Data Processing Agreement
Last updated: 2 October 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Felikss Veilands, trading as FSMCore ("Processor"), and the business that uses FSMCore ("Customer", the controller). It applies to personal data in Customer Data, as required by Article 28 of the General Data Protection Regulation (GDPR). It takes effect when the Customer accepts the Terms; no signature is needed.
1. Details of processing
- Subject and purpose: providing FSMCore, a job, time, estimate, invoice and file management service, and support for it.
- Duration: for the term of the agreement and until deletion under section 9.
- Data subjects: the Customer's users, staff, subcontractors, clients and their contacts, and anyone else whose data the Customer enters.
- Types of data: names, contact details, addresses, job and site details, time records, financial documents, photos and files, and any other data the Customer chooses to enter. The service is not designed for special category data; the Customer should not enter it unless needed and lawful.
2. Instructions
The Processor processes personal data only on the Customer's documented instructions. These Terms, this DPA and the Customer's use of the service settings are those instructions. The Processor will tell the Customer if it believes an instruction breaks data protection law.
3. Confidentiality
Anyone authorised by the Processor to process the data is bound by confidentiality. At the date of this DPA, the only person with access is the Processor himself.
4. Security
The Processor keeps appropriate technical and organisational measures, including: encryption in transit (HTTPS) and at rest for uploaded files and backups; separation of each company's data enforced in the application and checked by automated tests; access to production limited to the Processor using key-based access; two-factor sign-in available to users; daily backups kept with a separate provider; and restore tested. The Processor may improve these measures but will not reduce the overall level of protection.
5. Sub-processors
The Customer gives general authorisation for the sub-processors listed at /subprocessors. The Processor will email account admins and owners at least 30 days before adding or replacing one. If the Customer objects on reasonable data protection grounds and we cannot resolve it, the Customer may cancel and receive a pro-rata refund of any prepaid period. The Processor puts the same data protection obligations on each sub-processor by written contract and remains responsible for them.
6. International transfers
Where a sub-processor processes personal data outside the EEA, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses.
7. Helping the Customer
The Processor will help the Customer, as far as reasonably possible, to answer data subject requests (the export, edit and delete tools in FSMCore cover most needs), and with security, breach notification, data protection impact assessments and consultation with authorities.
8. Personal data breaches
The Processor will notify the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information then available.
9. Deletion and return
The Customer can export all company data at any time, also during the trial, and from the lock page. When the agreement ends, the Processor deletes Customer Data 30 days after the company is locked, or sooner if the Customer deletes it from the lock page. Copies in backups expire on their fixed schedule (at most about 7 months) and are used only to recover data after a failure or a mistake, never to bring back a deleted company. Data the law requires the Processor to keep is kept only for that purpose.
10. Audits
The Processor will make available the information needed to show compliance with this DPA. The Customer may audit once a year with at least 30 days' notice, at its own cost, by written questions first; an on-site audit only if written answers are not enough or a regulator requires it.
11. Liability and order
Liability under this DPA is subject to the limits in the Terms, except where the law does not allow it. If this DPA and the Terms conflict on data protection, this DPA wins.