Privacy Policy & Data Protection
Last updated 4 August 2026
This policy explains how THOSORO handles personal data on the THOSORO ERP platform. For data that a customer company (a “Tenant”) uploads about its own customers, suppliers and employees, the Tenant is the data controller and THOSORO acts as processor on its documented instructions. For account, billing and website data, THOSORO is the controller. This page is maintained by THOSORO; it describes the controls we actually operate and is not a certification.
1. Roles: controller and processor
- THOSORO as processor: all business records inside a Workspace — customers, contacts, employees, quotations, orders, invoices, purchase orders, assets and their locations. The Tenant decides what is uploaded and why; THOSORO processes it only to run the Platform.
- THOSORO as controller: platform account identities, authentication and MFA data, audit logs of privileged actions, billing records, support correspondence, and enquiries submitted through the public demo form.
- This policy, together with the Terms & Conditions, forms the data processing agreement between THOSORO and each Tenant. A separate signed DPA is available on request.
2. What we collect and why
- Identity & access: name, work e-mail, phone, job title, role, workspace membership, MFA enrolment status — to authenticate users and enforce permissions. Legal basis: contract performance.
- Business records: the commercial data a Tenant enters — to deliver the ERP functionality it subscribed to. Legal basis: contract / the Tenant’s own basis as controller.
- Location data: postal addresses converted to coordinates for the Map module, and asset installation locations. Legal basis: legitimate interest of the Tenant in servicing its equipment.
- Security & audit logs: sign-in events, privileged administrative actions, document sends, IP address — to detect abuse and evidence changes. Legal basis: legitimate interest in platform security.
- Billing: company details, VAT number, invoices. Legal basis: contract and legal obligation.
- Website enquiries: the details submitted in the demo request form. Legal basis: pre-contractual steps at your request.
THOSORO does not sell personal data, does not use it for advertising, does not build profiles of individuals, and does not use Tenant business data to train machine-learning models.
3. How your data is protected
- Tenant isolation: every business table enforces row-level security in the database, keyed to the signed-in user’s workspace membership. Isolation is enforced by the database itself, not only by application code.
- Least privilege: table-level grants are issued per role; privileged service credentials are used only inside server-side code after the caller’s identity and role have been verified. Payroll and salary data are deliberately not stored in THOSORO at all; they are held in a separate HR application reached over a signed, scoped and audited bridge.
- Authentication: accounts are created only by an administrator — there is no public sign-up. Multi-factor authentication (TOTP) is mandatory, and passwords are checked against known-breach lists.
- Encryption: all traffic is served over TLS; data at rest and backups are encrypted by the managed hosting platform.
- Documents: generated PDFs are stored in private buckets and shared only through short-lived signed links; every send is logged.
- Auditability: administrative and cross-tenant actions are written to an append-only audit log that cannot be edited or deleted through the application.
- Backups & recovery: the production database is backed up by the managed hosting platform with point-in-time recovery.
- Secrets: API keys and service credentials are stored in a managed secret store and are never committed to source code or exposed to the browser.
These are the controls in force today. No system is absolutely secure, and THOSORO makes no claim of regulatory certification, audit outcome or breach-proof operation.
4. Hosting, data residency and subprocessors
The Platform is hosted on managed cloud infrastructure within the European Union. THOSORO engages a limited set of subprocessors, each bound by written data-protection terms:
- managed database, authentication, storage and application hosting;
- transactional e-mail delivery, for invitations, password resets and documents a Tenant chooses to send;
- address geocoding and map tiles, used only when the Map or Assets modules are enabled.
A current subprocessor list is available on request from privacy@thosoro.com. Where any transfer outside the EEA occurs, it is covered by EU Standard Contractual Clauses.
Self-hosted tenants. Where a Tenant has agreed a dedicated deployment on its own cloud account or on-premise server, its business data is stored exclusively in that environment and is not held in THOSORO’s managed database. THOSORO then supplies the application only; it has no standing access to that data, and no third party — including any artificial-intelligence or model provider — is granted access to it. Support access is possible only where the Tenant explicitly and temporarily grants it, and the Tenant remains responsible for encryption at rest, backups, retention and access control in that environment.
In no deployment model does THOSORO use Tenant business data to train, fine-tune or evaluate machine-learning models, or make it available to any provider for that purpose.
5. Retention and deletion
- Business records are retained for as long as the Workspace is active, plus 30 days after termination to allow export, after which they are deleted or irreversibly anonymised.
- Invoices and related accounting records are retained for the statutory period (7 years in the Netherlands).
- Security and audit logs are retained for up to 24 months.
- Demo enquiries are deleted within 24 months if no contract follows.
6. Your rights
Subject to applicable law you may request access, rectification, erasure, restriction, portability, or object to processing, and lodge a complaint with your supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens). If your data sits inside a Tenant’s Workspace, address your request to that Tenant as controller — THOSORO will assist them promptly. Otherwise contact privacy@thosoro.com; we respond within one month.
7. Cookies and tracking
THOSORO uses strictly necessary cookies and local storage to keep you signed in and to remember workspace preferences. No advertising or cross-site tracking cookies are used.
8. Incidents and vulnerability reporting
THOSORO maintains an incident response process. Where a personal data breach affects Tenant data, THOSORO notifies the affected Tenant without undue delay and no later than 72 hours after becoming aware, with the information needed for the Tenant’s own notification duties. Report a suspected vulnerability to security@thosoro.com; we will not pursue good-faith researchers who act responsibly and avoid accessing other people’s data.
9. Changes to this policy
Material changes are announced at least 30 days in advance to workspace administrators. The version date at the top of this page always reflects the current text.