Data Processing Addendum
When you draft a report in Surveyor AI, the property and client information in it is yours, and we handle it for you. UK GDPR requires that arrangement to be written down. This Addendum is that contract, and it applies automatically to every customer — there is nothing to sign.
Last updated 23 September 2026 · Surveyor AI Solutions Ltd
For the personal data inside your surveys — your clients’ names, the property addresses, the photographs, anything you type into a report — you (the surveyor, or your firm) are the controller and Surveyor AI Solutions Ltd is the processor. You decide what goes in a report and who receives it; we process it to provide the service.
For your own account — your name, email address, job title and billing details — we are the controller, and our Privacy Policy explains that processing.
This Addendum forms part of our Terms of Service. Where it conflicts with them on data protection, this Addendum takes precedence.
Subject matter and purpose: providing the Surveyor AI platform — drafting survey reports from the photographs and notes you capture, storing your surveys, and exporting them to PDF or Word.
Duration: for as long as your account is active, and afterwards only as needed to meet a legal obligation.
Types of personal data: names and contact details of your clients where you enter them, property addresses, inspection photographs and video, dictated voice notes, and the text of your reports.
Categories of data subject: your clients, occupiers of the properties you inspect, and your own staff who use the platform.
We do not ask for special category data, and the platform is not designed to hold it.
We process personal data only on your documented instructions. Using the platform — creating a survey, uploading photographs, generating a report, exporting it — is your instruction to us.
If the law requires us to process it otherwise, we will tell you first unless the law forbids that.
If we believe an instruction breaches data protection law, we will tell you.
Everyone we allow to access personal data is bound by a duty of confidentiality, and only has access where their work requires it.
We take appropriate technical and organisational measures to protect personal data, taking into account the risk to the people the data is about.
These include encryption in transit and at rest, access control requiring authentication on every route, separation of each firm’s data, removal of location metadata from photographs on upload, and restricted administrative access.
We keep these measures under review as the service changes.
You give us general authorisation to engage the sub-processors listed on our Sub-processors page. Each is bound by written terms no less protective than this Addendum.
We will update that page and email account holders before a new sub-processor begins handling your data. If you object on reasonable data protection grounds, tell us and we will work through it with you — and if no alternative works, you may end your subscription and we will return or delete your data.
We remain responsible to you for what our sub-processors do.
If one of your clients asks for a copy of their data, asks you to correct or delete it, or objects to the processing, we will help you respond, taking into account what the platform allows and what you can do yourself.
You can export any report as PDF or Word at any time, and delete a survey from your account.
If a request reaches us directly, we will pass it to you rather than answer it ourselves.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, with what we know and what we are doing about it, so you can meet your own 72-hour obligation.
We will also give you reasonable help with data protection impact assessments, with prior consultation of the ICO, and with your security obligations, to the extent the information sits with us.
You can export your reports at any time while your account is active.
On termination, we will delete or return your personal data at your choice, and delete existing copies, unless we are required by law to keep something.
Backups are deleted on their normal cycle.
We will make available the information you reasonably need to show that we are meeting these obligations, and allow audits or inspections by you or an auditor you appoint.
In practice we would rather answer a supplier questionnaire and point you to our published documentation than put you through a site visit — but the right stands.
Your reports and photographs are stored in the EU, which the UK recognises as providing an adequate level of protection.
Some of our sub-processors, including the AI providers, are in the United States. Those transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
Where each provider sits is set out on our Sub-processors page.
Your reports, photographs and client data are not used to train AI models, by us or by our AI providers.
Content is sent to an AI provider only to draft the report you asked for, and is not retained by them to improve their models.
How the AI is used, and the controls around it, are set out in our AI due diligence page.
Some firms need a counter-signed copy, or have their own template for their procurement pack. Get in touch and we will sort it out.
Related: Sub-processors · AI due diligence · Compliance & Standards