Legal

Data processing agreement

Effective 1 September 2026 · forms part of the terms of service between you and Flotelligent

This agreement applies whenever we process personal data on your behalf through reorderly, netterms, weighpoint or commissionly. You are the controller; we are your processor. It takes effect automatically when you install an app — you do not need to sign or request it. If your organisation requires a countersigned copy with our full registered details, email [email protected].

1. Roles and scope

For the store data we process through the apps — your orders, products, inventory, companies, staff and shoppers — you are the controller and we are the processor. For your own account and billing details, and for how you use our website, we are a controller in our own right and our privacy policy governs instead. Where a merchant is itself a processor for someone else, we act as sub-processor and this agreement reads accordingly.

“GDPR” means Regulation (EU) 2016/679 and, where relevant, the UK GDPR and the Data Protection Act 2018. Terms such as controller, processor, personal data, processing and personal data breach carry the meanings given in the GDPR.

2. Our instructions

We process personal data only on your documented instructions. Your instructions are: this agreement, the terms of service, the settings and rules you configure inside each app, and any further written instruction you give us. Installing an app and configuring it is an instruction to process as described in Annex 1.

We will tell you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law, and we may pause that processing until it is resolved. We will not process personal data for our own purposes, and we will not sell it, share it for advertising, or use it — or permit anyone else to use it — to create, train, fine-tune or improve any machine-learning or artificial-intelligence system.

3. Confidentiality of personnel

Everyone we authorise to process your personal data is bound by a written duty of confidentiality that survives the end of their engagement, is granted access only to what their role requires, and is subject to multi-factor authentication and access logging.

4. Security

We implement and maintain the technical and organisational measures set out in Annex 2, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. We may update those measures over time, but not in a way that materially reduces the level of protection.

5. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex 3. Each is bound by written terms imposing data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.

We will give you at least 30 days’ notice by email to the store owner before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected app without further charge and receive a pro-rata refund of any prepaid fees for the unused period.

6. Assisting you with data subject requests

The apps let you find, export, correct and delete the records we hold for a given person, so most requests you can complete yourself. Where you cannot, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing, so you can respond within your statutory deadlines. If a data subject contacts us directly about data we process for you, we will not respond substantively — we will refer them to you and tell you promptly.

We also implement Shopify’s three mandatory compliance webhooks — customer data request, customer redact and shop redact — and act on them within the timeframes Shopify requires.

7. Personal data breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.

You are responsible for notifying your supervisory authority and affected individuals where the law requires it. We will provide reasonable assistance.

8. Data protection impact assessments

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36 GDPR.

9. Deletion and return

On uninstall, Shopify sends us a webhook. We stop processing immediately and delete or anonymise that store’s personal data within 48 hours, except where we are required by law to retain it — principally tax and accounting records, which are retained only for that purpose and remain subject to this agreement. Export your data before you uninstall; deletion is not reversible. We will confirm deletion in writing on request.

10. Audits and demonstrating compliance

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including the contents of this agreement and its annexes, and will respond to reasonable written security questionnaires no more than once a year. Where that is not sufficient for your regulator, we will permit an audit by you or a mutually agreed independent auditor, on at least 30 days’ notice, during business hours, no more than once in any twelve months except after a personal data breach, subject to confidentiality and to not disrupting our other customers. You bear the cost unless the audit reveals a material breach by us.

11. International transfers

We are based in Sweden, inside the EEA, and prefer EEA regions for every subprocessor. Where a subprocessor nevertheless processes personal data outside the EEA — see Annex 3 — that transfer is made under the European Commission’s Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), incorporated by reference and completed as follows:

For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to those Clauses, with Tables 1 to 3 completed by reference to the same annexes and Table 4 selecting “Importer”. For Swiss transfers, the Clauses apply with references to the GDPR read as references to the Swiss FADP, the competent authority read as the Swiss FDPIC, and “member state” read so as not to deprive data subjects in Switzerland of the right to sue in their place of habitual residence.

If a transfer mechanism we rely on is invalidated, we will adopt a valid alternative without undue delay rather than continuing the transfer.

12. United States state privacy law

Where the California Consumer Privacy Act as amended, or a comparable US state privacy law, applies to personal information we process for you, we act as a service provider (or processor, as that law terms it). We will not sell or share that personal information, retain, use or disclose it outside the direct business relationship with you, or combine it with personal information from another source except as that law permits. We will notify you if we determine we can no longer meet those obligations.

13. Liability and precedence

Each party’s liability under this agreement is subject to the limitations and exclusions in the terms of service, except where the GDPR provides otherwise as between controller and processor or in respect of a data subject’s claim. If this agreement conflicts with the terms of service on a data protection matter, this agreement prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.

14. Term

This agreement takes effect when you install an app and continues while we process personal data for you. Sections 3, 4, 9, 10, 11, 12 and 13 survive its end for as long as we hold any personal data of yours.

Annex 1 — Details of processing

Subject matter: provision of the apps you have installed. Duration: for as long as the app is installed, plus the deletion window in section 9. Nature and purpose: collection, storage, organisation, retrieval, use, disclosure to sub-processors, erasure — in order to provide the functions described below. Frequency: continuous.

AppPurpose of processingCategories of data subjectCategories of personal data
reorderlyDemand forecasting, purchase orders, receiving, supplier communicationYour staff; supplier contactsName, business email, business phone; no shopper records are accessed
nettermsCredit limits, invoicing, A/R aging, collections correspondence, checkout enforcementYour B2B customers’ company contacts; your staffName, email, phone, billing address, company affiliation, order and payment history, credit limit and status
weighpointPrice computation at the point of sale, fractional inventory, receiptsYour staff; shoppers indirectly via order recordsStaff identifier and role for override and PIN logging; order line data
commissionlySale attribution, commission calculation, payout periods and exportsYour retail staff; shoppers indirectly via order recordsStaff name, email, Shopify staff ID, role, home location, pay type, PIN hash; order and refund data attributed to them

No special categories of personal data under Article 9 GDPR are required by any app, and none should be entered into free-text fields.

Annex 2 — Technical and organisational measures

Annex 3 — Sub-processors

Sub-processorPurposeLocation
Shopify Inc.Platform, OAuth, billing, app distributionCanada / US
Cloud hosting and managed database providerApplication hosting and managed databaseEEA
Error and log monitoring providerFault diagnosis and error reportingEEA
Transactional email providerService notices, invoices and collection remindersEEA
Support desk providerSupport correspondenceEEA

Contact

[email protected] · Flotelligent, Sweden. Our registered business details are provided on request. Our supervisory authority is Integritetsskyddsmyndigheten (IMY), Sweden.