How EPRlog collects, uses, and protects your information.
Controller: EPRlog, operated by the EPRlog entity named in your order form. For any request under this policy, contact [email protected].
Name, work email, organisation, role, and billing contact for the Customer and its authorised Users.
IP address, device and browser type, pages visited and time spent, and diagnostic identifiers used to keep the service secure and reliable.
We process personal data to perform our contract with the Customer, to meet our legal obligations, and on the basis of legitimate interests in operating and securing the service. Where required, we act as a Data Processor on the Customer's documented instructions.
We share data only with sub-processors that support the service (hosting, payment processing, error monitoring), each bound by written data-protection terms; where legally compelled; and in connection with a corporate transaction, subject to this policy. We never sell personal data.
Data may be processed outside your jurisdiction under appropriate safeguards (Standard Contractual Clauses or equivalent).
Operational compliance records are retained for the period the applicable regulation requires and for the term of the Customer agreement. Account data is deleted or returned on termination, save where retention is legally required.
Subject to applicable law (including GDPR and POPIA) you may access, correct, delete, port or object to the processing of your personal data. Contact [email protected]; we respond within the statutory period.
We apply industry-standard technical and organisational measures, including encryption in transit and at rest, least-privilege access, and continuous monitoring. No method of transmission is perfectly secure, but we notify affected parties of any qualifying breach without undue delay.
The service is for business use and is not directed to children under 16.
We may update this policy and will notify Customers of material changes by email or in-product notice.