Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Inventro Terms of Service and governs the processing of personal data by Inventro on behalf of the Tenant.
1. Roles and Responsibilities
The Tenant is the Data Controller and determines the purposes and means of processing End Customer personal data. Inventro acts solely as the Data Processorand will only process personal data in accordance with the Tenant's documented instructions and the Terms of Service.
If Inventro considers that an instruction from the Tenant infringes applicable data protection law, Inventro will inform the Tenant without undue delay and may suspend performance of that instruction until it is confirmed, withdrawn, or amended.
2. Processing Scope
Inventro processes personal data solely to provide the Services, including:
- Categories of data: End customer names, email addresses, phone numbers, delivery/event addresses, and booking details
- Purpose: Booking management, invoicing, customer communication, and inventory allocation
- Duration:For the term of the Tenant's active account plus the retention period described in Section 7
3. Security Measures
Inventro implements the following technical and organizational measures to protect personal data:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Hashed and salted credential storage
- Tenant-level logical data isolation
- Role-based access controls and principle of least privilege
- Audit logging of administrative actions
- Regular security reviews and patch management
Inventro ensures that personnel authorised to process personal data are bound by an appropriate obligation of confidentiality, and that access is granted only to those who need it to perform their duties.
4. Subprocessors
Inventro engages the following subprocessors to deliver the Services. Each subprocessor is bound by contractual obligations to process data only as instructed and to maintain appropriate security safeguards:
This table covers subprocessors that handle Tenant Data or End Customer personal data. Analytics providers that only ever receive data about visitors to Inventro's own marketing website, and never Tenant Data, are listed in the Privacy Policy instead.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, object storage (S3), and content delivery | United States (us-east-1; backups replicated to us-west-2) |
| Resend | Transactional email delivery — booking confirmations, quotes, invoices, and contracts, including PDF attachments addressed to End Customers | United States |
| Stripe | Payment processing, payouts via Stripe Connect, and subscription billing | United States |
| Sentry | Error monitoring and diagnostics. Receives crash reports carrying internal user and organization identifiers, and a masked replay of the moments preceding an error | United States |
| PostHog | Organization-level operational telemetry: internal identifiers, enums, counts, and monetary amounts. Does not receive End Customer records or free-form content | United States |
| Google LLC | Calendar API, only where the Tenant connects Google Calendar. Receives the booking events Inventro writes, which describe End Customer name, address, booking reference, and time | United States |
Inventro will notify Tenants of any changes to subprocessors by updating this page and providing at least thirty (30) days' notice via email or in-platform notification before a new subprocessor begins processing personal data. If a Tenant objects to a new subprocessor, the Tenant may terminate the Services without penalty.
5. Breach Notification
In the event of a confirmed personal data breach, Inventro will:
- Notify the affected Tenant(s) without undue delay, and in any event within 24 hours of confirming the breach, so the Tenant retains time to meet its own regulatory notification deadlines
- Provide a written description of the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to mitigate the breach
- Cooperate with the Tenant in investigating and remediating the breach
- Where required by PIPEDA, report the breach to the Office of the Privacy Commissioner of Canada (OPC) if there is a real risk of significant harm
6. International Transfers
Personal data is processed in the United States by the subprocessors listed in Section 4, with production systems in AWS us-east-1 and backups replicated to us-west-2. Contractual safeguards are in place to ensure data receives a comparable level of protection.
7. Data Retention and Deletion
Upon termination of the Tenant's account:
- Tenant data (including End Customer personal data) will be available for export for thirty (30) days
- After the 30-day period, all personal data will be permanently deleted from production systems
- Backups containing personal data will be purged within ninety (90) days
- Data may be retained longer only where required by Canadian law (e.g., tax records for up to seven years)
8. Audits and Compliance
Upon reasonable request and subject to confidentiality obligations, Inventro will provide Tenants with information necessary to demonstrate compliance with this DPA. Inventro will also allow for and contribute to audits, including inspections, conducted by the Tenant or an auditor mandated by the Tenant, on reasonable notice and during normal business hours.
Inventro may satisfy an audit request in the first instance by providing relevant certifications, security reports, or third-party audit summaries. Where those do not reasonably answer the Tenant's question, the Tenant retains the right to an inspection.
9. Assistance to the Tenant
Taking into account the nature of the processing and the information available to it, Inventro will assist the Tenant in meeting its own obligations as Data Controller. Specifically, Inventro will:
- Assist the Tenant, by appropriate technical and organisational measures, in responding to requests from End Customers seeking to exercise their rights of access, rectification, erasure, restriction, portability, or objection
- Provide the Tenant with the information and cooperation reasonably needed to carry out a data protection impact assessment, and to consult a supervisory authority in advance where one is required
- Assist the Tenant in meeting its own security, breach notification, and breach communication obligations, including those described in Section 5
Where an End Customer contacts Inventro directly to exercise a right, Inventro will not respond on the Tenant's behalf unless instructed to, and will refer the request to the Tenant without undue delay.