Data Processing Addendum
Last updated : 2026-10-01
Ce document existe en français : version française.
This Addendum applies to personal information in customer content that Teyvor ("Processor") processes for the customer ("Controller") through Teyvor. It forms part of the Terms and reflects GDPR Article 28, UK GDPR and comparable laws such as Québec Law 25, PIPEDA and the CCPA/CPRA (where the customer is a "business" and we are its "service provider").
Scope
- Subject matter: hosting and processing of project management content to provide the Service.
- Duration: the term of the customer's subscription plus the export period.
- Data subjects: the customer's staff, subcontractors, suppliers, clients and other people named in project records.
- Categories: names, work contact details, roles, comments and other information the customer chooses to record. No special categories are intended.
Processor commitments
- Process personal information only on the customer's documented instructions (the Terms, this Addendum and the customer's use of the Service), and tell the customer if an instruction seems unlawful.
- Ensure people authorised to process the data are bound by confidentiality.
- Apply the technical and organisational measures described on our Security page.
- Assist the customer with data subject requests, impact assessments and consultations, taking into account the nature of processing.
- Notify the customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach.
- Delete or return customer personal information at the end of the Service, on request, unless the law requires retention.
- Make available information needed to show compliance and allow reasonable audits, no more than once a year unless a breach requires otherwise.
Subprocessors
The customer authorises the subprocessors below. We will give at least 30 days' notice of additions or replacements so the customer can object on reasonable data protection grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Canada (Montréal, AWS ca-central-1) |
| Netlify | Application hosting and delivery | United States and global edge network |
| Stripe | Payments and invoicing | United States and other regions |
| Brevo | Transactional email delivery | France / European Union |
International transfers
Where personal information from the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the parties rely on the Standard Contractual Clauses (module two, controller to processor; and module three where relevant), incorporated by reference, and on the supplementary measures described in our Security page. Comparable mechanisms apply for other regions.
Contact and signed copy
Questions or a countersigned copy: info@teyvorpm.com.