDPR; the Data Protection Act 2018; the Privacy and Electronic Communications Regulations 2003; and any other data protection or privacy law applicable to the processing.
  • Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Category Data, Supervisory Authority — as defined in UK GDPR.
  • Criminal Offence Data — personal data relating to criminal convictions and offences, or related security measures, within Article 10 UK GDPR and section 10 and Schedule 1 of the Data Protection Act 2018.
  • Customer Personal Data — personal data contained within Customer Data, processed by us on your behalf.
  • Restricted Transfer — a transfer of Customer Personal Data to a country outside the United Kingdom not covered by UK adequacy regulations.
  • Sub-processor — any processor engaged by us to process Customer Personal Data.
  • UK IDTA — the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or the UK Addendum to the EU Standard Contractual Clauses, as applicable.

2. Roles of the parties

You are the Controller. We are the Processor.

You determine the purposes and means of the processing. We do not determine the purposes of processing and will not do so; we process Customer Personal Data only on your documented instructions.

You confirm that:

  • you have a valid lawful basis under Article 6 UK GDPR for all Customer Personal Data you process using the products
  • where you process special category data, you have a valid condition under Article 9 UK GDPR and, where required, a condition in Schedule 1 of the Data Protection Act 2018 and an Appropriate Policy Document
  • where you process criminal offence data, you meet the requirements of Article 10 UK GDPR and section 10 of the Data Protection Act 2018, including an Appropriate Policy Document where required
  • you have provided all necessary privacy information to data subjects
  • your instructions to us do not breach Applicable Data Protection Law

We act as a controller in respect of the account and billing data described in our Privacy Policy. That processing is not governed by this agreement.

3. Our obligations as processor

We will process Customer Personal Data only on your documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law — in which case we will inform you of that requirement before processing, unless the law prohibits us from doing so on important grounds of public interest. Our contract with you, this agreement, your configuration of the product and your use of its documented functionality together constitute your documented instructions.

We will also:

  • inform you immediately if, in our opinion, an instruction infringes Applicable Data Protection Law — though we are not obliged to carry out a legal review of your instructions
  • ensure that everyone authorised to process Customer Personal Data is subject to a binding duty of confidentiality
  • implement and maintain the measures set out in Schedule 3, as required by Article 32 UK GDPR
  • engage sub-processors only under clause 5
  • assist you, by appropriate technical and organisational measures and so far as possible, in responding to requests to exercise data subject rights under Chapter III UK GDPR
  • assist you in complying with your obligations under Articles 32 to 36 UK GDPR, taking into account the nature of the processing and the information available to us
  • delete or return all Customer Personal Data at the end of the provision of services, at your choice, under clause 8
  • make available the information and allow the audits described in clause 7
  • maintain records of all categories of processing carried out on your behalf, as required by Article 30(2) UK GDPR

Where we receive a request directly from a data subject relating to Customer Personal Data, we will not respond to it substantively. We will forward it to you without undue delay and, where we can identify the relevant organisation, tell the data subject to contact you. The products include functionality allowing you to search, export, rectify, restrict and delete records, which in most cases will be enough for you to respond without our involvement.

We will not use Customer Personal Data for our own purposes. In particular, we will not use it to train, fine-tune, evaluate or develop any machine learning or artificial intelligence model, whether our own or a third party's. We will not sell, rent or licence it.

4. Your obligations as controller

You will:

  • comply with Applicable Data Protection Law in respect of Customer Personal Data
  • ensure your instructions are lawful and documented
  • configure the product appropriately, including user roles, permissions and retention settings
  • manage your own users' access, and remove access promptly when a user leaves
  • respond to data subject requests relating to Customer Personal Data
  • carry out any Data Protection Impact Assessment required by Article 35 UK GDPR
  • maintain your own Article 30(1) records
  • determine and apply appropriate retention periods for the records you hold, taking into account any statutory retention requirements in your sector

Retention is your responsibility. Several sectors we serve are subject to lengthy statutory record-retention requirements. The product provides retention and deletion tools; you decide how to configure them. We do not determine retention periods on your behalf.

You will not upload personal data outside the categories described in Schedule 2 for the relevant product without first informing us, so that we can confirm our measures remain appropriate.

5. Sub-processors

You give general written authorisation for us to engage sub-processors, subject to this clause. Our current sub-processors are listed in Schedule 4.

We will give you at least 30 days' notice before adding or replacing a sub-processor. You may object within 30 days of notice, on reasonable grounds relating to data protection. If you object, we will use reasonable efforts to make the product available without that sub-processor, or to offer an alternative. If we cannot do so within a reasonable period, you may terminate the affected subscription on written notice and receive a pro-rata refund of Fees for the unexpired part of the Subscription Term. That is your sole remedy.

We will impose on each sub-processor, by written contract, data protection obligations no less protective than those in this agreement. We remain fully liable to you for the performance of each sub-processor's obligations.

6. International transfers

Customer Personal Data is hosted in the United Kingdom or the European Economic Area.

We will not make a Restricted Transfer unless we have put in place an appropriate transfer mechanism: UK adequacy regulations covering the destination; the UK IDTA together with a transfer risk assessment; or another mechanism permitted by Applicable Data Protection Law.

Where the UK IDTA applies, the parties are deemed to have entered into it, with you as data exporter and the relevant recipient as data importer, and the information in the schedules to this agreement populating the corresponding tables. We will provide details of transfer mechanisms and transfer risk assessments on request.

7. Audit and information

We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR. We will satisfy audit requests in the first instance by providing our current security documentation and description of technical and organisational measures, and completed responses to your reasonable supplier assurance questionnaire.

We hold no third-party audit report, certification or penetration test summary. Where a customer requires one, that is a gap we will discuss before you subscribe rather than after.

Where that evidence is not sufficient to demonstrate compliance, you may audit us, or appoint an independent auditor who is not our competitor, subject to: at least 30 days' written notice, except following a personal data breach when 5 business days' notice applies; no more than one audit in any 12-month period, except where required by a Supervisory Authority or following a personal data breach; the audit being conducted during UK business hours without unreasonable disruption; the auditor signing a confidentiality undertaking; and the audit not extending to another customer's data or to information that would breach our confidentiality obligations.

You bear your own costs of an audit. We may charge our reasonable costs for on-site audits, except where the audit reveals a material breach of this agreement by us. Where a Supervisory Authority requires an audit or inspection, we will cooperate.

8. Deletion and return

During the Subscription Term you may export Customer Personal Data at any time using the product's export functionality.

On termination or expiry we will retain Customer Personal Data for 30 days to allow you to export it, and during that period you may request return in a structured, commonly used, machine-readable format. After that, we will delete it from live systems within a further 30 days, and from backups within 90 days of deletion from live systems, in line with our backup rotation.

You may instruct us in writing to delete or return Customer Personal Data earlier, at any time. We will certify deletion in writing on request. We may retain data where required by UK law, for as long as required and only for that purpose, and will continue to apply this agreement to it.

You are responsible for exporting records you are required by law to retain, before deletion occurs. Deletion under this clause is irreversible.

9. Personal data breach

We will notify you without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Our notification will include, to the extent known and progressively as more becomes known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information.

We will not make any public statement or notification to data subjects or a Supervisory Authority about a breach affecting Customer Personal Data without your prior written consent, unless legally required to do so.

We will cooperate fully and provide reasonable assistance to enable you to meet your obligations under Articles 33 and 34 UK GDPR, including your 72-hour reporting deadline. We will document all personal data breaches and make the record available to you on request.

10. Liability

Liability under this agreement is subject to the limitations in our Terms of Service, except that nothing limits either party's liability to a data subject or a Supervisory Authority under Applicable Data Protection Law.

Where both parties are liable for damage caused by processing, liability will be apportioned according to each party's responsibility under Article 82 UK GDPR.

11. General

This agreement takes effect on the Start Date and continues for as long as we process Customer Personal Data on your behalf. We may update it where necessary to reflect changes in Applicable Data Protection Law, guidance from a Supervisory Authority, or changes to the products; where a change materially reduces your rights we will give 30 days' notice. It is governed by the law of England and Wales.

Questions about this agreement, or a request for a signed copy: privacy@optixgroup.co.uk

Schedule 1 — Details of processing

Subject matterThe provision of the software services described in our contract.
DurationThe Subscription Term, plus the retention and deletion periods in clause 8.
Nature of the processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to Authorised Users, alignment, combination, restriction, erasure and destruction — by automated means through the product.
PurposeTo enable you to record, manage, monitor and report on the operational and compliance information relevant to your business, as described in Schedule 2.
Types of personal data and categories of data subjectAs set out in Schedule 2.

Schedule 2 — What this product processes

Special category and criminal offence data is called out where it applies. You must confirm your own Article 9 and Article 10 conditions, and your Schedule 1 Data Protection Act 2018 conditions, for any such processing — including an Appropriate Policy Document where one is required.

Data subjects: Scaffolders and inspectors; designers; client contacts; your staff.

Personal data: Name, contact details, CISRS card details, qualifications and competence records, inspection records and sign-offs, handover records and training records.

Special category data: Health information in accident records; fitness-for-work-at-height information.

Schedule 3 — Technical and organisational measures

Implemented in accordance with Article 32 UK GDPR. Every measure below is in place today.

Access control

  • Role-based access control, evaluated on the server on every request — the browser is never trusted to decide what a user may see
  • Each role's permissions are configurable by a customer administrator, and the server enforces the stricter of the customer's setting and the role default
  • Passwords are hashed by our identity provider using a modern algorithm, and are never stored in plaintext or written to logs
  • Sessions are carried in Secure, HttpOnly cookies, and signing out clears every session cookie
  • Access to production systems is limited to those who need it

Tenant isolation

  • Every database query runs inside a transaction scoped to the organisation derived from the authenticated session, enforced by the database rather than by application code
  • Organisation identifiers supplied by the browser are never trusted for authorisation
  • Record identifiers are validated against the authenticated organisation before a record is returned

Encryption

  • TLS 1.2 or above for all data in transit
  • Encryption at rest for databases, uploaded files and backups, provided by our database host

Resilience

  • Automated backups managed by our database provider, encrypted and held in the EEA
  • Uploaded documents are held in the same database as the records they belong to, so they inherit the same access controls and the same backup

Development and change management

  • Type checking and linting enforced before deployment
  • Separation of production and non-production environments
  • Production personal data is not used in development or test environments
  • Where error monitoring is used, it is configured to exclude personal data from error context

Organisational

  • Confidentiality obligations in staff and contractor contracts
  • Written contracts with all sub-processors meeting Article 28 requirements
  • A documented procedure for responding to a personal data breach

Measures not yet implemented

This schedule is a contractual warranty, not a statement of intent, so the following are listed separately rather than included above. They are on our roadmap and are not in place today.

  • Multi-factor authentication
  • Rate limiting and progressive delays on sign-in
  • A security audit log of authentication, permission and account changes, visible to customer administrators
  • Independent penetration testing, with summaries available to customers on request
  • Periodic tested restores from backup

We will update this schedule as each is delivered. If any of them is a procurement requirement for you, tell us before you subscribe rather than after.

Schedule 4 — Sub-processors

Sub-processorServiceData processedLocation
Vercel Inc.Application hosting and content deliveryAll Customer Personal Data in transit; technical request dataUK / EEA
Nile (Niledatabase, Inc.)Database hosting, uploaded files and backupsAll Customer Personal DataEEA (Frankfurt)
Stripe Payments Europe, Ltd.Payment processingBilling contact and card metadata only — no Customer Personal DataEEA, with onward transfer to the United States under the UK IDTA
Vercel Inc. (Web Analytics)Aggregate visitor measurement on our marketing sitesTechnical request data only — no cookie, no device identifierUK / EEA
Functional Software, Inc. (Sentry)Error monitoringTechnical error context, with personal data excluded by configurationEEA

This list is complete. We use no email service provider, because the platform sends no email; and no separate file-storage provider, because uploaded documents are stored in the same database as the records they belong to, inheriting the same access controls and the same backup.