Data Processing Agreement
This page is a contract between a shop using Happy ERP and us, covering the personal data of the shop's customers. Unlike the Privacy Policy, which is written for those customers to read, this page is written for the shop owner.
The shop is the controller — it decides what customer data to collect and why.
Happy ERP is the processor — we store and process it only on the shop's instructions.
1How this agreement is accepted
Creating a shop, or continuing to use the service after the effective date, accepts this agreement. No separate signature is needed. If you require a signed copy, contact us.
2What is processed, whose, for how long
| Item | Detail |
|---|---|
| Subject matter | Providing shop management — orders · stock · chat · shipping · reports |
| Data types | Name · phone · delivery address · chat messages · order history · payment slip images (if the customer uploads one) |
| Data subjects | The shop's customers · people who message the shop · the shop's affiliates |
| Duration | For as long as the shop uses the service, then per section 7 |
3What we commit to
- Process only on the shop's instructions — we do not sell the shop's customer data, do not use it to advertise other shops, and do not use it to train AI models
- One shop sees only its own data — separated by shop_id at every layer, with tests covering it
- Confidentiality — our staff with access are bound to confidentiality and access only when needed (fixing a problem the shop reported · restoring data)
- Help you answer your customers — when a customer asks for a copy or deletion, we assist within 5 working days
- Breach notice — within 72 hours of becoming aware, telling you what data was involved and what we did
- Audit — you may request security information once a year
4Security
- HTTPS everywhere · passwords stored hashed, never in plain text
- Admin access requires a per-person password plus a one-time code over Telegram
- Automatic daily backups, stored encrypted
- An audit log of who did what and when
5Sub-processors
The shop authorises the sub-processors below. If we add or change one, we give 30 days notice and you may object (on objection you may stop using the service at no charge).
| Who | What they do | What they see |
|---|---|---|
| Hostinger | Servers the system runs on | All data (storage) |
| Meta (Facebook) | Sending/receiving customer messages | Chat messages · ad events (if enabled) |
| Anthropic (Claude) | Drafting chat replies (only when the shop enables AI) | Chat messages + product data |
| Telegram | Notifying the shop owner | Order summaries, to a room the shop sets itself |
| Google Drive | Holding backups | Encrypted backup copies |
| Cloudflare | DNS only | No content (proxy is off) |
| BCEL OneProof | Verifying a transfer really happened | The QR code inside the slip |
If the shop enables API v1 or outbound webhooks to another system (accounting, courier), that is the shop's own decision and the shop owns that relationship. You can switch it off at any time.
6Where the data sits
The main servers are outside Laos (Hostinger data centres) and the sub-processors above are also abroad. By using the service the shop acknowledges and permits this transfer for the purpose of providing it.
7What happens when you stop
- You can export your data yourself at any time — Settings → System → Export
- Request account closure → we delete within 30 days and cut the Facebook connection immediately
- Remaining backup copies age out within 90 days
- You can cancel a closure request before the deadline
8The shop's responsibilities
- Tell your own customers what you collect and why
- Collect only what the sale needs — do not put sensitive data (health · religion · politics) into the system
- Keep passwords safe and give staff only the access they need
9Changes
For significant changes we give notice in the app or by email at least 30 days before they take effect (longer than the Privacy Policy, because this is a contract).
10Contact
Email: support@happyerp.la
Phone/WhatsApp: +856 20 5226 6557