Data Protection Policy

RedERP's GDPR compliance statement — legal bases for processing, your rights as a data subject, how to exercise them, international transfers, breach notification and our technical and organisational measures.

Official document:

This page reproduces the RedERP GDPR Compliance Statement, which serves as our Data Protection Policy. The authoritative version is published at cloud.rederp.pro/en/legal/gdpr. Last updated: January 2025. Read it alongside the Privacy Policy and the Terms of Service.

Red Digital Factory LLC and RedERP are committed to protecting the personal data of individuals in the European Union (EU) and European Economic Area (EEA) in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.

1. What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on 25 May 2018. It applies to:

  • Organisations established in the EU/EEA that process personal data
  • Organisations outside the EU/EEA that offer goods or services to EU/EEA residents
  • Organisations that monitor the behaviour of EU/EEA residents

As RedERP serves customers globally, including in the EU/EEA, we are committed to full GDPR compliance.

Under GDPR, we must have a lawful basis for processing your personal data. RedERP processes personal data on the following legal grounds:

2.1 Contract performance (Article 6(1)(b))

  • Providing RedERP services as outlined in our Terms of Service
  • Managing your account and subscription
  • Processing payments and billing
  • Delivering customer support

2.2 Legitimate interests (Article 6(1)(f))

  • Improving and developing our services
  • Ensuring network and information security
  • Preventing fraud and abuse
  • Analytics and performance monitoring
  • Direct marketing (where you have not opted out)

2.3 Consent (Article 6(1)(a))

  • Optional marketing communications
  • Non-essential cookies and tracking
  • Special category data (if applicable)

2.4 Legal obligation (Article 6(1)(c))

  • Tax and accounting regulations
  • Anti-money laundering laws
  • Court orders and legal requests
  • Regulatory requirements

3. Your rights under GDPR

RightWhat it means
Access (Art. 15)Confirm whether we process your personal data, access it and receive a copy, learn how and why we process it, and know its source if not collected directly from you.
Rectification (Art. 16)Request correction of inaccurate or incomplete data. Most information can be updated directly in your RedERP account settings.
Erasure (Art. 17)Request deletion when the data is no longer necessary, you withdraw consent and no other legal basis exists, you object and no overriding legitimate grounds exist, or the data was unlawfully processed.
Restriction (Art. 18)Request restriction while you contest accuracy, when processing is unlawful but you oppose erasure, when we no longer need the data but you need it for legal claims, or while an objection is being verified.
Portability (Art. 20)Receive your data in a structured, machine-readable format, transmit it to another controller, or request direct transmission where technically feasible.
Objection (Art. 21)Object to processing based on legitimate interests (including profiling), direct marketing, or scientific/historical research and statistics.
Automated decision-making (Art. 22)Not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. RedERP does not engage in automated decision-making that would trigger this right.

4. How to exercise your rights

4.1 Self-service

Many rights can be exercised directly in your RedERP account: access and update your personal information, export your business data, manage marketing preferences, and delete your account.

4.2 Contact our Data Protection Officer

For rights that cannot be exercised through self-service, or for complex requests, contact our Data Protection Officer at contact@rederp.org (website: cloud.rederp.pro). Include "GDPR" in the subject line; we respond within 30 days as required by GDPR.

4.3 Information to include

  • Your full name and the email address associated with your RedERP account
  • Specific details about your request
  • Proof of identity (if required for security purposes)
  • Any relevant dates or reference numbers

5. International data transfers

RedERP is operated by Red Digital Factory LLC (Qatar) and uses Microsoft Azure infrastructure, which may involve transfers of personal data outside the EU/EEA. We ensure adequate protection through:

  • Adequacy decisions — we prioritise data centres in countries with European Commission adequacy decisions where possible.
  • Standard Contractual Clauses (SCCs) — Microsoft Azure uses SCCs approved by the European Commission for international data transfers.
  • Additional safeguards — end-to-end encryption for data in transit and at rest, technical and organisational measures, regular compliance assessments and audits, binding corporate rules and data protection agreements.

6. Data breach notification

In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours, inform affected data subjects without undue delay, provide clear information about the nature of the breach, explain the likely consequences and measures taken, and describe steps you can take to mitigate potential harm.

7. Right to lodge a complaint

If you believe we have not handled your personal data in accordance with GDPR, you may lodge a complaint with the supervisory authority in your EU/EEA country of residence, in your place of work, or where the alleged infringement occurred. We encourage you to contact us first so we can address your concerns directly.

8. Our compliance measures

AreaMeasures
TechnicalEncryption of personal data in transit and at rest · pseudonymisation where appropriate · regular security testing and vulnerability assessments · access controls and authentication · automated backup and disaster recovery
OrganisationalAppointed Data Protection Officer · regular staff training · data protection policies and procedures · privacy by design and by default · regular compliance audits
DocumentationRecords of processing activities · data processing agreements with third parties · documentation of consent · logs of data subject requests and responses · evidence of compliance measures

9. Contact

Data Protection Officer — Red Digital Factory LLC Email: contact@rederp.org · Website: cloud.rederp.pro