Privacy Policy
Data Protection Notice & GDPR Compliance
This Privacy Policy outlines how Norbe Systems SAS (SIREN: 107967598), registered in France ("Norbe Systems", "we", "us", or "our"), collects, processes, and protects your personal data when you visit our website (herobm.com) or purchase a software license for HeroBM.
We are committed to full compliance with the European General Data Protection Regulation (Regulation EU 2016/679, "GDPR") and applicable French data protection legislation (Loi Informatique et Libertés).
Data Controller
The entity responsible for processing your personal data (the Data Controller) is:
Our Core Principle: Absolute Software Data Sovereignty
Unlike traditional SaaS ERP vendors, HeroBM is designed for complete data autonomy:
- Your ERP Database Stays Yours: When you deploy HeroBM in your own infrastructure or cloud, all operational business data, customer records, inventory balances, and general ledger transactions remain exclusively on your servers and within your PostgreSQL database.
- Zero Telemetry by Default: The HeroBM codebase contains no hidden tracking scripts, phone-home telemetry, or background usage reporting that transmits your business data back to Norbe Systems.
- Not a Data Processor: For self-hosted deployments, Norbe Systems has no access to your operational database and does not act as a data processor for the data you store inside HeroBM.
Information We Collect on This Website
We only collect personal data that is strictly necessary to communicate with you, process license orders, and ensure website security:
- Inquiries & Contact Requests
- Full name, business email address, company name, and the contents of your message submitted via our contact forms.
- Order & Transaction Metadata
- When you purchase a license, payment processing is handled by our Merchant of Record (Stripe). We receive customer contact email, billing country/address, VAT/tax identification number, company name, license tier ordered, and payment confirmation. We do not receive or store full credit card numbers.
- Technical Server Logs
- IP address, browser type, operating system, referring URL, and timestamps collected automatically for server diagnostics, DDoS defense, and security integrity.
Purposes and Legal Bases for Processing
Under Article 6 of the GDPR, we process personal data based on the following legal grounds:
Contract Performance (Art. 6(1)(b) GDPR)
To provision access to the software repository, issue license certificates, deliver electronic invoices, and manage client relations.
Legal Obligations (Art. 6(1)(c) GDPR)
To comply with statutory French and EU commercial accounting, VAT calculation, tax declaration, and financial record-keeping requirements.
Legitimate Interests (Art. 6(1)(f) GDPR)
To ensure website and network security, prevent fraudulent transactions, respond to pre-sales inquiries, and maintain our systems.
Consent (Art. 6(1)(a) GDPR)
Where you have explicitly requested communication or given specific consent (which may be withdrawn at any time).
Data Recipients and Third Parties
We do not sell, rent, or trade your personal data. We only share data with trusted service providers strictly necessary to operate our business:
- Payment & Invoicing: Stripe Inc. (Merchant of Record / payment processing and tax compliance).
- Infrastructure & Hosting: Cloud and CDN hosting providers operating secure data centers.
- Legal & Accounting Authorities: French tax administration, auditors, or statutory authorities when strictly required by law.
International Data Transfers
Whenever personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are implemented in compliance with Chapter V of the GDPR:
- Transfers to countries recognized by the European Commission as offering an adequate level of data protection (Adequacy Decision); or
- Execution of standard contractual clauses (SCCs) adopted by the European Commission, along with supplementary technical and organizational safeguards.
Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Customer & License Records: Retained for the duration of the license agreement plus 5 years for warranty and contractual defense purposes.
- Accounting & Invoicing Data: Retained for 10 years in compliance with Article L. 123-22 of the French Commercial Code.
- Contact Inquiries: Retained for a maximum of 3 years following the last contact from the prospective client.
- Technical Logs: Retained for a maximum of 12 months for security and auditing purposes.
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): Request confirmation and a copy of the personal data we hold about you.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17 GDPR): Request deletion of your personal data ("right to be forgotten"), subject to statutory retention obligations.
- Right to Restriction of Processing (Art. 18 GDPR): Request limitation of processing under specific legal circumstances.
- Right to Data Portability (Art. 20 GDPR): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR): Object at any time to processing based on legitimate interests.
To exercise any of these rights, please contact us at privacy@herobm.com. We will respond within one month of receipt.
You also have the right to lodge a complaint with the French data protection supervisory authority: CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr.
Contact & Inquiries
If you have questions about this Privacy Policy, your personal data, or our GDPR compliance practices, please contact:
Norbe Systems SAS — Data Privacy
Email: privacy@herobm.com