1. Roles & Scope
In the context of providing the EngiBridge OS Platform, the Customer (whether a Main Contractor, Subcontractor, or Developer) acts as the "Data Controller", retaining full legal control and ownership over the data inputted into the system.
EngiBridge acts strictly as the "Data Processor". We process the Controller's data exclusively upon their direct instructions (i.e., system inputs, automated workflows, and configuration settings) and solely for the purpose of operating the Platform as defined in the Enterprise Terms of Service.
2. PDPA & Global Compliance
EngiBridge is fully committed to operating in strict compliance with global data protection standards, including the General Data Protection Regulation (GDPR) and equivalent regional frameworks.
When processing highly sensitive workforce identity documents, including site safety cards, worker passports, and site access permits, we employ specialized safeguards. We ensure that this personal data is processed solely for the purposes of site safety compliance and operational validation, and is never repurposed.
3. Technical Security Measures
To protect Customer Data from unauthorized access, alteration, or destruction, EngiBridge mandates a Zero-Trust security architecture. The technical measures implemented across our infrastructure include:
- Encryption at Rest: All databases, document storage, and backups are encrypted using AES-256 standard encryption.
- Encryption in Transit: All data transmitted between the Customer and our servers is secured via TLS 1.3.
- Tenant Isolation: We enforce strict database Row-Level Security (RLS) policies, mathematically guaranteeing that cross-tenant data spillage is impossible.
4. Approved Sub-processors
To deliver our highly available cloud infrastructure, EngiBridge utilizes carefully selected, top-tier enterprise sub-processors. These currently include Supabase for database operations and Amazon Web Services (AWS) for physical cloud storage and compute.
All approved sub-processors are legally bound by strict data protection agreements that enforce security standards equal to or greater than those outlined in this DPA. We maintain a live registry of sub-processors and will notify Data Controllers prior to onboarding any new vendors.
5. Incident Response
In the highly unlikely event of a confirmed data breach or unauthorized access incident affecting Customer Data, EngiBridge guarantees swift and transparent action.
We will notify the affected Data Controller's designated security contact within 48 hours of verification. Alongside the notification, we will provide a comprehensive audit trail of the incident, an assessment of the impacted data scope, and our immediate remediation plan to neutralize the threat.