Data Processing Agreement
How we handle personal data on your behalf
Last updated: 21 September 2026
1. What this is
When you use GIMLabs, some of the data you put in may be personal data, such as the names of your staff, site crews or client contacts. For that data, you decide why and how it is used, and we process it for you. Data protection law calls you the controller and us the processor, and requires a written agreement between us. This is that agreement.
It forms part of our Terms of Service and applies automatically to every customer. You do not need to sign anything. If your organisation needs a signed copy, email privacy@gimlabs.io and we will provide one.
It does not cover personal data we collect for our own purposes, such as your account, billing and support details. We are the controller of that data, and our Privacy Policy explains how we use it.
“Data protection law” means the UK GDPR and the Data Protection Act 2018 and, where it applies to you, the EU GDPR.
2. What we process
| Subject matter | Providing the GIMLabs platform to you under the Terms of Service |
| Duration | For as long as you have an account, plus the export and deletion periods in section 10 |
| Nature and purpose | Hosting, storing, organising, displaying, exporting and backing up the data you put into GIMLabs, and providing support when you ask for it |
| Types of personal data | Names, initials, job titles, employers, work email addresses and phone numbers; signatures and sign-off records; the location of site works; photos and files that may incidentally show or name individuals; records of who created or changed data |
| Whose data | Your employees and contractors, site personnel such as drillers and loggers, your clients' and suppliers' contacts, and anyone else named in your project records |
| Special category data | GIMLabs is not designed for it and you agree not to upload it |
3. Our obligations
We will:
- process personal data only on your documented instructions, which are these terms and how you and your users configure and use the Services, unless the law requires otherwise, in which case we will tell you first where we are allowed to;
- tell you if we think an instruction breaks data protection law;
- make sure everyone we authorise to access the data is bound by a duty of confidentiality;
- keep the data secure using the measures in section 5;
- only use subprocessors as described in section 6;
- help you respond to requests from individuals exercising their rights, and help you with data protection impact assessments and dealings with regulators, as far as we reasonably can given what we hold; and
- at your choice, delete or return the data at the end of the Services, as described in section 10.
4. Your obligations
You are responsible for having a lawful basis for the personal data you put into GIMLabs, for telling the individuals concerned where the law requires it, and for the instructions you give us. Please only upload personal data that your work actually needs.
5. Security
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption. Data is encrypted in transit using TLS, and encrypted at rest by our hosting providers.
- Customer separation. Each customer’s data is logically separated, and every request is checked against the customer it belongs to.
- Access control. Role-based permissions, optional per-project access restrictions, and individual logins for every user. Passwords are stored as salted hashes and API keys are stored hashed.
- Accountability. Sign-in logs and audit logs record who accessed and changed data.
- Our own access. Only a small number of our staff can access production systems, and only to run and support the Services. Support access to your account is time-limited and removed afterwards.
- Resilience. Regular automated backups, and infrastructure run by established cloud providers with their own independent security certifications.
- Development practice. All changes go through version control and are checked before release, and we keep our software dependencies up to date.
We may update these measures over time, but never in a way that reduces the overall level of protection.
6. Subprocessors
You give us general authorisation to use subprocessors to help deliver the Services. The current list, with what each one does and where, is on our Subprocessors page.
We put a written agreement in place with each subprocessor that protects the data to the same standard as this agreement, and we remain responsible to you for what they do.
We will update the Subprocessors page at least 30 days before we start using a new subprocessor for Customer Data. You can ask to be emailed about changes by writing to privacy@gimlabs.io. If you have reasonable data protection grounds to object, tell us within that period. If we cannot resolve your concern, you may cancel the affected Services and we will refund any fees you have paid in advance for the period after cancellation.
7. International transfers
Our primary hosting is in the United Kingdom and the European Economic Area. Some subprocessors are based in, or may access data from, other countries, including the United States.
We only transfer personal data outside the UK where the law allows it: to a country covered by UK adequacy regulations, or under an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and in any event within 72 hours. We will give you the information we have about what happened, what data is affected and what we are doing about it, and we will keep you updated as we learn more.
9. Audits and information
We will give you the information you reasonably need to show that we comply with this agreement, including answering security questionnaires.
If that is not enough, you may carry out an audit once in any 12 month period, or at any time after a breach affecting your data, on at least 30 days’ written notice, during business hours, in a way that does not disrupt our business or put other customers’ data at risk. You bear your own costs, and we may charge for our reasonable time if an audit takes more than one working day.
10. Return and deletion
For 30 days after your subscription or trial ends you can export your data. We then delete it from our live systems within 90 days of the end of your subscription. Backup copies are overwritten in the normal course of our backup cycle and are not used for any other purpose in the meantime.
We may keep data for longer only where the law requires us to.
11. Liability and precedence
Each party’s liability under this agreement is subject to the limits in the Terms of Service. If this agreement and the Terms of Service conflict on a data protection matter, this agreement takes priority.
12. Contact
Data protection questions: privacy@gimlabs.io
SoTech Studio Limited, Cedar Barn, White Lodge, Walgrave, Northampton, NN6 9PY
Questions about this policy? Get in touch.