Data Processing Agreement

Last updated: 2026-01-01

1. Roles

For data uploaded by you (records, employee names, supplier contacts), you are the controller and Fudica is the processor. This DPA forms part of the Terms of Service.

2. Sub-processors

  • Supabase Inc. — database, auth, edge functions (EU region: eu-north-1 Helsinki).
  • Stripe Payments Europe Ltd. — payment processing (Ireland).
  • Resend Inc. — transactional email (EU region).
  • Vercel Inc. — static hosting + CDN (global edge; payloads contain no personal data beyond IP).

We will notify you of any new sub-processor at least 30 days before onboarding.

3. Security

All data in transit is encrypted via TLS 1.2+; data at rest is encrypted by Supabase. Access is gated by Postgres RLS — a cluster's data is never queryable from another cluster's session. Service-role keys are stored only in Supabase Edge Function secrets, never client-side.

4. Data subject requests

If a data subject contacts us directly, we will refer them to you within 5 working days. We will assist you in fulfilling access, rectification or erasure requests at no extra charge.

5. Audit

You may request a copy of our latest security review once per calendar year. On-site audits are not part of the standard agreement; contact us for enterprise terms.

6. Termination & deletion

Upon termination we will export your data on request and delete it from production within 30 days; backups are retained for at most 90 additional days and then cryptographically erased.


Questions? Email legal@fudica.com · FUDICA LTD.