ERPM

Privacy Policy

Privacy Policy for ERPM

Version: July 2026

1. Controller

GMI GmbH

Theodor-Rehbock-Strasse 3

76131 Karlsruhe, Germany

Represented by its managing directors Shaur Gul and Sayed Hadi Mortazavi

E-mail: info@gmitso.de · Phone: +49 (0)721 15659119 · Web: www.gmitso.de

This privacy policy covers the ERPM application (Windows, macOS, iOS, Android), the ERPM cloud service including the web portal, and the product website.

2. Guiding principle: your data belongs to you

ERPM is order-management and ERP software. Without an online account, ERPM works entirely locally: all business data (customers, orders, items, suppliers, warehouse, accounting, receipts) stays exclusively on your device, stored encrypted (SQLCipher, AES-256). In that case no data is transmitted to us, apart from the optional services listed in section 7.

Data is only transferred to our server once you create an online account and enable cloud synchronisation.

3. Online account and cloud synchronisation

When you use the online account, we process:

Purposes: providing the service, synchronisation between your devices, receipt storage, user and permission management, licence management and billing.

Legal bases: Art. 6(1)(b) GDPR (contract performance); for security logs Art. 6(1)(f) GDPR (legitimate interest in secure operation).

4. Roles and data processing on behalf

For our users' account data we are the controller within the meaning of the GDPR. For the business data entered in ERPM (e.g. data of your customers and suppliers), you as our customer are the controller; we process this data solely on your behalf as a processor (Art. 28 GDPR). A data processing agreement is available on request at info@gmitso.de.

5. Hosting

The ERPM server is operated in a data centre of Contabo GmbH (Aschauer Strasse 32a, 81549 Munich, Germany). The server is located in Germany; hosting does not involve transfers to third countries. A data processing agreement is in place with the provider.

6. Security

7. Recipients and third-party services

We only pass on data where necessary for contract performance. Data is never sold.

8. Device identification and licensing

To enforce the licence's device limit, the app generates a pseudonymous device ID and derives a device code from it. When using an online account, the device ID, device name and time of last use are stored per tenant; registered devices can be viewed and removed in the app and portal. For device-bound offline licences, the device code becomes part of the signed licence file. Legal bases: Art. 6(1)(b) and (f) GDPR.

9. Diagnostics and crash reports

Crash and error reports (technical error message, app version, operating system, excerpt from the error log) and your feedback via "Report a problem" are only transmitted if the diagnostics feature is enabled; you can disable it at any time in Settings (Diagnostics & feedback). Legal basis: Art. 6(1)(a) GDPR (consent). The sole purpose is bug fixing and product improvement.

10. Web portal and website

The portal and website use no analytics, tracking or advertising services and no tracking cookies. Only technically necessary items are stored locally in your browser (session token, language, display settings). When accessed, the server processes the usual connection data (IP address, time, requested resource) in short-lived server logs for operational security (Art. 6(1)(f) GDPR).

11. Retention

Data is kept as long as your account or tenant exists. Deleting the tenant removes all associated server data; backups rotate automatically and are overwritten within a short period. Statutory retention obligations (up to 10 years under German commercial and tax law) may apply to invoice and accounting data; complying with them is your responsibility as controller of your business data. You delete local data on your devices yourself.

12. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent at any time with effect for the future. A full export of your tenant data is available in the app and portal at any time – even without a valid licence.

You also have the right to lodge a complaint with a data protection supervisory authority. Competent for us: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstrasse 20, 70173 Stuttgart, Germany.

13. No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

14. Changes

We update this privacy policy when the feature set or legal situation changes. The current version is always available in the app (Legal), in the portal and on the product website.

15. Contact

Privacy questions: GMI GmbH, Theodor-Rehbock-Strasse 3, 76131 Karlsruhe, Germany · info@gmitso.de