Data Processing

Effective Date: July 7, 2026

This Data Processing Addendum ("DPA") summarizes how FonePaw Technology Limited ("IPMTrace," "Processor") processes personal data on behalf of customer organizations ("Customer," "Controller") in connection with the IPMTrace Service. This summary is intended to supplement, not replace, a fully executed DPA where required by applicable law.

This is a template for informational purposes. Consult with a qualified attorney for legal advice specific to your situation.

1. Roles of the Parties

  • Customer (Controller): determines the purposes and means of processing personal data submitted through the Service, including data about the Customer's employees (office users, field technicians) and any third-party individuals referenced in field notes, photos, or voice recordings (e.g., site contacts).
  • IPMTrace (Processor): processes personal data solely on behalf of, and per the documented instructions of, the Customer, to provide the Service — including work order management, field data capture, AI-assisted extraction, human review workflows, and export generation.

Where IPMTrace determines the means and purposes of processing account-level data needed to operate and secure the platform itself (e.g., billing, security logs), IPMTrace may act as an independent controller for that limited purpose, consistent with our Privacy Policy.

2. Categories of Data Subjects

  • Customer's office users and field technicians (employees/contractors of Customer).
  • Individuals referenced or incidentally captured within field notes, site photographs, or voice recordings (e.g., site occupants, property contacts).

3. Categories of Personal Data

  • Account/identity data: name, email, role, employer.
  • Authentication data: hashed passwords, OAuth identifiers, session tokens.
  • Field-captured content: text notes, photographs, voice recordings.
  • Derived data: AI-extracted structured treatment records (chemical/product, amount, unit, location).
  • Location data associated with jobs/work orders.
  • Usage and device/telemetry data.

4. Sub-processors

IPMTrace uses the following sub-processors to deliver the Service:

Sub-processorPurposeData Categories Involved
Google (Gemini / Google Cloud)AI-based extraction of structured treatment data from field notes, photos, and voice recordingsField notes, photos, voice recordings, derived treatment data
NeonManaged Postgres database hosting for structured application dataAccount data, work orders, treatment records
SupabaseObject storage for photos and voice recordingsPhotos, voice recordings, file metadata
VercelApplication hosting and infrastructureAll data transmitted through the Service (in transit/runtime)
ResendTransactional email delivery (e.g., account, notification emails)Name, email address, transactional content

Customer authorizes the use of these sub-processors. IPMTrace will provide notice of any new or replaced sub-processors and give Customer a reasonable opportunity to object, consistent with applicable law and any executed agreement. An up-to-date list is available upon request at support@ipmtrace.com.

5. Security Measures

IPMTrace maintains technical and organizational measures designed to protect personal data, including:

  • Encryption of data in transit (TLS).
  • Access controls and authentication safeguards (including OAuth-based login).
  • Role-based access separating office and technician permissions.
  • Logging and monitoring of system access.
  • Human-in-the-loop review requirements for sensitive AI-extracted fields prior to finalization.
  • Vendor security reliance on the infrastructure-level safeguards of Neon, Supabase, Vercel, and Google Cloud.

6. International Data Transfers

Sub-processors may process personal data in the United States and other countries outside the Customer's or data subjects' jurisdiction. Where such transfers involve personal data originating from the European Economic Area, United Kingdom, or Switzerland, IPMTrace relies on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum, incorporated by reference into the executed DPA.

7. Data Subject Request Handling

Where IPMTrace receives a request from a data subject relating to Customer Data (e.g., access, rectification, erasure, portability, or objection), IPMTrace will:

  • Promptly notify the Customer of the request, as Customer is typically the appropriate party to respond in its capacity as Controller.
  • Provide reasonable assistance to Customer in fulfilling data subject requests, including through account-level tools (e.g., data export in CSV/JSON, record deletion) and manual support where needed.
  • Not respond directly to the data subject unless required by law or instructed by Customer.

8. Personal Data Breach Notification

IPMTrace will notify Customer without undue delay upon becoming aware of a personal data breach affecting Customer Data, providing available information necessary for Customer to meet its own regulatory notification obligations (e.g., under GDPR Article 33).

9. Deletion and Return of Data

Upon termination of the Service or upon Customer's request, IPMTrace will, within a reasonable period, delete or return Customer Data, except where retention is required by applicable law or as otherwise agreed.

10. GDPR Compliance Summary

IPMTrace processes personal data as a Processor under Article 28 GDPR, and will:

  • Process personal data only on documented instructions from Customer.
  • Ensure personnel authorized to process personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational security measures under Article 32.
  • Engage sub-processors only under written agreements imposing equivalent data protection obligations.
  • Assist Customer with data protection impact assessments and data subject requests where reasonably required.
  • Make available information necessary to demonstrate compliance with this DPA and permit audits, subject to reasonable notice and confidentiality safeguards.

11. Governing Law

This DPA is governed by the laws of Hong Kong SAR, consistent with the governing law provisions of the underlying Terms of Service.

12. Contact

For DPA-related inquiries, data subject requests, or to request a fully executed DPA or Standard Contractual Clauses, contact: