Legal
Data Processing Addendum
Effective 28 August 2026
THE SHORT VERSION
For your shop's data, you are the controller and Inventovia is your processor: we act only on your instructions, protect the data as described below, and help you meet your own obligations to your customers and staff.
1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the merchant ("controller") and INVENTOVIA LIMITED ("processor") and applies to the personal data the merchant's use of Inventovia entrusts to us: staff records, and customer records kept for loyalty and credit ("Shop Personal Data").
2. Our commitments as processor
- Process Shop Personal Data only to provide the service and on the merchant's documented instructions, which these terms and the product's controls constitute.
- Ensure people we authorise to access it are bound by confidentiality.
- Apply the technical and organisational measures described in section 7 of the Privacy Policy (encryption in transit and at rest, hashed credentials, tenant isolation by row-level security, audited staff access, encrypted backups).
- Assist the merchant, with reasonable measures, in answering data-subject requests and meeting security and breach-notification obligations.
- Notify the merchant without undue delay on becoming aware of a personal data breach affecting Shop Personal Data.
- Delete Shop Personal Data as described on the account deletion page when the agreement ends, subject to legal retention duties.
- Make available the information reasonably necessary to demonstrate these commitments.
3. Subprocessors
The merchant authorises the subprocessors listed in section 6 of the Privacy Policy. We will update that list before adding a subprocessor that touches Shop Personal Data; if a merchant reasonably objects, their remedy is to end the service and export their records.
4. International transfers
Where providing the service transfers Shop Personal Data across borders, we rely on appropriate safeguards such as standard contractual clauses.
5. The merchant's responsibilities
The merchant is responsible for the lawfulness of the Shop Personal Data it records — including telling staff and customers what is recorded and why, honouring their rights, and configuring staff permissions appropriately.