Data Processing

Data Processing Terms

A factual, current-state foundation for business customers. It describes what actually happens today and is written to be completed under professional legal review.

Version 1.0

Effective 30 August 2026 · Last updated 30 August 2026. These documents describe how Business OS 365 works today. They are prepared for professional Malta/EU legal review and are not legal advice. Nothing here is certified, audited, regulator-approved or lawyer-approved.

1. Status of this document

This is a current-state description, not an executed data processing agreement. No signed Article 28 arrangement, certification, code of conduct adherence or audit outcome is claimed. A formal agreement will be offered following professional Malta/EU legal review.

2. What is processed on our servers

  • account data: user identifier, email address, display name and record timestamps;
  • company data: company name, business type, country, timezone, currency, optional phone and website, and onboarding timestamps;
  • membership data: which user belongs to which company, with role and status;
  • billing metadata: plan, subscription status, interval, period dates, trial and cancellation state, and provider customer, subscription and price identifiers.

3. What is not processed on our servers

Operational zone records — Inventory, Suppliers, Sales & Invoices, Expenses and Staff — are held in the user's own browser on the device in use. They are not transmitted to, stored on, or accessible from Business OS 365 servers, and are not backed up by us. Any personal data inside those records (supplier, customer or staff names, emails, phone numbers and notes) therefore remains under the customer's direct control on the device. This document does not pretend otherwise.

4. Purpose and instructions

Server-side data is processed to provide and operate the service: authentication, workspace membership and access control, subscription and entitlement handling, service communication such as verification and password-reset emails, and security and reliability. It is not sold and is not used for advertising or profiling.

5. Confidentiality and access control

Access to server-side data is limited to what is needed to operate the service. Traffic is served over HTTPS, database row-level security restricts records to the owning company, and role-based access applies inside the application. Card data is kept with Stripe and never reaches this application or its database.

6. Providers involved today

  • LovableApplication hosting, build and delivery of the web application.
  • SupabaseAuthentication and the server-side database holding profiles, companies, memberships and billing metadata. Supabase Auth also sends account emails such as verification and password reset.
  • StripePayment processing, subscriptions and the customer billing portal where paid access applies.

There is no external AI or model provider involved in processing today, and no analytics or marketing provider. Provider locations, transfer mechanisms and contractual safeguards depend on provider configuration and contracts and are subject to final review.

7. Assistance with incidents and data requests

We will assist a business customer with security incidents affecting server-side data and with requests relating to that data, within current technical limits and without claiming capabilities that do not exist. Self-service deletion and export are not implemented today, and device-local records can only be removed by the customer in their own browser.

8. Reserved for professional legal review

Controller and processor allocation, sub-processor notification commitments, audit rights, international transfer safeguards, breach notification deadlines and liability wording are reserved for professional legal review and are deliberately not asserted here.

Operator and contact

Business OS 365 is operated by YK Digital Marketing in Malta. Full operator and contact details — including registered address, company registration and VAT information where applicable — are to be finalised before publication.

Until a published contact address is finalised, legal, privacy and billing requests should be raised through the account or workspace channel you were invited with. A dedicated legal contact address will be published here before general availability.