Data Processing Agreement
Effective 13 September 2026 · Version 1.0
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Varian Terms of Service between Aurifex Digital (“Aurifex”, “we”) and the Customer. It sets out the terms on which Aurifex processes personal data within Customer Data on the Customer’s behalf, for the purpose of Article 28(3) UK GDPR. Terms not defined here have the meaning given in the Terms of Service or the Privacy Policy.
1. Roles
1.1 Where Customer Data includes personal data, the Customer is the controller and Aurifex is the processor. This DPA applies only to that processing; it does not affect Aurifex’s own role as controller of Account Data described in the Privacy Policy (clause 3).
2. Subject matter, duration, nature and purpose
2.1 Subject matter and duration. The provision of the Varian service for the term of the Terms of Service, and for the retention period at clause 8 thereafter.
2.2 Nature and purpose of processing. Storage, retrieval, structuring and display of Customer Data within the Service; computation of budget, cost and variance figures from it; and transmission of alert and notification content derived from it to Authorised Users, so that the Customer can track construction project costs.
2.3 Categories of data subjects. The Customer’s Authorised Users, and any individual named in free-text fields the Customer chooses to enter (for example a vendor contact named in a cost description).
2.4 Categories of personal data. Name and email address of Authorised Users; any personal data the Customer includes in free-text fields (descriptions, notes, vendor names, references). Aurifex does not require and does not knowingly process special category data, and the Customer shall not submit it to the Service.
3. Processing on instructions
3.1 Aurifex shall process personal data only on the Customer’s documented instructions, which consist of this DPA, the Terms of Service, and the Customer’s use of the Service’s features — unless required to do otherwise by UK law, in which case Aurifex shall inform the Customer of that legal requirement before processing, unless the law prohibits this.
3.2 Aurifex shall immediately inform the Customer if, in its opinion, an instruction infringes UK GDPR or other data protection law.
4. Confidentiality
4.1 Aurifex ensures that any individual authorised to process personal data (currently limited to Aurifex’s own personnel; see clause 6 for sub-processors) is subject to a duty of confidentiality, whether contractual or statutory.
5. Security
5.1 Aurifex implements appropriate technical and organisational measures under Article 32 UK GDPR, having regard to the state of the art, the costs of implementation, and the nature, scope and purposes of processing. These measures include:
- encryption of personal data in transit and at rest;
- logical separation of each organisation’s data, enforced at the data layer rather than solely within the application;
- role-based access control within each organisation;
- restriction and logging of privileged operations;
- maintenance of an attributable record of changes to financial records.
6. Sub-processors
6.1 The Customer gives general written authorisation to Aurifex’s engagement of the sub-processors listed in Annex A of the Privacy Policy. Aurifex will give notice of any intended addition or replacement, and the Customer may object on reasonable data protection grounds. Aurifex remains fully liable to the Customer for a sub-processor’s performance of its data protection obligations.
7. Assistance with data subject rights and breach notification
7.1 Taking into account the nature of the processing, Aurifex shall assist the Customer, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights under UK GDPR. A request received directly by Aurifex from a data subject will be forwarded to the Customer without undue delay and without responding to it, save to confirm receipt.
7.2 Where a personal data breach affecting Customer Data is likely to result in a risk to the rights and freedoms of data subjects, Aurifex will notify the Information Commissioner’s Office within 72 hours of becoming aware of it and will notify the Customer without undue delay, providing the information reasonably available to enable the Customer to meet its own notification obligations.
8. Return or deletion on termination
8.1 On termination, Customer Data — including personal data within it — is retained for 30 days to permit export or reinstatement, after which it is erased in accordance with the Privacy Policy. The Customer may export Customer Data at any time during the term in Excel, CSV and PDF formats.
9. Audit and information
9.1 Aurifex shall make available to the Customer, on reasonable written request no more than once per year, the information reasonably necessary to demonstrate compliance with this DPA. Given the scale of Aurifex’s operations, this is ordinarily satisfied by written responses and documentary evidence (for example, sub-processor DPAs and security documentation) rather than an on-site audit; an on-site or third-party audit may be agreed between the parties, at the requesting party’s cost, where written evidence is insufficient to address a specific, documented compliance concern.
10. Data protection impact assessments
10.1 Aurifex shall provide reasonable assistance to the Customer with any data protection impact assessment, and with any prior consultation with the Information Commissioner’s Office, that the Customer reasonably considers is required by Articles 35 or 36 UK GDPR in relation to the Customer’s use of the Service.
11. International transfers
11.1 Sub-processor locations are listed in Annex A of the Privacy Policy. Aurifex shall not transfer personal data outside the UK except to a country subject to UK adequacy regulations, or under a transfer mechanism recognised under UK GDPR (such as the International Data Transfer Addendum), or with the Customer’s prior written consent.
12. Precedence and contact
12.1 In the event of a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.
12.2 Enquiries concerning this DPA: Aurifex Digital, aurifex.digital@gmail.com.