Security & Data Protection

Fixra — fixra.ie

Last updated 1 April 2026

This document describes the technical and organisational measures Fixra employs to protect client data. It should be read in conjunction with our Privacy Policy.

1. Data Residency

All client data is stored and processed within the European Union. Our primary data infrastructure is located in the AWS eu-west-1 availability zone (Dublin, Ireland). No client data is transferred to, or accessible from, any jurisdiction outside the European Economic Area.

2. Encryption

Data is encrypted at every stage:

3. Data Isolation

Every client organisation’s data is logically isolated using row-level security (RLS) policies enforced at the database level. These policies ensure that:

This isolation model is equivalent to the multi-tenancy standard used by enterprise SaaS platforms handling financial and healthcare data.

4. Access Controls

Access to client data is governed by role-based access controls (RBAC). Each user is assigned a role within their organisation. Roles determine read, write, and administrative permissions. Authentication is handled via Supabase Auth with secure session management.

Fixra personnel access to production data is limited to named individuals and requires multi-factor authentication. Access logs are retained.

5. Backups and Recovery

Automatic daily backups are performed with point-in-time recovery (PITR) capability. Backups are stored in the same EU region as production data, encrypted at rest. In the event of data loss or corruption, restoration can be performed to any point within the backup retention window.

6. AI Processing

Where AI-assisted features are available (document generation, analysis), processing is carried out exclusively by EU-hosted AI providers. Specifically:

7. GDPR Compliance

Fixra processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 and the Data Protection Acts 1988–2018. This includes:

Full details are set out in our Privacy Policy.

8. Breach Response

In the event of a confirmed or suspected personal data breach:


Comparison

For context, the following table compares the security posture of a typical spreadsheet-based workflow with the measures implemented by Fixra:

SpreadsheetsFixra
Data locationLocal deviceDublin, Ireland (EU)
Encryption in transitNoneTLS 1.2+
Encryption at restNoneAES-256
BackupsManual (if at all)Daily, automatic, PITR
Access controlFile-level onlyRBAC + row-level security
GDPR complianceUnlikelyDocumented and auditable
Device lossData lostData unaffected
Audit trailNoneLogged

Infrastructure

The following third-party providers are engaged as data processors under written Data Processing Agreements in accordance with Article 28 GDPR:

Supabase Database, auth, storage
AWS eu-west-1, Dublin
Vercel Application hosting
EU edge network
Resend Transactional email
DKIM + SPF verified

For questions about our security practices or to request further detail, contact jack@fixra.ie.