Privacy Policy
Privacy Policy for ERPM
Version: July 2026
1. Controller
GMI GmbH
Theodor-Rehbock-Strasse 3
76131 Karlsruhe, Germany
Represented by its managing directors Shaur Gul and Sayed Hadi Mortazavi
E-mail: info@gmitso.de · Phone: +49 (0)721 15659119 · Web: www.gmitso.de
This privacy policy covers the ERPM application (Windows, macOS, iOS, Android), the ERPM cloud service including the web portal, and the product website.
2. Guiding principle: your data belongs to you
ERPM is order-management and ERP software. Without an online account, ERPM works entirely locally: all business data (customers, orders, items, suppliers, warehouse, accounting, receipts) stays exclusively on your device, stored encrypted (SQLCipher, AES-256). In that case no data is transmitted to us, apart from the optional services listed in section 7.
Data is only transferred to our server once you create an online account and enable cloud synchronisation.
3. Online account and cloud synchronisation
When you use the online account, we process:
- Account data: e-mail address, name, password (stored as a hash only), optional two-factor authentication settings.
- Tenant and licence data: tenant company name, booked plan, number of seats/devices, storage usage, term.
- Your tenant's business data: the data you enter in ERPM (e.g. customers, orders, invoices, items, receipts), insofar as synchronisation is enabled.
- Log data: login times, sessions, security-relevant events and business changes (audit log) for traceability and abuse prevention.
Purposes: providing the service, synchronisation between your devices, receipt storage, user and permission management, licence management and billing.
Legal bases: Art. 6(1)(b) GDPR (contract performance); for security logs Art. 6(1)(f) GDPR (legitimate interest in secure operation).
4. Roles and data processing on behalf
For our users' account data we are the controller within the meaning of the GDPR. For the business data entered in ERPM (e.g. data of your customers and suppliers), you as our customer are the controller; we process this data solely on your behalf as a processor (Art. 28 GDPR). A data processing agreement is available on request at info@gmitso.de.
5. Hosting
The ERPM server is operated in a data centre of Contabo GmbH (Aschauer Strasse 32a, 81549 Munich, Germany). The server is located in Germany; hosting does not involve transfers to third countries. A data processing agreement is in place with the provider.
6. Security
- Transport exclusively TLS-encrypted (HTTPS).
- The local database is encrypted with SQLCipher (AES-256).
- On the server, sensitive field contents and receipt files are additionally encrypted at rest (AES-256-GCM).
- Strict tenant isolation; access is role-based (including restricted customer and supplier accounts) and logged.
- Passwords are stored as salted hashes only; account lockout after repeated failed attempts; two-factor authentication (TOTP) available.
- Daily server backups; you can create local backups yourself at any time.
7. Recipients and third-party services
We only pass on data where necessary for contract performance. Data is never sold.
- Payments (Stripe): When you purchase a subscription or licence, payment is processed by Stripe Payments Europe, Ltd. (Ireland) or Stripe, Inc. (USA; certified under the EU-US Data Privacy Framework). Payment data (e.g. card details) is collected directly by Stripe and never reaches our servers; we receive payment status and subscription term from Stripe. Legal basis: Art. 6(1)(b) GDPR.
- E-mail delivery: System mails (e.g. password reset, invitations) and document e-mails from the app are sent via the configured SMTP provider. If you configure your own tenant SMTP, its provider is your own service provider.
- Push notifications (optional): If enabled, push messages are delivered via Firebase Cloud Messaging (Google Ireland Ltd. / Google LLC, USA; DPF-certified). A pseudonymous device token is stored for this purpose.
- Exchange rates: When using the foreign-currency feature, the app retrieves ECB reference rates from api.frankfurter.app. Only currency codes are transmitted, no personal data.
- App stores: When you obtain the app via the Apple App Store, Google Play or Microsoft Store, the store operators process data under their own responsibility and their own privacy policies.
8. Device identification and licensing
To enforce the licence's device limit, the app generates a pseudonymous device ID and derives a device code from it. When using an online account, the device ID, device name and time of last use are stored per tenant; registered devices can be viewed and removed in the app and portal. For device-bound offline licences, the device code becomes part of the signed licence file. Legal bases: Art. 6(1)(b) and (f) GDPR.
9. Diagnostics and crash reports
Crash and error reports (technical error message, app version, operating system, excerpt from the error log) and your feedback via "Report a problem" are only transmitted if the diagnostics feature is enabled; you can disable it at any time in Settings (Diagnostics & feedback). Legal basis: Art. 6(1)(a) GDPR (consent). The sole purpose is bug fixing and product improvement.
10. Web portal and website
The portal and website use no analytics, tracking or advertising services and no tracking cookies. Only technically necessary items are stored locally in your browser (session token, language, display settings). When accessed, the server processes the usual connection data (IP address, time, requested resource) in short-lived server logs for operational security (Art. 6(1)(f) GDPR).
11. Retention
Data is kept as long as your account or tenant exists. Deleting the tenant removes all associated server data; backups rotate automatically and are overwritten within a short period. Statutory retention obligations (up to 10 years under German commercial and tax law) may apply to invoice and accounting data; complying with them is your responsibility as controller of your business data. You delete local data on your devices yourself.
12. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent at any time with effect for the future. A full export of your tenant data is available in the app and portal at any time – even without a valid licence.
You also have the right to lodge a complaint with a data protection supervisory authority. Competent for us: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstrasse 20, 70173 Stuttgart, Germany.
13. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
14. Changes
We update this privacy policy when the feature set or legal situation changes. The current version is always available in the app (Legal), in the portal and on the product website.
15. Contact
Privacy questions: GMI GmbH, Theodor-Rehbock-Strasse 3, 76131 Karlsruhe, Germany · info@gmitso.de