Legal · v2026-07-29
Privacy Policy
How we process personal data under GDPR and related laws.
Last updated 29 July 2026
1. Who we are
Ecosys360 (“we”, “us”, “our”) operates Ecosys360 Retail & Ops Suite (the “Service”), a multi-tenant business platform for retail and operations — including point of sale, catalog, inventory, accounting, HR, payroll, logistics, ecommerce, and related modules.
For personal data relating to platform accounts, authentication, billing administration, security logs, and support communications, we act as a data controller under the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable privacy laws.
Privacy and data-protection contact: app.flakescapital@gmail.com. We aim to respond to valid requests within 30 days (or sooner where local law requires).
2. Scope of this notice
This Privacy Policy explains how we process personal data when you visit our marketing or product sites, create an account, join a workspace (tenant), use the Service as a staff user, or contact us for support.
It does not replace your organisation’s own privacy notices to its customers, employees, or suppliers. When your organisation stores those records in Ecosys360, your organisation is usually the controller of that data and we act as a processor — see section 4 and our Data Processing Addendum.
3. Personal data we process as controller
Depending on how you interact with Ecosys360, we may process categories such as:
- Identity and contact data — full name, email address, phone number, organisation or trading name, job title or role labels you provide
- Account and authentication data — hashed passwords, session tokens, multi-factor or recovery signals if enabled, roles, memberships, preferences, and profile fields
- Workspace / tenant metadata — tenant slug, display name, enabled modules, branch and location labels, approval status, and billing or subscription state
- Usage and technical data — IP address, approximate location derived from IP, device and browser type, referrer, request timestamps, error and security logs, rate-limit signals
- Trial-abuse prevention signals — a long-lived first-party device cookie, a hashed browser fingerprint, hashed phone/email/business identifiers, and payment-provider references (M-Pesa MSISDN / Paystack customer or authorization codes). We store keyed hashes and short operational hints (for example last-4 of a phone or an email domain), not raw card PAN/CVV or full fingerprint components
- Communications — emails, in-app messages, and support tickets you send to us, including metadata needed to respond
- Payment and commercial data — plan selection, invoices, payment references, provider transaction IDs, and status updates from payment processors (we do not store full card PAN or CVV)
- Legal acceptance records — timestamps and version identifiers when you accept Terms, Privacy, Cookies, and the DPA
4. Tenant business data (our processor role)
When your organisation uses Ecosys360 to store operational records — for example POS customers, sales, inventory, employees, payroll inputs, suppliers, ecommerce shoppers, or uploaded files — your organisation is typically the controller of that personal data. We process it on your documented instructions as a processor, as set out in the Data Processing Addendum.
You (or your organisation) must ensure there is a lawful basis to collect and process that data, that required notices are given to data subjects, and that you do not upload data you are not entitled to process.
Data-subject requests about POS customers, employees, or other third parties should normally be directed to the tenant organisation first. We will assist the tenant as reasonably required under the DPA.
5. How we collect data
We collect personal data from:
- You directly — registration, onboarding, profile updates, support requests, and forms you submit
- Your organisation’s administrators — when they invite you, assign roles, or configure your membership
- Automated means — cookies, local storage, server logs, and security monitoring when you use the Service
- Service providers — for example payment gateways returning success/failure and reference IDs for billing events
6. Purposes and legal bases (GDPR Art. 6)
We process personal data only where we have a legal basis. The main purposes and bases are:
- Providing the Service, creating and managing accounts and workspaces, authenticating users, and delivering modules you enable — performance of a contract (Art. 6(1)(b))
- Operating billing, subscriptions, rent, credits, and related accounting where applicable — contract and, where required, legal obligation (Art. 6(1)(b) and (c))
- Securing the platform, detecting abuse, preventing fraud and repeat free-trial abuse, enforcing rate limits, and investigating incidents — legitimate interests (Art. 6(1)(f)), balanced against your rights. Automated eligibility decisions may require a small M-Pesa confirmation (credited toward future System Rent) or platform-admin review; you may request human review of an automated trial denial
- Complying with law, responding to lawful requests, and establishing or defending legal claims — legal obligation and/or legitimate interests (Art. 6(1)(c) and (f))
- Improving reliability and product quality using aggregated or de-identified usage signals where feasible — legitimate interests (Art. 6(1)(f))
- Optional product announcements or service communications — consent where required, or legitimate interests with a clear opt-out for non-essential messages
7. Retention
We retain account and workspace administration data for as long as your account or tenant remains active, and thereafter for a reasonable period needed for security, dispute resolution, backup integrity, and legal compliance.
Trial-abuse signal hashes and claim history are retained while needed to prevent repeat free trials and fraud, then deleted or anonymised when no longer required for security or legal compliance.
Security and access logs are typically retained for shorter operational windows unless an investigation or legal hold requires longer retention.
When a workspace is terminated, we delete or anonymise tenant-hosted business data according to product capabilities and the DPA, except where we must retain information to meet legal obligations (for example tax or accounting records relating to our own billing).
You may request deletion of your account-related personal data subject to the exceptions described in “Your rights” below.
8. Sharing and recipients
We do not sell your personal data. We may share data with categories of recipients who help us operate the Service, under contracts that require appropriate protection:
- Hosting, database, storage, and infrastructure providers
- Email delivery and transactional messaging providers
- Payment processors and mobile-money or card gateways used for platform billing
- Professional advisers (legal, accounting) under confidentiality obligations when needed
- Authorities or courts when required by law or to protect rights, safety, and security
9. International transfers
Our infrastructure or sub-processors may process data in countries outside the European Economic Area (EEA) or United Kingdom.
Where GDPR or UK GDPR requires a transfer mechanism, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and UK addenda where applicable), or rely on an adequacy decision where one exists.
For more detail about transfers affecting your account, contact app.flakescapital@gmail.com.
10. Security
We apply technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS/TLS), password hashing, role-based access controls, tenant isolation in application logic, and monitoring for abusive activity.
No method of transmission or electronic storage is completely secure. You are responsible for choosing strong credentials, protecting devices and sessions, and promptly notifying us of suspected unauthorised access.
Report security concerns to app.flakescapital@gmail.com.
11. Your rights (GDPR and similar laws)
Where GDPR, UK GDPR, or comparable laws apply, you may have the right to:
- Access — obtain confirmation of processing and a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion in certain circumstances (“right to be forgotten”)
- Restriction — limit processing in certain circumstances
- Objection — object to processing based on legitimate interests, including profiling related to such interests
- Portability — receive certain data in a structured, commonly used, machine-readable format
- Withdraw consent — where processing is based on consent, without affecting prior lawful processing
- Lodge a complaint — with your local supervisory authority
12. How to exercise your rights
To exercise rights relating to your Ecosys360 account or platform administration data, email app.flakescapital@gmail.com with enough detail for us to verify your identity and locate the relevant records.
For personal data your organisation stores about third parties (for example retail customers or employees in POS/HR), contact your organisation first — they are usually the controller. We will support tenant controllers as described in the DPA.
We may refuse or limit requests where the law allows (for example, where fulfilling a request would adversely affect the rights of others, or where we must retain data for legal obligations).
13. Automated decision-making
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects on you within the meaning of GDPR Art. 22 for platform account holders. Security and abuse-prevention tooling may use automated signals (for example rate limits) to protect the Service.
14. Children
Ecosys360 is intended for business and professional use. It is not directed at children under 16 (or the higher age of digital consent in your jurisdiction). We do not knowingly create platform accounts for children. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
15. Third-party links and integrations
The Service may link to or integrate with third-party sites, payment providers, or tools. Their privacy practices are governed by their own policies. We are not responsible for third-party content or processing outside our instructions to them as our providers.
16. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date and document version will change when we do. For material changes, we may provide additional notice in-product, during signup/onboarding, or by email where appropriate.
Continued use of the Service after an update becomes effective constitutes acceptance of the revised policy where permitted by law. If you do not agree, you should stop using the Service and request account closure.
Last updated: 29 July 2026.
17. Contact
Controller contact for privacy matters: Ecosys360, email app.flakescapital@gmail.com.
General product support: app.flakescapital@gmail.com.

