Legal

Data Processing Agreement.

This agreement applies where you use Architectt as a business — a firm, studio or practice — and put personal data about your own clients, occupants or staff into the platform. In that case you are the controller and Architectt is your processor under Article 28 GDPR. It is incorporated into the Terms of Service and needs no separate signature, though we will sign a countersigned copy on request.

Last updated
20 September 2026
Version
2.1
Applies to
architectt.com and all Architectt subdomains

In plain language

  • You decide what client data goes in; we only process it to run the service for you.
  • We keep the named subprocessor list public and tell you before it changes.
  • We notify you without undue delay if your data is ever breached, and help you answer client data requests.
  • On termination we return or delete the data on your instruction.

This summary is for orientation only. The numbered sections below are the binding text.

01Roles and subject matter

Controller: you, the business account holder. Processor: Architectt, Bredgade 45 B, 1260 København K, Kingdom of Denmark, VAT 45438031.

Subject matter: provision of the Architectt platform — Blueprint projects, project management, client portals and shares, messaging, file storage, architect reviews, notifications and email.

Duration: for as long as your account is active, plus the retention periods described in section 8.

02Categories of data and data subjects

Data subjects: your staff and collaborators, your clients and their representatives, and reviewers engaged on your projects.

Personal data: names, email addresses, roles, messages and comments, project briefs and site information, uploaded photographs and drawings that may show property or people, budget and expense records, and activity logs.

Architectt is not designed for special-category data under Article 9 or for children's data. Do not upload it.

03Processing only on your instructions

We process personal data only to provide and secure the service, to comply with law, and on your documented instructions — the configuration and actions you take in the product being those instructions. We do not use your client data for our own purposes, do not sell it, and do not use it to train AI models. If we believe an instruction breaches data-protection law, we will tell you and may pause that processing.

04Confidentiality and personnel

Access is limited to personnel who need it to operate or support the service, under confidentiality obligations, using individually authenticated accounts. Administrative actions on member data are recorded in an audit log.

05Security measures

We maintain measures appropriate to the risk, including:

  • encryption in transit (TLS) and at rest for stored data and files;
  • row-level access rules enforced in the database, so each account and each project role can reach only its own data;
  • role separation for administrative functions, with privileged operations restricted to service credentials;
  • secret management outside the codebase, with no credentials in source control;
  • signed, expiring links for shared project views, and token-based invitations instead of open URLs;
  • automated backups of the database, monitoring of scheduled jobs, and error and security scanning;
  • least-privilege review before any new subprocessor is enabled.

06Subprocessors

You authorise the subprocessors named in our subprocessor list. Each is bound by written terms no less protective than these. We update the list before a new subprocessor starts processing and notify business account holders by email at least 14 days in advance. If you reasonably object on data-protection grounds, you may terminate the affected service and receive a pro-rata refund of prepaid fees.

07International transfers

Some subprocessors are established outside the EEA, principally in the United States. Such transfers rely on the EU Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, and supplementary technical measures including encryption. Details for each recipient are in the subprocessor list.

08Assistance, breaches and audits

Data subject requests: if a data subject contacts us directly we refer them to you and do not answer on your behalf. We help you respond using export, correction and deletion tools in the product, and manually where the tools do not cover a request.

Breach notification: we notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information available at the time and updates as the picture becomes clearer.

Audit: on reasonable written request, and no more than once a year unless required by a supervisory authority, we provide the information needed to demonstrate compliance with this agreement.

09Retention, return and deletion

Active data is kept while your account is open. On termination, project data remains retrievable on written request for 30 days — we return it as files and structured exports — and is then deleted from live systems. Backups are overwritten on our hosting provider's cycle and in no case held longer than 35 days. Records we must keep for accounting, tax or dispute purposes — invoices, payout records, audit logs — are retained for the statutory period and nothing more.

You may request earlier deletion at any time, and we will confirm in writing when it is done.

10Precedence and changes

Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. Material changes are notified to business account holders at least 14 days before they take effect.

To request a countersigned copy, or to raise a processing question, write to hello@architectt.com.