1. Scope and roles
This DPA applies when FinishLedger processes personal data contained in Customer project content on behalf of the Customer. The Customer is the controller or equivalent responsible party and FinishLedger is the processor or service provider. Each party remains independently responsible for personal data it controls for its own account, legal, security, support or billing purposes.
Applicable Data Protection Law means laws governing the processing, privacy and security of personal data relevant to the services, including where applicable the UAE Federal Decree-Law No. 45 of 2021 and the EU or UK GDPR.
2. Documented instructions
FinishLedger will process Customer personal data only to provide, secure, support and improve the contracted service; comply with the agreement; and follow documented lawful Customer instructions. The agreement, configured project features and authorised support requests form the Customer’s instructions.
FinishLedger will inform the Customer if it reasonably believes an instruction violates applicable law, unless prohibited from doing so.
3. Confidentiality and personnel
FinishLedger will restrict access to people and providers who need it for the service and are bound by appropriate confidentiality obligations. Access will be removed when no longer required.
4. Security measures
- encrypted transport and managed encryption at rest where provided by infrastructure services;
- managed authentication and password handling;
- company and project separation through database row-level policies and scoped application roles;
- private file buckets and controlled signed access;
- access revocation, audit timestamps and activity records;
- controlled production access, dependency maintenance and privacy-scrubbed error monitoring;
- backup and recovery capabilities supplied by contracted infrastructure tiers;
- incident investigation and remediation procedures.
Security measures may evolve to maintain or improve protection without materially reducing overall security.
5. Subprocessors
The Customer authorises the subprocessors listed at finishledger.com/legal/subprocessors. FinishLedger remains responsible for their processing to the extent required by law and its Customer agreement.
FinishLedger will post material changes to the list and, for commercial Customers who provide a legal notice email, give reasonable advance notice where practicable. A Customer may object on reasonable data-protection grounds. The parties will work in good faith on an alternative; if none is reasonable, the affected service may be terminated according to the agreement.
6. Data-subject and compliance assistance
Taking account of the nature of processing, FinishLedger will reasonably assist the Customer with verified rights requests, security obligations, impact assessments, regulator consultations and records needed to demonstrate compliance. The Customer remains responsible for responding to people and determining whether a request is valid.
If FinishLedger receives a request concerning Customer project data, it will direct the requester to the Customer unless legally required to respond.
7. Personal-data incidents
FinishLedger will notify the Customer without undue delay after confirming a personal-data breach affecting Customer project data. The notice will include available information about the nature, likely consequences, affected data, mitigation and contact point. Early information may be incomplete and may be updated.
Notification is not an admission of fault or liability. The Customer is responsible for regulator and individual notifications unless law assigns that duty to FinishLedger.
8. International transfers and government requests
Processing locations and transfer mechanisms must be recorded in the order form where required. When restricted personal data is transferred internationally, FinishLedger will use an available lawful mechanism such as approved contractual clauses or another recognised safeguard.
FinishLedger will review government demands, disclose only what is legally required, and notify the Customer where permitted.
9. Return, export, retention and deletion
During the agreement, the Customer may use available exports and request reasonable assistance with return of project data. On termination or valid instruction, FinishLedger will delete or return Customer project data, subject to agreed archive periods, technical backup rotation and legal retention requirements.
Where data remains in backups, it will remain protected and unavailable for ordinary use until deleted through the backup lifecycle.
10. Processing details
| Subject matter | Location-based construction completion, workforce, issue, evidence, material, reporting and collaboration records |
| Duration | For the Customer agreement and agreed archive/deletion period |
| People | Customer staff, project owners, managers, engineers, consultants, contractors, subcontractors, site workers, invitees, external ticket recipients and contacts |
| Data | Identity, business contact, role, project access, operational activity, location, workforce allocation, comments, issue responses, photos/files, timestamps, page presence and audit history |
| Sensitive data | Not intended. Customers must not upload special-category or highly sensitive data unless specifically agreed and lawfully controlled. |
| Frequency | Continuous during authorised service use |
| Customer instructions | The signed agreement, configured features and authorised support requests |
Questions or a signed DPA request: hello@finishledger.com.