Data Processing Addendum
Effective August 13, 2026
Changed on August 13, 2026: Section 6.1 now gives notice of a new or replaced subprocessor by publication to Annex C and the subprocessors page, rather than 30 days' advance notice by email or in the Service. Section 6.2 now gives Customer an unconditional right to terminate and receive a refund of prepaid unused fees following any subprocessor change, and allows Constructo to delete Customer Personal Data promptly in that case rather than following the standard Section 10.3 process. The previous version was effective August 11, 2026.
This Data Processing Addendum ("DPA") forms part of the Planlyx Terms of Service (the "Agreement") between Constructo, Inc. ("Constructo") and the subscribing firm ("Customer"). It governs Constructo's processing of Customer Personal Data in providing the Planlyx service (the "Service"). This DPA is incorporated into the Agreement automatically; no signature is required. A countersigned copy is available on request to legal@constructo.online.
1. Definitions
"Applicable Privacy Laws" means the United States federal and state privacy laws that apply to a party's processing of Customer Personal Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act, Cal. Civ. Code § 1798.100 et seq., and its regulations ("CCPA"), and comparable comprehensive state privacy laws.
"Customer Personal Data" means personal information that Constructo processes on Customer's behalf in providing the Service — information relating to Customer's clients, vendors, prospects, enquiry submitters, correspondents, and other individuals whose information Customer or its users submit to the Service, as further described in Annex A. It does not include Business Contact Data.
"Business Contact Data" means information Constructo processes for its own purposes as an independent business: Customer's account registration details, the identity and contact information of Customer's account users in their capacity as Constructo's own users, billing information, and Constructo's records of its relationship with Customer. Constructo's processing of Business Contact Data is described in the Planlyx Privacy Policy, not this DPA.
"Security Incident" means a confirmed breach of Constructo's security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
"Personal information," "business," "service provider," "sell," "share," "business purpose," and "consumer" have the meanings given in the CCPA; equivalent terms in other Applicable Privacy Laws (such as "controller" and "processor") are construed accordingly.
2. Roles and scope
2.1 For Customer Personal Data, Customer is the business (controller) and Constructo is Customer's service provider (processor). Constructo processes Customer Personal Data only to provide the Service under the Agreement and Customer's instructions given through the Service's features and settings, and for no other purpose.
2.2 United States scope. The Service is designed to process the personal information of individuals located in the United States, and this DPA addresses United States law only. Customer warrants that it will not cause Customer Personal Data of individuals located outside the United States to be processed through the Service, and Customer is solely responsible for any consequences of doing so. This DPA does not incorporate the GDPR, UK GDPR, standard contractual clauses, or any non-U.S. transfer mechanism.
3. Constructo's obligations as service provider
Constructo certifies that it understands and will comply with the following restrictions. Constructo will not:
- (a) sell or share Customer Personal Data;
- (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in Annex A, or as otherwise permitted for service providers under Applicable Privacy Laws;
- (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Constructo and Customer; or
- (d) combine Customer Personal Data with personal information received from another customer or collected from Constructo's own interaction with a consumer, except as permitted for service providers under Applicable Privacy Laws (for example, to detect security incidents or protect against fraudulent or illegal activity).
Constructo will provide the same level of privacy protection for Customer Personal Data as Applicable Privacy Laws require of Customer; will notify Customer without undue delay if it determines it can no longer meet its obligations under Applicable Privacy Laws; and, upon such notice, Customer may take reasonable and appropriate steps under Section 8 and may direct Constructo to stop and remediate any unauthorized use.
4. Customer's obligations
Customer is responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was acquired, including the warranties for imported contact lists in the Agreement; (b) providing all notices and obtaining all consents or authorizations that Applicable Privacy Laws require of Customer for the processing contemplated by the Agreement, including notices to individuals who submit Customer's enquiry forms; (c) its instructions to Constructo complying with law; and (d) its own compliance with laws governing its communications with individuals, including the CAN-SPAM Act.
5. Requests from individuals
5.1 Routing. If Constructo receives a request from an individual to exercise a privacy right (access, deletion, correction, portability, or similar) concerning Customer Personal Data, Constructo will not respond substantively except to inform the individual that the request has been forwarded, and will forward the request to Customer promptly.
5.2 Assistance. Taking into account the nature of the processing, Constructo will provide reasonable assistance to Customer in responding to verified consumer requests, using the Service's existing features where possible (record access, correction of contact records, project-record export, and — for deletion — the mechanism in Section 10.3). Customer remains responsible for verifying and responding to requests concerning Customer Personal Data.
6. Subprocessors
6.1 Customer generally authorizes Constructo to engage the subprocessors listed in Annex C to process Customer Personal Data for the purposes described there. Constructo will keep Annex C and the subprocessor list published on its website (currently planlyx.com/legal/subprocessors) current, updating both to record the date and nature of any addition or replacement of a subprocessor that processes Customer Personal Data. That publication is Constructo's notice to Customer of the change; Constructo does not separately notify Customer by email or in the Service before making it.
6.2 If Customer does not wish to continue using the Service following a change to the subprocessor list, Customer may terminate the Agreement for that reason at any time and receive a refund of prepaid unused fees. Upon a termination under this Section 6.2, Constructo may promptly delete Customer Personal Data — or, where a record structure is append-only or write-once by design and cannot be erased without compromising the integrity of the records of others, de-identify it — without waiting for the written request or the 90-day period described in Section 10.3, in order to end Customer Personal Data's exposure to the new subprocessor.
6.3 Constructo will bind each subprocessor by written contract to data-protection obligations no less protective than this DPA as applicable to the services it performs, and Constructo remains responsible for its subprocessors' performance.
7. Security
Constructo will implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of Customer Personal Data, as described in Annex B, and will ensure that personnel with access to Customer Personal Data are subject to confidentiality obligations. Constructo may update Annex B from time to time, provided the changes do not materially reduce the overall protection of Customer Personal Data.
8. Audits and oversight
Customer may take reasonable and appropriate steps to ensure that Constructo uses Customer Personal Data consistently with Customer's obligations under Applicable Privacy Laws. Upon written request no more than once in any 12-month period, Constructo will make available information reasonably necessary to demonstrate compliance with this DPA — documentation of its practices, its subprocessor list, and written responses to a reasonable security questionnaire. Any further audit will be subject to reasonable scope, timing, confidentiality, and cost arrangements agreed in advance, will not extend to other customers' data, and will be at Customer's expense unless it reveals material non-compliance.
9. Security Incidents
Constructo will notify Customer without undue delay after becoming aware of a Security Incident, and will provide, as information becomes available: a description of the incident and the categories and approximate volume of Customer Personal Data affected; the measures taken or planned to address it; and a contact point. Constructo will take reasonable steps to contain and remediate the incident and will cooperate with Customer's reasonable requests for information. Constructo's notification is not an admission of fault. Customer is responsible for any notification to individuals or regulators that Applicable Privacy Laws require of Customer as the business.
10. Retention, deletion, and return
10.1 During the term. Constructo retains Customer Personal Data for as long as the Agreement is in effect, in accordance with the Service's design — including its append-only activity records, message logs, and write-once approval records, whose retention and immutability are disclosed features of the Service that preserve the evidentiary integrity of Customer's project records.
10.2 Export. Customer may export project records through the Service's export features at any time during the term and during the post-termination access period described in the Agreement.
10.3 Deletion on request after termination. Upon Customer's written request made after termination or expiration of the Agreement, Constructo will, within 90 days of the request, delete Customer Personal Data or, where a record structure is append-only or write-once by design and cannot be erased without compromising the integrity of the records of others, de-identify the Customer Personal Data within it so that it no longer identifies any individual. The following are excepted from deletion: (a) data Constructo must retain to comply with legal obligations, resolve disputes, or enforce agreements, which will be retained only as long as needed for those purposes and remain protected by this DPA; and (b) residual copies in backup systems, which are deleted in the ordinary course of backup cycling (currently a seven-day window). On written request, Constructo will confirm completion of deletion.
10.4 Absent a request. If Customer makes no deletion request, Constructo retains Customer Personal Data in accordance with the Planlyx Privacy Policy, protected at all times by this DPA's restrictions.
11. General
11.1 This DPA is effective for as long as Constructo processes Customer Personal Data. Sections 3, 9, 10, and 11 survive termination of the Agreement until processing ceases.
11.2 This DPA is subject to the limitations of liability in the Agreement; each party's liability arising out of this DPA counts toward, and is capped by, those limitations.
11.3 If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls. If a provision of this DPA is unenforceable, the remainder stays in effect, and the parties will replace the unenforceable provision with an enforceable one that most closely achieves its intent.
11.4 Constructo may update this DPA as reasonably necessary to reflect changes in Applicable Privacy Laws or the Service, with notice as provided in the Agreement; updates will not materially reduce the protection of Customer Personal Data.
Annex A — Details of processing
Nature and purpose of processing. Hosting, storage, organization, display, transmission, and retrieval of Customer Personal Data as necessary to provide the Service: sales pipeline and contact management; project management; drawing storage, versioning, review, and comment; revision-round and change-order workflow; proposal and invoice generation; client-portal access; sending and receiving email on Customer's behalf, including commercial outreach initiated by Customer; enquiry-form intake; maintenance of append-only activity and approval records; abuse prevention on Customer's public forms; and support, security, and troubleshooting of the Service.
Business purposes (CCPA § 1798.140(e)). Performing services on behalf of Customer, including maintaining and servicing accounts, providing customer service, processing transactions, and providing similar services; helping to ensure security and integrity; debugging to identify and repair errors; and short-term transient use.
Duration. The term of the Agreement, plus the period until deletion or de-identification under Section 10.
Categories of individuals. Customer's clients and their co-reviewers; Customer's vendors and consultants; prospects and other sales contacts imported or entered by Customer; individuals who submit Customer's enquiry forms (including submissions rejected by abuse-prevention checks); individuals who correspond with Customer at its Service email address; and other individuals referenced in content Customer's users enter into the Service.
Categories of personal information. Identifiers and contact details (name, email address, telephone number, organization, postal address where entered); professional and commercial information (deals, proposals, change orders, invoices, project participation, approval records); communications content (messages, comments, email bodies and attachments, prospect replies); free-text notes entered by Customer's users; approval metadata (for proposal approvals, the approver's IP address and browser user-agent captured at the moment of approval); and hashed IP addresses recorded on Customer's public forms for abuse prevention.
Sensitive personal information. The Service does not request or require sensitive personal information. Customer should not submit it; if Customer's users include it in free-text content or files, it is processed only as content within the categories above.
Annex B — Security measures
- Authentication is by emailed one-time sign-in link; the Service stores no passwords. A team member or vendor gains access only upon acceptance of an invitation; clients reach the portal for a project once the Customer invites them.
- Tenant segregation between customers is enforced at the database layer through row-level security tied to authenticated identity, not solely in application code.
- Role-based access within an account (Owner, Team member, Vendor, Client) restricts each user to permitted records; client-portal reads pass through restricted database functions that return only permitted fields.
- File storage is private; project files are accessible only through short-lived signed URLs.
- Encryption in transit via TLS for connections to the Service. Encryption at rest is provided by the infrastructure platforms on which the Service runs.
- Record integrity: activity records are append-only and message content is immutable once recorded, both enforced by database constraint; attachments delivered with a message are attached when they arrive. Approval records are write-once.
- Backups: point-in-time recovery is enabled on the production database with a seven-day window; restoration has been exercised and verified.
- Public-interface protection: rate limiting and automated-submission checks on all public forms; submitter IP addresses stored only as salted one-way hashes.
- Personnel access to customer accounts is through a support console; every account-affecting action by Constructo personnel is recorded both in an internal ledger and in the affected customer's own visible activity record.
- Infrastructure account security: multi-factor authentication is enforced on Constructo's own infrastructure provider accounts.
Annex C — Subprocessors
| Subprocessor | Entity | Function | Data processed |
|---|---|---|---|
| Vercel | Vercel Inc. (US) | Application hosting and scheduled jobs | Request traffic and runtime logs |
| Supabase | Supabase Inc. (US) | Database, authentication, file storage | All Customer Personal Data stored in the Service |
| Resend | Resend Inc. (US) | Email transmission and receipt | Email sent and received through the Service, including bodies and attachments |
| Stripe | Stripe Inc. (US) | Subscription billing | Customer billing data (Business Contact Data; listed for transparency) |
| Cloudflare (Turnstile) | Cloudflare Inc. (US) | Automated-abuse prevention on public forms | Visitor IP address and browser signals |
| Anthropic | Anthropic PBC (US) | The in-app assistant in the help panel | Messages typed into the assistant and the conversation they belong to; passages from Constructo's own help guides; for subscription questions, the firm's plan name, subscription status, trial end date and active-project counts |
About the assistant subprocessor. Constructo's agreement with Anthropic PBC prohibits training models on data submitted through it. Anthropic deletes submitted inputs and outputs within 30 days, except where content is flagged under its usage policy, in which case it may be retained for up to two years. No project files, plan sets, drawings, comments, client messages, invoices or contact records are transmitted to it. Constructo deletes its own copy of each conversation 12 months after the conversation's last message.
Contacted by the end user's browser, not by Constructo. One flow reaches a third party directly from the user's device rather than from our servers, so Constructo does not transmit the data in it: address suggestions (as a user types into an address field, the typed text goes from their browser to Photon, operated by Komoot GmbH (Germany)). This is disclosed in the Planlyx Privacy Policy. Because this request is made by the user's own browser and not by Constructo's servers, Komoot GmbH is not a subprocessor and does not appear in the table above.
(Until 2026-08-09, a project-location map embedded a frame served by the OpenStreetMap Foundation, and Constructo's own servers separately queried Photon to convert a saved project address into map coordinates — which did make Komoot GmbH a subprocessor for that flow. Both the map and the server-side geocode were removed on 2026-08-09; neither service receives anything from Constructo now.)
The current subprocessor list is maintained at planlyx.com/legal/subprocessors.
Questions about this document: legal@constructo.online