Last updated 1 July 2026. In this document, Projexio, “we”, “us” and “our” mean the provider of the Projexio service, and “you” means the customer or visitor.
1. Roles of the parties
This addendum applies where we process personal data on your behalf in the course of providing the Projexio service. It forms part of our Terms of Service and is available to customers on every plan, not only Enterprise.
You are the controller of the personal data contained in your project content. We are the processor, and we act only on your documented instructions.
Separately, we are a controller of the account data described in our Privacy Notice, such as your billing contact and your sign-in records. This addendum does not govern that; the Privacy Notice does.
Where you are yourself a processor for a further controller, such as when your own client owns the underlying data, you confirm you have the authority to give us the instructions in this addendum on that controller's behalf.
2. Subject matter, duration and nature of processing
Subject matter: provision of a project delivery platform, including planning, task management, collaboration, approval capture, time tracking and reporting.
Duration: for the term of your subscription, plus the export and deletion windows described in section 10.
Nature and purpose: hosting, storage, transmission, display, backup and processing of your project content solely to provide, secure and support the service.
Categories of data subject: your personnel and contractors, your clients' personnel, and any other individual whose personal data you choose to record in a project.
Categories of personal data: names, business contact details, job titles, account identifiers, the content of comments and files you upload, activity and time records, and approval decisions with the identity of the approver.
Special category data: the service is not designed for special category or sensitive personal data, and we ask you not to put it into a workspace unless you have separately confirmed with us in writing that the additional conditions applicable to it are met.
3. Our obligations as processor
We will:
- Process personal data only on your documented instructions, which include your configuration of the service and any written instruction you give us. Using the service as intended constitutes an instruction.
- Not process personal data for our own purposes, and specifically not to train machine learning models, not to build a profile of any individual, and not for advertising.
- Immediately inform you if, in our opinion, an instruction infringes applicable data protection law, and pause processing pending your decision.
- Ensure that personnel with access are bound by confidentiality obligations that survive the end of their engagement, and that access is granted on a least-privilege basis and revoked promptly on role change or departure.
- Make available the information necessary to demonstrate compliance with this addendum, including the security documentation published on our security page.
4. Technical and organisational measures
We implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Our security page describes each control area in specific terms; the following is a summary of the measures we commit to here.
- Encryption of personal data in transit using TLS 1.2 or higher, and at rest including backups.
- Logical separation of customer workspaces enforced at the persistence layer, with automated cross-tenant access tests on every deployment.
- Role-based access control, per-item internal or shared visibility, and server-side authorisation on every request.
- Multi-factor authentication for all administrative access to production systems, with access logged.
- Automated encrypted backups with point-in-time recovery, replicated to a separate region, with restore procedures exercised on a schedule.
- Audit logging of authentication, permission changes, sharing changes and approvals, retained and exportable according to plan.
- A documented incident response procedure with defined severities, named owners and post-incident review.
- Peer review, static analysis and dependency vulnerability scanning as gates in our change process, with secrets held in a managed secret store.
We may update these measures over time, provided the level of protection is not reduced.
5. Sub-processors
You give us general authorisation to engage sub-processors to help provide the service. Each sub-processor is bound by a written agreement imposing data protection obligations no less protective than those in this addendum, and we remain fully liable to you for their performance.
Our current sub-processors are published on this site, together with the purpose of each engagement, the categories of data involved and the regions in which they operate.
We will give you at least 30 days' notice before adding or replacing a sub-processor. If you have a reasonable, substantiated objection on data protection grounds, raise it within that period and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.
6. International transfers
Your workspace's primary hosting region is the one you select at creation, from the United States, Singapore or Hong Kong SAR. Encrypted backups are replicated to a second region for resilience, within the same broad geography where our provider supports it.
Where processing involves a transfer of personal data out of a jurisdiction that restricts onward transfer, we rely on an appropriate safeguard for that transfer:
- The European Commission's standard contractual clauses, which are incorporated into this addendum by reference where the GDPR applies, with you as data exporter and us as data importer under the controller-to-processor module.
- The UK International Data Transfer Addendum to those clauses, where the UK GDPR applies.
- An adequacy decision, where one covers the destination.
- Consent or another lawful mechanism, where none of the above is available and you have confirmed it applies.
We will assist you with a transfer impact assessment on request, including by providing information about the legal regime applicable to our sub-processors and our record of government access requests.
7. Assisting with data subject requests
The service gives you direct control over the personal data in your workspace, so in most cases you can respond to an access, correction, deletion or portability request yourself using the interface, the export function or the API.
Where you cannot, we will assist you at no additional cost for reasonable requests. Contact support@projexio.org and we will respond within five business days.
If a data subject contacts us directly about personal data in your workspace, we will not respond substantively. We will tell them to contact you, and we will notify you of the request without undue delay.
8. Personal data breach notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting personal data we process on your behalf.
Our notification will include, to the extent known at the time and updated as we learn more:
- The nature of the breach, including the categories and approximate number of data subjects and records affected.
- The likely consequences of the breach.
- The measures we have taken or propose to take to address it and to mitigate its effects.
- A contact point at our end for further information.
We will not delay notification in order to complete an investigation. We will send you what we know and follow up.
You remain responsible for notifying your supervisory authority and affected data subjects where the law requires it. We will provide reasonable assistance.
9. Audits and information rights
We will make available the information reasonably necessary to demonstrate our compliance with this addendum. In the first instance this is our published security documentation and, for Enterprise customers, a completed security questionnaire covering each control area with its current status.
We do not currently hold a completed third-party audit report such as SOC 2 or ISO 27001, and this addendum does not represent that we do. We are working towards one and will make it available when it exists.
Where the information we publish is genuinely insufficient for your regulatory obligations, you may request a further audit no more than once in any 12-month period, on at least 30 days' written notice, conducted during business hours, subject to confidentiality, and in a manner that does not disrupt the service or risk the confidentiality of other customers' data. You bear the cost of such an audit unless it identifies a material breach of this addendum by us.
10. Return and deletion of data
You can export your project content at any time during the term, without asking us, using the export function or the API.
On termination or expiry of your subscription, your workspace becomes read-only for 90 days so you can complete an export. At the end of that period we schedule the personal data for irreversible deletion.
Individual items you delete during the term are removed from active systems immediately and purged from backups within 35 days as backup snapshots age out.
We may retain personal data where and for as long as applicable law requires us to, such as billing records retained for tax purposes. Anything retained on that basis remains subject to the security measures in this addendum and is not processed for any other purpose.
If you want us to delete a workspace before the 90-day window elapses, email support@projexio.org from the account owner's address and we will action it.
11. Liability and precedence
The limitation of liability in our Terms of Service applies to this addendum, except where applicable data protection law prohibits limiting liability to a data subject.
Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails. Where it conflicts with a signed enterprise agreement, that agreement prevails.
To request a signed copy of this addendum for your records, email support@projexio.org with your workspace name and the signing details you need.
Questions about this document
Email support@projexio.org, or use the contact page.