Skip to content

Legal

Data processing agreement

Version 2026-09-27.61cbc031067e, last updated 27 September 2026

For the free beta. This hasn't had legal review. Venqaro Ltd is not yet incorporated: its company registration is pending, so company details are shown as pending. We'll tell you before anything here changes in a way that affects you.

This agreement is part of the terms of service. It applies when a business (“you”) uses Venqaro Shop to keep personal information about other people, such as its customers and their contacts. For that information you're the controller and Venqaro Ltd (company registration pending) (“we”) is your processor, as the UK GDPR and the Data Protection Act 2018 use those words. It's written to meet Article 28 of the UK GDPR. The person who creates your workspace accepts it for you, with the terms of service and the beta terms, and we record which version was accepted, by whom and when.

1. What we process, and why

We process personal data only to provide Venqaro Shop to you, as described in Annex 1, for as long as you use it and until it's deleted under section 8.

2. Your instructions

We process your data only on your documented instructions. Those are these terms, the way you set up and use Venqaro Shop (for example, sending a quote emails it to the address you choose), and anything else you ask us in writing that we agree to. If we think an instruction breaks data protection law, we'll tell you immediately. If the law requires us to process your data in another way, we'll tell you first unless the law forbids it.

3. Your responsibilities

You decide what personal data goes into Venqaro Shop and why. You're responsible for having a lawful basis for it, for telling your customers how you use their information (your own privacy notice), and for the lawfulness of your instructions. Venqaro Shop isn't designed for special category data (such as health information) or criminal records, so please don't put them in it.

4. Confidentiality

Everyone we allow to process your data is bound to keep it confidential.

5. Security

We keep appropriate technical and organisational measures in place to protect your data, as described in Annex 2, and keep them up to date.

6. Subprocessors

You authorise us to use the subprocessors on our subprocessor list. Before we add or replace one, we'll update the list and email your workspace's owners from tomoya@venqaro.co.uk, saying who the provider is, what it will do, where it will process data and the date the change takes effect, which will be at least 30 days after our email.

If you object, email tomoya@venqaro.co.uk before that date with your data protection reasons. We'll consider them with you and reply in writing before the change takes effect. The same providers run Venqaro Shop for every business that uses it, so one objection can't stop a change for everyone. If we can't resolve yours, you may stop using Venqaro Shop before the change takes effect: download your data and delete your workspace as section 8 describes.

Each subprocessor is bound by a written contract with the same data protection obligations as these terms, and we remain responsible to you for what they do.

7. Helping you

  • People's rights. Venqaro Shop lets you find, correct and download your records yourself, and delete some of them, such as contacts, draft quotes and invoices, and files that weren't sent as proofs. Customers can be archived, enquiries closed, and orders and jobs cancelled, but not deleted on their own. Sent quotes and proofs and the decisions on them, messages, issued invoices, payments, credit notes and the workspace's history are kept as they were sent or recorded while the workspace exists. If someone contacts us about information in your workspace, we'll pass the request to you without undue delay and help where we reasonably can. If you need something the app can't do, email tomoya@venqaro.co.uk and we'll agree with you in writing what we'll do.
  • Security incidents. If we become aware of a breach affecting your data, we'll tell you without undue delay, with what we know and what we're doing about it, so you can meet your own duties (such as telling the ICO within 72 hours where required).
  • Assessments. We'll give you the information you reasonably need for a data protection impact assessment or a consultation with the ICO about your use of Venqaro Shop.

8. When you stop

When you stop, you decide whether to take a copy of your data before it's deleted. Your workspace's owner does both in Venqaro Shop:

  • Download. Settings → Data gives a ZIP of the workspace's records as spreadsheets (CSV) and JSON, including customers and contacts, enquiries, quotes, orders, jobs, proofs, invoices, credit notes, payments and messages, the evidence of your customers' decisions, your price lists and settings, your team list and the workspace's history. Uploaded files such as artwork are listed in it but not included, and neither are PDFs of your quotes, invoices and credit notes: download any you need from the app. Passwords and secure links are never included.
  • Close. A closed workspace is kept for 30 days in case the owner changes their mind, then deleted. During those 30 days the owner can still download the ZIP from the closed workspace's page; to download files or PDFs, they reactivate the workspace first.
  • Delete straight away. The owner can instead delete the workspace at once. From then on (as at the end of the 30 days) it can't be reactivated or downloaded.

Deleting a workspace removes its records from our database and its files from our storage, and we don't keep a copy unless the law requires it. Copies in our backups can't be removed one workspace at a time: they're kept secure, aren't used or restored except to recover the service after a failure, and are deleted when they're 30 days old (for a deleted file, 30 days from the next nightly copy). Before deleting a workspace we record its internal identifier and the time, nothing about what was in it, so that if we ever restore a backup, we delete it again, its records and its files, before anyone can use the service. We'll set up the backups and test that restore with hosting (Annex 2). If we end the service, or your use of it, we'll give you notice as section 10 of the terms describes, so you can download your data first.

9. Showing we keep to this

We'll make available all the information you need to show that we meet these terms, starting with written answers and documents. We'll also allow for and contribute to audits, including inspections, by you or an auditor you appoint, with reasonable notice and under confidentiality, each side meeting its own costs.

10. Transfers outside the UK

Your instructions (section 2) include the transfers needed to use the subprocessors you've authorised under section 6. Otherwise we'll only transfer your data outside the UK if you ask us to in writing, or if the law requires it (section 2 says what we'll tell you then).

A provider keeping data in the UK or the EU doesn't settle the question on its own: letting someone outside the UK reach the data, such as a provider's support staff or parent company abroad, can be a transfer too. Before we use a provider, we'll check where it processes and accesses data, and put in place a safeguard UK law allows for any transfer: UK adequacy regulations (including the UK–US “data bridge”, for US companies that have signed up to it), or the UK International Data Transfer Agreement or Addendum, with a transfer risk assessment. The subprocessor list will show each provider's locations and safeguard. They're still to be confirmed: the list shows the providers we plan to use, and none of them holds any customer data yet.

11. Where we decide

For a few things we're a controller in our own right, not your processor, and our privacy notice covers them:

  • the accounts of everyone who signs in, including your team: their names, email addresses and passwords (stored only as hashes), and their sign-in and security records, such as sessions, the recognised-device cookie and keyed hashes of IP addresses used to stop abuse;
  • the record of emails the service sends (who to, when and whether they were delivered), which we keep to run and support the service;
  • counts and service statistics that don't identify your customers;
  • support conversations and feedback you send us.

What your team does inside your workspace, such as who sent a quote or moved a job, is recorded in the workspace's history. That history is part of your records, and we process it for you under this agreement.

We don't use your records for anything else, such as marketing, selling or training models. We only look at them if you ask us to (for example, by inviting us as a read-only member to help with a problem), if we need to in order to keep the service running or put a fault right (for example, restoring a backup), or if the law requires it.

Annex 1: the processing

  • Subject matter and nature: hosting, storing, organising, displaying, emailing and deleting your business records in Venqaro Shop.
  • Purpose: providing Venqaro Shop to you: managing enquiries, customers, quotes, orders, production jobs, artwork approval, invoices and payments, and letting your customers view and respond to what you send them.
  • Duration: while you use Venqaro Shop, and until deletion under section 8.
  • People concerned: your customers and their contacts, people who send you enquiries, and your own team.
  • Personal data: names, job titles, email addresses, phone numbers, postal and delivery addresses, and business details; what they asked for, ordered and paid; messages, notes and files (such as artwork and site photos); for your team, their names, email addresses and roles in the workspace, and the history of what they do in it; and, when your customers accept or decline a quote, or approve or ask for changes to artwork, from a link, the name they type, their email if they give it, any note, the time, their IP address and browser details, as evidence of the decision.

Annex 2: security measures

In Venqaro Shop now, and checked by its automated tests on our own test systems:

  • Each workspace's records are separated by row-level security in the database, which the app's own database login can't bypass.
  • The site sends strict security headers and doesn't load scripts from other companies.
  • Passwords are hashed with scrypt; session, invitation and link tokens are stored only as hashes.
  • Sign-in, sign-up, password reset, public forms and customer links are rate-limited.
  • Uploaded files are private and served only to people with access, through short-lived links. Each new file is held until the virus scanner has checked it: files found infected are deleted, files it can't check are blocked, and while the scanner can't be reached, files wait.
  • Issued invoices, payments, credit notes and the history of a workspace can't be edited after the fact: a mistake is put right with a credit note or by voiding a payment, which is recorded too.
  • People who run the service have no in-app access to your records.
  • A deleted workspace is recorded, by its internal identifier and the time only, before anything is deleted. After a restore from a backup, the service stays closed until every recorded deletion has been applied again and checked.

Set up with hosting, and checked there before we hold any of your data:

  • HTTPS for every connection.
  • The virus scanner itself (ClamAV), as our tests use a stand-in. It looks for known malware only, and parts of a very large or deeply nested file beyond its limits aren't examined. No scanner catches everything.
  • Private file storage, and access to the servers, database, file storage and backups limited to the people who run the service and used only as section 11 describes.
  • Backups, used only to recover the service: encrypted, open only to the people who run it, and kept for 30 days on a rolling basis. A restore rehearsed on the real hosting, including re-applying deletions before the service reopens.

Annex 3: subprocessors

See the subprocessor list.