Universal privacy policy

Jilanov software platform privacy policy

This policy explains how personal and business data is handled across projects hosted and maintained by Jilanov.com. The page is public and can be used for Google Play, Apple App Store, OAuth reviews, and client portals.

Who operates the platform

Jilanov.com provides software, hosting, support, and integrations for business clients. For data stored in a specific client tenant, the client organization is usually the data controller and Jilanov.com acts as the technical service processor. When we process data for our own sales, support, or contracts, Jilanov.com is the controller for that data.

Systems covered by this policy

This policy covers projects and modules that link to privacy.jilanov.com:

  • ERP, CRM, BI, DMS, archive, storage, WMS, POS, and invoicing
  • webstores, B2B requests, service requests, and AI assistants when enabled for a specific client
  • public web pages, mobile apps, and client portals that link to this policy

Data we may process

  • profile data: name, email, phone, role, organization, and account preferences
  • security data: hashed password, sessions, IP addresses, audit logs, and access events
  • business records: customers, contacts, offers, orders, invoices, warehouse operations, tasks, documents, and reports
  • files and documents: uploaded files, versions, folders, metadata, permissions, and sharing history
  • ecommerce data: carts, orders, shipping, payment, promo codes, product interest, and service requests
  • communications: form submissions, chat, support correspondence, and service notes
  • technical data: browser/device information, language preference, telemetry, performance logs, and error logs
  • marketing and analytics identifiers such as UTM, gclid, gbraid, wbraid, fbclid, GA4/Meta events, only when enabled and, where required, after valid consent

How we use data

  • to provide the requested software service and support
  • to manage accounts, roles, permissions, and security
  • to process orders, requests, documents, invoices, payments, and shipping
  • to communicate with users and administrators about system operation
  • for diagnostics, abuse prevention, audit trails, and incident response
  • to improve the product when data is aggregated or lawfully processed
  • for marketing measurement and advertising attribution only when that module is enabled and a valid legal basis applies

Legal basis

Depending on the context, processing may rely on contract performance, legitimate interests, legal obligations, or consent. When analytics, advertising cookies, or ad tracking are used, consent controls apply according to the settings of the specific website or app.

Sharing with service providers

Data may be processed by infrastructure, email, backup, payment, courier, analytics, or advertising providers only to the extent needed for enabled functionality. Examples include hosting, SMTP providers, payment processors, courier integrations, Google Analytics/Google Ads, and Meta Pixel when configured. We do not sell personal data.

International transfers

Core infrastructure is operated in the EU or with providers that offer appropriate contractual and technical safeguards. When a client enables global providers such as Google or Meta, transfers outside the EEA may occur under those providers’ terms and safeguards.

Retention

Data is retained while needed for the service, contract, accounting or legal obligations, security, and audit trail purposes. Client tenant data can be deleted or exported at contract end according to the agreed terms. Backups expire under a separate retention schedule.

Security

  • TLS/HTTPS communication for public systems
  • password hashing and session protection
  • role-based access, tenant isolation, and audit logs
  • restricted administrative access
  • backups and operational recovery procedures
  • minimization of sensitive data in list, analytics, and export payloads

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability. For client tenant data, the request may need to be confirmed by the organization that controls the relevant project.

Children

The platform is intended for business use and is not directed to children. If you believe child data was submitted without a valid basis, contact us for review and deletion.

Contact

For privacy, access, or deletion questions, email [email protected].