Legal

Privacy Policy

This page explains what data UPnGO EDI handles, why we handle it, how long we keep it, and the choices available to you and your trading partners. It is maintained by the UPnGO EDI team and is not an independent certification.

Last updated: 1 August 2026

1. Who we are

UPnGO EDI provides EDI automation and an operations console for Microsoft Dynamics 365 Finance & Supply Chain Management. For account data we act as controller. For the trade documents you and your partners exchange through the platform, we act as processor on your instructions.

2. Data we collect

  • Account data — name, work email, company name, assigned role and authentication metadata such as sign-in timestamps and provider (email/password or Google).
  • Trading-partner data — partner name, identifiers, connection type, document coverage and health status.
  • Document data — purchase orders and lines, acknowledgements, ASNs, delivery notes, proformas and invoices, together with X12/EDIFACT payloads and control numbers. These may contain business contact details of your staff or your partners' staff.
  • Operational data — transaction events, correlation IDs, retry and error records, console usage and diagnostic logs.

We do not seek special-category personal data and ask that you do not place it in document fields.

3. Why we process it

  • To provide the service: authenticate users, route documents and generate the document trail.
  • To notify suppliers by email when a purchase order is posted to them.
  • To secure the platform: abuse prevention, audit logging and incident investigation.
  • To support you: diagnosing failed documents and replaying them on request.
  • To meet legal, tax and accounting obligations.

Our lawful bases are performance of a contract, legitimate interests in operating and securing the service, and compliance with legal obligations. We do not sell personal data and do not use your document content to train models.

4. Access controls

Access is enforced in the data layer with row-level security. Buyers see the orders they raise, suppliers see the orders assigned to them, and administrators see their organisation's records. Role assignments are visible only to the user concerned and to administrators. EDI transaction logs are limited to administrator, operator and viewer roles.

5. Processors and integrations

We use a small number of subprocessors to run the service: cloud hosting and managed database/authentication infrastructure, an email delivery provider for supplier notifications, and Microsoft Azure services where you deploy the container into your own subscription. Google is involved only if a user chooses Google sign-in.

Where data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses. A current subprocessor list is available on request.

6. Retention and deletion

Document and transaction records are retained for the life of your subscription and for a default 90 days after termination unless your contract specifies otherwise, then deleted or irreversibly anonymised. Account records are deleted within 30 days of account closure. Backups age out on their own cycle.

7. Security

We use encrypted transport (TLS) for all traffic, encryption at rest for stored data, role-based access, least-privilege service credentials held in managed secret storage, and centralised logging. Container deployments support Azure managed identity, Key Vault and Log Analytics.

No platform is risk-free. If we become aware of a breach affecting your data, we will notify you without undue delay with the information available to us and our remediation steps.

8. Cookies

We use strictly necessary cookies and local storage for sign-in sessions and preferences. We do not use advertising cookies or cross-site tracking.

9. Your rights

Depending on where you are, you may request access, correction, deletion, restriction, portability or objection in relation to your personal data. If you are a user of a customer's tenant, contact that customer's administrator first; we will support them in responding. Email requests to info@upngoapp.com and we will respond within one month.

10. Changes and contact

We will update this page when our practices change and revise the date above. For privacy questions, data processing agreements, or to report a suspected vulnerability, contact info@upngoapp.com.