Data Processing Addendum
Effective: May 25, 2026 · Forms part of your Terms of Service
1. Roles
Customer is the Controller; Tracks IT is the Processor for personal data processed on Customer's behalf within the Service.
2. Scope of processing
- Subject matter: provision of the Service.
- Duration: term of the subscription + 30-day export window.
- Data subjects: Customer's authorized users.
- Categories: identifiers, professional/role data, content uploaded by users (photos, voice notes, inspection metadata).
3. Sub-processors
Current sub-processors:
- Supabase (database, auth, storage) — EU region.
- Lovable AI Gateway → Google Gemini — AI inference, zero-retention.
- Cloudflare — edge delivery, DDoS protection.
We will give 30 days' notice before adding a new sub-processor.
4. Security measures
Encryption in transit and at rest, RBAC, row-level security, audit logs, MFA, least-privilege access for staff, annual penetration testing.
5. International transfers
EU Standard Contractual Clauses (2021/914) apply where applicable. UK IDTA addendum available on request.
6. Data subject requests
We will assist Customer in fulfilling DSARs within 5 business days of request via privacy@enginetracksit.com.
7. Breach notification
We will notify Customer of any personal data breach without undue delay, and in any event within 72 hours of confirmation.
8. Return / deletion
On termination, Customer may export data for 30 days; thereafter we will delete it within 60 days, subject to backup expiry cycles.
Need a counter-signed copy? Email legal@enginetracksit.com.