This Privacy Notice explains how Ordinal AB, organization number 559363-4602 ("Ordinal", "we", or "us"), handles personal data in connection with Foga. Foga is a product of Ordinal AB.
It covers visitors, prospective customers, customers, account users, and business contacts. It also explains the important distinction between data for which Ordinal decides the purpose and data that a business customer controls.
1. Scope and roles
When Ordinal is controller
Ordinal is the controller when it decides why and how to handle account, billing, security, website, support, and business-contact data. This Notice mainly describes those activities.
When Ordinal is processor
A Foga customer decides which receipts, invoices, messages, files, bank transactions, and related personal data to import or upload ("Customer Content"), and why. For that data, the customer is normally controller and Ordinal is its processor. Ordinal processes Customer Content on the customer's instructions under the Data Processing Agreement. If you appear in Customer Content but are not a Foga user, contact the relevant customer first; we will assist it with your request.
Customer Content may include receipt and invoice images, filenames and metadata, message and attachment metadata, merchant and contact details, dates, amounts, currency, VAT or tax values, references, addresses, limited card identifiers, bank accounts and transactions, counterparties, extracted text and fields, matches, corrections, export records, and deletion or deduplication metadata. The customer determines the purpose and lawful basis for this content.
Other providers
Some providers determine their own purposes because of their service or legal role. In particular, Polar is merchant of record for checkout and Enable Banking is a regulated account-information provider. Their own notices apply alongside this one.
2. Data, purposes, and legal bases
We receive data from you, your organization, your use of Foga, providers you connect, and the service providers described below. Where GDPR applies, we rely on the legal bases shown here.
- Account and business-contact data: contact details, organization, role, and settings used to create accounts and manage the relationship. The basis is contract performance for a Customer and our legitimate interests in serving its users and contacts otherwise.
- Service, usage, and security data: authentication, device, request, feature, audit, error, and diagnostic information used to provide, secure, and improve Foga. The bases are contract performance, our legitimate interests in reliable and secure operation, and legal obligations where applicable.
- Subscription and transaction data: plan, entitlement, renewal, payment status, invoice, billing-contact, and provider reference information used for access, payment, accounting, fraud prevention, and disputes. The bases are contract performance, legal obligations, and legitimate interests in financial administration. Foga does not receive full card details.
- Support and correspondence: messages, contact details, and information you choose to send, used to answer requests and keep necessary support or legal records. The bases are steps toward or performance of a contract and our legitimate interests in support and legal claims.
- Website and preference data: session, security, and requested settings used to provide functionality, preserve choices, and protect sessions. The bases are contract performance and our legitimate interests in a functioning, secure service.
Section 6 states the applicable retention periods. We delete or minimize each category when it is no longer needed, subject to legal obligations and claims.
We do not make decisions that produce legal or similarly significant effects about people solely by automated means. Extraction and matching suggestions support a user's review; the customer decides how to use them.
An email address, authentication and security information, and the applicable business or billing details are required to create and operate a paid or trial account. Without them, we cannot provide Foga. Connecting a mailbox, cloud-storage account, or bank is optional, but the related import or matching feature cannot work without the data and permissions shown when it is connected.
3. Connections, bank data, and AI
Email and cloud sources
When a user connects a source, Foga receives the account identifier and the data within the permissions the user approves. Gmail access uses read-only mail and basic email identity permissions; Outlook uses read-only mail, basic user identity, and offline access; Dropbox uses basic account information and read-only file metadata and content. Foga then examines the configured import scope for likely business documents. The initial look-back is normally 30 days unless the product presents another choice.
Access tokens are encrypted and used only to provide the connection. A user can revoke access with the provider or disconnect in Foga. Revocation stops future retrieval after it takes effect but does not erase material already imported; that is deleted separately through Foga.
Foga's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We do not use connected-source data for advertising, sell it, use it to determine creditworthiness, or permit human access except with user permission for support/security, where required by law, or where appropriately aggregated and anonymized for internal operations.
Bank information
If a user connects a business bank account through Enable Banking, Foga may receive account names and identifiers, balances, transaction dates, amounts, descriptions, counterparties, and available history. The connection is read-only. Foga cannot initiate payments or move funds. Enable Banking and the user's bank separately process authentication and regulated account-access data under their own notices and terms. Disconnecting stops future bank retrieval; bank data already imported follows the Customer Content retention period unless the customer deletes it sooner.
Automated processing and matching
Foga sends relevant document files, images or text and processing instructions to OpenAI to extract suggested fields. Where enabled, TypeSafe's Jev service receives document text to assess relevance, and merchant details together with bank counterparty names, descriptions, references and remittance information to assess supplier identity for matching. Ordinal does not train a general-purpose model on Customer Content. Users must review automated results.
5. International transfers and security
Foga's primary Customer Content and account data are hosted in the European Union. Limited support, service delivery, email, and automated processing may occur in the United States, United Kingdom, other EEA countries, or other documented provider locations.
For restricted transfers from the EEA, we use an adequacy decision where available or safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. You may request information about the relevant mechanism from us.
We use organizational and technical measures designed for the risk, including access restrictions, data separation, encryption, monitoring, recovery, secure development, deletion controls, and incident response. No internet service is risk-free, so users must also protect their accounts, devices, and authentication methods. More detail appears in Terms Section 12.
6. Retention and deletion
We keep personal data only for the shortest period needed for the relevant purpose, including providing Foga, following customer instructions, maintaining security, meeting legal obligations, and resolving claims. The main operational periods are:
- Customer Content remains while the service is active. When trial or paid access ends, it is retained during the ordinary 30-day grace period for owner export and reactivation, then scheduled for deletion from active content stores. Ordinary document access and deletion are blocked during grace.
- A customer with active product access can delete selected documents sooner. Connected credentials are removed when the source is disconnected, the relevant workspace is deleted, or they are no longer needed, subject to short operational delay.
- Generated export files and links expire within 24 hours. A fresh export may be requested during an applicable retrieval period.
- Raw Polar webhook payloads and operational logs are kept for no more than 30 days. Logs are designed to avoid document content, access tokens, and unnecessary email addresses.
- Minimal billing and security audit records may be kept for up to 180 days, and pseudonymized proof that a content purge completed for up to 365 days.
- A minimal account and workspace shell may remain while the account stays open so the user can sign in, see status, and reactivate without restoring deleted content. Full account closure removes that shell, except records that law requires us to retain.
- Invoices, tax and transaction records, dispute records, and evidence of consent or legal notices are retained for the period required by applicable law or reasonably needed for legal claims.
Encrypted backup copies may remain isolated until overwritten through ordinary backup cycles. They are not returned to active use except for disaster recovery and remain subject to protection and deletion controls.
8. Your rights
Depending on the circumstances, GDPR gives you the right to request access, correction, deletion, restriction, and data portability; to object to processing based on legitimate interests; and to withdraw consent without affecting earlier processing. You may also complain to a supervisory authority. These rights can be limited where an exemption applies or where we must keep information by law.
For data Ordinal controls, contact us using Section 10. We may need to verify your identity and clarify the request. We ordinarily respond within one month and will tell you if a lawful extension is needed. For Customer Content, direct the request to the business that placed your data in Foga; Ordinal will assist that business as its processor.
Requests are normally free. We may charge a reasonable fee or refuse a request only where GDPR permits it, such as when a request is manifestly unfounded or excessive.
In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY). You can find complaint information at imy.se. You may instead contact the authority where you live or work, or where the alleged infringement occurred.
9. Business service, children, and changes
Foga is a business-only service and is not directed to children or offered for private, family, or household use. Users must be at least 18. If you believe a child has provided account data directly to Ordinal, contact us so we can investigate and remove it where appropriate. Personal data may still incidentally appear in Customer Content under the customer's control.
We may update this Notice when Foga, our providers, or legal requirements change. We will post the new version here and change the effective date. We will give account users advance email or in-product notice of a material change where appropriate.
10. Contact
Contact Ordinal with privacy questions or requests at:
Ordinal AB
Organization number: 559363-4602
VAT number: SE559363460201
Tullgårdsgatan 10, 116 68 Stockholm
Sweden
Email: info@ordinal.sh