Eskadia

Data Processing Agreement

Version: August 10, 2026

This text is a draft pending legal review. It is not yet in force and no customer is being asked to accept it. Points marked as pending are awaiting a decision.

This agreement governs the processing of personal data that Eskadia carries out on behalf of the customer organisation. It forms part of the Terms of Service and is accepted, on behalf of their organisation, by whoever creates the account.

Position of the parties

The customer organisation is the Controller of the personal data it loads into the platform: it decides what data is processed, for what purpose and on what legal basis. Eskadia is the Processor and acts solely on the Customer's behalf. In respect of the Customer's own account data, by contrast, Eskadia acts as Controller, and that processing is described in the Privacy Policy. For data subjects under Colombian law, this relationship corresponds to that of Responsable and Encargado under Law 1581 of 2012.

Subject matter, duration and nature

The subject matter is the provision of the platform described in the Terms of Service. Operations include the collection, recording, storage, consultation, modification, disclosure to the recipients the Customer determines, and erasure of the data. The duration matches that of the contractual relationship.

Categories of data and of data subjects

Identification and contact data, professional data, financial and billing data, and communications. Where the Customer enables the corresponding modules, also employment, working-time and geolocation data. Data subjects may be employees, clients, business contacts, suppliers, students and users of the Customer's portals. It is the Customer who determines what data it loads, and it must refrain from entering special categories without a legal basis covering them.

Documented instructions

Eskadia will process the data solely on the Customer's documented instructions, being those that follow from the platform configuration and from these Terms. If Eskadia considers that an instruction infringes applicable law, it will inform the Customer. Eskadia will not use Customer data for its own purposes or to train models.

Confidentiality

Eskadia will keep the data confidential and will ensure that persons authorised to process it have committed to confidentiality. This duty survives termination of the agreement.

Security measures

Isolation between organisations through row level security policies, role-based access control, encryption in transit and at rest, two-factor authentication available for accounts, audit logging of sensitive operations, and periodic automated checks over critical controls.

Sub-processors

Eskadia relies on Supabase for the database and authentication, Vercel for hosting and execution, Resend for email delivery, and Sentry for error capture. Eskadia will give reasonable notice of the addition or replacement of any sub-processor, and the Customer may object on justified grounds. Providers configured by the Customer itself, in particular artificial intelligence services connected through a webhook, are the Customer's sub-processors and not Eskadia's.

Assistance to the Controller

Eskadia will assist the Customer in handling data subject requests, including access, rectification, erasure, restriction, objection and portability, as well as the rights of access, rectification, cancellation and objection in jurisdictions that name them so. The platform provides the export, opt-out and erasure mechanisms needed for this.

Personal data breaches

Eskadia will notify the Customer of any personal data breach without undue delay after becoming aware of it, providing the information the Customer needs to meet its own notification obligations. The specific maximum period is pending definition.

Audit

Eskadia will make available to the Customer the information needed to demonstrate compliance with these obligations and will allow audits, including inspections, conducted by the Customer or an auditor it appoints, upon request with reasonable notice and without compromising the security of other organisations.

Return and erasure on termination

Once the service ends, the Customer may export its data. After the period to be established, still pending definition, Eskadia will erase it, except for data whose retention is required by a legal obligation or necessary for the establishment or defence of legal claims, which will be blocked until the end of the applicable limitation period.

International transfers

Data is hosted on managed Supabase infrastructure located in the United States, region us-east-2, which entails an international transfer outside the European Economic Area. The transfer relies on the standard contractual clauses entered into with the providers. For data subjects under Colombian Law 1581 of 2012, it additionally relies on the data subject's express authorisation and on the corresponding contractual clauses.

Contact

For any question regarding this agreement, write to us at:

legal@eskadia.com