Outtrn
acumine.comSign In

Data Processing Addendum

Version 1.1 — 2 August 2026

This Data Processing Addendum (“Addendum”) forms part of the agreement between Acumine Ltd (“Acumine”, “we”, “us”) and the customer organisation (“Customer”, “you”) for use of the Outtrn™ platform (the “Services”).

It is incorporated into that agreement by reference and takes effect when you begin using the Services. You do not need to sign or request it — it applies automatically, and no separate negotiation is required. If your procurement process requires a countersigned copy, email support@acumine.com and we will provide one. Where this Addendum conflicts with the rest of the agreement on the subject of personal data, this Addendum prevails.

1. Definitions

“Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, in each case as amended, together with the EU GDPR where it applies to processing under this Addendum.

“Customer Personal Data” means personal data contained in content you or your users place in the Services, or which the Services derive from it.

“controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” have the meanings given in the Data Protection Legislation.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner. “SCCs” means those Standard Contractual Clauses.

2. Roles

You are the controller of Customer Personal Data and we are your processor. You are responsible for the lawfulness of the data you place in the Services, including having a lawful basis for it and giving the required information to the people it concerns.

We are an independent controller for a limited set of data about your users that we need in order to run the Services at all — account identity, sign-in records and fault diagnostics. That processing is described in our Privacy Policy and is not governed by this Addendum.

3. Our obligations

We will:

  • process Customer Personal Data only to provide the Services, in accordance with this Addendum and your documented instructions — using the Services is itself an instruction — and not for our own purposes;
  • not sell Customer Personal Data, and not use it to train machine-learning models;
  • tell you if, in our opinion, an instruction infringes the Data Protection Legislation, and may suspend that instruction until it is resolved;
  • ensure that personnel with access to Customer Personal Data are subject to a duty of confidence and receive appropriate data protection training;
  • limit access to those who need it to perform the agreement;
  • implement and maintain the technical and organisational measures in Annex II.

4. Sub-processors

You give general authorisation for us to engage sub-processors. Our current sub-processors, with their purpose, location and transfer safeguard, are listed at outtrn.com/legal/sub-processors.

We will give you at least 30 days' notice before a new sub-processor begins processing Customer Personal Data. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith to find an alternative; if we cannot, you may terminate the affected part of the Services without penalty for the unused portion of any prepaid fees.

We impose data protection obligations on each sub-processor that are no less protective than those in this Addendum, and we remain responsible to you for their performance.

5. International transfers

The database, sign-in system and file storage holding your workspace are located in the United Kingdom, as is the application compute. Where Customer Personal Data is transferred out of the UK — see the sub-processor page for exactly where and why — the transfer is made under an adequacy regulation where one applies, or otherwise under the SCCs together with the UK Addendum, which are deemed entered into by reference and incorporated into this Addendum.

One transfer deserves specific mention because it involves your content rather than metadata: the automated analysis that converts an uploaded programme file into a dashboard currently runs on build infrastructure provided by GitHub, Inc., whose location is determined by GitHub and may be outside the UK. We are working to relocate this processing to a host we can pin to the UK.

6. Assisting you

Data subject requests. The Services give your administrators the ability to access, correct, export and delete content within your workspace, which will usually let you answer a request yourself. Where it does not, we will provide reasonable assistance. If a data subject approaches us directly about Customer Personal Data, we will not respond substantively — we will refer them to you and forward the request without undue delay.

Personal data breach. We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses, and reasonable assistance with any notification you must make to the ICO or to affected people. Notifying you is not an admission of fault.

Impact assessments. We will provide reasonable assistance with any data protection impact assessment or prior consultation with the ICO that relates to the Services.

7. Audit

On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, we will provide the information reasonably necessary to demonstrate our compliance with this Addendum. Where that is insufficient for your regulatory obligations, we will co-operate with an audit carried out by you or an independent auditor appointed by you, on reasonable notice, during business hours, subject to confidentiality and to not disrupting the Services or the data of other customers.

8. Deletion and return

You may export your workspace content at any time during the term. On termination or expiry we will, at your choice, return or delete Customer Personal Data, and delete existing copies within 30 days, except where we are required by law to retain it. Backups are overwritten on their ordinary cycle, and any copy remaining in a backup stays subject to this Addendum until it is overwritten.

9. Liability and changes

Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the agreement.

We may update this Addendum where necessary to reflect a change in law, in the Services or in our sub-processors, provided the change does not materially reduce the protection given to Customer Personal Data. We will publish the updated version on this page with a new version number and date, and will notify you of material changes.

Annex I — Details of processing

A. Parties

Controller / data exporter: the Customer organisation identified in the agreement.
Processor / data importer: Acumine Ltd, West Lancashire Business Centre, White Moss Business Park, Maple View, Skelmersdale, England, WN8 9TG. Contact: Daniel Maddocks, support@acumine.com.

B. Subject matter, nature and purpose

Provision of the Outtrn platform: hosting a governed reporting workspace, ingesting and analysing construction programme (schedule) files, and producing reporting dashboards and commercial reporting outputs for the Customer.

C. Categories of data subject

  • the Customer's employees, officers and contractors who use the Services;
  • individuals named within content uploaded to the Services — in particular individuals identified in programme files, such as the person recorded as the author or last reviser of a programme or baseline;
  • employees and representatives of the Customer's supply chain who are invited into a work package.

D. Categories of personal data

  • identity and contact data: name, work email address;
  • access and permission data: organisation, project and package membership, role assignments;
  • usage and security data: sign-in timestamps, IP address, browser user-agent, and a record of governed changes made in the workspace;
  • personal data embedded in uploaded content: names and identifiers recorded by the Customer's scheduling or reporting tools within the files it uploads, and any personal data the Customer chooses to enter into free-text fields or attach as a file.

We ask you to note the fourth category specifically. Programme files exported from tools such as Asta Powerproject and Primavera P6 commonly carry author and reviser names in their metadata, and the Services read those fields as part of processing the file. You may need to account for this in your own record of processing and in the information you give to your staff.

E. Special category data

The Services are not designed for, and must not be used to process, special category personal data under Art. 9 UK GDPR or criminal offence data under Art. 10.

F. Frequency and duration

Continuous for the duration of the agreement. Retention and deletion are as set out in section 8 and in Part 6 of our Privacy Policy.

Annex II — Technical and organisational measures

  • Access control.Access requires a Microsoft account and an invitation to a workspace. Permissions are resolved on the server on every request from the Customer's own role assignments; a client cannot assert its own role.
  • Tenant isolation.Each organisation's data is separated both by database-level row security and by an organisation filter applied in the application on every query, so that a fault in one layer does not expose another tenant's data.
  • Session security. Sessions are held in cookies that scripts in the browser cannot read, scoped to our own origin, and protected against cross-site request forgery on every state-changing request.
  • Encryption. Data is encrypted in transit using TLS, with HTTP Strict Transport Security enforced, and encrypted at rest by our hosting providers.
  • Content delivery. Customer content is served only from our own origin behind an authenticated route, is never placed in a shared cache, and is served as a download rather than rendered as active content.
  • Auditability. Governed changes are written to an append-only audit record identifying the user, the change and the time.
  • Availability. The hosting platforms provide managed backups with point-in-time recovery.
  • Development controls. Changes are peer-reviewed and pass automated checks, including automated scanning for credentials, before release.
  • Abuse protection. Sensitive endpoints are rate-limited.
  • Personnel. Access by our staff is limited to those with a need to know, who are subject to confidentiality obligations.

These measures may be updated as the Services develop, provided the level of protection is not reduced.

Privacy PolicyCookie PolicyTerms & ConditionsData Processing AddendumSub-processorsAcumine®
© 2026 Acumine Ltd. All rights reserved. Outtrn and Acumine® are trademarks of Acumine Ltd.