Security & Data Protection
Fixra — fixra.ie
Last updated 1 April 2026
This document describes the technical and organisational measures Fixra employs to protect client data. It should be read in conjunction with our Privacy Policy.
1. Data Residency
All client data is stored and processed within the European Union. Our primary data infrastructure is located in the AWS eu-west-1 availability zone (Dublin, Ireland). No client data is transferred to, or accessible from, any jurisdiction outside the European Economic Area.
2. Encryption
Data is encrypted at every stage:
3. Data Isolation
Every client organisation’s data is logically isolated using row-level security (RLS) policies enforced at the database level. These policies ensure that:
This isolation model is equivalent to the multi-tenancy standard used by enterprise SaaS platforms handling financial and healthcare data.
4. Access Controls
Access to client data is governed by role-based access controls (RBAC). Each user is assigned a role within their organisation. Roles determine read, write, and administrative permissions. Authentication is handled via Supabase Auth with secure session management.
Fixra personnel access to production data is limited to named individuals and requires multi-factor authentication. Access logs are retained.
5. Backups and Recovery
Automatic daily backups are performed with point-in-time recovery (PITR) capability. Backups are stored in the same EU region as production data, encrypted at rest. In the event of data loss or corruption, restoration can be performed to any point within the backup retention window.
6. AI Processing
Where AI-assisted features are available (document generation, analysis), processing is carried out exclusively by EU-hosted AI providers. Specifically:
7. GDPR Compliance
Fixra processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 and the Data Protection Acts 1988–2018. This includes:
Full details are set out in our Privacy Policy.
8. Breach Response
In the event of a confirmed or suspected personal data breach:
Comparison
For context, the following table compares the security posture of a typical spreadsheet-based workflow with the measures implemented by Fixra:
| Spreadsheets | Fixra | |
|---|---|---|
| Data location | Local device | Dublin, Ireland (EU) |
| Encryption in transit | None | TLS 1.2+ |
| Encryption at rest | None | AES-256 |
| Backups | Manual (if at all) | Daily, automatic, PITR |
| Access control | File-level only | RBAC + row-level security |
| GDPR compliance | Unlikely | Documented and auditable |
| Device loss | Data lost | Data unaffected |
| Audit trail | None | Logged |
Infrastructure
The following third-party providers are engaged as data processors under written Data Processing Agreements in accordance with Article 28 GDPR:
For questions about our security practices or to request further detail, contact jack@fixra.ie.