Data Processing Addendum

Last updated: July 29, 2026 · Version 2026-08

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Victoria Winter Consulting LLC, a South Carolina limited liability company doing business as Invoe ("Invoe", "we", "us").

You do not need to sign or return anything. This DPA applies automatically whenever we process personal data on your behalf. If your organization needs a countersigned copy for its records, see section 14.

1. Definitions

"Data Protection Laws"means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the California Consumer Privacy Act as amended ("CCPA").

"Customer Personal Data" means personal data contained in the data you submit to, or that is generated in, the Service, and that we process on your behalf.

"controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in the GDPR.

"SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.

2. Roles of the parties

For Customer Personal Data — the data in your purchase orders, vendor records, product catalog, receiving history, and the accounts of your team members as you administer them — you are the controller and we are the processor. This DPA governs that processing.

For a limited set of data we determine the purposes of ourselves — your billing records, our security and audit logs, the record of your acceptance of our terms, and product analytics — we act as a controller. That processing is governed by our Privacy Policy, not by this DPA.

Under the CCPA, we act as a "service provider" with respect to Customer Personal Data. We do not sell it, do not share it for cross-context behavioral advertising, and do not retain, use, or disclose it for any purpose other than performing the Service — except as permitted by the CCPA.

3. Scope and duration

We process Customer Personal Data for as long as you use the Service, and afterwards only as described in section 10. The subject matter, nature, purposes, categories of data, and categories of data subjects are set out in Annex 1.

4. Processing on your instructions

We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, your configuration and use of the Service, and any further written instruction you give us.

If we believe an instruction breaches Data Protection Laws, we'll tell you. If we are required by law to process Customer Personal Data otherwise than on your instructions, we'll inform you first unless the law prohibits it.

5. Confidentiality

We limit access to Customer Personal Data to personnel who need it to provide the Service or to support you, and those people are bound by confidentiality obligations. We keep access under review and remove it when it is no longer needed.

6. Security

We implement appropriate technical and organizational measures to protect Customer Personal Data, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to data subjects. Those measures are described in Annex 2.

We may update our measures over time, provided we do not materially reduce the overall level of protection.

7. Subprocessors

You give us general authorization to engage subprocessors. Our current subprocessors are listed at invoeretail.com/subprocessors, which forms Annex 3 to this DPA.

Before a new subprocessor begins processing Customer Personal Data, we'll update that page and give you at least 30 days' noticeby email. You may object on reasonable data-protection grounds within that period. If you do, we'll work with you in good faith to find an alternative; if we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of any prepaid unused fees.

We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain responsible to you for their performance.

8. Data subject requests

The Service gives you direct access to Customer Personal Data — you can search, correct, export, and delete it yourself, which will usually let you answer a data subject request without involving us.

Where you can't, we'll provide reasonable assistance, at no charge for reasonable volumes. If a data subject contacts us directly about Customer Personal Data, we'll forward the request to you rather than answering it ourselves, unless you have told us otherwise.

We'll also give you reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, where required and where the assistance relates to our processing.

9. Personal data breaches

We'll notify you without undue delay, and in any case within 72 hours of confirming a personal data breach affecting Customer Personal Data. Our notification will describe what we know: the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, and the measures we have taken or propose to take.

Where we can't provide all of that at once, we'll provide it in phases as the investigation progresses. We'll cooperate with you and take the reasonable steps you direct to help you meet your own notification obligations.

10. Deletion and return

You can export all of your data from the Service at any time, in a standard format.

When your account is cancelled or the app is uninstalled, we revoke the store connection immediately, and you have 30 days to export. After that we delete Customer Personal Data. Deletion is permanent.

We may retain Customer Personal Data where Data Protection Laws require it, and we retain our own controller-role records — billing history, security and audit logs, and the record of your acceptance of our terms — as described in our Privacy Policy. Anything retained stays subject to this DPA.

11. Audits and information

On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, we'll provide the information reasonably necessary to demonstrate our compliance with this DPA.

We are a small company and do not currently hold a SOC 2 or ISO 27001 certification. We would rather say so than imply otherwise. In place of one, we'll answer a security questionnaire and provide our written security documentation. Where an on-site or third-party audit is genuinely required by Data Protection Laws, the parties will agree its reasonable scope, timing, and cost in advance.

12. International transfers

Customer Personal Data is processed in the United States.Our database and file storage run in Supabase's us-east-2region (Ohio) and our application runs on Vercel's US infrastructure. Some subprocessors process data in other regions, as noted on the subprocessors page.

Where we transfer Customer Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference, on this basis:

  • Module Two (controller to processor) applies, with you as data exporter and us as data importer.
  • Clause 7 (docking clause) does not apply. Clause 9 uses Option 2, general written authorization, with the notice period in section 7. Clause 11 does not include the independent dispute resolution option. Clause 17 selects the law of Ireland. Clause 18(b) selects the courts of Ireland.
  • Annex I, II and III of the SCCs are populated by Annex 1, Annex 2, and Annex 3 of this DPA respectively.
  • For UK transfers, the UK International Data Transfer Addendum applies to the SCCs, with the information in the Annexes above.
  • For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

If this DPA conflicts with the Terms of Service, this DPA governs the subject matter it covers. If this DPA conflicts with the SCCs, the SCCs govern.

14. Acceptance and countersigned copies

This DPA is incorporated into the Terms of Service and applies without further action when you accept those terms. No signature is required for it to be binding.

If your organization needs a countersigned copy, email support@invoeretail.com with the entity name and address to appear on it, and we'll return a signed PDF.

We may update this DPA to reflect changes in law, the Service, or our subprocessors. If a change materially reduces your protections, we'll give you advance notice.


Annex 1 — Details of processing

Subject matter and duration

Provision of the Invoe incoming-inventory service, for the duration of your subscription plus the retention periods in section 10.

Nature and purpose

Hosting, storage, and processing of purchase orders, vendor records, product and inventory data; automated parsing of documents you upload; drafting of product content; synchronizing products and inventory with your connected store; accounting export where you enable it; sending transactional email and, with consent, product email or SMS; providing support.

Categories of data subjects

  • Your personnel — owners, managers, buyers, and floor staff who use the Service
  • Your vendors' personnel, where their names or contact details appear in purchase orders, invoices, or vendor records you create

Not included: your shoppers. The permissions we request from Shopify do not include access to orders or customers, so end-customer personal data never reaches us.

Categories of personal data

  • Identity and contact data — name, email address, phone number where provided, role
  • Account and authentication data — hashed password, session and API key metadata
  • Business contact data appearing in vendor records and uploaded documents
  • Usage and technical data — activity logs, IP address, browser and device information
  • Communication preferences and consent records

Special category data

None. The Service is not designed to process special category data under GDPR Article 9, and you should not submit it.

Frequency

Continuous, for the duration of the subscription.

Annex 2 — Technical and organizational measures

Access control and tenant isolation

  • Row-level security on every database table, so an account can only reach its own data
  • Every API route authenticates its caller; an automated check fails the build if a new route does not
  • Role-based permissions within an account (owner, admin, member)
  • Scoped, expiring API keys for the browser extension, revocable by you at any time
  • Least-privilege third-party permissions — notably, no ability to modify your storefront's code or theme

Encryption

  • Encryption in transit (TLS/HTTPS) for all connections
  • Encryption at rest for the database and file storage
  • Store access tokens held server-side, restricted at the database level, never sent to a browser
  • Passwords stored only as salted hashes

Integrity and authenticity

  • Signature verification on every inbound webhook, using constant-time comparison
  • Signed, httpOnly session cookies
  • Uploaded files kept in private storage and served only via short-lived signed links
  • Defenses against server-side request forgery on any path that fetches a remote file

Monitoring, audit, and resilience

  • Append-only audit records for account activity, billing changes, and policy acceptance
  • Error monitoring with alerting
  • An automated security audit that runs weekly and on every relevant code change
  • A nightly check that the production database still refuses privileged operations to anonymous callers
  • Managed, backed-up database infrastructure with point-in-time recovery available from our hosting provider

Organizational measures

  • Access limited to personnel who need it, under confidentiality obligations
  • Code review before changes reach production, with automated checks that must pass
  • Documented security posture, reviewed on a schedule rather than on incident
  • Tenant deletion requires explicit human approval, so no automated process can erase an account's data unreviewed

Annex 3 — Subprocessors

The current list is maintained at invoeretail.com/subprocessors and forms part of this DPA. It records each provider, what it does, what data it can see, and where it processes that data.

Contact

Victoria Winter Consulting LLC (d/b/a Invoe)
1486 Indian St
Mount Pleasant, SC 29464
United States
support@invoeretail.com