1. Scope and relationship with customer agreements
This Policy applies to personal data processing related to access, administration, support and use of Supria Workspaces, including customer-authorized integrations.
Contracts, proposals, security addenda, data processing agreements and other specific instruments may establish additional obligations. If there is a conflict regarding the contracted subject matter, the applicable specific instrument controls.
2. Responsible entity and Data Protection Officer
2 S Biscayne Blvd, Ste 2450, Miami, FL 33131, United States.
Data Protection Officer
dpo@supria.com
3. Privacy roles in an enterprise environment
As a general rule, the customer determines which users may access its environment, which business data is entered or integrated, and which permissions are granted. For that data, the customer acts as controller or business and Supria acts as processor or service provider when processing data on the customer's behalf under its instructions and the applicable agreement.
Supria may act as controller or business for data it processes for its own legitimate purposes, such as account and access administration, security, support, billing and customer relationship management. The legal characterization may vary by purpose, applicable law and contract.
4. Categories of data processed
Depending on contracted features and customer-authorized integrations, Supria Workspaces may process:
- User and access data: identifiers and professional information needed for authentication, authorization, profile and environment administration.
- Project, portfolio and investment data: information entered by the customer or integrated from authorized sources, which may include references to individuals when relevant to the business process.
- Integration data: information selected and authorized by the customer from connected systems, applications, APIs or files.
- Support data: information provided in support requests, communications and support sessions.
- Technical and security data: records needed for operation, authentication, access control, audit, troubleshooting and protection of the environment, depending on the applicable implementation.
5. How data is used
Data may be processed, as applicable, to:
- provide and administer contracted features;
- authenticate users and enforce permissions;
- execute customer-authorized integrations and workflows;
- provide support and investigate technical incidents;
- maintain security, availability, integrity and traceability;
- comply with legal and contractual obligations.
6. Integrations and third-party services
Supria Workspaces may integrate with systems, applications, APIs and files authorized by the customer. The customer controls which integrations are enabled and must have the rights needed to connect and make the corresponding data available.
Third-party services connected to the environment remain subject to their own terms, policies and controls.
7. Service providers, location and transfers
Supria Workspaces operates in a Microsoft cloud environment and uses technology providers needed to deliver and protect the service. Providers and subprocessors with relevant access to systems or data are subject to security requirements appropriate to their role and, where applicable, contractual obligations addressing data protection, confidentiality and security.
Processing and storage locations may vary depending on architecture and the contracted environment. Where cross-border processing is subject to specific legal requirements, we use the mechanisms required by applicable law. Specific data-residency information may be set out in the technical or contractual documents applicable to the customer environment.
8. Retention, termination and deletion
During the contract term, retention depends on the nature of the record, applicable customer instructions, security and backup requirements, and legal or contractual obligations.
Unless a specific agreement or legal requirement provides otherwise, after contract termination the customer may request export of its data for up to 30 days in a structured format that is technically available. After that period, customer data maintained in production environments is securely deleted within up to 90 days.
Copies maintained in backups follow separate retention and expiration cycles for continuity and recovery and may remain longer than production data while continuing to be protected during that cycle. Metadata, audit records and access logs may be retained for the period required by law or as necessary to establish, exercise or defend legal rights.
9. Security
Supria maintains administrative and technical controls aligned with the nature of the service, including, as applicable, identity and access management, encryption of data in transit and at rest, monitoring, backups and recovery testing, incident response, vulnerability management and secure-development practices.
Supria maintains and reviews these controls as the platform evolves. Security also depends on customer configuration, identity management, granted permissions and the protection of connected systems.
10. Rights and requests
Individuals may exercise rights provided by applicable law. When a request relates to business data entered or controlled by the customer, it may need to be directed first to the organization administering the environment. Supria cooperates with customers as required by law and contract.
Privacy requests may be sent to dpo@supria.com.
11. Microsoft Marketplace and external channels
Supria Workspaces may be made available through external channels, including Microsoft Marketplace. This Policy applies to product-related processing without replacing terms, notices or conditions that apply to the acquisition channel.
12. Updates
We may update this Policy to reflect legal, technical, contractual or operational changes. Material updates will be identified by a new revision date and, where appropriate, additional notice.
Data Protection Officer
dpo@supria.com