Last updated: August 1, 2026

Privacy Policy

Your privacy matters. This policy explains what personal data we process, why, and the rights you have under the GDPR.

1. Overview

This Privacy Policy explains how PPS — Practical Programming Systems ("PPS", "we", "us") collects, uses, shares and protects personal data when you visit our website, create an account, or use our ERP platform (the "Service"). We are based in the Netherlands and are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Dutch law.

For any privacy question or request, contact us at info@ppserp.com.

2. Our role: controller and processor

  • As a controller. For personal data relating to your account, our website visitors and our direct business relationship (e.g. name, work email, billing details, usage analytics), PPS is the data controller and this Policy applies.
  • As a processor. For the business data you and your users enter into the Service (e.g. your customers, suppliers, orders and invoices), you are the controller and PPS acts as a processor on your instructions. Our handling of that data is governed by our customer agreement and Data Processing Agreement (DPA), which supplements this Policy.

3. Personal data we collect

  • Account data — name, email address, company name, role and authentication data.
  • Business data — records you enter into the Service; processed on your behalf as described above.
  • Billing data — plan, invoices and payment status. Card details are handled by our payment processor and are not stored by PPS.
  • Technical data — IP address, device and browser information, and security logs.
  • Usage data — how the Service and website are used, to improve reliability and features.
  • Communications — messages you send us via email, WhatsApp or the contact form.

5. How we use personal data

  • Provide, operate and secure the Service and your account.
  • Process transactions, subscriptions and send service notifications.
  • Provide customer support and respond to your enquiries.
  • Monitor, troubleshoot and improve performance and features.
  • Comply with legal, tax and regulatory obligations.

6. Sharing and sub-processors

We do not sell personal data. We share it only with trusted service providers who process it on our behalf under appropriate agreements, including:

  • Cloud hosting & infrastructure — to run the Service (hosted within the EU).
  • Payment processing — to handle subscriptions and invoicing securely.
  • Email & communications — to send transactional messages.
  • Analytics — to understand and improve usage (where consented).

We may also disclose data where required by law or to protect our rights, users and the security of the Service.

7. International transfers

We host and process personal data within the European Union. Where a provider processes data outside the EU/EEA, we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. Data retention

We retain personal data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes and enforce our agreements. Business data you enter is retained for the life of your account and deleted or returned after termination in line with your agreement and DPA, subject to statutory retention periods.

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, isolated data per company (tenant), role-based access control, per-location permissions and audit logging of critical actions. No method of transmission or storage is completely secure, but we work continuously to protect your data.

10. Your rights

Subject to conditions in the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting prior processing.

To exercise these rights, email info@ppserp.com. If PPS acts as a processor, we will refer your request to the relevant controller. You also have the right to lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.

11. Cookies

We use cookies and similar technologies as described in our Cookie Policy, and request consent for non-essential cookies via our cookie banner.

12. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children under 16.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date. Material changes will be communicated where appropriate.

Questions about this policy?

Contact us at info@ppserp.com.