ElecRoute
Features How it works Pricing FAQ
SK EN
Book a demo
Contents
  1. Agreement and parties
  2. Roles and scope
  3. Instructions and Customer duties
  4. Provider duties
  5. Confidentiality and security
  6. Subprocessors
  7. International transfers
  8. Assistance and incidents
  9. Return and deletion
  10. Information and audits
  11. Costs and general terms
  12. Schedule: processing details

ElecRoute

Data Processing Agreement

Version 22 September 2026 · effective upon acceptance by the Customer's authorised representative

This Data Processing Agreement (“DPA”) governs FlashDev's processing of Customer Personal Data when providing ElecRoute. It forms part of the Terms of Service and applies where the Provider processes Customer Personal Data on the Customer's behalf.

Download this DPA as HTML

1. Agreement and parties

Processor: FlashDev, s.r.o.
Bysterecká 2066/7, 026 01 Dolný Kubín, Slovakia
Company ID: 45 880 751 · Tax ID: 2023119439 · VAT ID: SK2023119439
Email: support@elecroute.com

The other party is the legal person or individual business identified as the Customer when its workspace is created. The person accepting the Terms and this DPA represents that they are authorised to bind the Customer. Electronic acceptance constitutes signature of this DPA, which takes effect upon acceptance.

For data-protection matters, this DPA prevails over the Terms in the event of conflict. Mandatory law and applicable Standard Contractual Clauses prevail over this DPA.

2. Roles, scope, and duration

The Customer may be a controller of Customer Personal Data or a processor for its own client. FlashDev acts respectively as processor or subprocessor. Where the Customer is a processor, it confirms that its controller has authorised the instructions and appointment of FlashDev and the subprocessors under this DPA.

“Customer Personal Data” means personal data in Customer Content or account, membership, role, and support information that FlashDev processes solely to operate the Customer-controlled workspace under the Customer's instructions. This DPA does not apply where FlashDev determines its own purposes as an independent controller, including contracting and billing records, legal compliance, abuse and security administration, its own business-support records, and genuinely anonymous statistics.

Paddle independently controls purchasing, payment, tax, invoicing, fraud prevention, and refund processing and is not a subprocessor under this DPA. Processing continues while the workspace exists and then until Customer Personal Data is returned or deleted under section 9.

3. Instructions and Customer responsibilities

The Customer instructs FlashDev to process Customer Personal Data as needed to provide, secure, and support ElecRoute under the Terms, this DPA, the Customer's configuration and use of the Service, and lawful written support requests. An additional instruction requires written agreement where it falls outside the agreed Service.

The Customer is responsible for lawful instructions, legal bases, data-subject notices, accuracy, data-subject rights, and any authorisation from its own controller. It must not intentionally submit special-category data, criminal-conviction data, children's data, or personal data unnecessary for electrical planning or site work without a separate written agreement.

If FlashDev believes an instruction violates applicable data-protection law, it will inform the Customer and may suspend the affected processing while the issue is clarified.

4. Provider obligations

FlashDev will:

  • process Customer Personal Data only on the Customer's documented instructions unless applicable law requires processing, in which case it will inform the Customer beforehand unless legally prohibited;
  • ensure authorised persons process data only as instructed and are bound by confidentiality;
  • maintain appropriate technical and organisational measures under section 5;
  • comply with the subprocessor conditions in section 6;
  • provide reasonable assistance under sections 8 to 10; and
  • not use Customer Personal Data for behavioural advertising or artificial-intelligence model training.

5. Confidentiality and security

Taking account of the state of the art, costs, nature, scope, context, purposes, and processing risks, FlashDev maintains security appropriate to the risk. As of this version, measures include:

  • workspace-based authorisation, private floor-plan storage, database Row Level Security, and server-side checks for privileged operations;
  • HTTPS/TLS for production connections and provider-supported encryption at rest for relevant cloud databases, object storage, available backups, and logs;
  • internal production access limited to the managing director/business owner and used only for maintenance, security, incident response, legal obligations, or requested support;
  • unique administrator credentials, restricted privileges, secrets kept out of source control, credential rotation after suspected exposure, and MFA where enabled;
  • disk encryption, login protection, automatic locking, supported updated software, and reasonable malware protection on production-access devices;
  • preference for synthetic development and test data, risk-based security updates, and investigation of material alerts; and
  • privacy-limited error reporting and access records protected from ordinary users.

FlashDev uses managed backup and recovery capabilities where included in the selected production services. Supabase database backups do not include objects stored through its Storage API, so this DPA promises no separate backup of uploaded floor plans, backup frequency, RTO, RPO, or uninterrupted availability. Deleted backup data is isolated from ordinary use and expires through providers' normal cycles.

6. Subprocessors

The Customer gives general written authorisation for the subprocessors listed in the Schedule. FlashDev will enter written terms with them that provide appropriate protection and the obligations required by GDPR Article 28, and remains responsible to the Customer for their performance to the extent required by law.

FlashDev will give reasonable advance notice before adding or replacing a subprocessor by emailing the workspace owner, or by publishing an updated DPA and notifying users of the material change, except where an urgent security or legal need prevents advance notice. The Customer may object within a reasonable period on legitimate data-protection grounds. The parties will try to resolve the concern; if they cannot, the Customer may terminate the affected Service.

7. International transfers

The primary project database and files are intended to remain in the EEA, currently Ireland. Some subprocessors or their suppliers may nevertheless process data outside the EEA. FlashDev will make such transfers only as permitted by law, including under an adequacy decision, the EU–US Data Privacy Framework for a verified certified recipient, the applicable 2021 European Commission Standard Contractual Clauses, or another valid safeguard.

Where Standard Contractual Clauses apply to a transfer to a subprocessor, the module corresponding to the parties' roles under the relevant vendor DPA applies. Information about a relevant safeguard may be requested at support@elecroute.com; confidential or security-sensitive portions may be redacted.

8. Assistance, data-subject rights, and incidents

If FlashDev receives a data-subject request concerning Customer Personal Data, it will forward the request to the Customer and act only on the Customer's instructions unless law requires otherwise. Taking account of the processing and information available, it will reasonably assist with data-subject rights, security duties, data-protection impact assessments, and prior consultation.

FlashDev will notify the Customer of a Customer Personal Data breach without undue delay after becoming aware of it. Based on available information, the notice will describe the nature of the breach, affected categories of data and people, likely consequences, measures taken or proposed, and a contact for further information. Information may be supplied in phases. The Customer is responsible for regulatory and data-subject notifications, with reasonable assistance from FlashDev.

9. Return and deletion

Subscription cancellation does not itself delete data while the Customer retains a read-only workspace. The Customer may use available exports and request reasonable additional assistance.

After the relevant Services end or upon a verified workspace-deletion request, FlashDev will, at the Customer's choice, return available data or delete active Customer Personal Data without undue delay unless law requires retention. Residual protected backup copies expire through providers' normal cycles and remain isolated from ordinary use in the meantime. FlashDev will provide written deletion confirmation on reasonable request.

10. Information and audits

FlashDev will provide information reasonably necessary to demonstrate compliance with GDPR Article 28. The Customer will first use available documentation and written questions. If insufficient and an audit is legally required, the Customer may conduct a reasonable audit no more than once in 12 months, or more often following a relevant incident or supervisory-authority instruction, on notice, during normal working hours, and without unreasonable disruption.

An audit must protect confidentiality, security, and other customers' data. FlashDev may satisfy a request with independent reports or subprocessor documentation and may refuse access that would compromise security or breach another obligation.

11. Costs, liability, and general terms

Ordinary assistance under this DPA is included in the Service. After advance notice, FlashDev may charge reasonable documented costs for unusually burdensome, repetitive, or Customer-caused work where law permits.

The Terms' liability limits apply to this DPA to the extent permitted by law. Responsibility for regulatory fines and data-subject claims follows applicable law and each party's responsibility. This DPA gives no additional indemnity, SLA, service credit, certification, or penetration-test report.

This DPA is governed by Slovak law and disputes are subject to the competent Slovak courts unless mandatory law or Standard Contractual Clauses require otherwise. The Slovak text controls; English is a convenience translation. Send questions and notices, including breach notifications, to support@elecroute.com.

12. Schedule: processing details

Subject matter, nature, and purpose

Hosting and operating ElecRoute: receiving, recording, storing, organising, retrieving, displaying, editing, transmitting, backing up where available, supporting, exporting, and deleting Customer Content as needed to provide and secure the electrical-installation planning Service.

Categories of data subjects

  • Customer employees, contractors, trainees, and Authorised Users;
  • Customer clients, property owners, tenants, occupants, site contacts, and suppliers; and
  • other people the Customer identifies in Customer Content.

Categories of personal data

  • names, business contact details, identifiers, roles, permissions, and membership information;
  • project, property, site, room, and location information linked to a person;
  • uploaded floor plans and images;
  • project names, room and device labels, free-text notes, and site status; and
  • timestamps and the identity of an Authorised User making a project change.

Subprocessor list

ProviderPurposePrincipal location and transfer safeguard
Supabase, Inc.Authentication including system emails, PostgreSQL database, object storage, available backups, and platform operationsPrimary project region Ireland; other processing under the Supabase DPA, with Standard Contractual Clauses where required
Vercel Inc.Application hosting, server functions, delivery, and operational logsApplication execution region Ireland; supporting processing may occur in the United States and elsewhere, protected by Vercel's DPA and Standard Contractual Clauses
Functional Software, Inc. d/b/a SentryPrivacy-limited application error reportingGermany data region; any United States transfer is protected by the EU–US Data Privacy Framework or Standard Contractual Clauses
Plus Five Five, Inc. (Resend)Delivery and processing of customer-support emailSending region eu-west-1 (Ireland); primary Service processing and storage in the United States, protected by the EU–US Data Privacy Framework and Standard Contractual Clauses under Resend's DPA
© 2026 ElecRoute · FlashDev, s.r.o.
Terms Privacy Data Processing Agreement
Privacy and cookies

On this website we use only essential storage and anonymous aggregated Cloudflare analytics without analytics or advertising cookies. Privacy details