Skip to content

Security

Last updated: 30 July 2026

Hotels, venues, and facilities teams use Fixray to log and resolve maintenance issues, which means we hold your operational records, photos, and details of the people who use it. This page explains where that data lives, how it is protected, and which other companies touch it. In short: your account and maintenance data is stored in the UK, encrypted in transit and at rest, and access to it is scoped to your organisation by controls enforced in the database itself.

Hosting and data residency

Your account and maintenance data is stored in AWS's London region (eu-west-2), on infrastructure provided by Supabase, which holds an ISO 27001 certification and a SOC 2 Type 2 report. Those belong to our infrastructure provider, not to Fixray — Fixray does not hold any certifications of its own. The United Kingdom holds an EU adequacy decision, so personal data belonging to EU customers is lawfully processed there under GDPR. Our analytics data is processed in the EU (Frankfurt). Our encrypted off-site backups are held by Cloudflare, which may store them outside the UK/EU.

Encryption

All traffic between your devices and Fixray is encrypted in transit with TLS. Data — including photos, videos, and voice notes — is encrypted at rest on our storage infrastructure using AES-256.

Access control

Fixray is multi-tenant by design. Every database query is constrained by row-level security policies enforced at the database layer, so each organisation's data is scoped to that organisation rather than filtered in the app. Within your organisation, role-based permissions control what each person can see and do. Multi-factor authentication is available for your team's accounts, and new or changed passwords are checked against a database of known breached passwords and rejected if they appear in it.

Backups

Databases are backed up automatically every day, so your maintenance history, photos, and audit trail can be recovered if something goes wrong.

Service status

Fixray is monitored continuously and we are alerted automatically when something stops responding. Live and historical availability is published at status.fixray.app.

If something goes wrong

If an incident affects the security of your data, we will contact the affected organisations directly with what we know and what we are doing about it, and post updates to our status page. Where the law requires us to notify the Information Commissioner's Office, we will do so.

Retaining and deleting your data

We keep your organisation's data for as long as you use Fixray, so that your maintenance history and audit trail stay intact — that record is the point of the product. You can export it, or ask us to delete it, at any time: contact your Fixray administrator or email hello@fixray.app.

When you close your account, or ask us to delete your data, we delete it within 30 days. Copies held in our encrypted backups are removed as those backups age out, within a further 90 days. Individual users can request access to, or deletion of, their personal data through their administrator, as set out in our privacy policy. Product-analytics records are kept for up to 12 months.

Subprocessors

We use a small number of vetted service providers to run Fixray. Each processes data only on our instructions. If we add or replace a provider, we will update this list and let existing customers know.

ProviderPurposeLocation
Supabase (on AWS)Database, authentication, file storage, and server functionsLondon, United Kingdom (AWS eu-west-2)
CloudflareHosting, content delivery, DNS, and bot protectionGlobal edge network (EU/UK entry points)
StripePayment processing and billingEU / United States
ResendTransactional email (invites, notifications, alerts)United States
Google WorkspaceOur business email — mail you send us, and mail we send from a person's addressUnited States / global
AnthropicThe AI assistant that runs our business-prospect outreach (marketing contacts only, never app data)United States
SlackOur internal workspace, where summaries of that outreach appearUnited States
OpenRouter / Google (Gemini)AI transcription and suggestion featuresUnited States / EU
PostHogProduct analyticsFrankfurt, Germany (EU)
SentryError monitoring and crash diagnosticsEuropean Union
HubSpotCustomer relationship management and support inboxEU / United States
ApolloIdentifying which companies visit our marketing site, for sales outreach (marketing site only, and only with analytics consent)United States
GitHubSource-code hosting and the automation that produces our encrypted backupsUnited States
Apple, Google and MozillaDelivering push notifications to your deviceUnited States / global

Subprocessor list last updated: 30 July 2026.

Data processing agreement

A standard data processing agreement (DPA) covering our GDPR obligations is available on request — email hello@fixray.app.

Reporting a vulnerability

If you believe you've found a security issue in Fixray, please email hello@fixray.app with the details. We investigate every report and will keep you informed of the outcome. Please don't test against production systems or access data that isn't yours while doing so.