Version 1.0 · Effective 25 July 2026
The Customer is the controller of personal data entered into its workspace — staff, engineers, contractors and reporters or tenants. Assurio is the processor, acting only on the Customer’s documented instructions, which include use of the platform’s features and this addendum. Where we process data about our own account holders for billing, security and service administration, we act as controller under our Privacy Policy.
The Customer gives general authorisation for the subprocessors below. We will give at least 30 days’ notice before adding or replacing a subprocessor, and the Customer may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service without penalty. Each subprocessor is bound by data protection terms no less protective than this addendum.
| Subprocessor | Purpose | Region |
|---|---|---|
| Lovable Cloud (Supabase) | Application hosting, managed Postgres database, authentication and file storage | European Union |
| Cloudflare | Edge delivery, TLS termination and DDoS protection for the web app | Global edge, EU-first routing |
| Email delivery provider | Transactional email: invitations, password resets and notifications | European Union |
| Hotel Stock Master (customer-enabled) | Two-way parts and stock synchronisation — only if the Customer enables the integration | As operated by the Customer |
| Apple / Google app stores | Distribution of the mobile apps and crash diagnostics | Global |
Personal data is hosted in the European Union. Where a subprocessor processes data outside the EEA or the UK, transfers rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, plus supplementary measures where required by a transfer risk assessment.
We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer data, with the information available to us and updates as the investigation progresses, so the Customer can meet its own 72-hour notification duty.
On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority, we will provide documentation about our security measures and respond to a reasonable security questionnaire. On-site audits are by prior agreement, during business hours, subject to confidentiality and without disrupting the service.
Customer admins can view, correct and export their workspace’s records directly in the app. Where a data subject contacts us directly, we will refer them to the relevant Customer and assist as reasonably required. See our support page for the request routes.
On termination the Customer may export its data for 30 days. After that period we delete Customer personal data from active systems, with backups aging out on their normal cycle within 90 days, except where retention is required by law.
Data protection contact: privacy@buildfix.app · Assurio