InventoryFlo
Billing & PlanSign in

Data Processing Agreement

Last updated: 16 May 2026 · Effective: 16 May 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Managa Digital LTD("Processor", "we") and the customer accepting these terms ("Controller", "you"). It applies when we process personal data on your behalf in providing the InventoryFlo service (the "Service"), and is required by Article 28 of the UK GDPR and EU GDPR.

1. Definitions

Terms not defined herein have the meaning given in the UK GDPR and the EU General Data Protection Regulation 2016/679. "Customer Personal Data" means personal data that you upload to or generate within the Service.

2. Subject matter, duration, nature and purpose of processing

  • Subject matter: hosting, processing, and providing access to Customer Personal Data through the Service.
  • Duration: for the term of your subscription plus the retention period described in Section 9.
  • Nature: storage, structured queries, backups, transmission, display, deletion on request.
  • Purpose: enabling you to operate inventory management and related business workflows.

3. Categories of data subjects and personal data

Categories of data subjects you may upload to the Service include:

  • Your employees, contractors, and authorised users
  • Your suppliers and supplier contacts
  • Your customers (where you enter their data, e.g., as recipients of pick lists or checkouts)

Categories of personal data processed may include:

  • Identification data: name, email, role, authentication credentials
  • Contact data: phone, address (for suppliers / staff)
  • Activity data: actions taken in the Service, timestamps, IP address

You must NOT upload special-category data (Art 9 GDPR) such as health, racial origin, religious beliefs, biometrics, or criminal-offence data, unless we have agreed separately in writing.

4. Obligations of the Processor

We will:

  • Process Customer Personal Data only on your documented instructions (the Terms of Service and this DPA constitute such instructions);
  • Ensure persons authorised to process Customer Personal Data have committed to confidentiality;
  • Implement appropriate technical and organisational measures (Section 6);
  • Engage subprocessors only under the conditions of Section 5;
  • Assist you in fulfilling your obligations to respond to data-subject requests;
  • Assist you with security, breach notification, and Data Protection Impact Assessments;
  • Delete or return Customer Personal Data at the end of provision of services per Section 9;
  • Make available all information necessary to demonstrate compliance with Article 28 of the GDPR.

5. Subprocessors

You authorise us to engage subprocessors. The current list is published in Section 7 of our Privacy Policy and may be updated from time to time. We will:

  • Impose data-protection obligations on subprocessors no less protective than those in this DPA;
  • Remain liable to you for the acts and omissions of subprocessors;
  • Provide at least 30 days' advance notice of new subprocessors via in-app notice or email.

If you reasonably object to a new subprocessor on data-protection grounds, you may terminate the affected portion of the Service within 30 days of the notice and receive a pro-rata refund of prepaid unused fees.

6. Technical and organisational measures

We implement the following measures:

  • Encryption in transit using TLS 1.3
  • Encryption at rest using AES-256
  • Password hashing with bcrypt (cost factor 12)
  • Role-based access control within tenant organizations
  • Two-factor authentication (TOTP) available for all users
  • Logical separation of tenant data via organization-scoped queries
  • Audit logging of administrative actions and data changes
  • Restricted, role-based internal access on a need-to-know basis
  • Automated dependency vulnerability scanning
  • Daily encrypted backups retained 30 days, restoration testing
  • Incident response procedure with 72-hour breach-notification target
  • Annual review of security controls

7. Personal-data breach

We will notify you of a personal-data breach affecting Customer Personal Data without undue delay and in any case within 48 hours of becoming aware of it. Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

8. International transfers

Customer Personal Data is primarily hosted in the European Union (France). Where transfers to third countries are necessary (e.g., for transactional email or error tracking), we rely on:

  • European Commission adequacy decisions; or
  • European Commission Standard Contractual Clauses (Module 2 or 3 as applicable, decision 2021/914); and
  • For UK transfers, the UK International Data Transfer Addendum.

On request we will provide copies of the executed SCCs with relevant subprocessors.

9. Deletion and return

At the end of provision of services, you may export Customer Personal Data via the in-app export feature for 30 days. After 30 days we will delete Customer Personal Data, except where law requires longer retention (e.g., financial records under UK Companies Act 2006 s.388 for 7 years). Backups containing deleted data are purged on the rolling 30-day backup cycle.

10. Audit

We make available the information necessary to demonstrate compliance with Article 28 GDPR. On your written request and no more than once per year (or following a personal-data breach), we will respond to a reasonable security questionnaire. Where required, we will permit audits by you or a mutually agreed third-party auditor under reasonable confidentiality and scheduling terms, with you bearing reasonable costs unless the audit reveals material non-compliance.

11. Cooperation with supervisory authorities

We will cooperate with the UK Information Commissioner's Office and any other competent supervisory authority in the performance of our obligations under this DPA.

12. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in the Terms of Service.

13. Conflict and order of precedence

In the event of conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict in respect of personal-data processing matters.

14. Governing law

This DPA is governed by the laws of England and Wales and is subject to the jurisdiction provisions of the Terms of Service.

15. Contact

For data-protection enquiries: privacy@inventoryflo.com


Annex 1 — Description of processing

  • Nature and purpose: as described in Section 2.
  • Duration: as described in Section 2.
  • Data subjects: as described in Section 3.
  • Categories of personal data: as described in Section 3.
  • Frequency: continuous, on a 24/7 basis.

Annex 2 — Subprocessors

See Section 7 of the Privacy Policy.

Annex 3 — Technical and organisational measures

See Section 6 above.

InventoryFlo
PrivacyTermsDPA© 2026 Managa Digital LTD