Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Structa Technologies Inc. (“Structa”, “we”) and the business using the service (“you”). It describes how we process personal data on your behalf. Where it conflicts with the Terms on the subject of personal data, this DPA wins.
1. Roles
For the personal data you put into Structa about your own clients, guests and employees, you are the controller and Structa is the processor: you decide what to collect and why, and we process it only to provide the service. For the data we hold about you as our customer — your account, your billing — Structa is the controller, and our Privacy Policy describes that.
2. What we process, and why
- Your clients’ data — names, contact details, bookings, visit history, and any notes or custom fields you choose to record. Processed to operate the modules you have enabled.
- Your employees’ data — names, sign-in credentials, roles, shifts, time entries, and wages where you use those modules.
- Payment data — handled by Stripe. Card numbers never reach Structa’s servers.
We process this data only on your documented instructions — which, in practice, means the actions you and your staff take in the product — except where the law requires otherwise.
3. Confidentiality and security
Access is restricted to personnel who need it to run and support the service, and they are bound by confidentiality. Each business’s data is isolated at the database level by row-level security, and access inside a business is further limited by the modules and role you assign to each person. Our Security page describes the current measures.
4. Subprocessors
We use the providers below to deliver the service. Each is bound by terms no less protective than this DPA, and we remain responsible for their performance.
- Supabase — database, authentication and file storage (United States).
- Vercel — application hosting and delivery (United States).
- Stripe — subscription billing and, where you enable it, guest payments.
- Resend — transactional and guest-facing email.
- Anthropic — powers the optional AI features. Data is sent only when someone uses them, and only from the modules that person can already see.
- Twilio & ElevenLabs — only if you enable the AI receptionist’s voice channel.
We will give notice before adding a subprocessor that processes your clients’ personal data, so you have a chance to object.
5. International transfers
Our infrastructure is operated in the United States. Where you or your clients are in a jurisdiction that restricts transfers, the transfer is made under the appropriate safeguards for that jurisdiction, and the subprocessors above are engaged on the same basis.
6. Your rights, and your clients’
The product is built so you can answer your clients directly: you can read, correct and delete any client record yourself, and export your business’s data at any time from Owner setup. If you receive a request you cannot satisfy in the product, contact us and we will help within the time the law allows.
7. Personal data breach
If we become aware of a breach affecting personal data we process for you, we will notify you without undue delay, with what we know and what we are doing about it, so you can meet your own notification duties.
8. Deletion and return
You can export your data at any time, including after you close your business. Closing does not delete anything — it ends the subscription and locks the workspace, so your data is still there if you change your mind.
To have it removed, ask for permanent deletion from the screen a closed business shows. We wait 30 days and email you the date, so a mistaken or unauthorised request can be caught; after that we permanently delete the personal data we process for you. The only things we keep are records we are legally required to retain — billing and tax records — and the suppression list that stops us emailing an address that asked us not to.
9. Audit
On reasonable request we will provide the information needed to demonstrate compliance with this DPA, including our security documentation.
10. Contact
Questions about this DPA, or a data request you need help with: security@structainc.com.