Data Processing Agreement

Effective for Customer when Customer first accepts Terms on or after July 28, 2026 that expressly incorporate this DPA, or when the parties otherwise agree in writing

This Data Processing Agreement (“DPA”) forms part of the Project Lens Terms of Service only when the applicable Agreement expressly incorporates this version or the parties otherwise agree in writing. For clarity, an Agreement accepted before July 28, 2026 does not incorporate this DPA version unless Customer affirmatively accepts updated Terms that reference it or otherwise agrees in writing. This DPA applies only to Customer Personal Data that Project Lens processes on Customer’s behalf as a processor or service provider. It should be read together with our Privacy Policy.

This DPA is entered into between Project Lens, LLC (“Project Lens,” “we,” “us,” or “our”) and the business or organization that accepts the Agreement (“Customer”). Publication of this DPA does not by itself amend an earlier Agreement that did not incorporate this version. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Definitions

Agreement: The Project Lens Terms of Service and any other written agreement governing Customer’s use of the Services.

Customer Data: Customer Content submitted to, stored in, transmitted through, or generated using the Services.

Customer Personal Data: Customer Data that identifies, relates to, describes, or could reasonably be linked to an individual or household and is protected by applicable Data Protection Laws.

Customer-Directed Third-Party Service: A third-party service that Customer independently chooses, connects, or directs Project Lens to interact with, such as a cloud-storage, CRM, project-management, or customer-notification integration.

Data Protection Laws: Privacy and data-protection laws that apply to a party’s processing of Customer Personal Data under the Agreement.

Security Incident: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data in the custody or control of Project Lens or its Subprocessors.

Subprocessor: A third party engaged by Project Lens to process Customer Personal Data on Customer’s behalf in connection with the Services.

2. Scope, Roles, and Customer Instructions

Customer is the controller or business for Customer Personal Data, and Project Lens is Customer’s processor or service provider. If Customer acts as a processor for another controller, Project Lens acts as Customer’s subprocessor. Each party will comply with the Data Protection Laws applicable to its role.

This DPA does not govern Personal Information that Project Lens processes for its own business purposes as a controller or business, such as account administration, billing, direct customer communications, security, and non-content service analytics. Those activities are described in the Privacy Policy.

Customer instructs Project Lens to process and transfer Customer Personal Data as necessary to provide, operate, maintain, secure, debug, and support the Services; to make Customer Data available as Customer directs; and to comply with the Agreement, this DPA, and Customer’s documented use of the Services.

Project Lens will process Customer Personal Data only for those purposes, unless another use is required by applicable law. If legally permitted, Project Lens will inform Customer before processing Customer Personal Data for a legally required purpose that is outside Customer’s instructions.

Project Lens will notify Customer if, in our reasonable opinion, a documented instruction violates applicable Data Protection Laws, unless those laws prohibit us from doing so.

3. Customer Responsibilities

Customer is responsible for the lawfulness, accuracy, and quality of Customer Data and for the means by which Customer obtains it. Customer represents that it has all rights, authority, notices, consents, and other permissions required to provide Customer Personal Data to Project Lens and to instruct Project Lens and its Subprocessors to process it.

This responsibility includes complying with recording and privacy laws before recording, uploading, or submitting another person’s voice or other Personal Information through Rundown. Customer will not instruct Project Lens to process Customer Personal Data in violation of Data Protection Laws.

4. Use of Customer Data

Project Lens will not sell Customer Personal Data or use Customer Content for advertising, general product-improvement purposes, or training or improving artificial intelligence or machine-learning models.

AssemblyAI is configured not to use Customer Data or de-identified data for model training, model improvement, or benchmarking. Anthropic’s Commercial Terms prohibit it from training models on Customer Content submitted through its commercial API.

5. Processing Details

Subject Matter and Purpose

Providing the Services, including project management, jobsite documentation, media storage, collaboration, support, security, transcription, Rundown generation, editing, and temporary PDF export.

Nature of Processing

Collection, receipt, storage, organization, retrieval, transmission, use, structuring, generation, disclosure as Customer directs, and deletion of Customer Personal Data as necessary to provide the Services.

Duration

For the term of the Agreement and afterward only for the retention periods and permitted purposes described in the Privacy Policy, this DPA, and applicable law.

Categories of Data Subjects

Customer’s users, employees, contractors, clients or homeowners, project contacts, coworkers, subcontractors, bystanders, and other people whose Personal Information is included in Customer Data.

Categories of Customer Personal Data

Identifiers and contact information; company, professional, project, location, account, and activity information; project photos and videos; and any other Personal Information Customer chooses to include in Customer Data. Where Customer uses Rundown, Customer Personal Data may also include jobsite audio recordings; normalized transcripts and timestamps; photo-marker identifiers and limited project context; generated Rundowns and reports; user edits and version history; and temporary exports.

Sensitive Data

Project Lens does not require Customer to submit sensitive or special-category data. Customer may nevertheless include such information in jobsite media, recordings, transcripts, or other Customer Data at its discretion and remains responsible for having a lawful basis to do so.

6. Confidentiality and Security

Project Lens will ensure that people authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and may access it only as needed to perform their responsibilities.

Project Lens maintains reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized access, use, alteration, disclosure, or destruction. These safeguards include, as applicable:

  • Encryption of production data in transit and at rest.
  • Private, access-controlled object storage for raw Rundown audio.
  • Logical access controls and account-scoped authorization for Customer Data.
  • Access limited to authorized personnel and service providers with a need to process the data.

7. Subprocessors

Customer authorizes Project Lens to engage the following Subprocessors to provide the Services:

Customer-Directed Third-Party Services are not Subprocessors engaged by Project Lens under this DPA. Customer instructs Project Lens to transfer Customer Data to and from those services as Customer directs, and the third party’s own agreement with Customer governs its processing.

Salesforce / Heroku

Purpose: Application hosting, managed database, and managed cache infrastructure

Customer Data: Customer Personal Data processed or stored by the Services

Amazon Web Services (AWS)

Purpose: Object storage

Customer Data: Project media and files, private Rundown audio, export artifacts, and related storage metadata

AssemblyAI

Purpose: Speech-to-text processing for Rundown

Customer Data: Raw Rundown audio, transcript text and timestamps, and transcription request metadata

Anthropic

Purpose: Large language model processing for Rundown structuring

Customer Data: Transcript text, deterministic photo-marker identifiers, and limited Rundown context such as the report title and processing or correction metadata; no image, audio, or other media bytes

MailerSend

Purpose: Transactional email delivery

Customer Data: Recipient names and email addresses and the project, notification, comment, estimate, report, export, or link details included in an email

Sentry

Purpose: Application error, performance, trace, log, and replay monitoring

Customer Data: User and account identifiers, request and device metadata, diagnostic information, and Customer Personal Data included in an error or monitored interaction

SolarWinds Papertrail

Purpose: Production log aggregation

Customer Data: Request and log metadata, identifiers, diagnostic information, and Customer Personal Data included in application logs

Expo

Purpose: Mobile push notification delivery through platform push services and application updates

Customer Data: Push tokens, notification title and body, project or record identifiers and links, and device and platform metadata

Mapbox

Purpose: Project geocoding, address search, and map display

Customer Data: Project addresses, coordinates, request IP address, and map usage metadata

Cloudflare

Purpose: Project-image transformation and content delivery when enabled

Customer Data: Project images, object URLs and keys, requester IP address, and delivery metadata

Project Lens will enter into a written agreement with each Subprocessor that imposes data-protection obligations providing an equivalent level of protection for Customer Personal Data as the obligations in this DPA, as applicable to the Subprocessor’s services. Project Lens will remain responsible for each Subprocessor’s performance of those obligations to the extent required by applicable law.

Our speech-to-text and large language model providers may engage downstream subprocessors to perform their services. Those subprocessors may process audio, transcript text, timestamps, request metadata, or other Customer Personal Data as needed for the applicable service, and processing may occur in multiple countries. Current downstream-subprocessor and location information is available through the AssemblyAI Trust Center and Anthropic Trust Center.

Project Lens will reflect any intended material addition or replacement of a Subprocessor on this page before the new Subprocessor begins processing Customer Personal Data and will provide Customer a reasonable opportunity to object on data-protection grounds by contacting legal@projectlens.com. If the parties cannot resolve an objection in good faith, Customer may stop using the affected feature or terminate the affected Services. Customer should review this page periodically for the current list.

8. International Transfers

Customer Personal Data may be processed in the United States and other countries where Project Lens, its Subprocessors, or their downstream subprocessors operate. Those countries may have data-protection laws that differ from the laws in Customer’s location.

When Data Protection Laws require a transfer mechanism for Project Lens’s transfer of Customer Personal Data to a Subprocessor, Project Lens uses the safeguards in its applicable Subprocessor agreement. Project Lens’s current agreements with AssemblyAI and Anthropic incorporate the European Commission’s Standard Contractual Clauses and applicable United Kingdom and Swiss transfer addenda.

This DPA does not itself incorporate the European Union Standard Contractual Clauses, the United Kingdom International Data Transfer Agreement or Addendum, or another transfer mechanism between Customer and Project Lens. Customer must not submit Customer Personal Data for which such a mechanism is legally required unless the parties first put an applicable mechanism in place in writing. Contact legal@projectlens.com to request additional transfer terms.

9. Data Subject Requests and Compliance Assistance

Customer is responsible for responding to requests from people exercising rights over Customer Personal Data. Taking into account the nature of the processing and the functionality available through the Services, Project Lens will provide reasonable assistance that Customer cannot reasonably complete without our help.

If Project Lens receives a request concerning Customer Personal Data processed on Customer’s behalf, we may direct the requester to Customer and, where legally permitted and reasonably identifiable, notify Customer of the request.

Taking into account the nature of processing and the information available to Project Lens, Project Lens will also provide reasonable assistance with Customer’s applicable security, breach-notification, data-protection impact assessment, and regulatory-consultation obligations.

10. Security Incidents

Project Lens will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. To the extent reasonably available, the notice will describe the nature of the Security Incident, the categories of data affected, likely consequences, and measures taken or planned to address it.

Project Lens will take reasonable steps to contain, investigate, and remediate the Security Incident and will provide reasonable cooperation to support Customer’s legally required response. Notification is not an admission of fault or liability.

11. Deletion and Retention

During the Agreement, Project Lens will handle verified deletion requests in accordance with the Privacy Policy and applicable law.

Following termination of the Agreement, at Customer’s choice, Project Lens will return Customer Personal Data in a reasonably available format or delete it from active systems, and will delete existing copies, unless applicable law requires storage. Customer must request return before deletion and may use available export features. Copies retained temporarily in backups will remain protected from further processing except as required for backup restoration or applicable law and will be deleted on the applicable deletion cycle.

  • Project Lens-held raw audio, transcripts, Rundowns, version history, and temporary PDF artifacts follow the artifact-specific retention schedule in Section 7.1 of the Privacy Policy.
  • Audio and transcripts submitted to AssemblyAI have a one-day time to live, at which point AssemblyAI begins deletion. Deletion may take additional time to complete, and limited metadata is retained for logging and billing.
  • Anthropic retains API inputs and outputs no longer than 30 days under Project Lens’s current commercial configuration. Content flagged by Anthropic’s automated trust-and-safety systems as violating its Usage Policy may be retained for up to two years, and related trust-and-safety classification scores may be retained for up to seven years. Anthropic may also retain data when required by law.
  • When Project Lens permanently deletes an account or project through its hard-deletion process, associated Rundown records are removed and associated stored artifacts are queued for deletion. Removing or archiving a project through the ordinary in-app workflow may retain its records.

Deletion from backups and Subprocessor systems may complete on different schedules. Project Lens will use available contractual and technical controls to instruct Subprocessors to delete Customer Personal Data when required by the Agreement, this DPA, or applicable law.

12. Compliance Information

Upon Customer’s reasonable written request, Project Lens will provide information reasonably available and necessary to demonstrate compliance with this DPA, subject to appropriate confidentiality, security, privilege, and third-party restrictions.

If that information is not reasonably sufficient, Customer may request a reasonable audit limited to Project Lens’s processing of Customer Personal Data. The parties will agree in advance on scope, timing, confidentiality, security, cost, and measures to avoid disrupting the Services. Customer may exercise this right no more than once in any 12-month period unless a Security Incident or applicable Data Protection Law reasonably requires otherwise.

This DPA does not represent that Project Lens holds any certification or participates in any privacy framework not expressly identified here.

13. General

If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls to the extent of that conflict. All other terms of the Agreement, including limitations of liability and dispute-resolution terms, remain in effect.

This DPA ends when Project Lens no longer processes Customer Personal Data on Customer’s behalf, except for provisions that must remain in effect to protect retained Customer Personal Data or fulfill their purpose.

Project Lens, LLC
Email: legal@projectlens.com