CONNEXION

Connexion sécurisée en cours…

Nous préparons votre essai Apsolu Pro. Vous pouvez revenir à l’accueil à tout moment.

APSOLUProDPA v1.019 May 2026
TRUST-003 — GDPR Compliance

Data Processing Agreement

Version 1.0 — Effective 19 May 2026— Ref. audit Rami Zam 14/05/2026 (Q12, Q15)

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CGID Project Management LLC, operating APSOLU Pro (“Processor”, “we”), and any organization subscribing to APSOLU Pro (“Controller”, “Customer”). It governs all processing of personal data carried out by APSOLU Pro on behalf of the Customer, in compliance with Regulation (EU) 2016/679 (“GDPR”).

§1Definitions

For the purposes of this DPA, the following terms apply as defined in Article 4 GDPR unless otherwise stated:

  • Personal Data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data (collection, storage, retrieval, use, disclosure, deletion).
  • Controller: the Customer — the entity that determines purposes and means of processing.
  • Processor: APSOLU Pro / CGID Project Management LLC — the entity processing data on the Controller’s behalf.
  • Sub-processor: any third party engaged by the Processor to process personal data.
  • Data Breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • EEA: European Economic Area.
  • SCCs: EU Standard Contractual Clauses (Commission Decision 2021/914/EU).

§2Subject Matter & Duration

This DPA governs the processing of personal data by APSOLU Pro in the context of providing its construction project management Software-as-a-Service (“Service”) to the Customer.

This DPA enters into force on the date the Customer first accepts APSOLU Pro’s Terms of Service and remains in force for the duration of the subscription. Upon termination, Section 11 (Data Retention & Deletion) applies.

§3Nature & Purpose of Processing

AttributeDetails
Nature of processingCollection, storage, organisation, retrieval, display, AI-assisted analysis, deletion
PurposeConstruction project management: meetings (CRR/MoM), action tracking, contact management, document handling, Gantt planning
Categories of data subjectsCustomer employees, project managers, construction professionals, subcontractors, site contacts
Types of personal dataFull names, professional email addresses, phone numbers, company affiliations, project roles, meeting notes and transcripts, action items, photo attachments (site inspections)
Special categories (Art. 9)None — APSOLU Pro does not collect special category data. Customers must not upload such data.

§4Data Residency

Primary storage: European Union (eu-central-1, Frankfurt, Germany). All Customer project data — database records and uploaded files — is stored in EU infrastructure by default.
SystemProviderRegionData stored
Primary database (PostgreSQL)Supabase, Inc.eu-central-1 — Frankfurt, DEAll project records, contacts, actions, programme data
File storage (R2)Cloudflare, Inc.EU bucket — Frankfurt, DEUploaded documents, photos, attachments
Application servers (CDN edge)Vercel, Inc.EU edge nodes (primary)No persistent data; request routing only
Authentication sessionsClerk, Inc.US (EU-proxied endpoints)Session tokens, user identity — SCCs apply
AI processing (transient)OpenRouter, Inc.USTranscript/document text — transient only, not retained
AI processing (meeting transcription, email extraction, programme import) transmits document text to OpenRouter/Google Gemini servers located in the United States for inference. This data is transient — it is not stored by OpenRouter after the API response. The Customer acknowledges this transfer occurs each time AI features are used.

§5Authorised Sub-processors

The Customer grants general authorisation to engage the sub-processors listed below. APSOLU Pro will notify the Customer at least 30 days before adding or replacing a sub-processor, giving the Customer an opportunity to object on reasonable grounds.

Sub-processorRoleCountrySafeguard
Supabase, Inc.Managed PostgreSQL databaseUSA (data in EU — eu-central-1)Supabase DPA + SCCs (2021/914/EU)
Vercel, Inc.Application hosting & CDNUSA (EU edge nodes)Vercel DPA + SCCs
Clerk, Inc.Authentication & identity managementUSA (EU-proxied)Clerk DPA + SCCs
Cloudflare, Inc.File storage (R2) & CDNUSA (EU bucket)Cloudflare DPA + SCCs
OpenRouter, Inc.AI inference gateway (transient)USAOpenRouter ToS — zero data retention commitment
Google LLC (via OpenRouter)AI model (Gemini Flash)USAGoogle Cloud DPA + SCCs — inference only
Stripe, Inc.Payment processingUSAStripe DPA + SCCs — billing data only

Sub-processor DPAs and SCCs are maintained by each respective provider and available on their legal pages. APSOLU Pro has executed or relies on standard DPA agreements with each sub-processor listed above.

§6Controller Obligations

The Customer, as Data Controller, agrees to:

  • Establish and maintain a lawful basis for processing personal data within the Service (e.g. legitimate interest, contract performance, consent where required).
  • Ensure data subjects (employees, contacts) have been informed of the processing, in accordance with Articles 13–14 GDPR.
  • Not upload special category data (Art. 9 GDPR) or data relating to children under 16 to the Service.
  • Provide APSOLU Pro with timely and accurate instructions where processing deviates from this DPA.
  • Designate a security contact in the APSOLU Pro account settings to receive breach notifications.

§7Processor Obligations

APSOLU Pro, as Data Processor, commits to:

  1. Process only on instructions. Process personal data solely on the documented instructions of the Controller, unless required by applicable law (in which case APSOLU Pro will inform the Controller, to the extent permitted by law).
  2. Confidentiality. Ensure all persons authorised to process personal data are bound by contractual or statutory confidentiality obligations.
  3. Security. Implement appropriate technical and organisational measures per Article 32 GDPR (see Section 8).
  4. Sub-processing. Not engage sub-processors without prior general or specific authorisation of the Controller (see Section 5). Impose equivalent data protection obligations on sub-processors by contract.
  5. Data subject rights. Assist the Controller, by appropriate technical and organisational measures, to fulfil its obligation to respond to data subject requests (see Section 9).
  6. Security assistance. Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIA).
  7. Deletion / return.At the Controller’s choice, delete or return all personal data on termination of the service (see Section 11).
  8. Audit cooperation. Make available all information necessary to demonstrate compliance and allow audits conducted by the Controller or their designated auditor (see Section 13).
  9. Notification of conflicts.Immediately notify the Controller if, in APSOLU Pro’s opinion, an instruction infringes applicable data protection law.

§8Security Measures

APSOLU Pro implements the following technical and organisational security measures pursuant to Article 32 GDPR:

MeasureImplementation
Encryption at restAES-256 — Supabase (database), Cloudflare R2 (files)
Encryption in transitTLS 1.2+ enforced on all endpoints
AuthenticationMulti-factor authentication via Clerk; APSOLU staff access uses MFA
Access controlRow-Level Security (RLS) in Supabase — all queries scoped by orgId; least-privilege staff access
Network isolationSupabase project with IP allowlist; Vercel environment isolation
Dependency managementAutomated vulnerability scanning (Dependabot); monthly dependency review
Secrets managementEnvironment variables via Vercel; no secrets in source code
Audit loggingAPI access logs retained 12 months; authentication events logged
BackupSupabase daily automated backups; 7-day rolling snapshot retention
Incident responseDocumented breach notification procedure (see Section 12)

§9Data Subject Rights

APSOLU Pro provides mechanisms to assist the Controller in responding to data subject requests under Articles 15–22 GDPR. Controllers may submit requests via privacy@apsolu.app.

RightScopeResponse time
Access (Art. 15)Export of all personal data held for a given individual30 days
Rectification (Art. 16)Correction of inaccurate personal data30 days
Erasure (Art. 17)Deletion of personal data subject to legal retention obligations30 days
Portability (Art. 20)Machine-readable export (JSON/CSV)30 days
Restriction (Art. 18)Suspension of processing for the individual72 hours (acknowledgment)
Objection (Art. 21)Cessation of processing based on legitimate interest30 days

APSOLU Pro will acknowledge all verified requests within 72 hours and complete the action within 30 days. Where technically complex or high volume, this period may be extended by a further two months, with notification to the Controller.

APSOLU Pro processes requests from Controllers only — not directly from data subjects. Controllers are responsible for verifying the identity of requesting data subjects before forwarding requests.

§10International Data Transfers

Where personal data is transferred outside the EEA (to Clerk, Vercel, OpenRouter, Google, Stripe — all US-based), APSOLU Pro relies on:

  • EU Standard Contractual Clauses (Commission Implementing Decision 2021/914/EU, Module 2: Controller-to-Processor) executed with each sub-processor.
  • Transfer Impact Assessments (TIA) conducted for US-based sub-processors — available on request.
  • For AI inference (OpenRouter/Google Gemini): transfers are transient (request/response cycle only) and covered by SCCs. No personal data is retained by these providers post-inference.

Primary data storage remains in the EU (eu-central-1). International transfers are limited to the minimum necessary for the operation of the Service.

§11Data Retention & Deletion

Data typeRetention periodBasis
Active project dataDuration of active subscriptionContract performance
Soft-deleted records (trash)30 days after deletion by user, then hard-deletedUser expectation
Audit & access logs12 months rollingSecurity / legal
Database backup snapshots7 days rollingDisaster recovery
Billing & invoice records7 years from invoice dateLegal obligation (accounting)
AI processing inputs (transient)Not retained beyond API response (~seconds)Zero retention — OpenRouter commitment
Post-termination export window: Upon subscription termination, the Customer has 90 days to export their data via the APSOLU Pro interface or by written request to privacy@apsolu.app. After 90 days, all Customer personal data is irreversibly and permanently deleted from all systems, except where retention is mandated by law (billing records).

§12Breach Notification

Ref: Audit TRUST-003 — Q15. In the event of a confirmed or suspected personal data breach, APSOLU Pro follows this notification procedure:

TimelineActionRecipient
Within 24 hours of detectionInitial notification — nature of incident, data categories potentially affected, estimated volume, immediate containment actions takenCustomer security contact (email) + security@apsolu.app
Within 48 hoursPreliminary incident report — likely consequences, short-term remediation measuresCustomer security contact
Within 72 hoursFull incident report — confirmed scope, root cause analysis, complete mitigation plan. Sufficient for Controller to fulfil Art. 33 GDPR notification to supervisory authorityCustomer security contact + documented in APSOLU Pro audit log
OngoingProgress updates until incident closed and post-mortem availableCustomer security contact
The Controller retains sole responsibility for notifying their competent supervisory authority (Article 33 GDPR — within 72 hours) and, where required, affected data subjects (Article 34 GDPR). APSOLU Pro provides the technical information required to support these notifications but does not notify supervisory authorities on the Controller’s behalf.

To report a suspected breach or security vulnerability: security@apsolu.app

§13Audit Rights

The Controller has the right to audit APSOLU Pro’s data processing activities to verify compliance with this DPA. The following procedure applies:

  • Written notice of at least 30 days prior to the audit.
  • Audits conducted during business hours, at most once per 12-month period.
  • Costs of the audit are borne by the Controller unless APSOLU Pro is found to be non-compliant.
  • APSOLU Pro may satisfy audit requests by providing current third-party certifications, audit reports (SOC 2 Type II from sub-processors), or penetration test summaries in lieu of direct on-site access.
  • Auditors must execute a confidentiality agreement before accessing any APSOLU Pro systems or documentation.

§14Liability

Each party’s liability under this DPA is subject to the limitations and exclusions set out in the APSOLU Pro Terms of Service. APSOLU Pro’s aggregate liability to the Controller for breaches of this DPA shall not exceed the total fees paid by the Controller in the 12 months preceding the incident.

APSOLU Pro is not liable for breaches caused by the Controller’s failure to comply with its obligations under Section 6, or by instructions provided by the Controller that conflict with applicable data protection law.

§15Governing Law

This DPA is governed by and construed in accordance with the data protection laws of the European Union(Regulation 2016/679 — GDPR). Where required by the Controller’s jurisdiction, additional local law requirements apply and are addressed in a supplementary schedule upon request.

Disputes arising from this DPA shall first be subject to good-faith negotiation between the parties. If unresolved within 30 days, disputes shall be referred to the competent courts of the Controller’s EEA member state, or — for non-EEA Controllers — to the courts of competent jurisdiction agreed in the Terms of Service.

§16Contact

TopicContact
Data protection & privacyprivacy@apsolu.app
Security incidents & breach reportssecurity@apsolu.app
DPA questions & sub-processor updateslegal@apsolu.app
Postal addressCGID Project Management LLC — Dubai, United Arab Emirates

For questions about this DPA, to request a signed copy, or to exercise Controller rights under GDPR, contact us at privacy@apsolu.app. We respond within 5 business days.

APSOLU Pro DPA — v1.019 May 2026. CGID Project Management LLC.