Data Processing

Last updated: June 26, 2026

This page describes the technical and organisational measures FxLeakage applies when processing personal data, our sub-processors, and the terms of our Data Processing Addendum (DPA) for customers where applicable.

1. Roles

For website visitors we act as controller. For customers using paid features that store their end-user data with us, we act as processor.

2. Sub-processors

We use the following sub-processors. Material changes are announced 30 days in advance where DPA is signed.

VendorPurposeRegion
Lovable Cloud (Supabase)Database, authentication, edge functionsEU / US
CloudflareEdge hosting, DNS, DDoS protectionGlobal
open.er-api.comReference FX rates (no personal data sent)US
ipapi.coCountry-level geolocation from IPEU / US
Google AdSenseAdvertising delivery and measurementGlobal

3. Security measures

  • TLS 1.2+ in transit; encryption at rest for databases.
  • Principle of least privilege for staff access; role-based access controls.
  • Row-level security policies on all user-data tables.
  • Secrets stored in managed secret vaults — never in source code.
  • Logging, monitoring and incident response procedures.

4. International transfers

Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (2021/914), the UK IDTA, or other lawful safeguards.

5. Data subject requests

As processor, we assist controllers in responding to data subject requests in a timely manner. See GDPR for rights.

6. Breach notification

We notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, and cooperate with regulator notifications.

7. Request a DPA

Customers can request a signed DPA at legal@fxleakage.app.