Legal
GDPR compliance
How FleekERP meets the EU General Data Protection Regulation: lawful basis, your rights as a data subject, transfers, and how to exercise them.
Last updated
The General Data Protection Regulation (Regulation 2016/679) applies to any organisation that processes personal data of EU residents. As FleekERP may be accessed by visitors and customers with operations in the EU, we are committed to GDPR compliance. For our full privacy practices, see the privacy policy.
1. Data controller and processor
For personal data collected through fleekerp.com, Nexfloe Technologies Private Limited is the data controller. For personal data processed inside the FleekERP product on behalf of customers, Nexfloe Technologies Private Limited is the data processor and each customer is the controller. This is governed by our data processing agreement.
2. Personal data collected on the website
| Category | Data fields | Lawful basis |
|---|---|---|
| Identity | Full name | Consent, legitimate interest |
| Contact | Work email, phone number | Consent, legitimate interest |
| Organisation | Company name, industry, company size | Consent, legitimate interest |
| Enquiry | Message about your production setup | Consent |
| Technical | IP address, browser type, pages visited | Legitimate interest (security, aggregate analytics) |
We do not collect special categories of personal data (Article 9) through this website.
3. Lawful basis
- Article 6(1)(a), consent: when you submit a form you consent to us using the information to respond. You may withdraw consent at any time.
- Article 6(1)(b), contract: where your enquiry leads to a service agreement with Nexfloe Technologies Private Limited.
- Article 6(1)(f), legitimate interests: server logs and aggregate analytics for security and website improvement. We have assessed that this interest is not overridden by individual rights.
4. Your rights
EU residents have the rights of access (Article 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), and to withdraw consent (7(3)). We do not use automated decision-making that produces legal or similarly significant effects (22). To exercise a right, email info@fleekerp.com. We respond within 30 days, extendable by 60 days for complex requests with notice.
5. Retention
| Data category | Retention | Basis |
|---|---|---|
| Contact form submissions | 24 months from submission | Legitimate interest |
| Email correspondence | 36 months from last contact | Legitimate interest |
| Server and security logs | 30 days, rolling | Legitimate interest |
| Customer contract data | Duration of contract plus 7 years | Legal obligation, Indian law |
6. International transfers
Nexfloe Technologies Private Limited is based in India. Data submitted by EU residents is transferred to and processed in India, and by our email and hosting sub-processors in their locations. The EU has not issued an adequacy decision for India. We rely on the EU Commission's Standard Contractual Clauses (2021/914) in our data processing and sub-processor agreements, with encryption in transit and at rest and access controls as supplementary measures.
7. Data processing agreement
For customers who process personal data of their own employees through FleekERP, Nexfloe Technologies Private Limited acts as processor under Article 28. A data processing agreement covering subject matter, data categories, sub-processing, security measures, data subject rights, breach notification and deletion at termination is available on request. Email info@fleekerp.com with the subject line "DPA request".
8. Sub-processors
| Sub-processor | Purpose | Transfer mechanism |
|---|---|---|
| Amazon Web Services (AWS), India region | Platform hosting and data storage | Provider DPA and SCCs |
| Website hosting and content delivery provider | Serving fleekerp.com | Provider DPA and SCCs |
| Resend | Transactional email delivery | SCCs |
| Google (Analytics, Tag Manager) | Aggregate website analytics, when enabled and consented | Google DPA and SCCs |
| Cloudflare (Turnstile) | Anti-spam check on the website's contact forms | Cloudflare DPA and SCCs |
Customers are notified in advance of intended changes to sub-processors and may object.
9. Breach notification
In the event of a personal data breach likely to result in a risk to EU individuals, we notify the relevant supervisory authority within 72 hours (Article 33), affected data subjects without undue delay where the risk is high (Article 34), and affected customers so they can meet their own obligations.
10. Cookies
Analytics cookies are set only with consent for visitors in the EEA, UK and Switzerland. See the cookie policy.
11. Supervisory authority
EU residents may lodge a complaint with their national data protection authority (edpb.europa.eu). We encourage you to contact us first at info@fleekerp.com so we can resolve the concern directly.
12. Contact
Nexfloe Technologies Private Limited, Chennai, Tamil Nadu, India. Email info@fleekerp.com. Phone +91 99411 11019.
Grievance Officer: K. Silambarasan, Grievance Officer and Data Protection Contact. Email grievance@fleekerp.com. We acknowledge within 48 hours and respond within 30 days, as required by the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021.