Data Processing Addendum

Effective: May 25, 2026 · Forms part of your Terms of Service

1. Roles

Customer is the Controller; Tracks IT is the Processor for personal data processed on Customer's behalf within the Service.

2. Scope of processing

  • Subject matter: provision of the Service.
  • Duration: term of the subscription + 30-day export window.
  • Data subjects: Customer's authorized users.
  • Categories: identifiers, professional/role data, content uploaded by users (photos, voice notes, inspection metadata).

3. Sub-processors

Current sub-processors:

  • Supabase (database, auth, storage) — EU region.
  • Lovable AI Gateway → Google Gemini — AI inference, zero-retention.
  • Cloudflare — edge delivery, DDoS protection.

We will give 30 days' notice before adding a new sub-processor.

4. Security measures

Encryption in transit and at rest, RBAC, row-level security, audit logs, MFA, least-privilege access for staff, annual penetration testing.

5. International transfers

EU Standard Contractual Clauses (2021/914) apply where applicable. UK IDTA addendum available on request.

6. Data subject requests

We will assist Customer in fulfilling DSARs within 5 business days of request via privacy@enginetracksit.com.

7. Breach notification

We will notify Customer of any personal data breach without undue delay, and in any event within 72 hours of confirmation.

8. Return / deletion

On termination, Customer may export data for 30 days; thereafter we will delete it within 60 days, subject to backup expiry cycles.

Need a counter-signed copy? Email legal@enginetracksit.com.