Control costs

Live job costing from labour, materials and machines.

Manage teams

Plan people, hours and schedules in one place.

Track materials

Know exactly what you own and where it is.

Run projects

One system from kickoff to closeout.

Not sure where to start?

See the whole platform mapped to your day-to-day in a 20-minute walkthrough.

Enterprise demo account

A test environment configured around your own processes, available on request.

Home Data Processing Addendum (DPA)
Legal

3. Data Processing Addendum (DPA)

The terms under which Envoo d.o.o., as processor, processes personal data on behalf of the controller.

Last updated: 31 October 2025
Service operator:

Provider: Envoo d.o.o., company no. 6195407000, VAT no. SI45695539

Registered office: Cesta dolomitskega odreda 10c, 1000 Ljubljana, Slovenia

Contact: info@relayplan.com

3.1. Subject matter and duration

  • The Processor processes personal data on behalf of the Controller for the purpose of providing the RelayPlan Service for the duration of the contract.

3.2. Nature and purpose of processing

  • Hosting, storage, organisation, access, transfer at the Controller’s request, backups and support.

3.3. Types of data and categories of data subjects

  • Data on employees, contractors, system users (name, contact, working hours, assignments and so on), suppliers and others entered by the Controller.

3.4. Obligations of the Processor

  • Processes exclusively in accordance with the Controller’s documented instructions.
  • Ensures the confidentiality of persons involved in processing and appropriate technical and organisational measures (TOMs).
  • Assists the Controller in meeting its obligations (data subject rights, security incidents, DPIA).
  • On termination of the contract, at the Controller’s choice, returns or deletes personal data unless the law requires retention.

3.5. Sub-processors

  • The Processor may engage sub-processors with prior notice to the Controller. All sub-processors must enter into written agreements with standards no lower than these.
  • The current list is in Annex A.

3.6. Transfers outside the EEA

  • Where a sub-processor or system entails a transfer outside the EEA, appropriate mechanisms are put in place (e.g. SCCs), together with a transfer risk assessment and supplementary measures where necessary.

3.7. Security incidents

  • The Processor notifies the Controller without undue delay of a personal data breach, provides the information required under Article 33 GDPR and cooperates in managing the incident.

3.8. Audits

  • The Controller may (reasonably and with prior notice) request compliance information or carry out an audit (once a year or on reasonable suspicion), without disclosure of trade secrets.

Annex A – List of sub-processors

  • Stripe Payments Europe, Ltd. – billing and payments, EEA/USA (SCCs).
  • Hetzner Online GmbH – hosting, EU/EEA.
  • Google – email.
  • Google – analytics.

Annex B – Technical and organisational measures (TOMs)

  • TLS encryption, tenant separation, RBAC, 2FA, audit trails, regular backups, access control, least privilege, update security.
Last updated: 31 October 2025
Contact us →

Ready to see RelayPlan?

Start free, or book a 20-minute walkthrough of how it maps to your operation.

Book a demo