Totatus — Jūsų verslo stiprinimas

Teisinė informacija

Privacy policy

How Toutatis collects, uses and protects personal data when you visit toutatis.eu, use Toutatis Connect, subscribe to cloud ERP hosting, or use our modules and client portal.

Visi teisiniai dokumentai

Paskutinis atnaujinimas: 2026-07-25

How Toutatis collects, uses and protects personal data when you visit toutatis.eu, use Toutatis Connect, subscribe to cloud ERP hosting, or use our modules and client portal.

1. Introduction

Toutatis Limited (“Toutatis”, “we”, “us”) respects your privacy. This policy explains what personal data we process, why we process it, how long we keep it, and what rights you have under the General Data Protection Regulation (GDPR) and applicable national law.

This policy applies to the marketing website toutatis.eu, contact and newsletter forms, live support chat, the client portal (subscriptions and billing), hosted Toutatis ERP / Dolibarr instances, the Toutatis Connect mobile application, and our proprietary modules (Peppol, HR time tracking, e-commerce connectors, POS, and related services).

2. Data controller

Controller for the activities described in this policy: Toutatis Limited — IT Solutions & Services

Contact: info@toutatis.eu · +32 485 12 36 33

Toutatis Limited (ТУТАТИС ООД)

OOD (Bulgarian limited liability company)

Registered office: Pine Tree complex, ul. Kosherinata 4/19, 2770 Bansko, Bulgaria

Company ID (EIK): 207559601

VAT: BG207559601

When we host an ERP instance for your organisation, we generally act as a data processor for the business data you store in that instance. The contractual relationship and data processing terms are set out in your subscription or service agreement and, where applicable, a data processing agreement (DPA).

3. Scope of services covered

This policy covers personal data processed in connection with:

  • Marketing website and lead generation (toutatis.eu).
  • Client portal — account creation, Stripe checkout, deployment status, magic-link authentication.
  • Toutatis ERP — managed Dolibarr instances hosted in the EU/EEA.
  • Toutatis Connect — native mobile app (iOS / Android) for sales, warehouse, quotes, field service and offline sync.
  • Toutatis HR time clock — check-in/out, kiosk mode, access control and EU labour-law workflows.
  • Peppol e-invoicing — Storecove integration for sending and receiving electronic invoices.
  • Modules and connectors — Totatus Bridge, TakePOS Hub, BankMatch AI, TotBookCal, VIES Export, Fiscal Control, TotLeadHub, TotDashboard, Email Builder and related extensions.
  • Consulting, migration, custom development and managed hosting.

4. Personal data we collect

Depending on how you interact with us, we may process:

  • Identity and contact data: name, email address, phone number, company name, job title, billing address, VAT number.
  • Account and authentication data: portal login email, magic-link tokens, session identifiers, role and permission metadata.
  • Message content: enquiries sent via contact, callback or support forms.
  • Newsletter data: email address and subscription preferences.
  • Technical data: IP address, browser or app version, device type, operating system, pages or screens visited, timestamps, server and application logs.
  • Support chat data: messages exchanged via our live chat widget, if enabled.
  • Subscription and billing data: plan selected, payment status, Stripe customer references, invoices (processed by Stripe; we do not store full card numbers).
  • ERP and module usage data: user accounts you create in your instance, audit logs, module configuration — as processor on your instructions.
  • Mobile app data: device identifiers necessary for sync, offline cache metadata, API tokens, optional biometric unlock on the device (stored locally by the OS, not on our servers unless explicitly configured).
  • HR time-tracking data: clock events, schedules, site/kiosk identifiers, access-control events — where you enable Toutatis HR time clock.
  • Peppol and fiscal data: invoice metadata, Peppol participant identifiers, transmission logs — where you use Storecove / Peppol modules.

5. ERP, cloud hosting and business data

When you subscribe to a hosted Toutatis ERP instance, you and your authorised users enter business data (customers, suppliers, employees, invoices, stock, projects, etc.) into the system. You determine the purposes and means of processing that business data; we provide the infrastructure, application stack, backups and security controls described in your agreement.

We access business data only to provide the service (hosting, updates, support, troubleshooting, billing), to comply with law, or as documented in a DPA. We do not use your ERP content for advertising or unrelated analytics.

Backups are retained according to your service tier and our retention schedule. Upon termination, export options are provided where contractually agreed; residual copies may remain in encrypted backups for a limited period before deletion.

6. Mobile application — Toutatis Connect

The Toutatis Connect app connects to your Dolibarr / Toutatis ERP instance via API. Data displayed in the app originates from your ERP; sync traffic is encrypted in transit (HTTPS/TLS).

The app may store an offline cache on the device so field teams can work without connectivity. Cached data remains on the device until sync completes or the cache is cleared. You are responsible for securing devices used by your staff.

If you connect the app to a third-party ERP URL, that instance’s administrator controls what data is exposed through the API. App store accounts (Apple App Store, Google Play) are subject to the platform operators’ privacy policies for downloads and updates.

7. HR time tracking — Toutatis Pointage RH

Where you enable HR time-tracking features, we process clock-in/out events, employee identifiers linked to your ERP user records, optional kiosk or QR pairing data, and audit trails required for labour-law compliance workflows (e.g. Belgium, France, Luxembourg, Netherlands, Germany — depending on modules activated).

You remain responsible for informing employees, establishing a valid legal basis (typically employment law / legitimate interest / consent where required), and configuring retention in line with national labour regulations. We provide the tool; you define policies and roles inside your instance.

Integrations such as Dimona or Checkin@Work transmit data to third-party government or sector platforms under your configuration; those transfers are governed by the relevant provider and your obligations as employer.

8. Peppol and e-invoicing

Peppol services involve transmission of invoice and party data to Storecove and the Peppol network. We process sender/receiver identifiers, invoice payloads (UBL), delivery status and error logs necessary to operate the integration.

You must ensure that invoice content is accurate and that you have a lawful basis to process recipient data. Peppol participant registration may require publication of certain identifiers in network directories as mandated by the scheme.

9. Purposes and lawful bases

We process personal data only when we have a valid legal basis:

  • Responding to enquiries — legitimate interest in operating our business and answering requests; pre-contractual steps where relevant (Art. 6(1)(b) and (f) GDPR).
  • Newsletter — consent (Art. 6(1)(a) GDPR). You may unsubscribe at any time.
  • Callback requests — legitimate interest / pre-contractual steps to call you back at your request.
  • Website security and abuse prevention — legitimate interest (Art. 6(1)(f) GDPR), including honeypot and rate-limiting on forms.
  • Client portal, cloud ERP, mobile app and modules — performance of a contract (Art. 6(1)(b) GDPR) and, for business data in your instance, processing on your documented instructions as processor (Art. 28 GDPR).
  • Billing and tax — legal obligations (Art. 6(1)(c) GDPR).
  • Legal compliance — where required by applicable law.

10. Retention

Contact and callback messages: up to 24 months unless a longer period is needed for an ongoing project or legal claim.

Newsletter data: until you unsubscribe, then suppressed from active mailing lists.

Server and application logs: typically up to 90 days for security and troubleshooting, unless longer retention is required for an incident investigation.

Contract, subscription and billing records: as required by tax and commercial law (generally up to 10 years where applicable).

ERP business data: for the duration of your subscription plus export/backup windows defined in your agreement; deleted or anonymised after termination unless law requires retention.

HR clock events and audit trails: according to your configuration and applicable labour-law minimum retention; we recommend aligning with your national requirements.

11. Recipients and subprocessors

We do not sell personal data. We share data only with trusted providers who help us operate our services, under data processing agreements where required:

  • European hosting infrastructure (EU/EEA data centres) — website, ERP instances, databases and object storage in the EU/EEA.
  • CapRover / container orchestration — application deployment for cloud instances.
  • Email delivery infrastructure — transactional messages, magic links and service notifications.
  • Stripe — payment processing and subscription billing via the client portal.
  • Storecove — Peppol access point and e-invoicing network connectivity.
  • Chatwoot (if live chat is enabled) — support conversations, EU/EEA hosting where possible.
  • Apple App Store / Google Play — app distribution (device-level data governed by platform policies).
  • Payment, banking and calendar providers you connect (Stripe, Mollie, GoCardless, Google/Microsoft OAuth for TotBookCal, Ponto for BankMatch, etc.) — only when you activate those integrations.
  • Professional advisers — lawyers or accountants when strictly necessary.

12. International transfers

We prioritise hosting and subprocessors in the European Union / European Economic Area. Some support or app-store services may involve transfers outside the EEA; where that occurs, we implement appropriate safeguards (Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms) and assess transfer risk.

13. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to certain processing. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.

If we process data in your ERP instance as processor, direct your request to your organisation’s administrator first; we will assist the controller as required by Art. 28 GDPR.

To exercise your rights as controller activities, email info@toutatis.eu. We respond within one month unless the request is complex.

You may also lodge a complaint with Commission for Personal Data Protection of the Republic of Bulgaria (CPDP), or your local EU/EEA authority.

14. Cookies and similar technologies

We use essential cookies for basic site operation and, with your consent where required, preference cookies. The mobile app does not use the website cookie banner; see our Cookie policy for web details.

15. Security

We apply technical and organisational measures appropriate to the risk: HTTPS/TLS, access controls, role-based permissions in ERP instances, encrypted backups, rate limiting on public forms, and European hosting. No method of transmission over the Internet is 100% secure; we continuously improve our posture. You must protect account credentials and configure user roles appropriately in your instance.

16. Children

Our website and B2B services are aimed at businesses and professionals. We do not knowingly collect data from children under 16 through our marketing channels.

17. Changes

We may update this policy from time to time. The “last updated” date at the top of this page indicates the latest revision. Material changes will be highlighted on this website or notified to active subscribers where appropriate.

18. Contact

Questions about this policy: info@toutatis.eu

Turite klausimų apie šiuos dokumentus? Mielai viską paaiškinsime.

Susisiekite su mumis

Toutatis

Klientų portalas

Valdykite savo prenumeratas, atsiskaitymus ir su jūsų paskyra susijusią informaciją.

Prisijungti

Įveskite savo el. pašto adresą, kad gautumėte saugią prieigos nuorodą.

Atidaryti visą klientų portalą