How Fixra protects your business data. Technical and organisational measures, infrastructure, and compliance. Read alongside our Privacy Policy.
All client data is stored and processed within the European Union. Our primary data infrastructure is located in the AWS eu-west-1 availability zone (Dublin, Ireland). No client data is transferred to, or accessible from, any jurisdiction outside the European Economic Area.
Data is encrypted at every stage:
Every client organisation's data is logically isolated using row-level security (RLS) policies enforced at the database level:
This isolation model is equivalent to the multi-tenancy standard used by enterprise SaaS platforms handling financial and healthcare data.
Access to client data is governed by role-based access controls (RBAC). Each user is assigned a role within their organisation. Roles determine read, write, and administrative permissions. Authentication is handled via Supabase Auth with secure session management.
Fixra personnel access to production data is limited to named individuals and requires multi-factor authentication. Access logs are retained.
Automatic daily backups are performed with point-in-time recovery (PITR) capability. Backups are stored in the same EU region as production data, encrypted at rest. Restoration can be performed to any point within the backup retention window.
Where AI-assisted features are available (document generation, analysis), processing is carried out exclusively by EU-hosted AI providers:
Fixra processes personal data in accordance with the GDPR and the Data Protection Acts 1988–2018:
Full details are set out in our Privacy Policy.
In the event of a confirmed or suspected personal data breach:
| Spreadsheets | Fixra | |
|---|---|---|
| Data location | Local device | Dublin, Ireland (EU) |
| Encryption in transit | None | TLS 1.2+ |
| Encryption at rest | None | AES-256 |
| Backups | Manual (if at all) | Daily, automatic, PITR |
| Access control | File-level only | RBAC + row-level security |
| GDPR compliance | Unlikely | Documented and auditable |
| Device loss | Data lost | Data unaffected |
| Audit trail | None | Logged |
Third-party providers engaged under written Data Processing Agreements in accordance with Article 28 GDPR:
We're happy to discuss our security practices in detail.
Get in touch →