Data Processing Addendum
Version 2026-08-14 · Effective August 14, 2026
This addendum forms part of the Terms of Service and applies whenever OhoSync processes personal data on your behalf. It is written to be read, not to be survived.
1. Who is who
You are the controller of the data in your shop and your supplier files. Monine AS, a company registered in Norway, operating OhoSync, is the processor: we act on your documented instructions, and using the service is that instruction.
For your own account details — your name, your email address, your login history — we are the controller, and the Privacy Policy governs them.
2. What we process, and what we deliberately do not
- Product and catalogue data from your supplier files: codes, titles, descriptions, prices, stock levels, image URLs, categories.
- Store credentials you issue to us, encrypted at rest, and revocable by you at any time from your own shop.
- Operational records: what each sync changed, what it refused and why, and errors returned by your shop.
- Account and access data: names, email addresses, hashed passwords, login times, and IP addresses used for rate limiting and the audit log.
OhoSync does not read, receive or store your customers' data. It does not touch orders, carts, checkouts, payment details or end consumers' names and addresses. Product data is not personal data in the ordinary case; where a supplier file happens to contain a person's details, it is processed only to place it in your shop as instructed.
The purpose is confined to providing the service: importing supplier files, applying your pricing rules, writing to your shop, and telling you what happened. The processing lasts as long as your account does.
3. Where it happens, and who else is involved
The service runs on servers in Helsinki, Finland (EU), including its database and backups. The full list of sub-processors, what each does and the country it processes in, is published in the Privacy Policy and is authoritative there so the two documents cannot drift apart.
We will name any new sub-processor there before it processes anything of yours. If you object to one, tell us: your remedy is to stop using the affected feature, or to terminate and have your data returned or deleted under section 6.
Two of the sub-processors are United States companies (Cloudflare for DNS, Google for analytics). Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Analytics runs only if a visitor accepts cookies; it processes website visitors, not your shop data.
4. Security
- Everything travels over TLS. Store credentials and API tokens are encrypted at rest with AES-256-GCM; the plaintext exists only in memory while a sync runs.
- Access to production is limited to the operator, and every operator action against a customer account — plan changes, suspension, impersonation, credit adjustments — is written to a permanent audit log.
- Passwords are stored as argon2id hashes. Two-factor authentication is available on accounts.
- Backups run nightly and are verified restorable; the restore is rehearsed rather than assumed.
- The service writes to your shop only through the credentials you issued, and only within the permissions you granted them.
5. Helping you meet your own obligations
If one of your customers or suppliers exercises a data-subject right and the data is in OhoSync, we will help you answer within the time the law gives you. Your account data can be exported in full at any time from your own settings, without asking us.
If we become aware of a personal-data breach affecting your data, we will tell you without undue delay and with what we know at the time — what happened, what data is involved, and what we are doing about it — rather than waiting until the picture is complete.
6. When you leave
Close your account and your personal data is deleted or anonymised within 30 days, except records we must keep for accounting or fraud prevention. Your product data in your own shop is untouched by this — it is yours and it stays where it is. Store credentials are destroyed immediately; you should also revoke them in your shop, which is the only step we cannot take for you.
7. Audits
On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a written audit questionnaire about the processing described here and provide evidence of the security measures in section 4.
8. Contact
Data protection questions, sub-processor objections and audit requests: hello@ovanap.no.