Last Updated July 14, 2026

SITEMESH 3D – DATA PROCESSING ADDENDUM (DPA)

This Data Processing Addendum ("DPA") supplements the SiteMesh 3D Terms of Service ("Main Agreement"). This DPA governs the processing of personal data in connection with the customer’s use of our 3D CCTV engineering design platform.

1. Definitions and Interpretation

  • "Data Protection Laws" means all privacy and data protection laws applicable to the processing of personal data under this agreement, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
  • "Customer Personal Data" means any personal data uploaded, sync'd, or processed within the SiteMesh 3D environment belonging to the Customer's team members, clients, or site managers.
  • "Controller" means the Customer who dictates the business purpose and parameters of data collection.
  • "Processor" means SiteMesh 3D, which processes data strictly on behalf of the Controller.
  • "Sub-processor" means any third-party engineering utility or transactional system engaged by SiteMesh 3D to carry out specialized processing functions.

2. Scope and Roles of Processing

The parties acknowledge and agree that with respect to Customer Personal Data, Customer is the Controller and SiteMesh 3D is the Data Processor. SiteMesh 3D certifies that it acts as a designated "Service Provider" and will process personal data exclusively to deliver the 3D map workspace utilities, compute camera DORI coverage arrays, and manage corporate subscription counts.

3. Processor Obligations

SiteMesh 3D warrants and covenants that it shall:

  • Process on Instructions Only: Process Customer Personal Data solely in accordance with the documented instructions of the Customer (including the layout parameter adjustments made within the platform UI) unless required by applicable law
  • Staff Confidentiality: Ensure that all platform administrators, engineering staff, and data log managers authorized to handle customer configurations are bound by strict contractual confidentiality agreements.
  • Data Subject Rights Assistance: Promptly forward to the Customer any data deletion, access, or portability requests received from end-users, providing reasonable dashboard features to help the Customer fulfill their legal transparency duties.

4. Security and Breach Notification

  • Technical Safeguards: SiteMesh 3D will deploy industry-standard technical and organizational security controls designed to safeguard database records against unauthorized entry, leakage, or loss.  
  • Security Incident Notification: In the event of a confirmed security breach affecting SiteMesh 3D’s storage systems, we will notify the affected Customer administrative contacts via email without undue delay (and within 72 hours of verification). We will provide sufficient event metadata to enable the Customer to meet their legal reporting deadlines.  

5. Authorised Sub-processors

The Customer provides a general written authorization for SiteMesh 3D to utilize the third-party infrastructure components listed below to process data. We enforce equivalent data protection obligations on all sub-processors:

Sub-processor Entity Processing Operations Data Location
Google Cloud / Maps Platform 3D environmental modeling, map tile caching, and geospatial coordinate rendering. Global Edge Networks
Stripe, Inc. Secure B2B transactional ledgers, usage prorations, and fraud checks. United States

Sub-processor Update Mechanism: SiteMesh 3D will update this public DPA ledger at least 14 days before adding any new infrastructural sub-processors, giving corporate clients an opportunity to object on valid data-protection grounds.

6. Data Deletion and Return

Within 30 days following the structural termination or native expiration of the Main Agreement, SiteMesh 3D will systematically scrub, overwrite, or delete all inactive Customer design records, project configurations, and camera arrays from our production database tables. This excludes historical row remnants required by law or locked inside encrypted automated backup snapshots (which are securely partitioned and rotated out within a standard 30-day window).

ANNEX 1: DETAILS OF PROCESSING DATA ARRAYS

  • Subject Matter: The rendering and visualization of structural closed-circuit television (CCTV) security optics layouts on a digital mapping interface.
  • Duration of Processing: The duration of the active subscription tier plus the post-cancellation deletion buffer window.
  • Categories of Data Subjects: Customer personnel, system administrators, system architects, and third-party facility contacts mapped inside the organization's layout project.
  • Categories of Personal Data Collected: Administrative names, emails, user access roles, localized device metadata, geographic installation coordinates, target structural polygons, and DORI calculation metrics.