What data Bite processes
Bite ingests structural engineering project files: analysis models (ETABS, SAFE), calculations, drawings (PDF, DWG), project correspondence (EML/MSG), and internal reports. We do not process personal data beyond user account details (name, email, organisation) unless your project correspondence names individuals.
GDPR (controller / processor)
Under UK and EU GDPR, you are the data controller for any personal data in your project f iles. Bite is the data processor. A Data Processing Agreement (DPA) compliant with UK GDPR Article 28 is available on request and sets out the liability allocation, sub-processor obligations, and breach notification commitments. EU Standard Contractual Clauses are in place where international transfers apply.
Incident response
In the event of a data incident, we comply with GDPR Article 33 (72-hour supervisory authority notification) and Article 34 (notification without undue delay to affected individuals where the risk is high). A documented incident response plan is being formalised internally (target: Q3 2026); in the interim, incidents are escalated immediately to the engineering lead and co-founders.
Building Safety Act 2022 / ISO 19650
Every file version and design change is recorded in an immutable, append-only commit log, and the log identifies who made each change and when. If a change needs to be rolled back, this does not remove the full audit trail that we store.
Data deletion
On request, all project data associated with your organisation (file blobs, database records, vector index entries) is deleted within 30 days. The audit trail itself is append-only for the duration of the contract.