This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Supligo Inc. (“Processor”) and the Customer (“Controller”). It applies where Supligo processes personal data on the Controller’s behalf.
This document is offered rather than required. A customer who needs a DPA — which is anyone with data subjects in the EU or the UK, and many who simply want one — asks for it, and it is recorded the same way as any other acceptance. Requiring it at signup would put a processor agreement in front of a restaurant supplier who has no use for one.
1. Which data this covers, and which it does not
Our role differs by data set, and stating that plainly is the point of this section.
- The Controller’s own staff data — names, emails, roles, sign-in records. Supligo is a controller of this, and the Privacy Policy governs it. This DPA does not apply to it.
- The Controller’s customer data — the contacts, addresses, orders, messages and delivery evidence a supplier records about the businesses they sell to. Here Supligo is a processor acting only on the Controller’s instructions. This is what the DPA covers.
2. Subject matter, duration, nature and purpose
Subject matter: providing the Supligo service. Duration: the term of the Terms of Service, plus the retention periods described there. Nature and purpose: hosting, storing, transmitting, structuring and displaying data so that the Controller can take orders, fulfil them, deliver them and invoice for them.
Categories of data subject: the Controller’s customers and their employees — the person who places an order, the person who accepts a delivery. Categories of personal data: names, business contact details, delivery addresses, the text of order messages, order and invoice history, delivery photographs, and the delivery location where the device provided one.
No special categories of personal data are intentionally processed. The Controller will not use free-text fields to record health, biometric, or other special category data.
3. Our obligations as processor
We will:
- process personal data only on the Controller’s documented instructions, of which the Terms of Service and ordinary use of the product are the standing instruction, unless required otherwise by law — in which case we will tell the Controller first, where it is lawful to;
- ensure everyone authorised to process the data is bound by confidentiality;
- implement the technical and organisational measures described in section 9 of the Privacy Policy;
- assist the Controller in responding to data subject requests, and in meeting its own obligations for security, breach notification and impact assessments;
- notify the Controller without undue delay after becoming aware of a personal data breach, with enough detail for the Controller to meet its own deadlines;
- at the Controller’s choice, delete or return the personal data at the end of the service, except where retention is required by law.
4. Sub-processors
The Controller gives general authorisation for the sub-processors below. We remain fully liable for their performance.
| Who | What they do | What they receive | Where |
|---|---|---|---|
| DigitalOcean, LLC | The server Supligo runs on — the database, the API, the web application and the background worker | Everything the product stores: supplier staff accounts, customer business contacts, addresses, order and invoice records, and the text of order messages. Also the HTTP request metadata of everyone who visits, including IP addresses. | Canada (Toronto) |
| Anthropic PBC | AI extraction — turning a customer’s order message into structured order lines | The text of the order message itself, which may contain the customer’s name, their business, quantities and any note they wrote. Nothing else: no price list, no account history, no contact database. | United States — outside Canada |
| Cloudflare, Inc. | Object storage (R2) for product photographs and delivery evidence | Product images uploaded by the supplier, and photographs taken by drivers at delivery — which may show a doorway, a loading bay, and goods left in place. | Automatic, with a Canadian jurisdiction restriction available on request — outside Canada |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Recipient email addresses and the contents of the messages Supligo sends on a supplier’s behalf: invitations, order confirmations, invoices and delivery notices. | United States (us-east-1) — outside Canada |
We will give 30 days’ notice before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, the Controller may terminate the affected part of the service without penalty.
5. International transfers
Personal data is processed outside Canada as set out in the table above. Where the GDPR or UK GDPR applies, transfers out of the EEA or the UK are made under the European Commission’s Standard Contractual Clauses (Module 2, controller to processor), together with the UK International Data Transfer Addendum where relevant, which are incorporated into this DPA by reference.
6. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a reasonable security questionnaire once in any twelve-month period.
We do not offer on-site audits as a matter of course, and we say so rather than agreeing to something we would then decline. Where an audit is required by law or by a supervisory authority, we will cooperate — on reasonable notice, during business hours, no more than once a year absent a breach, at the Controller’s cost, and subject to confidentiality.
7. Liability
Each party’s liability under this DPA is subject to the limitations in the Terms of Service. Nothing here limits a data subject’s rights, or either party’s liability to a supervisory authority.