EN · IT
Data Processing Agreement (DPA)
Template - signed with each customer at subscription. Last updated: 13 May 2026
1. Parties
This DPA is entered into between the customer organisation ("Controller") and Cloudend ("Processor"), and forms an integral part of the Terms of Service.
2. Subject matter and duration
The Processor processes personal data on behalf of the Controller for the sole purpose of providing the Cantieri SaaS service. Duration: for as long as the Terms of Service are in force.
3. Nature and purpose of processing
Hosting, storage and management of attendance records and worker registry data, in order to allow the Controller to track presence at construction sites.
4. Categories of data subjects
- Workers registered by the Controller
- Foremen and dashboard users authorised by the Controller
- The Controller's administrative contact
5. Categories of personal data
- Identification: first name, last name, internal employee code, hashed PIN
- Contact (optional): phone, email, address, emergency contact
- Attendance: site, check-in/check-out timestamps, user agent of the scan
- Authentication: email and hashed password for dashboard users
6. Obligations of the Processor
- Process personal data only on documented instructions from the Controller
- Ensure persons authorised to process the data are bound to confidentiality
- Implement appropriate technical and organisational security measures (see Annex A)
- Engage sub-processors only with the Controller's general written authorisation (see Annex B); notify the Controller of any intended change
- Assist the Controller in fulfilling data subject requests
- Notify the Controller without undue delay of any personal data breach
- On termination, delete or return all personal data as instructed by the Controller
7. Sub-processors (Annex B)
- Supabase Inc - database and authentication, EU region (Frankfurt)
- Cloudflare Inc - CDN, DNS, edge security, Workers
- Vercel Inc - frontend hosting
8. International transfers
Where sub-processors are located outside the UK/EEA, transfers are protected by appropriate safeguards (Standard Contractual Clauses, UK International Data Transfer Addendum).
9. Security measures (Annex A)
- Encryption in transit (TLS 1.2+) on all surfaces
- Row Level Security in the database for tenant isolation
- Role-based access control with check on each privileged RPC
- Rate limiting at the application and edge layers
- Service role keys kept only as server-side secrets
- Multi-factor authentication enforced on Processor's privileged accounts
- Daily database backups with up to 30 days retention
10. Audit
The Controller may, upon reasonable written notice, request information necessary to demonstrate Processor compliance with this DPA, no more than once per year.
11. Liability
The liability of each party under this DPA is subject to the limitations set out in the Terms of Service.
12. Signature
This DPA is signed electronically when the Controller subscribes to the Cantieri service and accepts the Terms of Service. A signed copy can be requested at any time at hello@cloudend.dev.
← Back to home