Data Processing
Effective Date: July 7, 2026
This Data Processing Addendum ("DPA") summarizes how FonePaw Technology Limited ("IPMTrace," "Processor") processes personal data on behalf of customer organizations ("Customer," "Controller") in connection with the IPMTrace Service. This summary is intended to supplement, not replace, a fully executed DPA where required by applicable law.
This is a template for informational purposes. Consult with a qualified attorney for legal advice specific to your situation.
1. Roles of the Parties
- Customer (Controller): determines the purposes and means of processing personal data submitted through the Service, including data about the Customer's employees (office users, field technicians) and any third-party individuals referenced in field notes, photos, or voice recordings (e.g., site contacts).
- IPMTrace (Processor): processes personal data solely on behalf of, and per the documented instructions of, the Customer, to provide the Service — including work order management, field data capture, AI-assisted extraction, human review workflows, and export generation.
Where IPMTrace determines the means and purposes of processing account-level data needed to operate and secure the platform itself (e.g., billing, security logs), IPMTrace may act as an independent controller for that limited purpose, consistent with our Privacy Policy.
2. Categories of Data Subjects
- Customer's office users and field technicians (employees/contractors of Customer).
- Individuals referenced or incidentally captured within field notes, site photographs, or voice recordings (e.g., site occupants, property contacts).
3. Categories of Personal Data
- Account/identity data: name, email, role, employer.
- Authentication data: hashed passwords, OAuth identifiers, session tokens.
- Field-captured content: text notes, photographs, voice recordings.
- Derived data: AI-extracted structured treatment records (chemical/product, amount, unit, location).
- Location data associated with jobs/work orders.
- Usage and device/telemetry data.
4. Sub-processors
IPMTrace uses the following sub-processors to deliver the Service:
| Sub-processor | Purpose | Data Categories Involved |
|---|---|---|
| Google (Gemini / Google Cloud) | AI-based extraction of structured treatment data from field notes, photos, and voice recordings | Field notes, photos, voice recordings, derived treatment data |
| Neon | Managed Postgres database hosting for structured application data | Account data, work orders, treatment records |
| Supabase | Object storage for photos and voice recordings | Photos, voice recordings, file metadata |
| Vercel | Application hosting and infrastructure | All data transmitted through the Service (in transit/runtime) |
| Resend | Transactional email delivery (e.g., account, notification emails) | Name, email address, transactional content |
Customer authorizes the use of these sub-processors. IPMTrace will provide notice of any new or replaced sub-processors and give Customer a reasonable opportunity to object, consistent with applicable law and any executed agreement. An up-to-date list is available upon request at support@ipmtrace.com.
5. Security Measures
IPMTrace maintains technical and organizational measures designed to protect personal data, including:
- Encryption of data in transit (TLS).
- Access controls and authentication safeguards (including OAuth-based login).
- Role-based access separating office and technician permissions.
- Logging and monitoring of system access.
- Human-in-the-loop review requirements for sensitive AI-extracted fields prior to finalization.
- Vendor security reliance on the infrastructure-level safeguards of Neon, Supabase, Vercel, and Google Cloud.
6. International Data Transfers
Sub-processors may process personal data in the United States and other countries outside the Customer's or data subjects' jurisdiction. Where such transfers involve personal data originating from the European Economic Area, United Kingdom, or Switzerland, IPMTrace relies on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum, incorporated by reference into the executed DPA.
7. Data Subject Request Handling
Where IPMTrace receives a request from a data subject relating to Customer Data (e.g., access, rectification, erasure, portability, or objection), IPMTrace will:
- Promptly notify the Customer of the request, as Customer is typically the appropriate party to respond in its capacity as Controller.
- Provide reasonable assistance to Customer in fulfilling data subject requests, including through account-level tools (e.g., data export in CSV/JSON, record deletion) and manual support where needed.
- Not respond directly to the data subject unless required by law or instructed by Customer.
8. Personal Data Breach Notification
IPMTrace will notify Customer without undue delay upon becoming aware of a personal data breach affecting Customer Data, providing available information necessary for Customer to meet its own regulatory notification obligations (e.g., under GDPR Article 33).
9. Deletion and Return of Data
Upon termination of the Service or upon Customer's request, IPMTrace will, within a reasonable period, delete or return Customer Data, except where retention is required by applicable law or as otherwise agreed.
10. GDPR Compliance Summary
IPMTrace processes personal data as a Processor under Article 28 GDPR, and will:
- Process personal data only on documented instructions from Customer.
- Ensure personnel authorized to process personal data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures under Article 32.
- Engage sub-processors only under written agreements imposing equivalent data protection obligations.
- Assist Customer with data protection impact assessments and data subject requests where reasonably required.
- Make available information necessary to demonstrate compliance with this DPA and permit audits, subject to reasonable notice and confidentiality safeguards.
11. Governing Law
This DPA is governed by the laws of Hong Kong SAR, consistent with the governing law provisions of the underlying Terms of Service.
12. Contact
For DPA-related inquiries, data subject requests, or to request a fully executed DPA or Standard Contractual Clauses, contact:
- Data Protection Officer: support@ipmtrace.com
- General inquiries: support@ipmtrace.com
- Mailing address: Unit 908-909, 9/F Tower A, Billion Centre, 1 Wang Kwong Road, Kowloon Bay, Kowloon, Hong Kong
