Trade Counter
Data Processing Agreement
Version 1.1 · Effective 10 September 2026 · Between the merchant and Orumio
This Data Processing Agreement (“DPA”) governs our processing of personal data on your behalf when you install and use Trade Counter. It takes effect automatically when you install the app, and no signature is required for it to bind us. If your organisation requires a countersigned copy, or a copy on your own paper, write to support@orumio.com and we will provide one.
1. Parties and definitions
“Processor”, “we”, “us”: Orumio, represented by Masanori Iwata, Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan, contact support@orumio.com. “Controller”, “you”, “Merchant”: the operator of the system of record the App is connected to — a Shopify store, or a Zoho Inventory + Books organisation — and of the mailbox connected to it. “App”: Trade Counter. “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Data Protection Law” means every privacy or data protection law applicable to the Processing under this DPA, including the EU GDPR, the UK GDPR, Japan’s Act on the Protection of Personal Information (APPI) and the US state privacy laws addressed in Annex IV.
2. Roles and scope
You are the Controller of the Personal Data in your system of record and in the mailbox you connect. We are your Processor and process that Personal Data only to provide the App to you. Your system of record (Shopify, or Zoho) and your mailbox provider are independent parties to this DPA; your relationships with them are governed by your agreements with them. A workspace has exactly one system of record, fixed by the first connection. This DPA applies for as long as the App is installed and survives uninstallation for as long as we hold any of your Personal Data.
3. Instructions
We process Personal Data only on your documented instructions, including in respect of transfers to a third country. Your instructions are: (a) this DPA, including Annex I; (b) the App’s documented functionality, which you direct by installing it, connecting a mailbox, ratifying a policy (which classes of work may run, with what exposure caps and for which retailers) and by the resolutions your staff take on exceptions; and (c) any further written instruction you give us that we accept.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We will not process Personal Data for our own purposes — specifically not for marketing, advertising, profiling, resale or the training of machine-learning models — and we pass the same prohibition to the interpretation provider in Annex III. If we are required by law to process Personal Data beyond your instructions, we will inform you of that requirement before processing, unless the law forbids it on important grounds of public interest.
4. Confidentiality
The App is operated by a single person, who is bound by a duty of confidentiality in respect of all Personal Data processed under this DPA. There are no staff accounts, contractors or support agents with access to Merchant data. If that ever changes, any person authorised to process Personal Data will be placed under an equivalent obligation of confidentiality before access is granted.
5. Security
We implement and maintain the technical and organisational measures in Annex II, appropriate to the risk having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing. We may update those measures over time but will not reduce the overall level of security.
6. Sub-processors
You give us general written authorisation to engage sub-processors. Those engaged at the effective date are listed in Annex III. Before we add or replace one we will update Annex III and notify you by email at the address on file at least 30 days in advance. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection you may terminate by uninstalling the App, and we will delete your data in accordance with §10. We impose obligations on each sub-processor no less protective than those in this DPA and remain fully liable to you for its performance.
7. Assistance with data subject rights
Taking account of the nature of the Processing, we will assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests to access, rectify, erase, restrict, port or object. Where a Data Subject contacts us directly we will not respond substantively ourselves; we will refer them to you and tell you promptly. We honour Shopify’s mandatory compliance webhooks: customers/data_request (we provide you with the data we hold about the contact), customers/redact (we delete or anonymise it) and shop/redact (we delete your tenant, per §10). Zoho has no equivalent signal, so for a Zoho workspace the same three outcomes are reached by writing to us, and we perform them within 10 business days. We state that rather than describe an automatic mechanism we do not have.
8. Personal data breach
We will notify you of a Personal Data Breach affecting your Personal Data without undue delay after becoming aware of it, and in any event targeting within 72 hours of confirming it, describing so far as known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences and the measures taken or proposed. Where the information cannot be provided at once we will provide it in phases. We maintain a written security incident response policy covering detection, containment, assessment, notification, remediation and post-incident review, and we review it after every significant incident.
9. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a Supervisory Authority.
10. Deletion and return
- On uninstallation we immediately discard the stored Shopify credentials and stop every scheduled sync, so no further Processing of Shopify data can occur; a connected mailbox is disconnected and its credentials discarded at the same time.
- Disconnecting a Zoho organisation revokes our authorisation at Zoho, erases the stored tokens and stops every scheduled sync, so no further Processing of Zoho data can occur. Any draft the App had prepared and not yet released stays in your organisation and is yours; we tell you so before the disconnect, because after it we hold no credential that could remove it.
- On receipt of Shopify’s
shop/redactrequest (about 48 hours after uninstallation) we delete your tenant: records, mailbox messages and attachments, receipts, exceptions and logs. As a backstop against a lost webhook, any installation uninstalled for more than 30 days is deleted the same way. Zoho sends no such request and there is no 30-day backstop for it; a Zoho workspace’s equivalent deletion is performed on your written request, within 10 business days, and we hold the records only while the organisation is connected or you ask us to keep them. - Before then, you may request an export of your receipts and records in a machine-readable format, or earlier deletion, at any time by writing to the contact address.
- Operational logs and telemetry contain identifiers, classifications, counts and timings only and expire on the hosting provider's ordinary schedule; audit events are kept 90 days and job events 180 days.
11. Audits and information
We will make available to you all information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In the first instance we respond to a reasonable written request with our data posture document, our incident response policy and a written description of the measures in Annex II; an inspection may be requested where that is not sufficient, on reasonable notice, no more than once in any twelve-month period except following a Personal Data Breach, and subject to confidentiality.
12. International transfers
We are established in Japan; the App’s database and application servers are in the United States (Annex III). Where Personal Data protected by the EU GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and take precedence over it in the event of conflict. For those Clauses: you are the data exporter and we the data importer; the optional docking clause applies; the general authorisation for sub-processors in §6 applies with 30 days’ notice; the governing law is that of Ireland; disputes are resolved in the courts of Ireland; and Annexes I–III below serve as Annexes I–III to the Clauses. Where Personal Data protected by the UK GDPR is transferred, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated by reference, completed by Annexes I–III. Japan has received an adequacy decision from the European Commission, and the United Kingdom has made an equivalent finding.
13. Japan (APPI)
Where Japan’s Act on the Protection of Personal Information applies, we act as a party entrusted with the handling of personal data (委託先) under Article 27(5)(i), and you retain the supervisory obligation under Article 25. The measures in Annex II are the measures we take for that purpose, and §12 records the location of the servers for the purposes of Article 28.
14. General
This DPA prevails over any conflicting term of our other agreements with you to the extent of the conflict. If a provision is held invalid, the remainder stays in force. We may update this DPA to reflect changes in law or in the App with 30 days’ notice by email; continued use after the effective date of a change is acceptance of it.
Annex I — Particulars of the Processing
| Item | Description |
|---|---|
| Subject matter | Running the Merchant's wholesale (B2B) order desk from its email conversations and the records in its system of record — a Shopify store, or a Zoho Inventory + Books organisation |
| Nature and purpose | Reading the connected mailbox; interpreting retailer requests; matching them to the companies, locations, contacts, products and orders in the Merchant's system of record; preparing and, under the Merchant's ratified policy, performing quotes, availability answers, purchase orders and order-status answers; recording receipts and exceptions. On Zoho, obtaining an authoritative total requires creating a draft Estimate or Sales Order in the Merchant's organisation and deleting it again on every path that does not place the order — disclosed to and accepted by the Merchant at connection; the App never submits its own approvals and never causes Zoho to send email |
| Categories of Data Subjects | Staff of the Merchant's retail customers (buyers, accounts payable, receiving); the Merchant's own staff |
| Categories of Personal Data | Business contact data (name, business email, business phone, job title, role); company location shipping and billing addresses; order data (PO numbers, line items, prices, fulfilment and tracking); the content and headers of emails in the connected mailbox, including attachments |
| Special categories | None. Payment card data is never processed |
| Frequency | Continuous while connected: mailbox polling / push; on Shopify, webhooks and a 15-minute sync; on Zoho, an hourly sync and direct reads per request (Zoho sends no webhooks to the App) |
| Duration | For the term of the installation; deletion per §10 |
Annex II — Technical and organisational measures
- Encryption in transit — HTTPS only; TLS to your system of record, the database and the mailbox providers. Every Zoho call is made against the regional host that answered your authorisation and is re-derived from the stored data centre before use, so a request carrying our credentials cannot be aimed elsewhere.
- Encryption at rest — provider-managed AES-256 for the database and its backups; OAuth, Shopify and Zoho tokens additionally sealed with AES-256-GCM under a key held only in the hosting secret store and bound to their own row.
- Structural separation — the component that reads untrusted email text cannot write to your system of record or send mail; the components that act see only typed, verified facts. Replies go only to the authenticated sender; orders ship only to the recorded address of the resolved location; address, payment and contact changes are never automated.
- Hold before any write — every action is held for a cancel window and re-validated against live records before it runs; every write carries an idempotency key and is reconciled before it is made, so a retry never produces a second order or a second email. One write comes before that window and is named here because this sentence used to imply otherwise: on Zoho the desk creates a draft Estimate or Sales Order to read the organisation’s own authoritative total, and deletes it again before the receipt is issued. On Shopify the equivalent is a calculation and writes nothing.
- Bounded execution — per-job and per-retailer exposure caps, velocity limits and counterparty scope set and versioned by the Merchant.
- Environment separation — production runs on its own database project; development and tests use separate projects and development stores; no production data in development.
- Access control — production access limited to the operator, with multi-factor authentication on every provider account; role-based access (owner / admin / operator) inside the App; identity resolution fails closed.
- Logging — an audit log of every critical change visible to the Merchant; telemetry carries identifiers only, never names, addresses, subjects or bodies.
- Minimisation and retention — only the fields in Annex I; retention periods in the privacy policy; deletion per §10.
- Incident response — the written policy in §8; quarterly credential-rotation drills.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, runtime logs, and attachment files in a private store | United States |
| Neon Inc. | Managed Postgres database | United States |
| Anthropic PBC (via Vercel AI Gateway) | Interpretation of message text into structured claims; no training on inputs | United States |
| Google LLC | Gmail API access when the Merchant connects a Gmail mailbox | United States |
| Resend Inc. | Forwarding intake and notification email | United States |
| Inngest Inc. | Background job orchestration (identifiers only) | United States |
| Clerk Inc. | Authentication of the Merchant's staff | United States |
| Functional Software Inc. (Sentry) | Error reporting (identifiers only, server-side) | United States |
Not sub-processors. Your system of record — Shopify Inc., or Zoho Corporation Pvt. Ltd. for a Zoho Inventory + Books organisation — and your mailbox provider are your own platforms and independent parties to this DPA (§2). We do not engage them; you do, and Personal Data reaches them on your instruction and under your agreement with them. They are named here because a reader looking for them should find them, not because they are engaged by us. Your Zoho organisation stays in the Zoho data centre it is already in; we call only the regional host that answered your authorisation and hold no copy of your Estimates, Sales Orders, invoices, packages or shipments.
Annex IV — United States state privacy laws
To the extent the CCPA/CPRA or another US state privacy law applies, we are your service provider / processor. We will not sell or share Personal Data; will not retain, use or disclose it for any purpose other than providing the App; will not combine it with Personal Data from other sources except as permitted for a service provider; will notify you if we can no longer meet these obligations; and grant you the right to take reasonable steps to stop and remediate unauthorised use. We certify that we understand these restrictions.