Fivexer

Data processing agreement

Our standard Article 28 terms for the personal data you route through Fivexer Cloud. Published rather than negotiated, so you can read it now instead of waiting on an email — version 1.0, effective 27 July 2026.

Last updated 27 July 2026

How to put it in place

These terms form part of the terms of service and apply automatically to every workspace processing personal data — you do not need to sign anything to rely on them.

If your process needs a countersigned document, email support@fivexer.com with your entity details and we will return a signed copy of this text. We will also review your own paper, but this version is the one we can execute the same day.

Parties & roles

Processor: Testreel OÜ, registered in Estonia (12592678), Aiavilja tn 9-8, Paide linn, 72712 Järva maakond.

Controller: you, the account holder. You decide what personal data enters Fivexer and why; we process it only on your documented instructions, which are the configuration you set and the API calls you make.

Separately, we are the controller of your own account data (name, email, login records). That relationship is governed by the privacy notice, not by this agreement.

Annex I — the processing

Subject matterSkill-based routing of work items to the people or systems that should handle them.
DurationFor as long as your account is open, plus the deletion window below.
Nature and purposeStoring and indexing tasks and workers, computing matches, recording a decision trace for each match, delivering webhooks you configure, and archiving completed work.
Categories of data subjectYour workers (staff, contractors, or automated agents you register), and any people described in task content you choose to send.
Categories of personal dataWorker identifiers, tags and skill weights; optional worker email addresses when you use worker-portal invitations; and whatever appears in optional task title, description, context and comment fields.
Special-category dataNone is required and none is expected. Routing needs tags and identifiers, not case contents.

Free-text fields are the risk, and they are yours to control. Nothing stops you putting a customer's medical or financial details in a task description, and if you do, we process them without knowing what they are. Send tags and identifiers; keep the case file in the system that is built for it.

Annex II — security measures

These are the measures in place today, described in full on the security page:

  • Processing takes place in Frankfurt, Germany, inside the European Union, with the exceptions listed in Annex III.
  • Encryption in transit (TLS) and at rest for the database and object storage.
  • Credentials are never stored recoverably: passwords are scrypt-hashed, API keys kept as SHA-256 digests, and session, verification and invite tokens hashed and single-use.
  • Customer-supplied connection secrets are sealed with authenticated encryption.
  • Workspace-scoped access control; browser sessions never carry long-lived API keys.
  • Backups of the control plane (DigitalOcean's default automated backups for managed databases), with restores tested rather than assumed.
  • Deletion that reaches every store, including object storage — see the deletion section below.

What we do not claim. No SOC 2 or ISO 27001 certification, no third-party penetration test, and no formal access-review programme. If your assessment requires any of those, it will fail here today and we would rather you learn that from this page than from a questionnaire three weeks in.

Annex III — subprocessors

You give general authorisation for the subprocessors below. We will give at least 30 days' notice by email before adding one, and you may terminate for that reason before it takes effect.

SubprocessorPurposeLocationTransfer safeguard
DigitalOceanKubernetes cluster, managed Postgres, object storageFrankfurt, Germany (fra1)Not applicable — processing stays in the EU
SendGrid (Twilio)Transactional emailUnited StatesStandard Contractual Clauses in the provider’s data processing addendum
OpenAIopt-in featureAI portal builder in the Worker-Portal Studio (optional feature)United StatesStandard Contractual Clauses in the provider’s data processing addendum

Our obligations

  • Process personal data only on your documented instructions, including for transfers.
  • Keep everyone with access bound to confidentiality, and limit access to what support and incident response actually require.
  • Maintain the measures in Annex II, and not materially weaken them during the agreement.
  • Notify you without undue delay after becoming aware of a personal-data breach affecting your data, with what we know at the time rather than waiting for a complete picture.
  • Make available the information needed to demonstrate compliance with Article 28, and support your data-protection impact assessments where the processing here is relevant to them.
  • Never sell your data, use it for our own purposes, or train models on it.

Your obligations

  • Have a lawful basis for the personal data you send, and give the notices your own data subjects are owed.
  • Send the minimum the routing decision needs. The platform is designed to work on tags and identifiers alone.
  • Keep your API keys and account credentials secure, and rotate them when someone leaves.
  • Configure webhooks only to endpoints you control.

Transfers

The platform itself does not transfer personal data outside the EEA. Two subprocessors do, both listed in Annex III with their safeguard: transactional email, and — only if you use the Worker-Portal Studio — the AI portal builder. Each is covered by the Standard Contractual Clauses incorporated in that provider's own data processing addendum.

If you need zero non-EEA processing, both are avoidable: the Studio is opt-in, and worker invitations can be issued as links you deliver yourself instead of by email.

Audits & assistance

We will answer security questionnaires and reasonable written audit requests, and will support you in responding to data-subject requests — most of which you can satisfy yourself, since your data is readable and deletable through the API at any time.

On-site audits are not something a team this size can host meaningfully. If your policy requires one, say so early and we will find something that actually works — usually a call with the person who built the system.

Deletion at the end

Deleting a workspace deletes its data: archived tasks, task content, comments, attachment records and configuration from the control plane; live routing state and usage counters from the data plane; and the attachment bytes queued for deletion from object storage.

On account closure we delete everything within 30 days of the request. Export first — deletion reaches the archive and cannot be undone. Backups age out on their own retention cycle, so a copy can persist there briefly after live deletion.

DPA and privacy questions: support@fivexer.com

Version: 1.0, effective 27 July 2026