Legal

Data Processing Policy

This policy summarises Retail HQ principles for handling business and customer data associated with its services. Contract-specific data-processing terms may apply to individual customers.

1. Scope

This policy applies to business data processed by Retail HQ when providing software, hosting, configuration, support, reporting or related services.

2. Customer Control

Customers remain responsible for deciding what information is entered into their Retail HQ environment, ensuring staff use is lawful and appropriate, and managing the permissions assigned to authorised users.

3. Retail HQ Responsibilities

Retail HQ processes information to provide, secure, maintain and support the contracted services. Access by Retail HQ personnel is limited to legitimate operational, support, security or legal requirements.

4. Types Of Data

Depending on configuration, the platform may process sales, product, inventory, supplier, staff, customer, loyalty, transaction, device, support and audit information. Customers should avoid entering information that is unnecessary for the business purpose.

5. Access Controls

The platform may provide role-based access controls. Customers are responsible for creating individual accounts, protecting credentials, removing access when staff leave and reviewing permissions regularly.

6. Service Providers

Retail HQ may use hosting, infrastructure, communications, backup and support providers. Providers are selected for their ability to support reliable service and are expected to protect information appropriately.

7. Security Measures

Retail HQ applies reasonable measures intended to protect confidentiality, integrity and availability. These may include access controls, authentication, logging, backups, infrastructure protection and operational procedures.

8. Support Access

When support is requested, authorised Retail HQ personnel may need temporary access to relevant system information. Access is limited to the work required to diagnose or resolve the issue.

9. Retention And Deletion

Data is retained according to service requirements, contractual terms, backup schedules and applicable obligations. Requests for export or deletion should be raised before service termination where continuity or record-keeping is important.

10. Incident Management

Retail HQ investigates suspected security incidents and takes reasonable steps to contain, assess and resolve them. Customer notification will be handled according to the circumstances, contractual terms and applicable requirements.

11. Customer Responsibilities

Customers should use strong passwords, assign appropriate permissions, train users, protect devices and networks, report suspected misuse promptly and maintain any additional records required by their business or industry.

12. Questions And Contract Terms

For detailed data-processing requirements, contact hello@retailhq.asia. Where a signed agreement differs from this general policy, the signed agreement governs the customer relationship.

WHATSAPPLINE