TerenIQ
Back to tereniq.com

Data Processing Agreement

Last updated: 3 September 2026

The parties and when this applies

This Data Processing Agreement ("DPA") is entered into between Tech Box d.o.o., Šipkovica 4, 10000 Zagreb, Croatia, OIB 63205904527 ("Processor", "we") and the company that operates a TerenIQ workspace ("Controller", "you").

It forms part of the Terms of Service and applies automatically whenever we process personal data on your behalf. It satisfies article 28(3) of Regulation (EU) 2016/679 (GDPR). Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.

Roles

For the content your users enter into your workspace — projects, tasks, issues, RFIs, inspections, daily reports, permits, safety briefs, directory entries and the media attached to them — you are the controller and we are your processor.

For account administration, authentication, billing, security and our direct support correspondence we act as controller in our own right. That processing is described in our Privacy Policy and is outside the scope of this DPA.

Processing on documented instructions

We process personal data only on your documented instructions, including on transfers to a third country, unless required to do otherwise by Union or Croatian law. Where such a legal requirement applies we will inform you before processing, unless that law prohibits it on important grounds of public interest.

Your use of the service, the settings you choose and the Terms of Service together constitute your documented instructions. If we consider an instruction to infringe the GDPR or other data protection law, we will tell you without delay.

Confidentiality

We ensure that every person authorised to process personal data under this DPA is bound by a duty of confidentiality, whether by contract of employment or a separate written undertaking, and that access is limited to those who need it to provide or support the service.

Security

We implement appropriate technical and organisational measures under article 32 of the GDPR. The measures in force are described in Annex II. We may change them, provided the level of security is not reduced.

Sub-processors

You give general written authorisation for us to engage sub-processors. The current list is published at tereniq.com/subprocessors.html and forms Annex III to this DPA.

We will notify workspace owners by email at least 30 days before adding or replacing a sub-processor that processes workspace content. You may object on reasonable data-protection grounds within that period; if we cannot provide an alternative, you may terminate the affected part of the service without penalty for the remainder of the paid period.

We impose on each sub-processor the same data protection obligations as are set out in this DPA, and we remain fully liable to you for their performance.

Helping you answer data subjects

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests from data subjects under Chapter III of the GDPR.

In practice much of this is self-service: a workspace owner or administrator can export the whole workspace data set at any time from the product, an individual user can export their own personal data, and a user can delete their own account from the mobile apps. Where those tools are not enough, write to [email protected] and we will assist without undue delay.

Helping you with articles 32 to 36

We assist you in ensuring compliance with the obligations in articles 32 to 36 of the GDPR — security of processing, breach notification, data protection impact assessments and prior consultation — taking into account the nature of processing and the information available to us.

Personal data breaches

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.

Where we cannot provide all of that information at once, we provide it in phases without further undue delay. Notification does not constitute an admission of fault or liability.

Return and deletion

On termination of the service, and at your choice, we delete or return the personal data processed on your behalf and delete existing copies, unless Union or Croatian law requires storage.

You can export the full workspace data set yourself at any time while the workspace is active, and for 30 days after termination on request. After that period we delete workspace content within 90 days, subject to the retention rules described in the Privacy Policy and to backups being overwritten on their ordinary cycle.

Audits

We make available to you all information necessary to demonstrate compliance with article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance we will answer reasonable written questions and provide our security documentation. On-site audits may be requested no more than once in any twelve-month period, on 30 days' written notice, during normal business hours, without unreasonably disrupting the service, and subject to confidentiality. You bear your own costs; we bear ours unless the audit reveals a material breach by us.

International transfers

Our D1 database and R2 file storage are provisioned in the European Union. Where a sub-processor transfers personal data outside the European Economic Area, that transfer is covered by the European Commission's standard contractual clauses, an adequacy decision or another lawful transfer mechanism, as set out in Annex III.

Annex I — Details of the processing

Subject matter: provision of the TerenIQ construction field operations service. Duration: for as long as the workspace is active, plus the retention periods in the Privacy Policy.

Nature and purpose: storing, organising, displaying, transmitting and deleting workspace records so that your team can plan, record and evidence work on site.

Categories of data subjects: your employees and other authorised users; individuals named in directory entries and organisation contacts; individuals who appear in photographs, videos, voice notes or signatures your users capture.

Categories of personal data: name, work email, telephone number, job title and trade, profile photograph, workspace role and access scope; records authored, assigned to or acknowledged by a person, with timestamps; location coordinates where a user chooses to attach them to a record; signatures on handovers; media content.

Special categories: not requested by the service. Safety briefs, incident notes and daily reports are free-text fields into which your users could enter health-related information about a person. If they do, you remain the controller for it and must ensure an article 9 condition applies.

Annex II — Technical and organisational measures

Access control: every request is authenticated with a short-lived bearer token bound to a server-side session that is validated on each request, so revoking a session or deactivating an account takes effect immediately. Authorisation is enforced per company and per role, from owner down to guest, and can be narrowed further to named sites. Passwords are stored as PBKDF2-SHA256 hashes with 100,000 iterations and a per-user salt; we never store them in a recoverable form.

Tenant separation: every record carries its company identifier and every query is scoped to the caller's company, so one customer's workspace cannot be read from another's session.

Encryption: all traffic is encrypted in transit with TLS. Data at rest in Cloudflare D1 and R2 is encrypted by the platform.

Rate limiting and abuse control: authentication, token, invitation and upload endpoints are rate limited per identity and per source to blunt credential stuffing and enumeration.

Logging and accountability: administrative actions on customer accounts are written to an immutable audit log with the acting person and the target. Request logs record method, route template, status, duration and a request identifier, and deliberately exclude URLs, request bodies, recipients and tokens. Scheduled job runs are recorded with their outcome, and only an error class is stored, never a message or stack.

Deletion: retention is enforced by a scheduled sweep that deletes expired records and the files attached to them through a storage ledger, so removing a record removes its media rather than orphaning it.

Resilience and change control: the platform provider operates redundant infrastructure across regions. Changes to the service pass an automated typecheck and test suite before release.

Annex III — Sub-processors

The current list, with the role and location of each sub-processor and the transfer mechanism relied on, is published and maintained at tereniq.com/subprocessors.html and forms part of this DPA.

Governing law

This DPA is governed by the law of the Republic of Croatia. The courts of Zagreb have exclusive jurisdiction, without prejudice to any mandatory right of a data subject to bring proceedings elsewhere.