Data Processing Addendum
Version 1.0 · Effective 25 July 2026
1. Roles
The Customer is the controller of personal data entered into its workspace — staff, engineers, contractors and reporters or tenants. Assurio Hub is the processor, acting only on the Customer’s documented instructions, which include use of the platform’s features and this addendum. Where we process data about our own account holders for billing, security and service administration, we act as controller under our Privacy Policy.
2. Subject matter, duration and nature
- Subject matter: provision of the Assurio Hub maintenance and work-order platform.
- Duration: for the term of the subscription, plus a 30-day export window.
- Nature and purpose: hosting, storage, retrieval, transmission, backup and deletion of workspace records so maintenance and statutory safety work can be recorded and reported.
- Data subjects: Customer staff, engineers and contractors; reporters and tenants who raise jobs; named contacts on assets and sites.
- Categories of data: name, work email, phone, role, workspace membership; job reports, comments and activity history; photographs and annotations attached to jobs; site, building, location and asset references; parts usage; fire-walk checkpoint scans with timestamps and the identity of the person performing the walk; device and error diagnostics.
- Special category data: not requested and not required. Customers must not enter health or other special category data into free-text fields or photographs.
3. Processor obligations
- Process personal data only on documented instructions, including for transfers, unless required by law.
- Ensure personnel with access are bound by confidentiality obligations.
- Implement the technical and organisational measures in section 5.
- Respect the conditions in section 4 for engaging subprocessors.
- Assist the Customer with data subject requests, taking into account the nature of processing.
- Assist with security, breach notification and data protection impact assessments under Articles 32–36.
- Delete or return personal data at the end of the service, as directed by the Customer.
- Make available information necessary to demonstrate compliance and allow audits under section 8.
4. Subprocessors
The Customer gives general authorisation for the subprocessors below. We will give at least 30 days’ notice before adding or replacing a subprocessor, and the Customer may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service without penalty. Each subprocessor is bound by data protection terms no less protective than this addendum.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Managed Postgres database, authentication, file storage and realtime | European Union |
| VPS hosting provider [CONFIRM PROVIDER] | Application hosting and TLS termination | [CONFIRM REGION] |
| Email delivery provider | Transactional email: invitations, password resets and notifications | European Union |
| Hotel Stock Master (customer-enabled) | Two-way parts and stock synchronisation — only if the Customer enables the integration | As operated by the Customer |
| Apple / Google app stores | Distribution of the mobile apps and crash diagnostics | Global |
5. Security measures (Article 32)
- Encryption in transit (TLS) and encryption at rest for the database and file storage.
- Row-level security enforced per workspace and per role, so one workspace cannot read another’s records.
- Private storage buckets; job photographs are reachable only through short-lived signed links issued to signed-in members.
- Invite-only account creation; sign-ups from uninvited addresses are rejected at the database layer.
- Least-privilege database roles; privileged helper functions held in a non-public schema and not callable through the API.
- Automated backups with point-in-time recovery, and periodic restore checks.
- Audit trails of work-order activity, and immutable timestamps on fire-walk checkpoint scans.
- Regular automated security scanning of the database access model.
6. International transfers
Personal data is hosted in the European Union. Where a subprocessor processes data outside the EEA or the UK, transfers rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, plus supplementary measures where required by a transfer risk assessment.
7. Personal data breaches
We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer data, with the information available to us and updates as the investigation progresses, so the Customer can meet its own 72-hour notification duty.
8. Audits
On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority, we will provide documentation about our security measures and respond to a reasonable security questionnaire. On-site audits are by prior agreement, during business hours, subject to confidentiality and without disrupting the service.
9. Data subject requests
Customer admins can view, correct and export their workspace’s records directly in the app. Where a data subject contacts us directly, we will refer them to the relevant Customer and assist as reasonably required. See our support page for the request routes.
10. Deletion and return
On termination the Customer may export its data for 30 days. After that period we delete Customer personal data from active systems, with backups aging out on their normal cycle within 90 days, except where retention is required by law.
11. Contact
Data protection contact: privacy@assurio.app · Assurio Hub