Data Processing Agreement
For business customers: how Future Point Consult (Pty) Ltd processes personal data on your organisation's behalf when you use InFieldX.
Last updated: 16 July 2026
1. Parties, roles and scope
This Data Processing Agreement (“DPA”) forms part of the InFieldX Terms of Use between the customer organisation (“Customer”) and Future Point Consult (Pty) Ltd, trading as “InFieldX”, registered at 298 Glenwood Rd, Lynnwood Park, Pretoria, 0081, South Africa (“InFieldX”, “we”). By accepting the Terms and using the Service as a business customer, the Customer agrees to this DPA; no separate signature is required. A counter-signed copy for procurement or audit purposes is available on request from privacy@infieldx.co.
For personal data the Customer stores in InFieldX — its clients' names, contact details, addresses, job and billing records — the Customer is the controller (GDPR) / responsible party (POPIA) and InFieldX is the processor (GDPR) / operator (POPIA). InFieldX processes such data only on the Customer's documented instructions, which are given through the Customer's use of the Service, unless processing is required by law — in which case we inform the Customer unless the law forbids it.
2. Our obligations as processor
We: (a) process only on the Customer's instructions; (b) ensure persons processing the data are bound by confidentiality; (c) implement the security measures in Annex B; (d) engage sub-processors only under section 4; (e) assist the Customer in responding to data-subject requests; (f) assist the Customer with its own security, breach and impact assessment obligations; (g) delete or return the data at the end of the engagement under section 7; and (h) make available the information reasonably necessary to demonstrate compliance, including audits under section 6.
3. Security of processing
We apply technical and organisational measures appropriate to the risk, in line with POPIA section 19 and GDPR Article 32, including per-organisation isolation enforced by row-level security in the database, role-based access control, encryption in transit and at rest, immutable audit logging of changes to business records, recoverable (soft) deletes, and rate limiting and bot protection on authentication. Annex B and the Security page describe these measures.
4. Sub-processors
The Customer authorises the sub-processors in Annex C. We impose data protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We will give at least 30 days' notice before adding or replacing a sub-processor; the Customer may object on reasonable data protection grounds, and if we cannot accommodate the objection, the Customer may terminate the affected service and export its data.
5. Personal data breach
We notify the Customer of a personal data breach affecting its data without undue delay, and in any event no later than 48 hours after becoming aware of it, with the information reasonably available to us at the time — so the Customer can meet its own notification duties (72 hours under GDPR Article 33; notification to the Information Regulator and data subjects under POPIA section 22).
6. Data-subject rights and audits
Taking into account the nature of the processing, we assist the Customer with requests from data subjects to access, correct, delete, restrict or port their personal data — in the first instance through the Service itself, and otherwise via privacy@infieldx.co. The Customer may audit our compliance with this DPA on at least 30 days' written notice, no more than once per year absent a breach or regulator requirement; we may first satisfy the request with relevant certifications, audit reports or documentation.
7. Return and deletion
On termination of the Customer's account, the Customer has 30 days to request an export of its organisation's data. We then delete the data from active systems within 90 days and from backup rotation within 180 days, except records we must retain by law (such as financial records for tax purposes), which are kept only as long as the law requires and remain protected by this DPA.
8. International transfers
Customer data is hosted with Supabase in the European Union. Where processing involves a transfer out of the EU/EEA or UK (see Annex C), the transfer is made under the EU Standard Contractual Clauses (Module Two: controller-to-processor, incorporated by reference) and, for UK data, the UK International Data Transfer Addendum. Transfers of personal information originating in South Africa comply with the conditions for transborder information flows under POPIA section 72, on the basis of these binding agreements.
9. Liability, term and law
Liability under this DPA is subject to the exclusions and cap in the Terms of Use, except where data protection law does not permit liability to be limited. This DPA applies for as long as we process personal data for the Customer and survives termination until deletion is complete. It is governed by the laws of the Republic of South Africa. Contact for all data protection matters: privacy@infieldx.co.
Annex A — Description of processing
Subject matter and nature: hosting and processing of business records the Customer stores in InFieldX (clients, contacts, job cards, quotes, invoices, time entries, expenses and related documents), including — only when a user invokes AI Assist — transmission of the user's messages and the records needed to answer them to the AI sub-processor to generate a response. Duration: the life of the Customer's account plus the deletion periods in section 7. Data subjects: the Customer's personnel and its clients (including sole proprietors and representatives of juristic persons). Categories of data: names, contact details, addresses, job and billing history. The Service is not intended for special personal information (such as health data, biometrics or children's data), and the Customer instructs us not to expect it.
Annex B — Security measures
Row-level security on every table enforcing per-organisation isolation in the database itself; all writes through server-side procedures that re-check organisation and role; encryption in transit (TLS with strict transport security) and at rest; immutable audit logging; soft-delete with recoverability; passwordless sign-in with one-time codes, bot protection and rate limiting; AI processing that operates within the invoking user's permissions, requires explicit user confirmation for changes, cannot delete records, and whose conversations are not stored by the Service (usage metadata only).
Annex C — Authorised sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Application database, authentication and encrypted file storage | European Union |
| Vercel | Application hosting and content delivery | EU/US edge network |
| Anthropic | AI processing for AI Assist, only when a user invokes it | United States |
| Resend | Transactional email delivery | United States |
| Cloudflare | Bot protection on sign-in (Turnstile) | Global |
| Upstash | Rate limiting | European Union |
| Sentry | Error monitoring | United States |
Anthropic processes AI Assist conversations under its commercial terms, which prohibit the use of Customer data to train its models.