Data processing agreement
This agreement applies whenever we process personal data on your behalf, and forms part of the terms. You are the controller and we are the processor.
1. What is being processed
| Subject matter | Moving documents and warehouse events between your Business Central company and your Ongoing WMS goods owner, and posting them. |
| Duration | As long as you use Weave, plus the retention period below. |
| Nature and purpose | Reading, storing, mapping, sending and posting the data your two systems hold, and keeping a record of each request and answer. |
| Types of personal data | On sales orders sent to the warehouse and shipments read back: your customers' names, delivery addresses, email addresses and phone numbers, and order and return references. With warehouse events: the identifier of the warehouse operator who handled them. Names, email addresses and Microsoft account identifiers of your staff who sign in. If you connect Klaviyo: your customer's email address with the order event sent to your account. |
| Data subjects | Your customers, your employees who use Weave, and the warehouse's staff. |
| Special categories | None. Weave is not designed to receive them and you should not send them. |
2. How little of it there is
Worth stating plainly, because it shapes the risk. Weave works on articles, quantities, locations and document numbers, and no posting depends on who a person is. Delivery details travel on sales orders because the warehouse needs them to deliver, and Weave keeps them only for the retention period below.
3. Our obligations
- Only on your instructions. We process personal data only as needed to provide the service and as you instruct. If we think an instruction breaks data protection law we will say so.
- Confidentiality. Everyone we let near it is bound to confidentiality. Our staff who operate and support Weave can reach the data in the course of doing so, and nobody else.
- Security. The measures in section 8.
- Sub-processors. You give general authorisation for those listed on the sub-processors page. We give notice by email before adding or replacing one; you may object on reasonable data protection grounds, and if we cannot resolve it you may terminate the affected part of the service without penalty.
- Helping you. We will help you answer requests from data subjects, and help with impact assessments and consultations with the regulator, taking into account what we can see.
- Breaches. We will tell you without undue delay and in any case within 48 hours of becoming aware, with what we know and what we are doing.
- Deletion or return. On your request, or when the agreement ends, we delete or return the personal data, unless the law says we must keep it.
- Audits. We will give you the information you need to show compliance, and allow an audit on reasonable notice, no more than once a year unless a regulator or an incident requires it.
4. International transfers
Where a sub-processor is outside the EEA we rely on the European Commission's standard contractual clauses, together with any additional measures the transfer needs. The current location of every sub-processor is on the sub-processors page.
5. Retention
Weave keeps what it needs never to post twice and to explain recent work. Records it has finished with, including shipments with their delivery details and the audit log, are deleted once they are older than a retention period you set, 90 days by default and never under 30, as soon as you switch deletion on; until then they are kept while you use Weave. Sales history used to check old returns is kept up to three years from the sale, because a claim can be made that long after it.
6. Services you connect
If you connect Slack or Klaviyo, Weave sends that service what the integration needs (exception notices to your Slack channel, order events to your Klaviyo account) on your instruction. Those services act under your own agreement with them, and so do Microsoft for Business Central and the operator of your warehouse system.
7. What Weave never does with the data
It does not profile anyone, make automated decisions about anyone, advertise, or use the data to train models. It does not read email, files, calendars or contacts in your Microsoft tenant.
8. Security measures
- Encryption in transit, and credentials for the connected systems encrypted at rest with AES-256-GCM, the key held apart from the database.
- Sign-in through Microsoft work accounts. We hold no passwords, and signing in grants nothing until an administrator adds a person to a company.
- Every query restricted to one customer in the data-access layer, so one customer cannot reach another's data.
- An audit log of every request made to your systems and the answer received, with secrets redacted.
- Read-only clients for reading the warehouse, and every write through one fixed list of named operations.
- Nothing run by hand writes to a production connection without two separate confirmations.
- Managed infrastructure in Frankfurt, with the provider's backup and recovery.
9. Liability
The liability provisions in the terms apply to this agreement too.