Data Processing Agreement
How we handle your data.
Our UK GDPR commitments as your processor.
1. Parties and scope
AAA BuildOps is provided by Hamiltonn Cloud (“Hamiltonn Cloud”, “we”, “us”). Hamiltonn Cloud is the cloud-platform brand of Hamiltonn Ltd, registered in England and Wales, company number 15023569, registered office Flat 1, 117 Station Road, Edgware, London HA8 7JG. AAA BuildOps is the name of the product; Hamiltonn Cloud is the company that provides it and with which you contract.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Hamiltonn Cloud (the “Processor”) and the company that subscribes to AAA BuildOps (the “Controller”). It applies to all personal data in Customer Data that the Processor processes for the Controller in providing the service (“Personal Data”). “UK GDPR” means the UK General Data Protection Regulation and the Data Protection Act 2018. Terms such as “controller”, “processor”, “personal data” and “personal data breach” have their UK GDPR meanings.
2. Roles and instructions
The Controller decides why and how the Personal Data is used; the Processor processes it only on the Controller's documented instructions, which are these Terms, this DPA and the Controller's use of the service's features. The Processor tells the Controller if it believes an instruction breaks the law. Where the Processor uses information about the Controller's account for its own purposes (billing, security, accounts), it acts as a controller; see the Privacy Policy.
3. Details of the processing
| Item | Description |
|---|---|
| Subject matter and nature | Hosting and operating AAA BuildOps for the Controller: storing, retrieving, displaying, transmitting, backing up and deleting data; AI-assisted processing of content the Controller's users submit to AI features |
| Purpose | Providing, securing and supporting the service |
| Duration | The subscription, plus the retention periods in section 9 |
| Data subjects | The Controller's staff, workers and subcontractors; its customers and prospects and their contacts; its suppliers; other people named in documents |
| Types of data | Names, contact details, addresses and postcodes; job and site information; photographs; attendance records including GPS location at clock-in and clock-out; pay and bank details of workers; identity and compliance documents the Controller uploads; quotations, contracts, invoices and receipts; messages and notes |
| Special category data | None is requested. The Controller must not upload special category or criminal-offence data except where it needs to for its legal duties |
4. Staff and confidentiality
The Processor's staff who can reach Customer Data are bound by confidentiality and limited to what they need. Access to a customer's site by the Processor is only through a named, time-limited support session with a recorded reason, which the Controller's owner can see and end at any time.
5. Security
The Processor applies technical and organisational measures appropriate to the risk, including:
- each customer's data in its own isolated site and database;
- encryption in transit (HTTPS) and encrypted backups (AES-256);
- sign-in with a password policy and a required authenticator code, a lock-out after repeated failures, and sessions that expire;
- role-based and job-scoped access inside each company, with an audit trail of changes;
- an administration console protected by multi-factor sign-in, role checks and a recorded reason for every action;
- monitoring, nightly backups, regular tested restores, and software released only after automated testing.
6. Sub-processors
The Controller authorises the sub-processors below. The Processor gives at least 30 days' notice, by email to the owner, before adding or replacing one; the Controller may object on reasonable data-protection grounds within that time, and if the objection cannot be resolved may cancel without penalty. The Processor stays responsible for its sub-processors and binds them to terms that give the same protection as this DPA.
| Sub-processor | What it does | Location |
|---|---|---|
| IONOS Cloud (IONOS SE) | Hosting of the servers and storage | London, United Kingdom |
| IONOS (email service) | Delivery of emails sent by the platform | United Kingdom |
| AI model providers: Anthropic, OpenAI, Google | Answering requests to AI features (contract checks, receipt reading, bank matching, accounting assistant, site reports). Only the content of the request is sent, through the Processor's AI gateway | Outside the UK (safeguards in section 8) |
This list is subject to final operator confirmation before public launch.
Stripe processes payment details for the Processor's own billing and is not given Customer Data. If the Controller chooses to connect its own messaging bot or service, that is the Controller's own supplier, not a sub-processor of the Processor.
7. Helping the Controller
Taking account of the nature of the processing, the Processor helps the Controller to answer requests from data subjects (the Controller can export, correct and delete records itself; the Processor helps where it cannot), to carry out data-protection impact assessments, and to deal with the regulator. The Processor tells the Controller without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting Personal Data, with the information the Controller needs to meet its own duties.
8. International transfers
The sites are hosted in the United Kingdom. Where Personal Data is sent outside the UK (to the AI providers above), the Processor relies on an adequacy decision or on the UK addendum to the standard contractual clauses or the International Data Transfer Agreement, and tells the Controller on request which applies.
9. Backups, return and deletion
- Each customer site is backed up every night, in encrypted form. We keep the most recent 14 scheduled copies, 10 manual copies and 5 copies taken before software releases; older copies are removed in rotation. A further encrypted copy is kept on a separate machine that we control.
- When the subscription ends the site is closed and the data is kept for at least 30 days, during which the Controller can ask for an export. After that the site is deleted once the Controller or the Processor schedules deletion.
- When a site is deleted, its encrypted backups are kept for 90 days after the deletion, so that a deletion made in error can be reversed. They are then securely deleted, including the copy kept on a separate machine, and only a record of what was deleted (names, sizes and checksums, never contents) remains. They are kept longer only while a legal hold, a dispute, a regulatory or accounting requirement, or an explicit decision of the Processor applies. The Processor deletes them earlier when the Controller asks in writing.
- The Processor deletes or returns Personal Data at the Controller's choice when the service ends, unless the law requires it to be kept.
10. Audits
The Processor makes available the information needed to show it complies with Article 28 of the UK GDPR and allows reasonable audits by the Controller or an auditor it appoints, with reasonable notice, during working hours and without disrupting other customers.
11. Liability and law
Liability under this DPA is subject to the limits in the Terms of Service. This DPA is governed by the laws of England and Wales; if it conflicts with the Terms of Service on the handling of Personal Data, this DPA prevails.
12. Contact
Data-protection questions: support@aaabuildops.com. Last updated 5 October 2026.