Last updated: August 8, 2026
At ERPLORA CLOUD S.L. we take the protection of your personal data seriously. This policy explains what data we collect, why, and what rights you have, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018, on the Protection of Personal Data and guarantee of digital rights (LOPD-GDD).
1. Data Controller
ERPLORA CLOUD S.L. — CIF B27593136
Avda Lisboa 17, Pta. C, 28822 Coslada (Madrid), España.
Data protection contact:
privacy@erplora.com
2. Data we process
- Account data: name, email, password (hashed), language, time zone, interface preferences.
- Billing data: customer's company name, tax ID (NIF/CIF), fiscal address, payment method (managed by Stripe — ERPlora does NOT store card numbers), payment history.
- ERP/POS operational data: data entered by the customer in their Hub (end customers, products, sales, employees, calendar, etc.). In this case ERPlora acts as data PROCESSOR; the CONTROLLER is the customer operating the Hub.
- Technical usage data: IP address, session identifier, access logs, error logs, service usage metrics.
- Cookies: see the Cookie Policy.
3. Purposes and legal basis
- Provision of the contracted SaaS service: performance of a contract (Art. 6.1.b GDPR).
- Invoicing and compliance with tax obligations: legal obligation (Art. 6.1.c GDPR; Commercial Code, General Tax Law).
- Technical support to the customer: performance of a contract (Art. 6.1.b GDPR).
- Commercial communications about similar products: legitimate interest (Art. 6.1.f GDPR) with the right to object at any time.
- Marketing communications outside the above scope: explicit consent (Art. 6.1.a GDPR).
- Platform security and fraud prevention: legitimate interest (Art. 6.1.f GDPR).
4. Retention periods
- Account and operational data: for the duration of the contractual relationship and, after its termination, for 6 years to comply with accounting and tax legal obligations (Commercial Code art. 30; General Tax Law art. 66), unless erasure is requested beforehand.
- Billing data: 6 years from the last entry (art. 30 Commercial Code).
- Marketing data: until consent is withdrawn.
- Technical logs: 12 months for security investigation purposes.
5. Recipients — Data processors
To provide the service, we engage the following PROCESSORS, with whom we have signed Art. 28 GDPR agreements:
- Hetzner Online GmbH (Germany): hosting, database, backups, storage, and observability. Data hosted in European Union data centers.
- Amazon Web Services EMEA SARL (Ireland): alternative cloud infrastructure provider (fallback, currently inactive). Data hosted in European Union data centers.
- Stripe Payments Europe Ltd. (Irish): payment processing. Does NOT receive the customer's ERP data, only billing data.
- Cloudflare Inc. (USA): CDN, DNS protection, and anti-DDoS. HTTP traffic transit; EU-approved standard contractual clauses.
- Alibaba (Netherlands) B.V. (Netherlands) — Alibaba Cloud Model Studio, Germany (Frankfurt) region: provider of the language model the AI assistant uses BY DEFAULT. Processing takes place in the European Union. Used ONLY when the customer enables this feature and after explicit consent in the Hub, under a Data Processing Addendum incorporating EU Standard Contractual Clauses.
- OpenAI Ireland Ltd. and Anthropic Ireland Ltd. (Ireland): BACKUP language model providers, used only if the European provider is unavailable. Each one under its own DPA.
What the AI assistant does — and does not — receive
- The assistant is OPTIONAL. If the customer does not enable it, no data whatsoever is sent to a language model provider.
- Your hub database is never replicated or copied, neither to ERPlora nor to the model provider. The model holds no standing access to it and cannot query it on its own.
- The model receives only your message, any document you attach to it, and the result of the specific query each question requires. If you ask about today's sales, your hub runs that query locally and hands over only that result — there is no dump of your catalogue, your sales history or your customer file.
- We do not store the content of the conversation: the platform acts as a stateless gateway between your hub and the provider. We only record a message counter and token consumption, for billing.
- None of these providers uses the data to train their models, under the API terms of service applicable to us.
6. International transfers
The AI assistant is served from Alibaba Cloud Model Studio's Germany (Frankfurt) region, on a workspace whose deployment scope is restricted to the European Union: queries are processed inside the EU and are NOT transferred to China.
Some processors may process data outside the EEA: Cloudflare (USA), for HTTP traffic transit, and the backup model providers, only if the European one is unavailable. These transfers are carried out under Standard Contractual Clauses (SCCs) approved by the European Commission (EU Decision 2021/914) or, when possible, by keeping the data within the EU through regional configuration. The customer may request a copy of the SCCs at privacy@erplora.com.
7. Your rights
You have the right to:
- Access your data (Art. 15 GDPR)
- Rectify them if inaccurate (Art. 16)
- Erase them when no longer necessary (Art. 17)
- Restrict their processing (Art. 18)
- Port them to another controller in a structured format (Art. 20)
- Object to processing based on legitimate interest or marketing (Art. 21)
- Withdraw consent without retroactive effect (Art. 7.3)
To exercise these rights: privacy@erplora.com attaching a copy of your ID/NIE. You have the right to file a complaint with the Spanish Data Protection Agency (AEPD) if you believe your right has not been honored.
8. Source of data
You provide the data directly when registering and using the service. We do not obtain personal data from third parties, except for technical data generated by your browser and device when interacting with the platform.
9. Automated decisions
We do not make automated decisions with legal effects on users. The Hub's AI assistant is a productivity tool under the customer's control; no action is executed without human confirmation when it affects critical data.
10. Maintenance and updating of the system
ERPlora keeps and updates the software that processes the data on its own initiative, without the customer having to request it. This forms part of the service the customer contracts and is one of the security measures required by article 32 of the GDPR, in particular the ongoing integrity, availability, and resilience of the processing systems and the regular evaluation of the measures in place.
An update replaces the software, not the data: it does not change the purposes of the processing, the categories of data, the retention periods, or the recipients, and no data is copied outside the customer's Hub in order to carry it out.
For that reason an update is not a change of sub-processor and does not open the right to object provided for in article 28.2 of the GDPR. That right is unaffected for the processors listed in section 5: any addition or replacement among them is notified in advance, and the customer may object.
The terms on which ERPlora updates the service, and what it undertakes in return, are set out in section 7 of the Terms of Use.
11. Changes
This policy may be updated. Material changes will be notified at least 30 days in advance by email to the registered account and/or through a prominent notice in the dashboard.