DRAFT — not yet in effect. These documents are under review and are shown for evaluation only.

Lumanvio Data Processing Addendum (DPA)

Version 1.0 · Effective [EFFECTIVE DATE]

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Urban Builders Consulting Inc ("Lumanvio") and the Customer, and applies where Lumanvio processes Personal Data on Customer's behalf.

1. Roles and scope

  • Customer is the controller (or "business" under US state privacy laws) of Personal Data it submits to the Service — in particular data about its clients, leads, subcontractors, suppliers, and team members ("Customer Personal Data").
  • Lumanvio is the processor / service provider and processes Customer Personal Data only to provide the Service.
  • For Lumanvio's own account, billing and usage data, Lumanvio acts as an independent controller under its Privacy Policy.

2. Processing instructions

Lumanvio will process Customer Personal Data only: (a) to provide, secure and support the Service; (b) as documented in the Terms, this DPA and Customer's use of Service features (each feature use — sending a document, requesting a signature, running an AI extraction — is an instruction); and (c) as required by law, in which case Lumanvio will notify Customer unless legally prohibited.

Lumanvio will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain or use it outside the business purpose, or combine it with data from other sources except to provide the Service — and certifies it understands these restrictions (CCPA/CPRA service-provider terms).

3. Confidentiality

Persons Lumanvio authorizes to process Customer Personal Data are bound by confidentiality obligations.

4. Security

Lumanvio implements appropriate technical and organizational measures described in Annex B, including encryption in transit and at rest, per-tenant row-level access controls, and least-privilege access. Lumanvio will not materially decrease the overall security of the Service during a subscription term.

5. Subprocessors

  • Customer provides general authorization for the subprocessors listed at /subprocessors (Annex C).
  • Lumanvio will update that page at least 15 days before adding a new subprocessor [mechanism: page + email/in-app notice — CONFIRM]. Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, Customer may terminate the affected subscription with a pro-rata refund of prepaid fees.
  • Lumanvio remains responsible for its subprocessors' performance.

6. Assistance

Taking into account the nature of the processing, Lumanvio will reasonably assist Customer in:

  • responding to data subject requests (access, deletion, correction). The Service's built-in export, edit and delete tools are the primary mechanism; requests reaching Lumanvio directly from Customer's clients or workers will be forwarded to Customer;
  • meeting security, breach-notification and assessment obligations, considering the information available to Lumanvio.

7. Personal Data Breach

Lumanvio will notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration or unauthorized disclosure of Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.

8. Deletion and return

Upon account deletion or termination, Lumanvio deletes Customer Personal Data after the 30-day export window described in the Terms, except where retention is required by law. The Service's export tools allow Customer to retrieve data before deletion.

9. Audits

Upon written request (no more than once per year, absent a breach), Lumanvio will make available information reasonably necessary to demonstrate compliance with this DPA — security documentation and summaries of third-party attestations of its infrastructure providers. If this is insufficient, the parties will agree on a reasonable, confidential audit at Customer's expense.

10. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on data-protection matters, this DPA controls.


Annex A — Details of processing

Subject matter Providing the Lumanvio contractor-management platform
Duration Subscription term + 30-day deletion window
Nature and purpose Hosting, storage, transmission, display, PDF generation, e-signature capture, payment facilitation, AI-assisted extraction/transcription — to operate the Service
Categories of data subjects Customer's clients and prospects (leads), subcontractors, suppliers and their staff, Customer's team members, document signers
Categories of personal data Names, emails, phone numbers, job/site and business addresses, project and financial document data (estimates, invoices, bills, payments status), supplier tax IDs, signature images and audit data (IP, device, timestamp), photos and media that may contain identifiable persons, voice recordings submitted for transcription
Sensitive data Supplier tax identification numbers (may be SSNs for sole proprietors) — protected as described in Annex B

Annex B — Security measures (summary)

  • Encryption in transit (TLS 1.2+) and at rest (infrastructure-level AES-256)
  • Tenant isolation via database row-level security policies on every table and storage path
  • Private storage buckets with time-limited signed URLs for sensitive files (bills, jobsite media, plans, submittals)
  • Additional protection for tax IDs: masked display, reveal restricted to owner/admin roles
  • Authentication via Supabase Auth (hashed passwords, OAuth); session management with secure cookies
  • Least-privilege internal access; production access limited to authorized personnel
  • Signed-document integrity: SHA-256 hash captured at signature time; signed PDFs stored immutably
  • Infrastructure providers with SOC 2 attestations (see Subprocessors)
  • Backups with defined retention; deletion propagates on schedule

Annex C — Subprocessors

The current list is maintained at /subprocessors.

On this page

  • 1. Roles and scope
  • 2. Processing instructions
  • 3. Confidentiality
  • 4. Security
  • 5. Subprocessors
  • 6. Assistance
  • 7. Personal Data Breach
  • 8. Deletion and return
  • 9. Audits
  • 10. Liability and order of precedence
  • Annex A — Details of processing
  • Annex B — Security measures (summary)
  • Annex C — Subprocessors
LumanvioTermsPrivacyE-SignDPASubprocessorsDMCA