Privacy Policy
Version 2026-10-01 · Omer ERP, operated by Peluve (Pty) Ltd (registration 2021/406050/07, South Africa).
This Policy explains how Peluve (Pty) Ltd (“we”, “us”) handles personal information in Omer ERP (the “Service”), a cloud inventory, manufacturing and stock-control application.
Two different relationships run through this Policy, and they carry different duties:
- Your own account. For the details of the people who sign in — name, email, role — we are the responsible party (POPIA) / controller (GDPR) and this Policy governs.
- The records you put in your workspace. Your customers, suppliers, leads, staff and the people you invite in from outside remain yours. There you are the responsible party / controller and we are only your operator / processor. Our Data Processing Addendum governs that, not this Policy.
1. Information we collect
Account data: email address (which is the login), name, surname, mobile number if given, role and permissions, the date and version of the Terms you accepted, and your password stored only as a salted scrypt hash — never in a form we can read.
Workspace data: the business records you enter — items, stock, batches, formulations, customers, suppliers, sales and purchase orders, leads and enquiries, quality records. These frequently contain personal information about your contacts: names, email addresses, phone numbers, delivery addresses. We do not look for personal information in these records and do not use them for anything except running the Service for you.
Audit trail: the Service records every create, update and delete on your business records, with the username who did it, what changed from what to what, and when. It is kept for the life of the workspace.
Technical data: server logs held by our hosting provider, which include request paths and timestamps. Your IP address reaches our server and is used in memory to rate-limit sign-in and password-reset attempts against brute force; it is not written to our database. Error reports (see the table below) can carry diagnostic context.
Files you upload: when you import a spreadsheet of items, customers, suppliers, a recipe or sales history, the file is written to the application server's temporary storage between the preview step and the moment you confirm or cancel the import, and is deleted at that point. An import you start and abandon can leave that file on the server until the server is next replaced. Nothing else you upload is stored as a file — a company logo, for example, is held in the database, not on disk.
Billing data: the email address used for billing, the plan bought, and references our payment processor gives us for your customer and subscription records. Card numbers are typed on the processor's own page — they never reach the Service and we never store them.
Outside users you invite: when you invite someone from a contract manufacturer or partner site, we hold the email, first and last name, mobile and company you enter, the access you granted, who sent the invitation, whether the invitation email went out, and whether it is still pending, accepted, expired or revoked. We do not track whether the email was opened.
2. How we use it
To provide, secure, support and improve the Service; to authenticate you and keep sessions safe; to take subscription payments; to send transactional email (password resets, invitations, and the requests for quotation you send to your own suppliers); to comply with our legal obligations; and to detect and prevent abuse. We do not sell personal information, and we do not use your workspace data for advertising, profiling or to train any model.
3. Lawful bases and POPIA conditions
Under GDPR/UK GDPR we process personal data to perform our contract with you, on the basis of our legitimate interests in securing and improving the Service, to comply with legal obligations, and on consent where consent is what the law requires.
Under POPIA we process personal information on the grounds in section 11 — that processing is necessary to carry out the contract you are party to, to comply with an obligation imposed by law, and for our legitimate interests — and we apply the eight conditions for lawful processing in Chapter 3, including accountability (s 8), purpose specification (s 13), security safeguards (s 19) and notification of breaches (s 22).
4. Sub-processors — who else touches the data
We do not sell your data. It reaches the providers below, each under contract and confidentiality, because the Service cannot run without them. This is the complete list as at version 2026-10-01.
-
Render — application hosting.
Receives: everything you send to or read from the Service passes through it, plus server logs, and briefly any spreadsheet you import.
Sits: servers in Frankfurt, Germany — the region is fixed in our deployment configuration. Render Services, Inc. is a United States company. -
Neon — managed PostgreSQL database.
Receives: the entire database at rest — account records, every workspace record, the audit trail.
Sits: the database region is chosen when the database is created rather than fixed in our code; it is intended to be Frankfurt, Germany, and is [to be confirmed before publication]. Neon is a United States company. -
Paystack — card payments and subscriptions; the live payment route.
Receives: the billing email address, which plan is being bought, and an internal workspace reference. Your card details are entered on Paystack's own hosted page and are held by Paystack, not by us.
Sits: Paystack Payments Limited, a Stripe company, operating in Nigeria and South Africa; South African card transactions settle locally in rand. Exact processing locations [to be confirmed before publication]. -
Lemon Squeezy — merchant-of-record billing; secondary, and not switched on for this deployment.
Receives: the same billing fields as above, for any workspace billed through this route.
Sits: United States. Where both are configured, Paystack takes precedence. -
Resend — transactional email.
Receives: the recipient's address and the full content of the message — password-reset links, invitations to outside users, and requests for quotation you send your own suppliers.
Sits: United States. Sending region [to be confirmed before publication]. -
Xero — accounting push; optional, and inactive until you connect it yourself.
Receives: draft sales invoices and supplier bills we push out — the customer's or supplier's name, document numbers, dates, product codes, descriptions, quantities and prices. Nothing is pulled back.
Sits: Xero Limited, New Zealand. Data-centre location [to be confirmed before publication]. -
Sentry — error reporting; only active when an error-reporting key is configured.
Receives: an automatic report when something breaks — the page, the stack trace and diagnostic context, which can include personal information that happens to appear in the record being processed or in an error message. It is configured not to send cookies, session contents or IP addresses.
Sits: depends on the region of the key in use [to be confirmed before publication].
Email you route yourself. A workspace can put its own email credentials into Setup → Email — its own Resend key, or its own Gmail or other SMTP account. When it does, outgoing mail leaves through that provider instead of ours. That provider is then the workspace's own choice and its own sub-processor, not one of ours, and we hold those credentials only to send on that workspace's instruction. Credentials you give us this way — and an accounting connection's tokens, your API keys and your webhook signing secrets — are stored in the database, protected by our database provider's encryption at rest and by the access controls described in section 7, and not separately encrypted by the Service.
Places you send data yourself. The Service can post events to any web address you configure, and issue API keys that let your own systems read your workspace. Where that data goes is your decision and your responsibility.
We will publish any change to this list on this page and notify workspace administrators by email at least 30 days before a new sub-processor starts processing.
5. Where your data is, and transfers out of South Africa
The Service runs in Frankfurt, Germany. The database is provisioned separately and is intended to sit in the same region [to be confirmed before publication]; either way it is not in South Africa. So if you are in South Africa, your personal information leaves the Republic the moment you use the Service, and further personal information leaves it whenever payment, email, accounting or error-reporting is used.
Section 72 of POPIA governs that transfer. We rely on it on the basis that the recipient is subject to a law or binding agreement that upholds principles substantially similar to POPIA, and that the transfer is necessary to perform the contract between us. Germany is in the European Economic Area and subject to the GDPR; transfers onward to providers in the United States and elsewhere are covered by those providers' own contractual safeguards, including Standard Contractual Clauses where they apply. The specific mechanism for each provider is being confirmed as part of legal review.
For customers in the EEA or UK, hosting is in the EEA, the database is intended to be, and data leaves the EEA for the providers marked above.
6. Retention and deletion — what actually happens
We describe this plainly because the software behaves in a particular way and the Policy should not claim otherwise.
- While you are a customer, we keep your workspace data for as long as the workspace exists. Nothing ages out and nothing is deleted automatically — not records, not the audit trail.
- When a free trial lapses and no plan has been paid for, the workspace is not deleted and nothing in it is removed. Once online billing is live for your workspace, changes are blocked until a plan is paid for, while reading and exporting stay open.
- When a subscription is cancelled, access continues to the end of the period already paid for. After that, changes are blocked and the data stays where it is, readable and exportable. Cancelling does not delete anything.
- Deletion is on request. There is no self-service “delete my workspace” button in the Service today. Write to us at admin@foodchem.co.za and we will delete the workspace and everything in it within 30 days, other than records we must keep — invoices and payment records for the retention period South African tax law requires.
- Backups. Deleted data can persist in our database provider's automated backups until those roll off on that provider's own schedule.
7. Security (POPIA s 19)
We maintain appropriate, reasonable technical and organisational measures, and review them as the Service changes. In place today: HTTPS everywhere with HSTS; passwords stored only as salted scrypt hashes; session cookies marked Secure, HttpOnly and SameSite; a session identity tied to the password hash, so a password change or reset signs every existing session out; CSRF protection on every form; rate limiting on sign-in and password reset; per-tenant isolation applied automatically at the database-query layer, so one workspace's query cannot return another's rows; role-based access with a fail-closed allowlist for outside users, meaning a page they were not granted is refused rather than merely hidden; and an append-only audit trail of every change, which the Service never edits or erases.
No system is perfectly secure. You are responsible for keeping your credentials safe, for who you invite into your workspace, and for keeping your own exports.
8. Breach notification (POPIA s 22)
If personal information in our care is accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after establishing that it happened, in the manner section 22 requires and unless a public body directs us to delay. Where the personal information belongs to your workspace, we will notify you without undue delay and in any event within 72 hours of becoming aware, with enough detail for you to meet your own duties — see the DPA. Under GDPR we will support your 72-hour notification to your supervisory authority.
9. Your rights
Subject to applicable law you may ask for access to your personal information, correction or deletion of it, an export of it, or that we restrict or stop a particular processing, and you may withdraw consent where consent was the basis. Deletion is by request to admin@foodchem.co.za, as described above. Requests about records inside a workspace belong to the workspace owner as responsible party; if you reach us instead, we will pass the request to them.
What the self-service export actually contains. Setup → Export gives you, at any time and in machine-readable CSV, your item groups and items, locations, stock lots and movements, recipes and their lines, production batches and what they consumed, customers, sales orders and lines, suppliers, purchase orders and lines, the audit trail, and a list of your users without password hashes. It does not yet cover every part of a workspace — leads and lead activity, supplier contacts, invitations, requests for quotation and supplier quotes, quality records (non-conformances, corrective actions, control points and their checks), write-offs, work centres, exchange rates, business settings, API keys, webhooks and accounting connections are not in it. Ask us at admin@foodchem.co.za and we will extract anything the download leaves out.
You may complain to a regulator. In South Africa that is the Information Regulator (complaints.IR@inforegulator.org.za); in the EEA or UK, your own supervisory authority.
10. Information Officer
Our Information Officer under POPIA can be reached at admin@foodchem.co.za. Name and registration with the Information Regulator: [to be confirmed before publication].
11. Cookies and browser storage
We use one cookie: the signed session cookie that keeps you signed in and holds your chosen interface language. It is essential, and it is marked Secure, HttpOnly and SameSite=Lax. If you tick “remember me”, a second essential cookie with the same protections keeps you signed in between visits. There are no advertising, analytics or tracking cookies, and no third-party cookies.
Your light/dark theme choice and a few layout preferences are kept in your browser's own local storage. They stay on your device and are never sent to us.
12. Children
The Service is a business tool, is not directed at children, and we do not knowingly collect the personal information of anyone under 18.
13. Changes
We may update this Policy. The version and date at the top change with it, and material changes will be notified in-app or by email.
14. Contact
Peluve (Pty) Ltd (registration 2021/406050/07, South Africa) — admin@foodchem.co.za. Support: admin@foodchem.co.za.