Connexion sécurisée en cours…
Nous préparons votre essai Apsolu Pro. Vous pouvez revenir à l’accueil à tout moment.
Nous préparons votre essai Apsolu Pro. Vous pouvez revenir à l’accueil à tout moment.
Version 1.0 — Effective 19 May 2026— Ref. audit Rami Zam 14/05/2026 (Q12, Q15)
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CGID Project Management LLC, operating APSOLU Pro (“Processor”, “we”), and any organization subscribing to APSOLU Pro (“Controller”, “Customer”). It governs all processing of personal data carried out by APSOLU Pro on behalf of the Customer, in compliance with Regulation (EU) 2016/679 (“GDPR”).
For the purposes of this DPA, the following terms apply as defined in Article 4 GDPR unless otherwise stated:
This DPA governs the processing of personal data by APSOLU Pro in the context of providing its construction project management Software-as-a-Service (“Service”) to the Customer.
This DPA enters into force on the date the Customer first accepts APSOLU Pro’s Terms of Service and remains in force for the duration of the subscription. Upon termination, Section 11 (Data Retention & Deletion) applies.
| Attribute | Details |
|---|---|
| Nature of processing | Collection, storage, organisation, retrieval, display, AI-assisted analysis, deletion |
| Purpose | Construction project management: meetings (CRR/MoM), action tracking, contact management, document handling, Gantt planning |
| Categories of data subjects | Customer employees, project managers, construction professionals, subcontractors, site contacts |
| Types of personal data | Full names, professional email addresses, phone numbers, company affiliations, project roles, meeting notes and transcripts, action items, photo attachments (site inspections) |
| Special categories (Art. 9) | None — APSOLU Pro does not collect special category data. Customers must not upload such data. |
| System | Provider | Region | Data stored |
|---|---|---|---|
| Primary database (PostgreSQL) | Supabase, Inc. | eu-central-1 — Frankfurt, DE | All project records, contacts, actions, programme data |
| File storage (R2) | Cloudflare, Inc. | EU bucket — Frankfurt, DE | Uploaded documents, photos, attachments |
| Application servers (CDN edge) | Vercel, Inc. | EU edge nodes (primary) | No persistent data; request routing only |
| Authentication sessions | Clerk, Inc. | US (EU-proxied endpoints) | Session tokens, user identity — SCCs apply |
| AI processing (transient) | OpenRouter, Inc. | US | Transcript/document text — transient only, not retained |
The Customer grants general authorisation to engage the sub-processors listed below. APSOLU Pro will notify the Customer at least 30 days before adding or replacing a sub-processor, giving the Customer an opportunity to object on reasonable grounds.
| Sub-processor | Role | Country | Safeguard |
|---|---|---|---|
| Supabase, Inc. | Managed PostgreSQL database | USA (data in EU — eu-central-1) | Supabase DPA + SCCs (2021/914/EU) |
| Vercel, Inc. | Application hosting & CDN | USA (EU edge nodes) | Vercel DPA + SCCs |
| Clerk, Inc. | Authentication & identity management | USA (EU-proxied) | Clerk DPA + SCCs |
| Cloudflare, Inc. | File storage (R2) & CDN | USA (EU bucket) | Cloudflare DPA + SCCs |
| OpenRouter, Inc. | AI inference gateway (transient) | USA | OpenRouter ToS — zero data retention commitment |
| Google LLC (via OpenRouter) | AI model (Gemini Flash) | USA | Google Cloud DPA + SCCs — inference only |
| Stripe, Inc. | Payment processing | USA | Stripe DPA + SCCs — billing data only |
Sub-processor DPAs and SCCs are maintained by each respective provider and available on their legal pages. APSOLU Pro has executed or relies on standard DPA agreements with each sub-processor listed above.
The Customer, as Data Controller, agrees to:
APSOLU Pro, as Data Processor, commits to:
APSOLU Pro implements the following technical and organisational security measures pursuant to Article 32 GDPR:
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256 — Supabase (database), Cloudflare R2 (files) |
| Encryption in transit | TLS 1.2+ enforced on all endpoints |
| Authentication | Multi-factor authentication via Clerk; APSOLU staff access uses MFA |
| Access control | Row-Level Security (RLS) in Supabase — all queries scoped by orgId; least-privilege staff access |
| Network isolation | Supabase project with IP allowlist; Vercel environment isolation |
| Dependency management | Automated vulnerability scanning (Dependabot); monthly dependency review |
| Secrets management | Environment variables via Vercel; no secrets in source code |
| Audit logging | API access logs retained 12 months; authentication events logged |
| Backup | Supabase daily automated backups; 7-day rolling snapshot retention |
| Incident response | Documented breach notification procedure (see Section 12) |
APSOLU Pro provides mechanisms to assist the Controller in responding to data subject requests under Articles 15–22 GDPR. Controllers may submit requests via privacy@apsolu.app.
| Right | Scope | Response time |
|---|---|---|
| Access (Art. 15) | Export of all personal data held for a given individual | 30 days |
| Rectification (Art. 16) | Correction of inaccurate personal data | 30 days |
| Erasure (Art. 17) | Deletion of personal data subject to legal retention obligations | 30 days |
| Portability (Art. 20) | Machine-readable export (JSON/CSV) | 30 days |
| Restriction (Art. 18) | Suspension of processing for the individual | 72 hours (acknowledgment) |
| Objection (Art. 21) | Cessation of processing based on legitimate interest | 30 days |
APSOLU Pro will acknowledge all verified requests within 72 hours and complete the action within 30 days. Where technically complex or high volume, this period may be extended by a further two months, with notification to the Controller.
Where personal data is transferred outside the EEA (to Clerk, Vercel, OpenRouter, Google, Stripe — all US-based), APSOLU Pro relies on:
Primary data storage remains in the EU (eu-central-1). International transfers are limited to the minimum necessary for the operation of the Service.
| Data type | Retention period | Basis |
|---|---|---|
| Active project data | Duration of active subscription | Contract performance |
| Soft-deleted records (trash) | 30 days after deletion by user, then hard-deleted | User expectation |
| Audit & access logs | 12 months rolling | Security / legal |
| Database backup snapshots | 7 days rolling | Disaster recovery |
| Billing & invoice records | 7 years from invoice date | Legal obligation (accounting) |
| AI processing inputs (transient) | Not retained beyond API response (~seconds) | Zero retention — OpenRouter commitment |
Ref: Audit TRUST-003 — Q15. In the event of a confirmed or suspected personal data breach, APSOLU Pro follows this notification procedure:
| Timeline | Action | Recipient |
|---|---|---|
| Within 24 hours of detection | Initial notification — nature of incident, data categories potentially affected, estimated volume, immediate containment actions taken | Customer security contact (email) + security@apsolu.app |
| Within 48 hours | Preliminary incident report — likely consequences, short-term remediation measures | Customer security contact |
| Within 72 hours | Full incident report — confirmed scope, root cause analysis, complete mitigation plan. Sufficient for Controller to fulfil Art. 33 GDPR notification to supervisory authority | Customer security contact + documented in APSOLU Pro audit log |
| Ongoing | Progress updates until incident closed and post-mortem available | Customer security contact |
To report a suspected breach or security vulnerability: security@apsolu.app
The Controller has the right to audit APSOLU Pro’s data processing activities to verify compliance with this DPA. The following procedure applies:
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the APSOLU Pro Terms of Service. APSOLU Pro’s aggregate liability to the Controller for breaches of this DPA shall not exceed the total fees paid by the Controller in the 12 months preceding the incident.
APSOLU Pro is not liable for breaches caused by the Controller’s failure to comply with its obligations under Section 6, or by instructions provided by the Controller that conflict with applicable data protection law.
This DPA is governed by and construed in accordance with the data protection laws of the European Union(Regulation 2016/679 — GDPR). Where required by the Controller’s jurisdiction, additional local law requirements apply and are addressed in a supplementary schedule upon request.
Disputes arising from this DPA shall first be subject to good-faith negotiation between the parties. If unresolved within 30 days, disputes shall be referred to the competent courts of the Controller’s EEA member state, or — for non-EEA Controllers — to the courts of competent jurisdiction agreed in the Terms of Service.
| Topic | Contact |
|---|---|
| Data protection & privacy | privacy@apsolu.app |
| Security incidents & breach reports | security@apsolu.app |
| DPA questions & sub-processor updates | legal@apsolu.app |
| Postal address | CGID Project Management LLC — Dubai, United Arab Emirates |
For questions about this DPA, to request a signed copy, or to exercise Controller rights under GDPR, contact us at privacy@apsolu.app. We respond within 5 business days.
APSOLU Pro DPA — v1.0 — 19 May 2026. CGID Project Management LLC.