
Legal
The terms Kinetic Build Limited provides Kinetic Project and Kinetic BIM Standard and Kinetic BIM Pro under, and how we handle the data you keep in them.
Draft — not yet legally reviewed. These documents were prepared in-house and describe how the service actually works today, but they have not been reviewed by a lawyer. Don't rely on them as a final statement of your rights, and don't sign a customer up against them until that review has happened.
Data Processing Addendum
This addendum applies whenever Kinetic Build Limited (we) processes personal information on behalf of a customer organisation (you) in the course of providing Kinetic Project and Kinetic BIM Standard and Kinetic BIM Pro. It forms part of the Terms of Service. Where this addendum and the Terms of Service conflict on the handling of personal information, this addendum wins.
1. Roles
You determine what personal information goes into the Service and why. We process it only to provide the Service to you. In New Zealand terms, the information remains held by you as the agency, and we hold it solely as your agent under section 11 of the Privacy Act 2020. Where the GDPR or UK GDPR applies, you are the controller and we are the processor.
You are responsible for the lawfulness of what you put in — including having told your own staff and clients that you use a system like this, and having any consent your own obligations require.
2. Processing on your instructions
We process personal information only on your documented instructions. Your use of the Service, including its configuration and the integrations you connect, is your instruction. We will not process it for our own purposes, and specifically we will not use it for advertising, sell it, or use it to train machine-learning models.
If we believe an instruction breaches privacy law, we will tell you rather than simply carry it out. If we are legally required to process personal information beyond your instructions, we will tell you first unless the law forbids that.
3. Our people
Access to your data is limited to those who need it to provide or support the Service, and everyone with access is under a binding duty of confidentiality that survives the end of their engagement.
4. Security
We maintain the technical and organisational measures set out in Annex B. We may change them, provided the level of protection is not reduced.
5. Subprocessors
You give general authorisation for us to engage the subprocessors listed on the subprocessor page. We impose data protection obligations on each of them no less protective than those in this addendum, and we remain responsible to you for their performance.
We will give you at least 30 days' notice by email before adding or replacing a subprocessor that processes your data. If you reasonably object on data protection grounds within that period, we will work with you to find a solution; if none is available, you may terminate the affected part of the Service without penalty, with a pro-rata refund of fees paid in advance.
6. International transfers
Your data is stored in the ap-northeast-2 region (Seoul, South Korea), and is processed by providers in the United States and elsewhere as set out in the subprocessor list.
- New Zealand. We disclose personal information overseas only where we are satisfied the recipient is required to protect it to a standard comparable to the Privacy Act 2020, as information privacy principle 12 requires, and our agreements with those providers require it.
- UK and EU. Where the GDPR or UK GDPR applies, transfers are made under the relevant adequacy decision or, where none applies, the applicable standard contractual clauses, which are incorporated into this addendum by reference.
7. Helping you meet your obligations
- Requests from individuals. The Service lets you find, correct, export and delete records yourself, which will normally be enough. If you need more, we will help at no charge for a reasonable volume of requests. If an individual approaches us directly about your data, we will not respond substantively — we will refer them to you and tell you.
- Impact assessments. We will give you the information you reasonably need to carry out a privacy or data protection impact assessment.
8. Breach notification
If we become aware of a security breach affecting your personal information, we will notify you without undue delay, and in any case within 48 hours of becoming aware. The notification will describe what happened, the categories and approximate volume of data involved, the likely consequences, and what we are doing about it — and we will keep you updated as we learn more rather than waiting until we know everything.
You remain responsible for deciding whether the breach is notifiable to a regulator or to affected individuals under the law that applies to you.
9. Audit
On request, and no more than once a year unless we have had a breach, we will provide the information reasonably necessary to demonstrate compliance with this addendum, including a description of our security measures and the results of our tenant-isolation testing. Where that is not enough for your obligations, we will accommodate an audit by you or an independent auditor you appoint, on reasonable notice, during business hours, at your cost, and subject to confidentiality.
10. Return and deletion
On termination, we will make your data available for export for 30 days, then delete it from the live Service within a further 30 days. Copies held in routine backups are deleted as those backups age out — we keep the most recent 90 nightly backups, so within about three months. We will confirm deletion in writing if you ask. We will keep data for longer only where the law requires, and then only for as long as required.
11. Liability
Liability under this addendum is subject to the limitations in the Terms of Service.
Annex A — Details of processing
| Subject matter | Provision of Kinetic Project and Kinetic BIM Standard and Kinetic BIM Pro to you. |
|---|---|
| Duration | For the term of your subscription, plus the deletion window in clause 10. |
| Nature and purpose | Hosting, storage, organisation, retrieval, display and transmission of your project and commercial records; sending notifications and portal invitations on your behalf; and importing correspondence and accounting records from systems you connect. |
| Categories of data subject | Your staff and contractors; your clients' staff and their contacts; people appearing in correspondence you file into the Service. |
| Categories of personal information | Names, work contact details, job titles, employment role and internal cost or charge rates; records of work performed, including time entries; correspondence content and attachments; financial records including invoices and payment status; authentication and activity records. |
| Special category / sensitive data | None is required by the Service, and none should be entered. Where it appears in correspondence you import, it is processed only incidentally as part of that content. |
Annex B — Technical and organisational measures
- Tenant isolation. Every record carries an organisation identifier, and database row-level security policies scope every query to the organisation on the requester's access token. The boundary is enforced by the database, not by application code. It is verified by an automated suite that attempts cross-organisation reads and asserts that each one fails.
- Authentication. Passwordless sign-in by single-use emailed link or code. Role and organisation are injected into the access token at issue; a client-portal token resolves no internal records at all.
- Encryption. TLS in transit. Encryption at rest by the hosting provider. Mailbox refresh tokens are separately encrypted with AES-256-GCM before storage and are never exposed to the browser.
- Least privilege. Privileged database credentials are held server-side only. Administrative access to production is limited to those who need it.
- Change control. All changes are version-controlled and deployed from a reviewed source repository. Database changes are applied as recorded, ordered migrations.
- Segregation. Confidential fields can be masked in the interface, and internal correspondence is structurally unavailable to client-portal users.
Annex C — Subprocessors
The current list is maintained at /legal/subprocessors and forms part of this addendum.
Questions about this addendum, or a request for a signed counterpart, go to bim@kineticbuild.co.nz.