Version 1.1 — 2 August 2026
This Data Processing Addendum (“Addendum”) forms part of the agreement between Acumine Ltd (“Acumine”, “we”, “us”) and the customer organisation (“Customer”, “you”) for use of the Outtrn™ platform (the “Services”).
It is incorporated into that agreement by reference and takes effect when you begin using the Services. You do not need to sign or request it — it applies automatically, and no separate negotiation is required. If your procurement process requires a countersigned copy, email support@acumine.com and we will provide one. Where this Addendum conflicts with the rest of the agreement on the subject of personal data, this Addendum prevails.
“Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, in each case as amended, together with the EU GDPR where it applies to processing under this Addendum.
“Customer Personal Data” means personal data contained in content you or your users place in the Services, or which the Services derive from it.
“controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” have the meanings given in the Data Protection Legislation.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner. “SCCs” means those Standard Contractual Clauses.
You are the controller of Customer Personal Data and we are your processor. You are responsible for the lawfulness of the data you place in the Services, including having a lawful basis for it and giving the required information to the people it concerns.
We are an independent controller for a limited set of data about your users that we need in order to run the Services at all — account identity, sign-in records and fault diagnostics. That processing is described in our Privacy Policy and is not governed by this Addendum.
We will:
You give general authorisation for us to engage sub-processors. Our current sub-processors, with their purpose, location and transfer safeguard, are listed at outtrn.com/legal/sub-processors.
We will give you at least 30 days' notice before a new sub-processor begins processing Customer Personal Data. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith to find an alternative; if we cannot, you may terminate the affected part of the Services without penalty for the unused portion of any prepaid fees.
We impose data protection obligations on each sub-processor that are no less protective than those in this Addendum, and we remain responsible to you for their performance.
The database, sign-in system and file storage holding your workspace are located in the United Kingdom, as is the application compute. Where Customer Personal Data is transferred out of the UK — see the sub-processor page for exactly where and why — the transfer is made under an adequacy regulation where one applies, or otherwise under the SCCs together with the UK Addendum, which are deemed entered into by reference and incorporated into this Addendum.
One transfer deserves specific mention because it involves your content rather than metadata: the automated analysis that converts an uploaded programme file into a dashboard currently runs on build infrastructure provided by GitHub, Inc., whose location is determined by GitHub and may be outside the UK. We are working to relocate this processing to a host we can pin to the UK.
Data subject requests. The Services give your administrators the ability to access, correct, export and delete content within your workspace, which will usually let you answer a request yourself. Where it does not, we will provide reasonable assistance. If a data subject approaches us directly about Customer Personal Data, we will not respond substantively — we will refer them to you and forward the request without undue delay.
Personal data breach. We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses, and reasonable assistance with any notification you must make to the ICO or to affected people. Notifying you is not an admission of fault.
Impact assessments. We will provide reasonable assistance with any data protection impact assessment or prior consultation with the ICO that relates to the Services.
On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, we will provide the information reasonably necessary to demonstrate our compliance with this Addendum. Where that is insufficient for your regulatory obligations, we will co-operate with an audit carried out by you or an independent auditor appointed by you, on reasonable notice, during business hours, subject to confidentiality and to not disrupting the Services or the data of other customers.
You may export your workspace content at any time during the term. On termination or expiry we will, at your choice, return or delete Customer Personal Data, and delete existing copies within 30 days, except where we are required by law to retain it. Backups are overwritten on their ordinary cycle, and any copy remaining in a backup stays subject to this Addendum until it is overwritten.
Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the agreement.
We may update this Addendum where necessary to reflect a change in law, in the Services or in our sub-processors, provided the change does not materially reduce the protection given to Customer Personal Data. We will publish the updated version on this page with a new version number and date, and will notify you of material changes.
Controller / data exporter: the Customer organisation identified in the agreement.
Processor / data importer: Acumine Ltd, West Lancashire Business Centre, White Moss Business Park, Maple View, Skelmersdale, England, WN8 9TG. Contact: Daniel Maddocks, support@acumine.com.
Provision of the Outtrn platform: hosting a governed reporting workspace, ingesting and analysing construction programme (schedule) files, and producing reporting dashboards and commercial reporting outputs for the Customer.
We ask you to note the fourth category specifically. Programme files exported from tools such as Asta Powerproject and Primavera P6 commonly carry author and reviser names in their metadata, and the Services read those fields as part of processing the file. You may need to account for this in your own record of processing and in the information you give to your staff.
The Services are not designed for, and must not be used to process, special category personal data under Art. 9 UK GDPR or criminal offence data under Art. 10.
Continuous for the duration of the agreement. Retention and deletion are as set out in section 8 and in Part 6 of our Privacy Policy.
These measures may be updated as the Services develop, provided the level of protection is not reduced.