Summary
The key provisions in plain language. This summary does not replace the policy; where they differ, the provisions below prevail.
- We collect only what is needed. We take only the data required to provide the service and meet our legal obligations (Sections 3 and 4).
- We do not sell data. We do not disclose it to anyone for advertising purposes (Section 6).
- Business data belongs to the business. We process your customers' data only on your instructions (Section 5).
- The website uses no cookies. There are no tracking tools and no third-party analytics (Section 13).
- We do not conceal breaches. If a security breach occurs, we notify you and the competent authorities (Section 10).
- You stay in control. You have the right to access, correct and erase your data, and to lodge a complaint (Section 11).
1 Who we are and what this policy covers
-
1.1.
Controller: Storex (TODO: registered legal name, state registration number, registered address).
-
1.2.
This policy applies to personal data that Storex collects for its own purposes through the storex.mn website, the signup form, the app.storex.mn cloud system and the point-of-sale application.
-
1.3.
When a customer business enters data about its own customers and employees into the system, that business is the controller and Storex is the processor (Section 5). Questions about such data should be directed to that business.
2 Definitions
- “Personal data”
- Any information that directly or indirectly identifies, or can identify, an individual.
- “Data subject”
- The individual to whom personal data relates.
- “Controller”
- The party that determines the purposes and means of processing data and is accountable for it.
- “Processor”
- A party that processes data on the controller's instructions and on its behalf.
- “Processing”
- Any operation performed on data, such as collecting, recording, storing, using, transferring or erasing it.
3 The data we collect
| Category | Data | Source |
|---|---|---|
| Account | Organization name, taxpayer number, contact person's name, phone number, email address, password (stored only in one-way hashed form) | Signup form |
| User access | Employee name, job title, access level, sign-in date and time | Customer's administrator |
| Payment | Orders, invoices, payment dates and amounts, e-Barimt receipts | Customer, bank |
| Technical | IP address, browser, device type, point-of-sale device identifier, error logs | Collected automatically by the system |
| Correspondence | Support requests, emails and their attachments | You |
We do not collect sensitive personal data (such as health, religious belief or biometric data) for Storex's own purposes.
4 Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Creating an account, signing in, providing the Service | Entering into and performing a contract |
| Issuing invoices and e-Barimt receipts, keeping accounting records | Legal obligation |
| Ensuring security, preventing fraud and unauthorized access | Performance of a contract, legal obligation |
| Technical support, sending service notices | Performance of a contract |
| Sending news about new features and promotions | Your consent, which you may withdraw at any time |
| Complying with lawful requests from competent authorities | Legal obligation |
If we intend to use data for a purpose other than, and incompatible with, the purpose for which it was collected, we will notify you in advance and, where required, obtain your consent.
5 Customer business data
-
5.1.
Businesses enter into the system their customers' names, phone numbers, appointments, purchase history, loyalty points, and employee payroll and bonus calculations. Storex processes this data only on the instructions of the business concerned and in accordance with the Data processing agreement.
-
5.2.
Storex does not use such data for its own marketing, for profiling, or for sharing with other businesses.
6 Who data is disclosed to
-
6.1.
We disclose data only to the following parties, and only to the extent necessary for the purpose:
- providers of servers, data centers and backup services TODO: names;
- the e-Barimt system, under the legal obligation to register receipts;
- QPay and banks, when you pay with the payment method you have chosen;
- text message and email delivery providers, to send verification codes and notices;
- courts, prosecutors, tax and other competent authorities, on the grounds and by the procedures provided by law.
-
6.2.
The full list of sub-processors is published in the Data processing agreement. TODO: full list of sub-processors
-
6.3.
Storex does not sell or rent personal data, or pass it to advertising networks.
7 Where data is stored
-
7.1.
Data is stored on servers located in TODO: server location.
-
7.2.
So that it can work without a network connection, the point-of-sale application temporarily stores the branch's products, prices and completed sales on the device, and sends them to the cloud system as soon as the connection is restored.
-
7.3.
If data needs to be transferred outside the territory of Mongolia, we will meet the conditions and safeguards required by law and set this out in this policy in advance.
8 Retention periods
| Data | Period |
|---|---|
| Account and user access | For the term of the contract and 60 days thereafter, then erased within 30 days |
| Invoices, payments, e-Barimt receipts | The period required by accounting and tax law |
| Technical and security logs | 12 months |
| Support correspondence | 3 years after the request is closed |
| Consent to receive promotional news | Until consent is withdrawn |
| Backups | Within 90 days, through routine rotation |
Data whose retention period has expired is erased irrecoverably or anonymized so that no one can be identified from it.
9 How we protect data
-
9.1.
We take the following measures, consistent with the Law on Cybersecurity and common industry standards:
- encrypting all connections with TLS;
- storing passwords only in one-way hashed form;
- isolating each customer's data at the database level;
- limiting employee access to what their work requires, and logging access;
- making regular backups and testing that they can be restored;
- binding employees to confidentiality obligations.
-
9.2.
Because no system that transmits data over the internet can be free of risk, we ask you to keep your sign-in details confidential and to notify us immediately of any suspicious activity.
10 Breach notification
-
10.1.
If a personal data security breach is detected, Storex will stop the breach immediately and take measures to mitigate its consequences.
-
10.2.
If the breach is likely to harm the rights of data subjects, Storex will, within 72 hours of detecting it, notify the National Human Rights Commission and the other bodies required by law, as well as the data subjects concerned. TODO: have a lawyer confirm the statutory provision and deadline
-
10.3.
The notice will describe the nature of the breach, the types of data affected, the likely consequences, the measures taken and those the data subject can take, and contact details.
11 Your rights
-
11.1.
As a data subject, you have the right to:
- know whether data about you is being processed, and its content and purpose;
- obtain a copy of your data free of charge;
- have inaccurate or incomplete data corrected;
- have your data erased, or its processing restricted, on the grounds provided by law;
- withdraw your consent at any time; processing carried out before withdrawal remains lawful;
- lodge a complaint with the National Human Rights Commission or a court if you believe your rights have been violated.
-
11.2.
Please send your request to info@storex.mn. Once we have verified your identity, we will respond within the period provided by law.
-
11.3.
Data that the law requires us to keep (for example, financial records) cannot be erased before its retention period ends; in that case, processing is restricted to storage.
12 Minors
The Service is intended for businesses. We do not knowingly collect data about anyone under 18 for Storex's own purposes; if we find that such data has been collected, we will erase it.
13 Cookies and device storage
-
13.1.
The storex.mn website does not use cookies, tracking tools or third-party analytics. IP addresses and browser information in the server's technical logs are kept for the period set out in Section 8.
-
13.2.
app.storex.mn and the point-of-sale application use strictly necessary cookies to keep you signed in, and device storage needed to work without a network connection. These are not used for advertising.
14 Changes to this policy
Each version of this policy is identified by its date. We will give notice of changes that materially affect your rights by email and within the system 30 days before they take effect.
15 Contact
Please send questions and requests about personal data to info@storex.mn. Employee responsible for personal data protection: TODO: name, job title.