Assurio
Home

Data Processing Addendum

Version 1.0 · Effective 25 July 2026

This addendum forms part of the Terms of Service and applies where Assurio processes personal data on behalf of a Customer under the EU GDPR, the UK GDPR and the Irish Data Protection Act 2018.

1. Roles

The Customer is the controller of personal data entered into its workspace — staff, engineers, contractors and reporters or tenants. Assurio is the processor, acting only on the Customer’s documented instructions, which include use of the platform’s features and this addendum. Where we process data about our own account holders for billing, security and service administration, we act as controller under our Privacy Policy.

2. Subject matter, duration and nature

  • Subject matter: provision of the Assurio maintenance and work-order platform.
  • Duration: for the term of the subscription, plus a 30-day export window.
  • Nature and purpose: hosting, storage, retrieval, transmission, backup and deletion of workspace records so maintenance and statutory safety work can be recorded and reported.
  • Data subjects: Customer staff, engineers and contractors; reporters and tenants who raise jobs; named contacts on assets and sites.
  • Categories of data: name, work email, phone, role, workspace membership; job reports, comments and activity history; photographs and annotations attached to jobs; site, building, location and asset references; parts usage; fire-walk checkpoint scans with timestamps and the identity of the person performing the walk; device and error diagnostics.
  • Special category data: not requested and not required. Customers must not enter health or other special category data into free-text fields or photographs.

3. Processor obligations

  • Process personal data only on documented instructions, including for transfers, unless required by law.
  • Ensure personnel with access are bound by confidentiality obligations.
  • Implement the technical and organisational measures in section 5.
  • Respect the conditions in section 4 for engaging subprocessors.
  • Assist the Customer with data subject requests, taking into account the nature of processing.
  • Assist with security, breach notification and data protection impact assessments under Articles 32–36.
  • Delete or return personal data at the end of the service, as directed by the Customer.
  • Make available information necessary to demonstrate compliance and allow audits under section 8.

4. Subprocessors

The Customer gives general authorisation for the subprocessors below. We will give at least 30 days’ notice before adding or replacing a subprocessor, and the Customer may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service without penalty. Each subprocessor is bound by data protection terms no less protective than this addendum.

SubprocessorPurposeRegion
Lovable Cloud (Supabase)Application hosting, managed Postgres database, authentication and file storageEuropean Union
CloudflareEdge delivery, TLS termination and DDoS protection for the web appGlobal edge, EU-first routing
Email delivery providerTransactional email: invitations, password resets and notificationsEuropean Union
Hotel Stock Master (customer-enabled)Two-way parts and stock synchronisation — only if the Customer enables the integrationAs operated by the Customer
Apple / Google app storesDistribution of the mobile apps and crash diagnosticsGlobal

5. Security measures (Article 32)

  • Encryption in transit (TLS) and encryption at rest for the database and file storage.
  • Row-level security enforced per workspace and per role, so one workspace cannot read another’s records.
  • Private storage buckets; job photographs are reachable only through short-lived signed links issued to signed-in members.
  • Invite-only account creation; sign-ups from uninvited addresses are rejected at the database layer.
  • Least-privilege database roles; privileged helper functions held in a non-public schema and not callable through the API.
  • Automated backups with point-in-time recovery, and periodic restore checks.
  • Audit trails of work-order activity, and immutable timestamps on fire-walk checkpoint scans.
  • Regular automated security scanning of the database access model.

6. International transfers

Personal data is hosted in the European Union. Where a subprocessor processes data outside the EEA or the UK, transfers rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, plus supplementary measures where required by a transfer risk assessment.

7. Personal data breaches

We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer data, with the information available to us and updates as the investigation progresses, so the Customer can meet its own 72-hour notification duty.

8. Audits

On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority, we will provide documentation about our security measures and respond to a reasonable security questionnaire. On-site audits are by prior agreement, during business hours, subject to confidentiality and without disrupting the service.

9. Data subject requests

Customer admins can view, correct and export their workspace’s records directly in the app. Where a data subject contacts us directly, we will refer them to the relevant Customer and assist as reasonably required. See our support page for the request routes.

10. Deletion and return

On termination the Customer may export its data for 30 days. After that period we delete Customer personal data from active systems, with backups aging out on their normal cycle within 90 days, except where retention is required by law.

11. Contact

Data protection contact: privacy@buildfix.app · Assurio