FolioPO

Data Processing Agreement

Version September 8, 2026, revision 2 · Contact: [email protected]

Parties and instructions

This agreement is between the merchant accepting it in FolioPO and the operator of FolioPO, reachable at the contact above. The merchant determines the purposes of processing customer information. FolioPO processes that information on the merchant’s documented instructions to provide the app. Accepting this agreement and choosing to upload, review, export, delete or create a draft order are instructions. We will inform the merchant if we believe an instruction infringes applicable data protection requirements.

Scope

Processing includes receiving, storing, extracting, matching, displaying, exporting and deleting purchase-order information, and creating merchant-approved draft orders in Shopify. Information may include customer names, emails, phone numbers, delivery addresses, purchase-order references and order lines. Data subjects include the merchant’s customers and their business contacts. Processing lasts while the service is provided, subject to the deletion and backup periods below.

Merchant responsibilities

The merchant must have authority and an applicable legal basis to provide the data, inform affected people, manage authorized Shopify staff, and use only necessary information. Do not upload payment card numbers, government identification, health information or other sensitive information unrelated to a purchase order. Review extracted information before creating drafts.

Confidentiality and security

We restrict access to authorized personnel and service providers who need it for the service and are subject to confidentiality obligations. Our safeguards include Shopify authentication, shop-scoped access, application encryption of personal content and original files, encrypted backups, access records, download controls and an incident response procedure. Staff with operational access must use unique strong passwords and multi-factor authentication. Safeguards are reviewed when the service changes.

Service providers and locations

The merchant authorizes DigitalOcean for hosting and database services in the United States, GitHub Actions for private encrypted recovery backups and recovery automation on GitHub-hosted infrastructure that may process data in the United States, and Volcengine Ark (Doubao) for AI extraction and OCR through its China-region service. Document content is sent to Ark when AI extraction or OCR is used. Shopify receives the draft data that the merchant approves. We use these providers only for their stated service functions and remain responsible for our processing obligations. We will notify merchants through the app before adding a provider or materially changing processing locations, giving 30 days to raise a reasonable data protection objection or stop the affected processing.

This agreement does not itself create a statutory international-transfer mechanism. Where applicable law requires additional transfer terms or safeguards, those must be arranged before affected data is uploaded. Contact us before use if your data cannot be processed in the stated locations.

Requests and cooperation

We assist with access, correction, export and deletion using the app’s controls and verified support requests. If a customer contacts us, we direct them to the merchant unless instructed otherwise. We provide reasonable information about our processing and security controls for merchant assessments, and cooperate with required impact assessments and regulator requests. Review requests must protect other merchants’ information and credentials.

Incidents

We will notify the affected merchant without undue delay after becoming aware of a personal-data breach. Our operational target is an initial notice within 24 hours of confirmation, with available facts, affected information, likely consequences, mitigation and a contact. We provide updates as facts become available and preserve investigation records. The merchant remains responsible for its own legally required notifications.

Return, retention and deletion

Merchants can export their data and request deletion. Original files expire according to the selected retention settings. Extracted records remain until deleted or the shop is redacted. Operational audit history follows the plan’s retention; security access records expire after 90 days. Encrypted recovery backups expire within seven days and are used only for recovery. Deletion requests are reapplied before restored data is returned to service. Any legally required retention is limited to its required purpose and period. Drafts already created in Shopify remain under the merchant’s control.

Acceptance and changes

The app records the accepting shop, pseudonymous Shopify user identifier, time and agreement version. Material changes require renewed acceptance before further document uploads. This agreement governs customer-data processing where other service wording conflicts. Contact us for a copy or questions.

Privacy policy · Support