Privacy policy

This Privacy and Data Usage Policy governs the processing of data by Salesorder in connection with our business-to-business (B2B) software-as-a-service platform.

1. Introduction & Scope

This Policy applies exclusively to corporate entities, business clients, and their authorized representatives (“Client”, “You”) using the Salesorder platform. Salesorder provides enterprise sales order management solutions on a strictly B2B basis. This policy does not apply to individual consumer relationships.

Under applicable data protection legislation, including the General Data Protection Regulation (GDPR):

  • Salesorder as Data Controller: We act as a Data Controller regarding Client account registration, administrative usage data, and billing details.
  • Salesorder as Data Processor: We act as a Data Processor regarding proprietary operational data, sales order records, and end-customer information uploaded or integrated into the platform by the Client.

2. Categories of Data Processed

We process data necessary to provide, secure, and maintain our enterprise platform:

  • Account & Billing Data: Corporate contact details (names, business email addresses, job titles, phone numbers), company name, registration numbers, billing address, and payment transaction details.
  • Operational & Order Data: Sales orders, product catalogs, customer transaction histories, supplier details, and related business data imported or generated through platform integrations.
  • Usage & Telemetry Data: IP addresses, browser types, log files, system interaction patterns, feature utilization metrics, and device diagnostics collected automatically during platform usage.

3. Purpose & Legal Basis of Processing

Salesorder processes corporate and personal data strictly under valid legal bases:

  • Contract Performance: Delivering platform functionality, fulfilling order management processes, processing payments, and providing dedicated customer support.
  • Legitimate Business Interests: Maintaining system integrity, detecting and preventing security risks or fraud, optimizing technical infrastructure, and generating aggregated statistical insights.
  • Legal Compliance: Complying with statutory accounting, tax, and legal obligations.
  • Aggregated & Anonymized Analytics: We may aggregate and anonymize operational metrics to train algorithms, improve user experience, and publish industry benchmarks. Aggregated data contains no identifiable personal or proprietary company information.

4. Data Ownership & Usage Rights

  • Client Data Ownership: The Client retains all right, title, and interest, including all intellectual property rights, in and to all proprietary operational and sales data uploaded to Salesorder.
  • Limited Processing License: The Client grants Salesorder a worldwide, non-exclusive, royalty-free license to host, copy, transmit, and display Client data solely as necessary to provide, secure, maintain, and improve the platform services.
  • No Commercialization: Salesorder does not sell, rent, or trade Client operational data or business contact lists to third parties for marketing purposes.

5. Sub-processors & Third-Party Disclosures

Salesorder engages vetted third-party vendors (Sub-processors) to deliver essential infrastructure and operational services:

  • Service Infrastructure: Cloud hosting providers, database infrastructure services, enterprise analytics providers, and payment gateways.
  • Sub-processor Vetting: All third-party providers undergo stringent technical and organizational security evaluations and are bound by data processing agreements ensuring equivalent protection standards.
  • Legal Disclosures: We disclose data only when legally required by valid court orders, regulatory inquiries, or compulsory legal processes.

6. Security Measures & Retention

  • Technical Security: Salesorder employs robust security protocols, including AES-256 encryption for data at rest, TLS 1.3 encryption for data in transit, multi-factor authentication, role-based access controls, and regular penetration testing.
  • Data Retention: Account and operational data are retained for the duration of the active subscription agreement.
  • Post-Termination Deletion: Upon agreement termination, Clients have thirty (30) days to export their operational data. Following this grace period, all Client data stored on active production servers is permanently deleted or anonymized, subject to statutory record-retention requirements.

7. International Data Transfers

Where data is transferred outside the European Economic Area (EEA), Salesorder ensures adequate protection through legally recognized transfer mechanisms, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Verification of adequacy decisions for recipient countries.
  • Supplementary technical and administrative safeguards to protect cross-border data flows.

8. Corporate Rights & Contact Information

Authorized corporate representatives may request access to, correction of, or deletion of their account administration data. Where Salesorder acts as a Data Processor on behalf of a Client, end-customer requests will be forwarded directly to the respective Client for handling.

For questions regarding this Policy or to submit data protection requests, contact our privacy officer:

  • Data Protection Team: Juhan Pukk CEO info@salesorder.eu
  • Address: Kotzebue 13a, Tallinn, Estonia.