Data Processing Addendum
The processor terms that apply when a firm's use of Baseline PCR involves personal data, including security measures, subprocessors, breach notification, international transfers and deletion.
Version 1 · effective 2026-09-17
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer identified in the Account ("Customer") and MoldMind LLC, doing business as Baseline PCR ("Baseline PCR"). It applies to the extent Baseline PCR processes Personal Data on Customer's behalf in providing the Service. Capitalized terms not defined here have the meaning in the Terms. Where a Customer requires a countersigned copy, email legal@baselinepcr.com and we will return one.
1. Roles
Customer is the controller (or a processor acting for its own client) of Personal Data contained in Customer Content. Baseline PCR is Customer's processor. For Account, usage and billing data Baseline PCR is an independent controller, as described in the Privacy Policy.
2. Subject Matter, Duration, Nature and Purpose
Subject matter: Personal Data in photographs, field notes, questionnaires, owner-provided documents, interview notes, Reports and workspace metadata. Duration: the term of the Terms plus the deletion period in Section 12. Nature: storage, automated classification and extraction, drafting, rendering, delivery on instruction, backup and deletion. Purpose: enabling Customer to prepare property condition reports. Categories of data subjects: Customer's personnel; Customer's clients and their personnel; property owners, managers and their personnel; persons named in documents; persons incidentally photographed. Categories of data: names, business contact details, roles, statements made in interviews, images, and any other Personal Data Customer includes. Special categories: none intended; Customer must not upload health, biometric or other special-category data.
3. Customer Instructions
Baseline PCR processes Personal Data only on Customer's documented instructions, which are the Terms, this DPA, and Customer's use of the Service's features, unless law requires otherwise, in which case Baseline PCR will inform Customer before processing unless legally prohibited. Baseline PCR will inform Customer if it believes an instruction infringes data-protection law.
4. Customer Responsibilities
Customer is responsible for the lawfulness of the Personal Data it uploads, for any notice or consent required (including for photographing people or private premises), for the accuracy of instructions, and for responding to data subjects. Customer will not upload Personal Data it is not entitled to process.
5. Confidentiality
Baseline PCR ensures that persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate training.
6. Security Measures
Baseline PCR implements and maintains the technical and organizational measures in Annex II, which include: encryption of data in transit and at rest; logical tenant isolation of database rows and storage objects by organization; authentication through a dedicated identity provider with multi-factor authentication available; least-privilege, logged access for Baseline PCR personnel; signed, expiring URLs for uploads and shares; validation of all inputs at system boundaries; an audit log of workspace actions; automated backups; and vulnerability management of dependencies. Baseline PCR may update the measures provided the overall level of protection is not reduced.
7. Data Subject Rights
Taking into account the nature of the processing, Baseline PCR will assist Customer with reasonable technical measures to respond to data-subject requests. Requests received directly by Baseline PCR that relate to Customer Content will be forwarded to Customer within five business days without responding on the merits, unless law requires otherwise.
8. Subprocessors
Customer authorizes the subprocessors in Annex III and the current Subprocessor List. Baseline PCR will give at least thirty days' notice by email of any intended addition or replacement. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service with a pro-rata refund of prepaid fees. Baseline PCR imposes data-protection obligations on each subprocessor no less protective than this DPA and remains liable for their performance.
9. Personal Data Breach
Baseline PCR will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data, with the information reasonably available: the nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed, and a contact. Baseline PCR will cooperate with Customer's investigation and notifications.
10. International Transfers
Baseline PCR processes Personal Data in the United States. For transfers subject to the GDPR, the UK GDPR or Swiss law, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable), with the UK International Data Transfer Addendum and the Swiss amendments where relevant, and Baseline PCR has equivalent terms with its subprocessors. Clause 7 (docking) applies; Clause 9 option 2 with the notice period in Section 8; Clause 11 optional language does not apply; Clause 17 option 1 with Irish law; Clause 18 the courts of Ireland. Annexes I through III of this DPA serve as the Annexes to the Clauses.
11. Audit and Records
Baseline PCR will make available the information necessary to demonstrate compliance with this DPA, including summaries of third-party assessments of its providers where available, and will permit an audit by Customer or an independent auditor bound by confidentiality no more than once a year on thirty days' notice, at Customer's expense, during business hours, in a manner that does not compromise the security of other customers.
12. Deletion and Return
Customer may export and delete Customer Content at any time through the Service. On termination of the Terms, Baseline PCR will delete or de-identify Customer's Personal Data within ninety days, except billing and audit records retained under law and copies in encrypted backups that expire under the backup provider's retention schedule and are not restored except in a disaster recovery, in which case this DPA continues to apply to them.
13. United States State Privacy Laws
Where the CCPA/CPRA or a similar state law applies, Baseline PCR is a service provider or processor. Baseline PCR will not sell or share Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purpose specified, or combine it with Personal Data from other sources except as permitted, and will notify Customer if it can no longer meet these obligations. Customer may take reasonable steps to stop and remediate unauthorized use.
14. Liability
Each party's liability under this DPA is subject to the limitations in the Terms, and the parties agree that those limitations apply in aggregate across the Terms and this DPA.
15. Precedence; Term; Governing Law
In a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms with respect to processing of Personal Data. This DPA lasts as long as Baseline PCR processes Personal Data for Customer. It is governed by the law governing the Terms except where the Clauses require otherwise.
Annex I: Description of Processing
See Section 2. Frequency: continuous while an Account is active. Retention: per Section 12 and the Privacy Policy. Competent supervisory authority (EU): the authority of the member state where Customer is established, or where Customer's representative is established.
Annex II: Technical and Organizational Measures
- Encryption in transit (TLS 1.2+) and at rest for database and object storage.
- Tenant isolation: every row and object is scoped to an organization id and every read is filtered by the caller's organization.
- Identity: managed identity provider; passwords never stored by Baseline PCR; MFA available; session tokens rotated.
- Access control: personnel access is least-privilege, individually authenticated and logged; no standing access to Customer Content.
- Uploads: direct-to-storage with signed, single-use, expiring URLs; file type and size validated server-side; images re-encoded for thumbnails.
- Input validation: every external input, including AI output, is validated against a fixed schema before use.
- AI processing: server-side only; zero-data-retention vendor configuration where offered; no training on Customer Content; prompt-injection resistance by treating uploaded content as data.
- Logging: audit log of workspace actions; server logs without Customer Content payloads; retained per the Privacy Policy.
- Backups: automated by the database and storage providers; encrypted; restoration tested by the providers.
- Vulnerability management: dependencies monitored and updated; continuous integration runs type checks, tests and end-to-end checks before deployment; security reports handled through security@baselinepcr.com.
- Business continuity: hosting across the providers' redundant infrastructure; documented deployment and rollback.
Annex III: Subprocessors
The current list is published as the Subprocessor List and is incorporated by reference.