Data Processing Agreement

Effective 27 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer", acting as data controller) and Apex Build Systems Ltd ("Coupler", "we", acting as data processor) for use of the coupler. platform. It applies whenever you upload personal data about your clients, staff, suppliers or other individuals into coupler. It is drafted to satisfy Article 28 of the UK GDPR and the equivalent provisions of EU GDPR.

1. Roles

  • You are the Controller for personal data you enter into coupler. about your clients, staff, suppliers, or third parties. You decide what to upload and for what purpose.
  • We are the Processor. We process that data only on your documented instructions (which are: "operate coupler. for me"), and only for the purposes described in this DPA.
  • For data about you as a registered Coupler user (your name, email, company name, billing info), we act as Controller — that is governed by our Privacy Policy.

2. Subject matter and duration

Subject matter: our processing of personal data on your behalf for the purpose of providing the coupler. service.
Duration: for the duration of your subscription, and for the limited post-termination period described in Section 9 below.

3. Nature and purpose of processing

We process the personal data you upload in order to:

  • Store it on a multi-tenant database, isolated from other Coupler customers using PostgreSQL Row-Level Security.
  • Make it available to authorised users in your organisation through the coupler. interface.
  • Generate PDFs, send emails on your behalf via Resend, render addresses via Google Places, and produce reports as you instruct.
  • Back up the data to protect against loss.
  • Provide support if you ask for it.

4. Types of personal data and categories of data subjects

Types of personal data

Names, email addresses, telephone numbers, postal addresses, job titles, dates and identifiers of work performed, employment details (where you enter them for staff), and any other personal data you choose to upload.

Categories of data subjects

Your clients, your clients' on-site contacts, your employed and subcontracted staff, your suppliers, and any other individuals you choose to record.

Special category / criminal-offence data

coupler. is not designed to hold special-category data (health, religion, sexual orientation, etc.) or criminal-offence data. You must not upload such data without a lawful basis under Article 9 or 10.

5. Our obligations as processor

  • Documented instructions. We process personal data only on your documented instructions. Use of the coupler. interface constitutes documented instructions for the purposes described in Section 3.
  • Confidentiality. Everyone we let access personal data is bound by confidentiality obligations (employees by contract; sub-processors by their own DPAs with us).
  • Security. We apply appropriate technical and organisational measures, as described in Section 6.
  • Assistance. We will assist you, taking into account the nature of processing, to respond to data subject requests (access, rectification, erasure, portability, restriction, objection) and to fulfil your security, breach-notification and DPIA obligations under Articles 32–36.
  • Breach notification. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and provide such information as is reasonably available to help you comply with your Article 33/34 obligations.
  • Sub-processor disclosure. We list our current sub-processors below (Section 7) and at our Privacy Policy. We will notify you of changes via email or in-app notice; you may object to a new sub-processor by terminating your subscription within 30 days of the notice.
  • Audit rights. We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 and allow for, and contribute to, audits, including inspections, conducted by you or another auditor mandated by you, no more than once per year and at your reasonable cost.

6. Technical and organisational security measures

  • All data encrypted in transit using TLS 1.2 or above.
  • All data encrypted at rest by Supabase using AES-256.
  • Tenant isolation enforced at the database layer using PostgreSQL Row-Level Security; one tenant cannot read or write another tenant's rows.
  • Authentication via passwordless magic links; no plaintext passwords stored.
  • Role-based access controls within each tenant (director, office, supervisor, scaffolder).
  • Daily backups retained for 7 days at the database layer.
  • Access to production systems restricted to a small number of authorised personnel.
  • All sub-processors selected only where they offer equivalent or higher security guarantees.

7. Sub-processors

As at the effective date, our sub-processors are:

  • Supabase — database, authentication, file storage (eu-west-1, Ireland)
  • Vercel — application hosting and CDN
  • Resend — outbound email delivery via AWS SES (eu-west-1, Ireland)
  • Google Places API — address autocomplete
  • Cloudflare Turnstile — bot protection on sign-in

The current list is also published at our Privacy Policy.

8. International transfers

Personal data is stored in the EU (Ireland). Some sub-processors are headquartered in the United States. Any transfer of personal data outside the UK / EEA is made under appropriate safeguards — typically the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or reliance on the UK Adequacy decision for the United States where the receiving party is certified.

9. Return or deletion of personal data

On termination of your subscription, you may export your data via the in-app "Export my company data" tool (Settings → Account & Password) within 30 days. Thereafter we will permanently delete or anonymise all personal data we hold on your behalf within 90 days, except where retention is required by law (HMRC retention obligations for invoice / accounting records may apply, in which case data is held only for the relevant period and only for that purpose).

10. Liability and indemnity

Each party's liability under this DPA is subject to the limitation of liability provisions of our Terms of Service. Nothing in this DPA limits any liability that cannot be limited by law (including liability for fraud, death or personal injury caused by negligence, or under Article 82 of the UK GDPR).

11. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.

12. How this DPA is entered into

By using coupler. to process personal data about identifiable individuals, you accept this DPA. If you require a counter-signed version on your or your client's letterhead, please email privacy@coupler.software and we will provide one within a reasonable time at no charge.