GDPR & Data Processing
Last updated: 25 August 2026
This page summarises how a1RepairFlow supports GDPR compliance — both what we do as a company, and what the platform gives your repair shop as a data controller.
1. Roles
- You (the shop) are the data controller for your customers' data that you enter into the platform.
- a1RepairFlow is your data processor: we process that data only on your documented instructions, to provide the Service.
2. Data processing terms
By using the Service, a data-processing agreement on the following terms applies between the shop and a1RepairFlow:
- We process personal data solely to deliver the Service and never for our own marketing.
- All production data is hosted in data centers within the EU.
- Sub-processors (hosting, email/SMS delivery, payments) are bound by equivalent data-protection obligations. A current list is available on request.
- We apply technical and organisational measures including encrypted transport (TLS), tenant isolation, access control and backups.
- We notify you without undue delay after becoming aware of a personal-data breach affecting your tenant.
- On termination, we return or delete your tenant data in line with the retention windows in the Privacy Policy.
3. GDPR tools built into the platform
- Consent capture — customer signature and consent at intake, stored with the ticket.
- Right of access / portability — export a customer's data from their customer card.
- Right to erasure — anonymise or delete a customer record, subject to invoice-retention rules.
- Retention — invoices are retained as required by bookkeeping law even if a customer record is erased.
4. Requests from your customers
If your customer contacts us directly about their data, we will refer them to you as the controller, and assist you with fulfilling the request where needed.
5. Contact
Data-protection questions and sub-processor list: [email protected].