Data Processing
Last updated: June 26, 2026
This page describes the technical and organisational measures FxLeakage applies when processing personal data, our sub-processors, and the terms of our Data Processing Addendum (DPA) for customers where applicable.
1. Roles
For website visitors we act as controller. For customers using paid features that store their end-user data with us, we act as processor.
2. Sub-processors
We use the following sub-processors. Material changes are announced 30 days in advance where DPA is signed.
| Vendor | Purpose | Region |
|---|---|---|
| Lovable Cloud (Supabase) | Database, authentication, edge functions | EU / US |
| Cloudflare | Edge hosting, DNS, DDoS protection | Global |
| open.er-api.com | Reference FX rates (no personal data sent) | US |
| ipapi.co | Country-level geolocation from IP | EU / US |
| Google AdSense | Advertising delivery and measurement | Global |
3. Security measures
- TLS 1.2+ in transit; encryption at rest for databases.
- Principle of least privilege for staff access; role-based access controls.
- Row-level security policies on all user-data tables.
- Secrets stored in managed secret vaults — never in source code.
- Logging, monitoring and incident response procedures.
4. International transfers
Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (2021/914), the UK IDTA, or other lawful safeguards.
5. Data subject requests
As processor, we assist controllers in responding to data subject requests in a timely manner. See GDPR for rights.
6. Breach notification
We notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, and cooperate with regulator notifications.
7. Request a DPA
Customers can request a signed DPA at legal@fxleakage.app.