These Terms of Service ("Terms") are a binding agreement between Ordinal AB, organization number 559363-4602 ("Ordinal", "we", or "us"), and the business or professional customer using Foga ("Customer" or "you"). Foga is a product of Ordinal AB.
By creating an account, starting a trial, placing an order, or using Foga, you accept these Terms. If you act for an organization, you confirm that you may bind it. If you do not accept the Terms, do not use the Service.
The Data Processing Agreement and its schedules below form part of these Terms. Our Privacy Notice explains how Ordinal handles personal data in its own role. It is a notice, not a separate service agreement.
1. Agreement and business use
Business-to-business only
Foga is offered only for business and professional use. Customer must be a legal entity, or a natural person acting primarily for a trade, business, craft, or profession, including a sole trader. The Service is not offered for private, family, or household purposes.
By using Foga, you confirm that the account and purchase are for business or professional purposes. Private use is outside the agreed scope and is a breach of these Terms; the person choosing to use Foga privately is responsible for doing so outside that scope.
Ordinal does not require an organization number, routinely verify a user's legal status or purpose, or monitor accounts to determine whether use is private. Ordinal has no duty to investigate or police that question. A failure to verify, investigate, object, suspend, or enforce in a particular case does not change the business-only scope or waive these Terms.
No consumer withdrawal right, consumer warranty, or consumer dispute procedure is contractually granted. Nothing in these Terms excludes a right or remedy that applicable mandatory law does not permit the parties to exclude.
Contract documents
The agreement consists of these Terms and the plan, duration, price, usage limits, trial conditions, and other terms shown at checkout or in an order confirmation (the "Order"). The Order prevails only where it expressly varies these Terms. For processing of Customer Personal Data, the Data Processing Agreement prevails over conflicting general terms.
You must be at least 18, provide accurate account and billing information, and ensure that your users comply with the agreement. An account may be used only for the business or businesses that Customer is authorized to represent.
2. The Service
Foga helps businesses collect receipts, invoices, and similar documents; extract and organize document data; search and review records; connect read-only bank data; match documents with transactions; and export information for use in accounting workflows. Available features and limits depend on the Order.
Document sources
Customer may upload documents or connect supported services such as Gmail, Microsoft Outlook, and Dropbox. Foga retrieves only through the permissions and import scope presented in the Service. An initial look-back, ongoing synchronization, file criteria, and other source settings are shown or configured in the product. Customer can disconnect a source at any time.
Disconnecting stops future access after revocation takes effect, but does not automatically remove information already imported into Foga. Customer can delete imported information separately. The connected provider's terms and availability also apply to its service.
Automated processing
Foga uses OpenAI for document extraction and, where enabled, TypeSafe's Jev service for document relevance and supplier identity checks used in matching. Outputs are probabilistic and may be incomplete or wrong. Customer must review them before relying on or exporting them. Foga does not use Customer Data to train a general-purpose Ordinal model.
Bank connections
If Customer connects a bank, the connection is supplied by Enable Banking, a regulated account-information provider. It is read-only: Foga does not initiate payments, move or hold funds, or provide banking services. Customer must have authority over each connected business account and accept any terms presented by the bank or Enable Banking.
What Foga is not
Foga is workflow software, not an accountant, auditor, tax adviser, bank, statutory archive, or complete accounting system. It does not determine legal deductibility, VAT treatment, bookkeeping treatment, or compliance. Customer remains responsible for original records, required retention, review, accounting entries, filings, and professional advice.
3. Accounts and connections
Customer is responsible for its users, devices, email accounts, passkeys, one-time codes, and all activity under its account. Keep access secure, use reasonable security controls, and notify Ordinal promptly of suspected misuse. A passkey stores public credential information; Foga does not receive a fingerprint, face scan, or other device biometric.
Customer instructs Ordinal to access and process data from a connected service when Customer authorizes the connection and chooses an import. Customer confirms it has all rights, permissions, notices, and lawful bases needed to connect the account and process the selected information. Customer must not connect a private mailbox, storage account, or bank account for which it lacks business authority.
Third-party services may change, restrict, suspend, or stop their APIs. Ordinal is not responsible for a third-party service or for delay, loss, or failure caused by that provider, but will use reasonable efforts to explain a known material integration problem.
4. Customer Data and responsibilities
Ownership and permission
"Customer Data" means documents, messages, files, bank information, metadata, instructions, and other content submitted to or retrieved by Foga for Customer, together with extracted and matched data. Customer retains its rights in Customer Data. Customer gives Ordinal a limited, non-exclusive right to host, copy, transmit, transform, and otherwise process Customer Data only to provide, secure, support, and improve the Service as permitted by the agreement and Customer's instructions.
Ordinal may create statistics that are irreversibly anonymized and no longer identify Customer or any person, and may use those statistics to operate and improve Foga. Ordinal does not sell Customer Data or use it for advertising.
Customer responsibilities
Customer is responsible for:
- the lawfulness, accuracy, quality, and content of Customer Data and instructions;
- giving required privacy notices and obtaining required permissions from employees, suppliers, customers, and other people represented in the data;
- selecting appropriate sources, access rights, retention, exports, and deletion actions; and
- checking documents, extracted values, bank matches, and exports before using them for accounting or another business decision.
Foga is not designed for health data, biometric data, highly sensitive identity documents, or other special categories of personal data. Customer must not submit such data unless it is strictly necessary, lawful, and suitable for the Service and Customer has documented the required safeguards.
Acceptable use
Customer must not use Foga to break the law or another person's rights; access data without authority; distribute malicious code; interfere with security or availability; probe or bypass safeguards, limits, or metering; provide the Service to third parties as a competing or resold service; or reverse engineer it except where applicable law expressly permits that activity.
5. Plans and payment
Plans may be monthly or annual and may include a limited trial. The Order states the current price, billing cycle, included usage, trial requirements, and when charging begins. Usage categories are measured separately, reset as stated in the Order, and do not roll over unless the Order says otherwise.
Checkout and billing are provided by Polar, which acts as merchant of record and reseller for the transaction. Customer buys access through Polar, accepts Polar's checkout terms, and gives payment information to Polar or its payment provider—not to Foga. Ordinal receives subscription, entitlement, transaction, and invoice information, but not full card details.
A recurring subscription renews for the same billing period until cancelled. Customer can cancel renewal through the billing portal; cancellation takes effect at the end of the paid period unless the Order, Section 14, or mandatory law says otherwise. If a trial is configured to convert automatically, it converts on the date shown at checkout unless cancelled first.
Fees are payable in advance and are non-refundable except where the Order, Polar's applicable terms, or mandatory law requires otherwise. Polar determines and collects applicable sales taxes or VAT. Failed payment may restrict new processing while recovery is attempted. Ordinal may change future prices on at least 30 days' notice; a change applies no earlier than the next renewal after that notice.
Before submission, checkout presents the selected plan, billing period, price, applicable tax, and trial or renewal terms and allows Customer to correct entered information. Polar provides an electronic transaction confirmation. Customer can save these Terms and may request the version applicable to its Order from Ordinal.
6. Service, security, and intellectual property
Operation and changes
Ordinal will provide Foga with reasonable skill and care and use reasonable measures designed to protect Customer Data. Foga has no service-level agreement unless an Order expressly includes one. Maintenance, incidents, internet conditions, and third-party dependencies may cause downtime. Ordinal may change the Service, but will not materially reduce the core paid functionality during a current prepaid term without reasonable notice or an appropriate remedy.
Preview or beta features may be changed or withdrawn at any time and are provided for evaluation. Customer should not rely on them for production records.
Ordinal property
Ordinal and its licensors own Foga, its software, design, documentation, trademarks, and all related intellectual property, excluding Customer Data. During the agreement, Ordinal grants Customer a limited, revocable, non-transferable, non-exclusive right for its authorized users to use Foga for Customer's internal business purposes. No other right is granted.
Confidentiality
Each party must protect the other's non-public business, technical, and financial information with at least reasonable care and use it only for the agreement. This does not cover information lawfully known without a duty, independently developed, publicly available without breach, or lawfully received from another source. A party may disclose information where required by law after giving notice where legally permitted.
7. Suspension, termination, and exit
Customer may stop using Foga and cancel renewal at any time. Either party may terminate for a material breach that is not cured within 14 days after written notice, or immediately if cure is impossible, the other party becomes insolvent, or law requires termination.
Ordinal may suspend only the affected access or function where reasonably necessary for a security threat, unauthorized or unlawful use, non-payment, material breach, or legal requirement. Where practicable, Ordinal will give notice, explain the reason, and restore access when the issue is resolved.
Grace-period access and deletion
When paid or trial access ends, Foga ordinarily provides a 30-day grace period for export and reactivation. During that period, the workspace owner may export existing Customer Data and manage the subscription to restore access. Ordinary document viewing, individual downloads, and deletion are blocked, along with new imports, processing, matching, and bank synchronization. Ordinal may limit this access where law, security, or Customer's own deletion instruction requires it.
After the grace period, Customer Content is scheduled for deletion from active systems. Export artifacts expire after 24 hours for security, but a fresh artifact may be requested during the applicable retrieval period. Residual encrypted backups are overwritten through normal cycles. Limited account, billing, security, and deletion evidence may remain for legal, fraud-prevention, and audit purposes as described in the Privacy Notice.
Deleting particular documents and closing an entire account are separate actions. Customer should request full account closure if it also wants the remaining account and workspace shell removed, subject to legally required records.
Effect of termination
Payment obligations accrued before termination and terms that by nature should continue—including confidentiality, intellectual property, liability, dispute, and data deletion provisions—survive. Termination does not remove Customer's duty to retain its own legally required records.
8. Warranties and liability
Limited warranty
Ordinal warrants that the paid Service will perform materially as described when used as instructed. If it does not, Customer's primary remedy is for Ordinal to re-perform or correct the affected Service; if that is not reasonably possible, Customer may terminate the affected subscription and receive a proportionate refund of unused prepaid fees.
To the maximum extent permitted by law, Foga is otherwise provided "as available". Ordinal does not warrant uninterrupted or error-free access; perfect extraction, classification, matching, or export; preservation by a third-party source; or that an output is complete, compliant, or suitable for a particular accounting, tax, or legal purpose.
Liability limit
Neither party is liable for indirect or consequential loss, loss of profit, revenue, goodwill, anticipated savings, or business opportunity, or for business interruption, except to the extent such loss cannot lawfully be excluded. Ordinal is not liable for a result that Customer could reasonably have avoided by reviewing an output, keeping required source records, or following a notified security or export instruction.
Ordinal's total aggregate liability arising from the Service and agreement, including the Data Processing Agreement, will not exceed the fees paid or payable for Foga in the 12 months before the event giving rise to the first claim. For a claim arising solely during an unpaid trial, the cap is EUR 100.
The exclusions and cap do not apply to fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence, Customer's payment obligations, or any liability that applicable law does not permit a party to limit. They apply to the maximum extent permitted regardless of the legal basis of a claim.
Third-party claims
Customer will defend and indemnify Ordinal against a third-party claim to the extent caused by Customer Data, an instruction, or use that infringes that party's intellectual-property or privacy rights or violates law. Ordinal must promptly notify Customer, allow Customer to control the defense, and reasonably assist at Customer's cost. Customer may not settle a claim in a way that admits fault or imposes an obligation on Ordinal without consent.
If Foga itself is found or reasonably believed to infringe a third party's intellectual property, Ordinal may obtain continued use rights, modify or replace the affected feature, or terminate it and refund unused prepaid fees. This paragraph states Customer's exclusive remedy for that type of claim, except where law does not permit that limitation.
9. General terms
Ordinal may update these Terms for legal, security, product, or operational reasons. Material changes will be notified by email or in the Service at least 30 days before taking effect, unless urgent law or security needs require a shorter period. If a material change substantially harms Customer, Customer may cancel before it takes effect. The effective date at the top identifies the current version.
Notices may be sent to the account email or displayed in Foga. Customer must keep its contact details current. Neither party is responsible for delay caused by events beyond its reasonable control, excluding payment obligations. Customer may not assign the agreement without Ordinal's consent; Ordinal may assign it with its business or to an affiliate, provided Customer's rights are not materially reduced.
These Terms and the Order are the entire agreement about Foga and replace earlier proposals on the same subject. If a provision is unenforceable, it is adjusted only as needed and the rest remains effective. Delay in enforcement is not a waiver. The parties are independent contractors; no third party receives rights under the agreement.
Swedish law governs, without regard to conflict-of-law rules. The courts of Sweden have exclusive jurisdiction, with Stockholm District Court as the court of first instance. The English version controls if a translation differs.
10. Data Processing Agreement
This section and Sections 11–15 form the data processing agreement ("DPA") between Customer and Ordinal under Article 28 GDPR. It takes effect automatically when Ordinal processes personal data in Customer Data on Customer's behalf ("Customer Personal Data"). It remains effective for as long as that processing continues.
"Personal data", "processing", "controller", "processor", "personal-data breach", and related terms have the meanings given in GDPR. Nothing in this DPA limits a data subject's mandatory rights or a supervisory authority's powers.
Roles and law
Customer is controller of Customer Personal Data, or a processor that is authorized by the relevant controller to appoint Ordinal. Ordinal is Customer's processor or subprocessor. Each party will comply with the GDPR and other data-protection law applicable to its role.
Ordinal is a separate controller for account contacts, billing and supplier records, security administration, legal compliance, and its own business communications, as explained in the Privacy Notice. Those activities are not governed by this DPA.
Documented instructions
Customer instructs Ordinal to process Customer Personal Data to provide, secure, support, and delete Foga in accordance with these Terms, the Order, Customer's configuration and actions in the Service, and lawful written instructions consistent with the Service. Ordinal will process it only on those documented instructions, including for transfers, unless EU or Member State law requires processing. Where legally permitted, Ordinal will tell Customer before legally required processing.
Ordinal will promptly inform Customer if it believes an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. Customer is responsible for the lawfulness of its instructions, a valid legal basis, required notices, data accuracy and minimization, and responding as controller to data subjects.
Ordinal obligations
Ordinal will:
- ensure that people authorized to process Customer Personal Data are bound by confidentiality and receive appropriate privacy and security instructions;
- maintain the technical and organizational measures in Section 12, taking account of risk, technology, cost, scope, and the nature of the processing;
- assist Customer, taking account of the nature of processing and information available to Ordinal, with data-subject requests, security obligations, breach notifications, impact assessments, and prior consultations;
- notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide available information reasonably needed for Customer's assessment and notification;
- make information reasonably necessary to demonstrate compliance with Article 28 available to Customer; and
- at Customer's choice on termination, delete Customer Personal Data or make it available for return or export and then delete existing copies, as described in Sections 7 and 14, unless applicable law requires retention; and
- maintain records and cooperate with a competent supervisory authority to the extent required by law.
A breach notice will describe, as information becomes available, the nature of the breach, affected data and people, likely consequences, contact point, and measures taken or proposed. Information may be supplied in phases. Customer remains responsible for deciding and making its controller notifications.
Requests and audits
If Ordinal receives a request from a person concerning Customer Personal Data, it will direct the person to Customer unless law requires otherwise. Customer may use available product tools first; additional assistance that requires disproportionate work may be charged at a reasonable agreed rate unless the need results from Ordinal's breach.
Customer may audit compliance once per 12-month period, and additionally after a relevant breach or regulator request. Audits will normally begin with current certifications, summaries, and written responses. If reasonably necessary, an independent auditor bound by confidentiality may inspect relevant systems on at least 30 days' notice, during business hours, without accessing another customer's data or disrupting the Service. Customer bears its audit costs unless the audit finds material non-compliance by Ordinal.
11. Processing details
Scope and duration
To provide Foga, Ordinal receives, retrieves, records, organizes, extracts, classifies, compares, stores, displays, exports, restricts, and deletes business documents, transactions, and related information. This happens on demand or continuously when Customer uses the Service or a connected source. Processing lasts for the agreement, applicable retrieval periods, and limited backup or legal retention stated in these Terms and the Privacy Notice.
People and information
Data subjects may include Customer users and personnel, suppliers, merchants, customers, contractors, payers, payees, invoice recipients, and others appearing in Customer-selected documents, messages, files, or bank transactions. Data may include names, business and contact details, identifiers, metadata, document content, invoice and receipt fields, payment and bank information, extracted values, matches, notes, and audit events.
Foga does not require special-category, criminal-offence, national-identity, or similarly sensitive data. If it appears incidentally in Customer Content, Customer must minimize it and provide any required safeguards and instructions.
Customer control
Customer retains its controller rights and is responsible for instructions, legal bases, transparency, accuracy, minimization, retention choices, and handling data-subject rights.
12. Security measures
Ordinal maintains the following measures for Customer Personal Data. Measures may evolve with technology and risk, provided overall protection is not materially reduced.
- Defined security responsibilities, confidentiality duties, least-privilege access, access revocation, security awareness, vendor review, and incident procedures.
- Authentication and authorization controls, logical separation of customer data, restricted production access, and protection of secrets and connected-service credentials.
- Encryption in transit and at rest, with additional protection for credentials where appropriate.
- Secure development, review, testing, configuration, dependency, deployment, and environment controls proportionate to risk.
- Monitoring, limited security and operational logging, backups, restoration, and recovery measures designed for the Service's availability needs.
- Controlled export and deletion, backup expiry, and documented incident triage, containment, recovery, and legally required notification cooperation.
13. Subprocessors and transfers
General authorization
Customer gives general written authorization for Ordinal to use the subprocessors listed below. Ordinal will impose written data-protection obligations no less protective than this DPA and the same Article 28 obligations where applicable, and remains responsible for their processing to the extent required by GDPR. Ordinal will notify Customer's account contact at least 30 days before adding or replacing a subprocessor that may process Customer Personal Data.
Customer may object within that period on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the concern. If Ordinal cannot provide a commercially reasonable alternative, Customer may stop the affected feature or terminate the affected Service before the change takes effect and receive a proportionate refund of unused prepaid fees.
Current subprocessors
Supabase, Inc.
Core service infrastructure and account and Customer Content handling. Primary customer data is hosted in an EU region; support and approved providers may operate elsewhere.
Vercel Inc.
Application hosting, delivery, and security. Processing may occur in the EU, United States, and global delivery locations.
OpenAI
Automated document extraction using document files, images or text and processing instructions. International transfers are subject to the applicable data-processing terms.
TypeSafe AI, Inc.
Document relevance and supplier identity checks through Jev, where enabled, using document text, merchant details and bank counterparty names, descriptions, references and remittance information. The service is hosted in the United States.
API Hero Ltd, trading as Trigger.dev
Background task processing in the United Kingdom, EU, United States, and approved provider locations.
Plus Five Five, Inc., trading as Resend
Transactional and service email delivery in the United States, with selected EU delivery options where available.
Connected and independent providers
Google (Gmail), Microsoft (Outlook), and Dropbox provide services Customer chooses to connect and also act under their own terms. Enable Banking acts as an independent regulated provider for bank access. Polar acts as merchant of record for billing. These providers are not treated as Ordinal subprocessors for activities where Customer contracts or connects directly with them or they determine processing purposes required by their own legal role.
International transfers
Where Customer Personal Data is transferred outside the EEA to a country without an applicable adequacy decision, Ordinal will use the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with supplementary technical, contractual, and organizational measures where required. On request, Ordinal will provide relevant transfer information, subject to confidentiality and security restrictions.
14. Switching and data portability
Customer may switch from Foga to another service or its own systems and may request export by using available product tools or emailing Ordinal. Ordinal will provide reasonable assistance and maintain service continuity during the transition, subject to Customer's cooperation, security, technical feasibility, and the agreement.
Timing and charges
- Customer may give notice at any time. Any contractual notice period will not exceed two months.
- The standard transition period is no more than 30 calendar days after that notice period. If technically infeasible, Ordinal will explain why within 14 working days and identify an alternative period, which will not exceed seven months. Customer may extend the transition once by a period it considers appropriate.
- Customer will have at least 30 calendar days after the transition period to retrieve exportable data. For security, each generated artifact or download link may expire after 24 hours; Customer may request a fresh one during the retrieval period.
- Ordinal charges no switching or data-egress fee. Regular subscription fees remain due through the effective end date, and unused prepaid fees are handled under the Order and these Terms.
- At Customer's choice, the affected service will end when a switch completes, when the notice period ends if Customer requests deletion without switching, or on a later date agreed by the parties. Ordinal will confirm completion and contractual termination.
Exportable data
Exportable data includes Customer-uploaded and imported document originals; extracted document fields and status; user-entered corrections, notes, and classifications; available bank accounts and transaction data; document-to-transaction matches; and a manifest describing files and relationships. Exports are provided in original file formats plus structured, commonly used, machine-readable JSON manifests, packaged as independent TAR parts where needed.
Exports exclude Ordinal software and models; internal security, fraud, and diagnostic data; third-party secrets, OAuth tokens, credentials, cursors, provider-internal identifiers, signed URLs, and raw provider payloads; legally protected information; and data that cannot be exported without harming another person's rights or security. Ordinal will explain a material category-based exclusion on request.
After the retrieval period and successful switching, Ordinal will erase exportable Customer Data and notify Customer when deletion is complete, except for data that Customer asks Ordinal to retain, isolated backups awaiting expiry, and records that law requires Ordinal to keep.
15. Infrastructure and international access
Foga's primary Customer Data is hosted in the European Union. Limited service delivery, support, automated processing, and service email may involve the United States, United Kingdom, other EEA countries, and provider locations described in Section 13. Customer controls which external email, storage, and bank services it connects.
Ordinal uses the contractual, organizational, technical, and transfer measures described in Sections 12 and 13 to protect European data. Ordinal assesses legally binding governmental requests, seeks to narrow or challenge requests that appear unlawful or disproportionate, and notifies Customer where legally permitted. Ordinal does not voluntarily provide a third-country authority with direct access to Customer Data.
Current technical formats, known limitations, export procedures, and processing jurisdictions are stated in Sections 11–14. Customer may contact Ordinal for additional information reasonably required to assess switching, interoperability, or international-access risk.
16. Contact
Questions, legal notices, data-protection instructions, and switching requests may be sent to:
Ordinal AB
Organization number: 559363-4602
VAT number: SE559363460201
Tullgårdsgatan 10, 116 68 Stockholm
Sweden
Email: info@ordinal.sh