Version 1.0 · in force from 2026-09-06
Effective date: 5 September 2026
1. Who this is between
This Agreement is between:
- CELCO GROUNDWORKS & CONSTRUCTION LIMITED, trading as CostTakeoff, a private company limited by shares registered in Ireland under company number 823396, with its registered office at 40 Bay Meadows Avenue, Dublin 15, D15 Y66T, Ireland ("we", "us", "our"); and
- the customer named in the signature block, or, where it is not signed, the account holder who accepts our Terms of Service ("you", "your").
It forms part of our Terms of Service and applies whenever we process personal data on your behalf. Where this Agreement and the Terms of Service conflict on the processing of personal data, this Agreement governs.
"GDPR" means Regulation (EU) 2016/679 and, where it applies, the UK GDPR. "Personal data", "controller", "processor", "sub-processor", "processing" and "supervisory authority" have the meanings given in the GDPR. "Your data" means personal data we process on your behalf under this Agreement.
2. Which of us is which
You are the controller. We are the processor. You decide what goes into the Service and why; we hold it and act on your instructions.
This is worth stating plainly, because the Service holds two different kinds of personal data and they are not in the same position:
- The data you put in — your clients' names and addresses, the people on your team, the contents of the documents you issue. You are the controller of that. We are your processor and this Agreement governs it.
- Your own account details — the email address you sign in with, your sign-in history, your subscription. We are the controller of that, because we decide to keep it in order to run a business with you. It is covered by our Privacy Policy, not by this Agreement.
Paddle.com Market Limited is a separate controller for your payment. It is not our sub-processor, we do not instruct it, and it is not covered by this Agreement.
3. What we do with your data, and what we do not
We process your data only:
- on your documented instructions, which are given by your use of the Service and by this Agreement and the Terms of Service; and
- where we are required to do so by Irish or European Union law, in which case we will tell you before processing unless that law forbids it.
We do not use your data for any purpose of our own. We do not use it to train models, to build products, to market to you or to anyone in it, and we do not sell it or share it for advertising.
Annex I sets out the subject matter, duration, nature and purpose of the processing, the categories of data subject and the categories of personal data.
If we think an instruction of yours breaches data protection law, we will tell you and may pause that processing until it is resolved.
4. Confidentiality
We keep your data confidential. Anybody who can reach it — which today means the people named in Annex I — is bound by a duty of confidentiality that survives the end of this Agreement, and has access only so far as their work requires.
5. Security
We take the technical and organisational measures set out in Annex II and keep them under review. Annex II describes what is in place, not what is planned.
6. Sub-processors
You give us general authorisation to appoint sub-processors. The current list is published at costtakeoff.com/legal/sub-processors and forms part of this Agreement.
Before we add or replace a sub-processor we will update that list and give you at least 30 days' notice by email to the address on your account. If you reasonably object on data protection grounds within those 30 days, tell us and we will either not make the change for your account or, if that is not possible, you may terminate the affected part of the Service and we will refund any fees you have paid for a period you have not used.
Each sub-processor is bound by written terms imposing obligations no less protective than those in this Agreement. We remain fully liable to you for a sub-processor's performance.
7. International transfers
Where a sub-processor is established outside the European Economic Area, we transfer your data to it only under a mechanism permitted by Chapter V of the GDPR — the European Commission's Standard Contractual Clauses, or an adequacy decision where one covers the transfer.
Annex III names each sub-processor established outside the EEA, says where your data actually rests, and states the mechanism relied on for that transfer. Where a provider is outside the EEA but your data rests inside it, Annex III says so, because the two are different facts.
8. Helping you meet your own obligations
Taking into account the nature of the processing and what we know:
- Requests from people whose data you hold. The Service lets you find, correct, export and delete that data yourself. Where a request reaches us instead, we will not answer it ourselves; we will pass it to you without undue delay. If you need help beyond what the Service offers, we will give reasonable assistance.
- Impact assessments and prior consultation. We will give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority, so far as it concerns our processing.
- Personal data breaches. If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware, with what we know at the time: what happened, which categories and roughly how many records are affected, the likely consequences and what we are doing. We will keep you informed as we learn more. We will not notify a supervisory authority or the people affected on your behalf unless you ask us to in writing.
⚠ These are two different duties that happen to share a number, and it is worth not confusing them. Article 33(2) of the GDPR requires a processor to notify the controller "without undue delay" and sets no fixed period; the 72 hours above is our own commitment to you, not a statutory deadline. Article 33(1) separately requires you, as controller, to notify your supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware". Your 72 hours runs from when YOU become aware — which, for a breach at our end, is when we tell you — not from when we became aware. They are not the same clock, and ours does not consume yours.
9. Return and deletion
At the end of the Service, or earlier if you ask:
- You can export everything you hold in the Service, at any time and free of charge, in a machine-readable form. That remains available throughout the read-only period described in our Terms of Service.
- We delete your data on the timetable set out in our Privacy Policy, and permanently once the recovery window in that policy has passed.
- Where Irish or European Union law requires us to keep something — invoices, credit notes and payment records — we keep only that, and we keep it protected and stop processing it for any other purpose. The period is six years: the Companies Act 2014 s.285 requires accounting records to be preserved "for a period of at least 6 years after the end of the financial year" to which they relate; the Value-Added Tax Consolidation Act 2010 s.84(3) requires invoices, credit notes and receipts to be retained "for a period of 6 years from the date of the latest transaction"; and the Taxes Consolidation Act 1997 s.886(4)(a)(i) requires records to be kept "for a period of 6 years after the completion of the transactions". Because the Companies Act period runs from the end of the financial year rather than from the document's own date, a document issued early in a financial year is covered for nearly seven calendar years. ⚠ In practice we keep these records indefinitely. Six years is the statutory minimum, not the point at which we delete: no timetable removes them, and they are deliberately left in place when an account is deleted. Keeping them beyond the statutory minimum is our own decision, not a legal requirement.
Backups are overwritten on their own cycle; the retention periods in our Privacy Policy describe it.
10. Audit
We will make available the information you reasonably need to show that we meet the obligations in Article 28 of the GDPR, and will allow and contribute to an audit conducted by you or an auditor you appoint.
An audit may be requested once in any twelve-month period, on 30 days' written notice, during business hours, subject to confidentiality, and must not disrupt the Service or expose another customer's data. If a supervisory authority requires an audit, that limit does not apply. You bear your own costs; you bear ours only if the audit finds a material breach of this Agreement, in which case we bear both.
11. Liability
Each party's liability under this Agreement is subject to the limitations and exclusions in the Terms of Service. Nothing in this Agreement limits either party's liability where the law does not allow it to be limited.
12. Duration, changes and law
This Agreement runs for as long as we process your data and ends when the last of it is deleted or returned. We may update it to reflect a change in the law or in how the Service works; we will give you at least 30 days' notice of a change that affects your rights, by email to the address on your account.
This Agreement is governed by the law of Ireland, and the courts of Ireland have exclusive jurisdiction.
Annex I — the processing
| Subject matter | Providing the CostTakeoff service: quantity takeoff from drawings, bills of quantities, quotations, invoices, payment claims and the documents produced from them |
| Duration | For as long as your account exists, and then for the retention periods in our Privacy Policy |
| Nature and purpose | Storing, organising, structuring, retrieving, displaying, exporting and deleting the data you put in, so that you can produce and issue your own documents. Backing it up. Nothing else |
| Categories of data subject | Your clients and their staff; the people on your own team who use the Service; anyone named in a drawing, a document or a message you create or upload |
| Categories of personal data | Names, business addresses, email addresses, telephone numbers, company and tax registration numbers of your clients; the contents of quotations, invoices, credit notes, claims and statements you create; the contents of drawings and files you upload; the names and email addresses of your team members and their activity in the Service |
| Special category data | None is required and none should be put into the Service. If you put it in, you do so as controller and on your own basis |
| Who can reach it | Our personnel, so far as their work requires; and the sub-processors in Annex III, for the purposes stated there. Today that is one person, who operates the Service on behalf of the company |
| Frequency | Continuous, for the duration of the Service |
Annex II — technical and organisational measures
These are the measures in place. They describe what is running, not what is intended.
Where it runs. The application, the database and the file store run on a single dedicated server operated by Hetzner Online GmbH in its Nuremberg data centre, Germany. The server is not shared with another tenant.
In transit. All traffic to the Service is over HTTPS with modern TLS. There is no unencrypted route in.
At rest. Off-site backups are encrypted on our own server before they are uploaded, so the storage provider holds ciphertext and never holds the key. The database dump is encrypted with AES-256 (PBKDF2, 200,000 iterations) as it is written, and only the encrypted file is uploaded; the drawing files go through a client-side encrypted remote that encrypts filenames as well as contents. The passphrase and the remote's key live on our own server, in files readable only by the operating-system account that runs the backup.
Access control. Sign-in to the Service is handled by Clerk, with an email address and a password. A sign-in from a device we have not seen before must be confirmed with a one-time code sent to the account's email address. Administrative screens and endpoints are gated on every request rather than at sign-in, by a check against a named list of addresses held in the server's configuration, or against an administrative token where one is presented; with nothing configured the check denies by default. Remote access to the server itself is over SSH, by key only — password authentication and password-based root login are disabled — and is limited to the person who operates the Service.
Separation. What a person may see is decided in one place: a single visibility rule applied by every route that lists or opens a job. A person reaches their own work, and their firm's work only through an active membership of that firm that somebody deliberately granted. Nothing is shared between accounts by default, by a migration, or as a side effect of any change we make.
Logging. We keep application error records, web-server logs and an audit record of administrative actions, to run and repair the Service and for no other purpose. The periods differ by kind and are stated here rather than rounded into one number: application error records are pruned after 30 days; web-server logs are rotated daily and kept for 14 days; the operating system's own journal is bounded by disk space rather than by time and in practice holds several months.
Resilience. Database backups are taken hourly and drawing-file backups daily, both off-site and encrypted as described above. ⭐ The restore path is exercised weekly, not assumed: an automated drill downloads the encrypted dump, decrypts it, restores it into a scratch database and compares it against the live one — row counts table by table and money totals as well. The most recent drill was 30 August 2026 and it matched live on every table it checked, including 757 invoices and a gross invoiced total of €1,528,035.36.
Deletion. Deletion in the Service is real. An account deletion opens a 30-day recovery window during which nothing is touched and one click restores everything; after it, projects, drawings, uploads and personal content are permanently deleted. Financial records are kept, for the statutory period described in clause 9.
Change management. Every change is version-controlled and every release is recorded against the exact commit it was built from. A release passes a chain of automated gates before it can go live — licence and secret scanning, a type and lint pass, a build, a check that the built identifier equals the commit, a migration-safety check against the code that is live at that moment, and a check that the served site answers and reports the new build. Any failure rolls the previous build back automatically, and the commit is pushed to the code repository only after the deploy is verified live, so the repository can only ever hold releases that actually shipped. ⚠ There is no second-person code review: the Service is written and released by one person, and the gates above are what stands in place of a reviewer.
People. The Service is operated by one person, who is bound by confidentiality and who is the only person with administrative access to it or to the server. Should that change, this Annex changes with it.
Annex III — sub-processors, where your data rests, and the transfer basis
The authoritative list is published at costtakeoff.com/legal/sub-processors. This Annex adds, for each, where the data actually rests and the basis for any transfer outside the EEA.
| Sub-processor | Established | Where your data rests | Outside the EEA? | Basis |
|---|---|---|---|---|
| Hetzner Online GmbH — hosting: the server that runs the application, the database and the file store | Germany | Nuremberg, Germany | No | Not applicable |
| Zoho Corporation B.V. — the mailbox that receives mail sent to costtakeoff.com | Netherlands | European Union | No | Not applicable |
| Backblaze, Inc. — off-site backups, encrypted before upload | United States | Amsterdam, Netherlands (the provider's EU region) | The provider is; the data is not | Standard Contractual Clauses under the provider's data processing addendum. The backups are encrypted with a key the provider does not hold |
| Resend, Inc. — sends the email we send you | United States | Sending infrastructure in the provider's EU region (AWS eu-west-1, Ireland); the provider's own operations are in the United States | The provider is; the sending infrastructure is not | Standard Contractual Clauses under the provider's data processing agreement |
| Clerk, Inc. — sign-in and account identity | United States | The provider's infrastructure, in Google Cloud and Cloudflare data centres. ⚠ The specific region configured for our account is not stated here because it has not been established — see the note below | Yes | The EU–US Data Privacy Framework, under which the provider is self-certified, with Standard Contractual Clauses as the fallback where the Framework cannot be relied on |
| Cloudflare, Inc. — protects the sign-in service against abuse | United States | Handled at the nearest point of the provider's global network | Yes | Standard Contractual Clauses, and the EU–US Data Privacy Framework where it applies |
⚠ What is not stated, and why. Our sign-in provider's own agreement says it hosts personal data "primarily in Google Cloud data centers and Cloudflare", and its transfer basis is stated above; the region configured for our particular account has not been established. It is not visible from the running service or from the provider's public interfaces, and nothing here will assert it before it is known. It would be settled by one of three things: the region field on our account in the provider's own dashboard, a written answer from the provider's support to a direct question, or the provider's data-residency documentation applied to our plan. When it is settled this row will say it. An unexplained transfer in a data processing agreement is worse than one whose limits are stated plainly.
Paddle.com Market Limited is not in this table. It is the Merchant of Record for your subscription and a separate controller for that payment, not our sub-processor. It is established in the United Kingdom, which is covered by a European Commission adequacy decision. We do not receive or store your card number.
Signature
Agreed on behalf of the processor:
CELCO GROUNDWORKS & CONSTRUCTION LIMITED, trading as CostTakeoff
Name: Hakan Celep Title: Director Date: ______________________________ Signature: ______________________________
Agreed on behalf of the controller:
Company: ______________________________
Name: ______________________________ Title: ______________________________ Date: ______________________________ Signature: ______________________________