Data Processing Agreement
Version 1.0 — Effective 19 May 2026— Ref. audit Rami Zam 14/05/2026 (Q12, Q15)
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CGID Project Management LLC, operating APSOLU Pro (“Processor”, “we”), and any organization subscribing to APSOLU Pro (“Controller”, “Customer”). It governs all processing of personal data carried out by APSOLU Pro on behalf of the Customer, in compliance with Regulation (EU) 2016/679 (“GDPR”).
§1Definitions
For the purposes of this DPA, the following terms apply as defined in Article 4 GDPR unless otherwise stated:
- Personal Data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data (collection, storage, retrieval, use, disclosure, deletion).
- Controller: the Customer — the entity that determines purposes and means of processing.
- Processor: APSOLU Pro / CGID Project Management LLC — the entity processing data on the Controller’s behalf.
- Sub-processor: any third party engaged by the Processor to process personal data.
- Data Breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- EEA: European Economic Area.
- SCCs: EU Standard Contractual Clauses (Commission Decision 2021/914/EU).
§2Subject Matter & Duration
This DPA governs the processing of personal data by APSOLU Pro in the context of providing its construction project management Software-as-a-Service (“Service”) to the Customer.
This DPA enters into force on the date the Customer first accepts APSOLU Pro’s Terms of Service and remains in force for the duration of the subscription. Upon termination, Section 11 (Data Retention & Deletion) applies.
§3Nature & Purpose of Processing
| Attribute | Details |
|---|---|
| Nature of processing | Collection, storage, organisation, retrieval, display, AI-assisted analysis, deletion |
| Purpose | Construction project management: meetings (CRR/MoM), action tracking, contact management, document handling, Gantt planning |
| Categories of data subjects | Customer employees, project managers, construction professionals, subcontractors, site contacts |
| Types of personal data | Full names, professional email addresses, phone numbers, company affiliations, project roles, meeting notes and transcripts, action items, photo attachments (site inspections) |
| Special categories (Art. 9) | None — APSOLU Pro does not collect special category data. Customers must not upload such data. |
§4Data Residency
| System | Provider | Region | Data stored |
|---|---|---|---|
| Primary database (PostgreSQL) | Supabase, Inc. | eu-central-1 — Frankfurt, DE | All project records, contacts, actions, programme data |
| File storage (R2) | Cloudflare, Inc. | EU bucket — Frankfurt, DE | Uploaded documents, photos, attachments |
| Application servers (CDN edge) | Vercel, Inc. | EU edge nodes (primary) | No persistent data; request routing only |
| Authentication sessions | Clerk, Inc. | US (EU-proxied endpoints) | Session tokens, user identity — SCCs apply |
| AI processing (transient) | OpenRouter, Inc. | US | Transcript/document text — transient only, not retained |
§5Authorised Sub-processors
The Customer grants general authorisation to engage the sub-processors listed below. APSOLU Pro will notify the Customer at least 30 days before adding or replacing a sub-processor, giving the Customer an opportunity to object on reasonable grounds.
| Sub-processor | Role | Country | Safeguard |
|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL database | USA (data in EU — eu-central-1) | Supabase DPA + SCCs (2021/914/EU) |
| Vercel, Inc. | Application hosting & CDN | USA (EU edge nodes) | Vercel DPA + SCCs |
| Clerk, Inc. | Authentication & identity management | USA (EU-proxied) | Clerk DPA + SCCs |
| Cloudflare, Inc. | File storage (R2) & CDN | USA (EU bucket) | Cloudflare DPA + SCCs |
| OpenRouter, Inc. | AI inference gateway (transient) | USA | OpenRouter ToS — zero data retention commitment |
| Google LLC (via OpenRouter) | AI model (Gemini Flash) | USA | Google Cloud DPA + SCCs — inference only |
| Stripe, Inc. | Payment processing | USA | Stripe DPA + SCCs — billing data only |
Sub-processor DPAs and SCCs are maintained by each respective provider and available on their legal pages. APSOLU Pro has executed or relies on standard DPA agreements with each sub-processor listed above.
§6Controller Obligations
The Customer, as Data Controller, agrees to:
- Establish and maintain a lawful basis for processing personal data within the Service (e.g. legitimate interest, contract performance, consent where required).
- Ensure data subjects (employees, contacts) have been informed of the processing, in accordance with Articles 13–14 GDPR.
- Not upload special category data (Art. 9 GDPR) or data relating to children under 16 to the Service.
- Provide APSOLU Pro with timely and accurate instructions where processing deviates from this DPA.
- Designate a security contact in the APSOLU Pro account settings to receive breach notifications.
§7Processor Obligations
APSOLU Pro, as Data Processor, commits to:
- Process only on instructions. Process personal data solely on the documented instructions of the Controller, unless required by applicable law (in which case APSOLU Pro will inform the Controller, to the extent permitted by law).
- Confidentiality. Ensure all persons authorised to process personal data are bound by contractual or statutory confidentiality obligations.
- Security. Implement appropriate technical and organisational measures per Article 32 GDPR (see Section 8).
- Sub-processing. Not engage sub-processors without prior general or specific authorisation of the Controller (see Section 5). Impose equivalent data protection obligations on sub-processors by contract.
- Data subject rights. Assist the Controller, by appropriate technical and organisational measures, to fulfil its obligation to respond to data subject requests (see Section 9).
- Security assistance. Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIA).
- Deletion / return.At the Controller’s choice, delete or return all personal data on termination of the service (see Section 11).
- Audit cooperation. Make available all information necessary to demonstrate compliance and allow audits conducted by the Controller or their designated auditor (see Section 13).
- Notification of conflicts.Immediately notify the Controller if, in APSOLU Pro’s opinion, an instruction infringes applicable data protection law.
§8Security Measures
APSOLU Pro implements the following technical and organisational security measures pursuant to Article 32 GDPR:
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256 — Supabase (database), Cloudflare R2 (files) |
| Encryption in transit | TLS 1.2+ enforced on all endpoints |
| Authentication | Multi-factor authentication via Clerk; APSOLU staff access uses MFA |
| Access control | Row-Level Security (RLS) in Supabase — all queries scoped by orgId; least-privilege staff access |
| Network isolation | Supabase project with IP allowlist; Vercel environment isolation |
| Dependency management | Automated vulnerability scanning (Dependabot); monthly dependency review |
| Secrets management | Environment variables via Vercel; no secrets in source code |
| Audit logging | API access logs retained 12 months; authentication events logged |
| Backup | Supabase daily automated backups; 7-day rolling snapshot retention |
| Incident response | Documented breach notification procedure (see Section 12) |
§9Data Subject Rights
APSOLU Pro provides mechanisms to assist the Controller in responding to data subject requests under Articles 15–22 GDPR. Controllers may submit requests via privacy@apsolu.app.
| Right | Scope | Response time |
|---|---|---|
| Access (Art. 15) | Export of all personal data held for a given individual | 30 days |
| Rectification (Art. 16) | Correction of inaccurate personal data | 30 days |
| Erasure (Art. 17) | Deletion of personal data subject to legal retention obligations | 30 days |
| Portability (Art. 20) | Machine-readable export (JSON/CSV) | 30 days |
| Restriction (Art. 18) | Suspension of processing for the individual | 72 hours (acknowledgment) |
| Objection (Art. 21) | Cessation of processing based on legitimate interest | 30 days |
APSOLU Pro will acknowledge all verified requests within 72 hours and complete the action within 30 days. Where technically complex or high volume, this period may be extended by a further two months, with notification to the Controller.
§10International Data Transfers
Where personal data is transferred outside the EEA (to Clerk, Vercel, OpenRouter, Google, Stripe — all US-based), APSOLU Pro relies on:
- EU Standard Contractual Clauses (Commission Implementing Decision 2021/914/EU, Module 2: Controller-to-Processor) executed with each sub-processor.
- Transfer Impact Assessments (TIA) conducted for US-based sub-processors — available on request.
- For AI inference (OpenRouter/Google Gemini): transfers are transient (request/response cycle only) and covered by SCCs. No personal data is retained by these providers post-inference.
Primary data storage remains in the EU (eu-central-1). International transfers are limited to the minimum necessary for the operation of the Service.
§11Data Retention & Deletion
| Data type | Retention period | Basis |
|---|---|---|
| Active project data | Duration of active subscription | Contract performance |
| Soft-deleted records (trash) | 30 days after deletion by user, then hard-deleted | User expectation |
| Audit & access logs | 12 months rolling | Security / legal |
| Database backup snapshots | 7 days rolling | Disaster recovery |
| Billing & invoice records | 7 years from invoice date | Legal obligation (accounting) |
| AI processing inputs (transient) | Not retained beyond API response (~seconds) | Zero retention — OpenRouter commitment |
§12Breach Notification
Ref: Audit TRUST-003 — Q15. In the event of a confirmed or suspected personal data breach, APSOLU Pro follows this notification procedure:
| Timeline | Action | Recipient |
|---|---|---|
| Within 24 hours of detection | Initial notification — nature of incident, data categories potentially affected, estimated volume, immediate containment actions taken | Customer security contact (email) + security@apsolu.app |
| Within 48 hours | Preliminary incident report — likely consequences, short-term remediation measures | Customer security contact |
| Within 72 hours | Full incident report — confirmed scope, root cause analysis, complete mitigation plan. Sufficient for Controller to fulfil Art. 33 GDPR notification to supervisory authority | Customer security contact + documented in APSOLU Pro audit log |
| Ongoing | Progress updates until incident closed and post-mortem available | Customer security contact |
To report a suspected breach or security vulnerability: security@apsolu.app
§13Audit Rights
The Controller has the right to audit APSOLU Pro’s data processing activities to verify compliance with this DPA. The following procedure applies:
- Written notice of at least 30 days prior to the audit.
- Audits conducted during business hours, at most once per 12-month period.
- Costs of the audit are borne by the Controller unless APSOLU Pro is found to be non-compliant.
- APSOLU Pro may satisfy audit requests by providing current third-party certifications, audit reports (SOC 2 Type II from sub-processors), or penetration test summaries in lieu of direct on-site access.
- Auditors must execute a confidentiality agreement before accessing any APSOLU Pro systems or documentation.
§14Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the APSOLU Pro Terms of Service. APSOLU Pro’s aggregate liability to the Controller for breaches of this DPA shall not exceed the total fees paid by the Controller in the 12 months preceding the incident.
APSOLU Pro is not liable for breaches caused by the Controller’s failure to comply with its obligations under Section 6, or by instructions provided by the Controller that conflict with applicable data protection law.
§15Governing Law
This DPA is governed by and construed in accordance with the data protection laws of the European Union(Regulation 2016/679 — GDPR). Where required by the Controller’s jurisdiction, additional local law requirements apply and are addressed in a supplementary schedule upon request.
Disputes arising from this DPA shall first be subject to good-faith negotiation between the parties. If unresolved within 30 days, disputes shall be referred to the competent courts of the Controller’s EEA member state, or — for non-EEA Controllers — to the courts of competent jurisdiction agreed in the Terms of Service.
§16Contact
| Topic | Contact |
|---|---|
| Data protection & privacy | privacy@apsolu.app |
| Security incidents & breach reports | security@apsolu.app |
| DPA questions & sub-processor updates | legal@apsolu.app |
| Postal address | CGID Project Management LLC — Dubai, United Arab Emirates |
For questions about this DPA, to request a signed copy, or to exercise Controller rights under GDPR, contact us at privacy@apsolu.app. We respond within 5 business days.
APSOLU Pro DPA — v1.0 — 19 May 2026. CGID Project Management LLC.