This Data Processing Agreement (“DPA”) forms part of the Terms of Service between fieldGRID (fieldGRID is the registered business name of Adelino Duarte, a sole trader, business name number 776526) and the Customer. It applies automatically; a countersigned copy is available on request.
1. Scope and roles
For personal data in the Customer's workspace (“Customer Personal Data”), the Customer is the controller and fieldGRID is the processor. For data fieldGRID needs to run its own business (for example billing contacts, security logs and support correspondence), fieldGRID is a controller as described in the Privacy notice.
2. Details of the processing
- Subject matter and duration: providing the fieldGRID service for the term of the agreement and until deletion under section 10.
- Nature and purpose: hosting, storing, organising, displaying, transmitting, exporting and deleting data so the Customer can manage field operations, workforce records, forms, files and related workflows; securing and supporting the service.
- Data subjects: the Customer's employees, contractors and other authorised users, and people who appear in records the Customer creates (for example clients or site contacts).
- Types of personal data: identity and contact details; role, team and organisation unit; sign-in and device information; work logs, timesheets, leave and expenses; pay rates and gross pay figures where Payroll Prep is used; photos, files and their location metadata; form answers, safety, training and fleet records; messages and notes.
- Special categories: none are required by the service. The Customer decides whether to enter any (for example in safety or training records) and is responsible for having a lawful basis.
3. Processing on instructions
fieldGRID processes Customer Personal Data only on the Customer's documented instructions, which are the agreement, the Customer's configuration and use of the service, and other written instructions we agree. If we believe an instruction breaks data-protection law, we will tell the Customer. If the law requires other processing, we will inform the Customer first unless the law forbids it.
4. Confidentiality
Everyone authorised by fieldGRID to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide, secure or support the service.
5. Security measures
fieldGRID maintains appropriate technical and organisational measures, including:
- separation of each company's data, with every read and write checked against the user's active company membership by security rules and trusted server code;
- role-based access built from specific capabilities and organisation scopes, with extra checks for payroll data;
- encryption in transit (HTTPS/TLS) and at rest (Google Cloud encryption);
- two-step verification available to every user; revocable sessions; bot protection on sign-in;
- audit trails for access, membership and billing changes;
- data stored in the EU (europe-west1, Belgium), with managed backups and file soft-delete for recovery;
- least-privilege access for fieldGRID personnel and review of changes before release.
More detail is on our Security page. We may update these measures as long as the overall level of protection is not reduced.
6. Subprocessors
The Customer gives general authorisation for fieldGRID to use the subprocessors listed below. fieldGRID has a written agreement with each that gives at least the same data-protection obligations as this DPA, and remains responsible for their performance.
We will give at least 30 days' notice of a new or replacement subprocessor by email to the company owner. The Customer may object on reasonable data-protection grounds within that period; if we cannot reasonably address the objection, the Customer may end the affected service and receive a refund of prepaid fees for the unused period.
7. International transfers
Customer Personal Data is stored in the European Union. Where a subprocessor processes it outside the EEA, fieldGRID ensures a lawful transfer mechanism is in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
8. Assistance and data-subject rights
- The portal lets administrators view, correct, export and delete user and company data. If a data subject contacts fieldGRID directly about Customer Personal Data, we will pass the request to the Customer and not respond ourselves unless instructed.
- We will provide reasonable help with the Customer's security obligations, data-protection impact assessments and consultations with the supervisory authority, taking into account the information available to us.
9. Personal data breaches
fieldGRID will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We will share the information the Customer needs to meet its own notification duties, take reasonable steps to contain the breach, and keep the Customer updated.
10. Return and deletion
Company administrators can export data at any time. After the agreement ends, the Customer may request an export within 30 days. fieldGRID then deletes Customer Personal Data from the live service within 90 days, unless EU or Irish law requires it to be kept. Backup copies are deleted as backups expire on their normal cycle and are not used in the meantime.
11. Information and audits
fieldGRID will make available the information reasonably needed to show compliance with this DPA, including answers to security questionnaires. Where that is not enough, the Customer may carry out an audit, at its own cost, no more than once a year, with at least 30 days' notice, during business hours and subject to confidentiality.
12. General
The limitations of liability in the Terms of Service apply to this DPA, to the extent the law allows. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. This DPA is governed by the laws of Ireland. The lead supervisory authority for fieldGRID is the Data Protection Commission (Ireland). Questions: contact@fieldgrid.cloud.
Subprocessor list
Current as of 1 October 2026.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Google Cloud EMEA Limited / Google Ireland Limited (Google Cloud and Firebase) | Hosting, database, file storage, sign-in, server functions, backups and security (App Check / reCAPTCHA) | European Union (europe-west1, Belgium) for stored data; Google may process limited service data globally | EU data residency; Google Cloud Data Processing Addendum with Standard Contractual Clauses |
| Google Maps Platform (Google) | Map display in Map View | Global | Google Maps Platform terms with Standard Contractual Clauses |
| MapTiler AG | Map tiles and place search in map features | Switzerland | EU adequacy decision for Switzerland |
| Heinlein Support GmbH (mailbox.org) | Sending service and notification emails | Germany (EU) | Processing within the EU |
