Data protection

Data processing agreement (DPA)

Last updated: June 2026

This agreement under Art. 28 GDPR governs the processing of personal data by the Provider on behalf of the customer when using BauKIT. It forms part of the user agreement.

This English translation is provided for convenience only. The German version is legally binding; in case of any discrepancy, the German version prevails.

§ 1 Subject matter, roles and duration

  1. (1)The customer is the controller under data protection law ("Controller") for the personal data it processes via BauKIT, in particular the data contained in uploaded plans and input. Devion Digitalagentur Wienis the processor ("Processor") in this respect.
  2. (2)The subject matter is the processing of personal data to provide the services described in the terms and conditions (AI-assisted quantity takeoff and preparation of bills of quantities from permit plans).
  3. (3)The duration of processing corresponds to the term of the user agreement plus the agreed deletion/return periods.

§ 2 Nature, purpose, types of data and data subjects

Nature and purpose of processing: storage, retrieval, analysis and processing of plan data and input for the automated preparation of quantity takeoffs and priced bills of quantities, including transfer to the sub-processors listed in § 6.

Types of personal data (typically):

  • Contact and account data of the customer or its users (e.g. name, email)
  • Company/staff data (e.g. company name, address, VAT ID)
  • third-party data contained in plans (e.g. name and address of building owners, plot details, details of the plan author)
  • content entered freely in chat/input fields

Categories of data subjects: the customer’s users, building owners or clients, plan authors and other persons named in the documents.

Processing of special categories of personal data (Art. 9 GDPR) is not intended; the customer does not upload such data.

§ 3 Controller’s right to issue instructions

  1. (1)The Processor processes the data only on documented instructions from the Controller, unless required to do so by Union or Member State law.
  2. (2)The customer’s contractual use of the Service counts as a documented instruction. Additional individual instructions must be sent in text form to office@baukit.at.
  3. (3)If the Processor considers an instruction to be unlawful, it informs the Controller and is entitled to suspend its execution until confirmed.

§ 4 Obligations of the Processor

  • Processing only on instructions, and confidentiality: persons authorised to process the data are bound to confidentiality.
  • Implementation of appropriate technical and organisational measures under Art. 32 GDPR (see § 5).
  • Assistance to the Controller with data subject rights and data protection obligations (Art. 32–36 GDPR) as far as possible.
  • Assistance in handling requests from data subjects for access, rectification, erasure and restriction.
  • Deletion or return of the data after termination (see § 10).
  • Provision of the information needed to demonstrate compliance (see § 11).

§ 5 Technical and organisational measures (TOM)

  1. (1)The Processor takes appropriate technical and organisational measures to protect the data, in particular: transport encryption (TLS), access control via authentication and role-based permissions, tenant separation, storage in secured cloud infrastructure and selection of sub-processors that comply with data protection law.
  2. (2)The detailed measures are described in a separate TOM document, which is provided on request and updated in line with the state of the art.

§ 6 Sub-processors

  1. (1)The Controller consents to the use of the sub-processors listed below. Contracts that ensure a level of data protection in line with Art. 28 GDPR are in place or will be concluded with each sub-processor.
  2. (2)The Processor informs the Controller in text form in good time of any intended changes (addition or replacement); the Controller may object for an important reason relating to data protection.

Anthropic PBC (Claude)

· USAThird country
Purpose
AI processing of plan and chat data (analysis of permit plans, quantity takeoff, answers).
Data
Text extracted from the plan and rendered plan sections (images), chat input; may contain personal data (e.g. name/address of the client shown on the plan).
Safeguard
Data processing agreement (DPA) with EU Standard Contractual Clauses (SCC); processing via the commercial API without use of the data for model training.

OpenAI, L.L.C.

· USAThird country
Purpose
Generation of vector embeddings for searching the construction work item catalogue.
Data
Search text snippets (descriptions of construction work); as a rule no personal data.
Safeguard
DPA with EU Standard Contractual Clauses (SCC); API data is not used for model training.

Supabase Inc.

· EU
Purpose
Database, file storage and authentication: storage of accounts, conversations, transcripts, results and uploaded plans.
Data
Account data (email), company profile, uploaded plans, conversation and result data.
Safeguard
Processing in the EU; data processing agreement (DPA) with Supabase.

Stripe Payments Europe, Ltd. / Stripe, Inc.

· Ireland / USAThird country
Purpose
Payment processing and subscription/billing management.
Data
Email, customer/payment identifiers, plan/billing data (payment details are collected and processed directly by Stripe).
Safeguard
DPA with Stripe; EU Standard Contractual Clauses (SCC) for transfers to the USA. Stripe is partly an independent controller for payment data.

Railway Corp.

· EU
Purpose
Hosting and execution of the backend application (containers).
Data
Data arising temporarily during processing (including uploaded plans in memory/cache).
Safeguard
Processing in the EU; data processing agreement (DPA) with Railway.

Vercel Inc.

· USA (global CDN)Third country
Purpose
Hosting and delivery of the web interface (frontend).
Data
Technical connection data (e.g. IP address, browser data) needed to deliver the page.
Safeguard
DPA with Vercel; EU Standard Contractual Clauses (SCC) for transfers to the USA.

Resend (resend.com)

· USAThird country
Purpose
Sending transactional emails (e.g. enquiries via the website).
Data
Name, email address and content of the message.
Safeguard
DPA with Resend; EU Standard Contractual Clauses (SCC) for transfers to the USA.

§ 7 Transfers to third countries

Where data is transferred to sub-processors outside the EU/EEA (marked as "third country" in the list, including the USA), this is done on the basis of appropriate safeguards under Art. 46 GDPR, in particular the EU Standard Contractual Clauses (SCC), supplemented by any additional measures required. The specific safeguards for each provider are documented in the respective data processing agreements (DPA).

§ 8 Assistance and data subject rights

If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without delay. The Processor assists the Controller with appropriate technical and organisational means in fulfilling data subject rights (access, rectification, erasure, restriction, data portability, objection).

§ 9 Notification of personal data breaches

The Processor informs the Controller without delay after becoming aware of a personal data breach affecting the data covered by this agreement, and provides the information needed to meet the notification and communication obligations (Art. 33, 34 GDPR).

§ 10 Deletion and return after termination

  1. (1)After processing has ended, the Processor deletes the personal data or, at the Controller’s choice, returns it, unless a statutory retention obligation applies.
  2. (2)The customer can delete conversations and uploaded plans in the Service; deletion covers the related files and database entries. Data may remain in backups for a limited period of up to 30 days and is then overwritten.

§ 11 Evidence and audits

The Processor provides the Controller with the information needed to demonstrate compliance with the obligations under Art. 28 GDPR and allows reasonable audits, provided this does not disproportionately impair business operations. Evidence may also be provided through suitable certifications or reports of the sub-processors.

§ 12 Final provisions

  1. (1)In the event of conflicts between this DPA and the terms and conditions, the provisions of this DPA take precedence with regard to data processing.
  2. (2)Austrian law applies; otherwise the final provisions of the terms and conditions apply accordingly.

Provider / contact

Devion Digitalagentur Wien · Wien, Austria · office@baukit.at