Data Processing Agreement
The processor terms we offer shops in the UK and EU — what we do with your customers' data, how it is secured, who else touches it, and what you can hold us to.
Last updated 11 September 2026 · Inventrixo
Draft — pending legal review
This document was prepared from how the Inventrixo service is actually built, but it has not yet been reviewed by a qualified data-protection lawyer. It is published for review and is not yet a binding statement of our practices. Please do not rely on it when making a purchasing or compliance decision — contact us at privacy@inventrixo.com and we will answer directly.
1.Parties and how this agreement applies
This Data Processing Agreement (“DPA”) is between Inventrixo of (“Inventrixo”, “we”, the processor) and the customer who has subscribed to the Inventrixo service (“you”, the controller).
It forms part of, and is incorporated into, our Terms of Service. It takes effect when you begin using the service and continues for as long as we process personal data on your behalf. Where this DPA and the Terms conflict on the subject of personal data, this DPA prevails.
You do not need to sign or request anything to rely on it. If your own procurement process requires a countersigned copy, or your own paper instead of ours, write to privacy@inventrixo.com and we will accommodate it.
2.Which data this covers
This DPA covers only the personal data we process on your instructions — principally the records you enter about your own customers. It does not cover your own account data, for which we are the controller and our Privacy Policy applies.
| Required detail | For the Inventrixo service |
|---|---|
| Subject matter | Provision of the Inventrixo point-of-sale, inventory and repair-tracking service |
| Duration | For the term of your subscription, plus the deletion period in section 9 |
| Nature and purpose | Storage, retrieval, organisation, display and deletion of records you enter, so that you can operate your shop |
| Categories of data subject | Your customers; your staff whose accounts you create; where applicable, your suppliers' contacts |
| Categories of personal data | Names; contact details (email, phone, postal address); purchase and repair history; device identifiers such as IMEI or serial numbers; free-text notes you choose to record |
| Special category data | None is required by the service, and none should be entered. The free-text notes fields are not designed or secured for health, biometric or other special category data. Do not enter it. |
3.What we undertake
We will:
- Process personal data only on your documented instructions, which for ordinary use means: as needed to provide the service, and as directed by your use of its features.
- Not use your customers' personal data for our own purposes. We will not use it to train AI models, to build a product, to market to your customers, or to profile them.
- Ensure that anyone with access to it is bound by a duty of confidentiality.
- Implement and maintain the technical and organisational measures set out in section 5.
- Tell you without undue delay if we believe an instruction from you would breach data-protection law, and not simply carry it out.
- Assist you in meeting your own obligations — responding to data subjects, carrying out impact assessments, and dealing with a supervisory authority.
We will also tell you if we receive a request for your data from a law-enforcement or government body, unless we are legally prohibited from doing so — and where prohibited, we will challenge the prohibition where there are reasonable grounds.
4.What you undertake
As the controller, the decisions about your customers' data are yours, and so are the corresponding duties. You confirm that:
- You have a lawful basis for the personal data you enter into the service, and have given your customers the information the law requires — normally through your own privacy notice.
- Your instructions to us will not require us to breach data-protection law.
- You will keep your own account credentials secure, and will use the role settings in the product to limit what each member of staff can access.
- You will not enter special category data, as noted in section 2.
This is not us pushing risk onto you. It reflects the actual division of control: we cannot know why you recorded a customer's phone number, and you cannot know how our database is encrypted. Each side is answerable for what it decides.
5.Security measures
The measures below are what we actually do, and are the ones we are committing to under Article 32. We may change them, but not in a way that materially reduces the protection in place.
- Encryption in transit for all traffic to and from the service (TLS).
- Encryption at rest for the hosted database, provided by our infrastructure provider.
- Encryption at rest for the desktop application's local database, using AES-256-GCM with PBKDF2-SHA256 key strengthening at 210,000 iterations, and authenticated so that tampering is detected rather than silently accepted.
- Passwords stored only as salted hashes; optional two-factor authentication on web accounts.
- Role-based access control within each customer's account, and tenant isolation between customers.
- Access to production systems limited to personnel who require it to operate the service.
- An immutable activity log within each account, so that actions can be attributed.
- Rate limiting and abuse controls on authentication and public endpoints.
6.Sub-processors
You give general authorisation for us to engage the sub-processors listed below. Each is engaged under a written contract imposing data-protection obligations no less protective than those in this DPA, and we remain responsible to you for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and content delivery | United States, with a global edge network |
| Neon Inc. | Managed PostgreSQL database — where account and shop records are stored | United States (AWS us-east-1, N. Virginia) |
| Lemon Squeezy LLC | Subscription billing. Acts as merchant of record and handles all card data | United States |
| Anthropic PBC | AI assistant and product suggestions, when a user invokes an AI feature | United States |
| Resend Inc. | Transactional email — account, billing and notification messages | United States |
| Twilio Inc. | SMS notifications, where a shop enables them | United States |
We will give you at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, tell us within that period and we will work with you to find an alternative; if none is workable, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees. We will not treat an objection as a breach of contract.
7.International transfers
The hosted service stores personal data in the United States (AWS US East, Northern Virginia). Every sub-processor in section 6 is also United States based. We state this plainly because it is the first thing a UK or EU controller needs to assess, and burying it would not serve you.
Where we transfer personal data out of the UK or the EEA, that transfer is made under the following safeguards, which are incorporated into this DPA by reference:
- For EEA transfers: the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with you as data exporter and us as data importer.
- For UK transfers: the same clauses as amended by the UK International Data Transfer Addendum (IDTA) issued by the Information Commissioner.
- For Swiss transfers: the same clauses, read with reference to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.
The completed annexes to those clauses are available on request — write to privacy@inventrixo.com and we will send them with a countersigned copy of this agreement.
The alternative we would rather offer you.The Inventrixo desktop application stores your shop's records in an encrypted file on your own computer and does not transmit them to us at all. Used that way, there is no international transfer of your customers' data to assess. If data location is your primary concern, that is the deployment to choose.
8.Personal data breaches
If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay and in any event within 48 hours of becoming aware of it — sooner where we can, so that you can meet your own 72-hour duty to your supervisory authority.
Our notification will include, so far as we know it at the time:
- What happened, and when we became aware of it
- The categories and approximate number of data subjects and records involved
- The likely consequences
- What we have done and are doing to contain and remediate it
- A contact point for follow-up questions
We will not wait until we have a complete picture before telling you. An incomplete first notification followed by updates is more useful to you than a late and tidy one.
9.Return and deletion of data
You can export your data at any time, without asking us. The desktop application does it in one click — the complete database as JSON plus a spreadsheet per table. For the hosted service we will provide an export in the same format on request.
On termination, or at your request at any time, we will delete the personal data we process for you within 30 days, and from routine backups as those backups age out of their retention window. We will confirm deletion in writing if you ask.
The exception is anything we are required by law to keep — principally billing records for tax purposes. That is retained only for as long as the law requires, and only for that purpose.
10.Information and audit
On reasonable request, we will provide the information you need to demonstrate our compliance with this DPA, and will co-operate with an audit or inspection you or your appointed auditor carry out.
We would ask for reasonable notice, that audits happen no more than once a year unless a breach or a regulator's instruction warrants otherwise, and that your auditor is bound by confidentiality — not to obstruct you, but because we host other shops on the same infrastructure and owe them the same protection we owe you.
11.Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing limits liability where the law does not permit it to be limited — which includes a data subject's rights to compensation, and any liability that cannot be limited under applicable data-protection law.
Where a dispute cannot be resolved between us, it will be governed by the law of the jurisdiction in which Inventrixo is established, and we will tell you which that is on request. Save — save that, for transfers made under the Standard Contractual Clauses or the IDTA, the governing law and forum specified in those instruments apply to them.