Data Processing Addendum (DPA)
Last updated: 26 August 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Mufaddal Maimoon, trading as Projexa (a sole trader, no company number), of Rutland House, 23-25 Friar Lane, Leicester, LE1 5QQ ("Processor", "we") and the Customer ("Controller", "you"), and applies automatically to every Customer using the Service — it does not require separate signature unless you request a signed copy for your own records.
Where UK GDPR applies, this DPA reflects the obligations of Article 28.
1. Definitions
Terms like "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in UK GDPR. "Sub-processor" means a third party engaged by us to process personal data on your behalf.
2. Subject matter, duration, and purpose
We process personal data on your behalf for the duration of your subscription to the Service, solely to provide, secure, and support the Service as described in the Terms of Service — see Section 4 below.
3. Categories of data subjects and personal data
- Data subjects: your team members, your clients and their contacts, and (if you use the client portal) your clients' own users.
- Personal data types: names, email addresses, phone numbers, job titles/roles, project and financial records associated with those individuals, uploaded documents, and system-generated activity/audit data.
4. Nature and purpose of processing
We process this data to: host and operate the Service; authenticate users; store and retrieve project, client, and financial records you enter; send transactional emails you or your team trigger (e.g. invites, progress reports); maintain audit logs; and provide customer support.
5. Our obligations
We will:
- Process personal data only on your documented instructions (including as set out in the Terms and this DPA), unless required otherwise by law;
- Ensure people authorised to process the data are bound by confidentiality;
- Implement appropriate technical and organisational security measures (Section 8);
- Assist you in responding to data subject requests and in meeting your own UK GDPR obligations (Section 6);
- Notify you without undue delay after becoming aware of a personal data breach affecting your data (Section 7);
- Not engage a new sub-processor without giving you prior notice and a reasonable opportunity to object (Section 9);
- At your choice, delete or return all personal data at the end of the relationship, subject to any legal retention requirement (Section 10);
- Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits (Section 11).
6. Assistance with data subject rights
Where a data subject contacts us directly about data you control, we will redirect them to you as the Controller and, where appropriate, notify you. We will provide reasonable assistance to help you respond to access, rectification, erasure, restriction, portability, and objection requests.
7. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting your data, including (to the extent known): the nature of the breach, likely consequences, and measures taken or proposed. See also our Incident Response Summary for what we commit to and how quickly.
8. Security measures
- Encryption in transit (TLS) and at rest.
- Role-based access control enforced at the database level via row-level security, not only in the application layer.
- Audit logging of key actions, itself access-controlled.
- Tenant isolation between Customers (multi-tenant architecture with per-company data scoping).
- Daily automated backups with 7-day retention (Supabase Pro tier, confirmed live 2026-08-26).
9. Sub-processors
You give general authorisation for us to engage the sub-processors listed at getprojexa.com/legal/sub-processors, which we will keep up to date. We will give at least 30 days' notice before adding a new sub-processor (e.g. by email or an in-app notice), during which you may object on reasonable data-protection grounds; if unresolved, either party may terminate the affected part of the Service.
10. Return and deletion of data
On termination, you may export your data for 30 days. After that window, we will delete or anonymise personal data, except where retention is required by law.
11. Audit rights
We will make available information reasonably necessary to demonstrate compliance with this DPA (e.g. security documentation, this DPA itself, relevant sub-processor certifications) and permit audits, including inspections, on reasonable notice, no more than once per year absent cause, subject to confidentiality.
12. International transfers
Our primary infrastructure processes data within the EU (Ireland). Where a sub-processor processes personal data outside the UK/EEA, we will ensure an appropriate transfer mechanism is in place (UK International Data Transfer Addendum to the EU SCCs, an adequacy regulation, or equivalent) before that transfer occurs. See the Sub-processor list for current transfer status per provider.
13. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service.
14. Governing law
This DPA is governed by the laws of England and Wales.