This privacy policy describes how Zigma360 AS ("we", "us"), a Norwegian company, collects, uses, retains, and discloses personal data in connection with the Zigma ERP integration application ("the Application"). The Application transfers accounting documents (customer invoices and credit notes) from the Zigma ERP system to the accounting system chosen and authorized by the customer (such as Visma Net, PowerOffice GO, Tripletex, or Unimicro).
1. Data we process
The Application processes the following categories of data:
- Invoice data: invoice numbers, dates, amounts, currency, payment references, order lines, and invoice document files, as registered by the customer in Zigma ERP.
- Business contact data contained in invoices: customer company names, organization numbers, addresses, and reference person names and e-mail addresses.
- Application user accounts: name, e-mail address, and a securely hashed password for the people the customer authorizes to operate the integration.
- Technical logs: synchronization run history and error messages, which may include the invoice data listed above.
The Application does not process special categories of personal data.
2. Purpose and legal basis
Data is processed solely to transfer accounting documents from Zigma ERP to the customer's accounting system, to monitor and troubleshoot those transfers, and to notify the customer's designated contacts about errors. The legal basis is the performance of the agreement with the customer (GDPR art. 6(1)(b)) and our legitimate interest in operating a reliable service (art. 6(1)(f)). For invoice content, the customer is the data controller and Zigma360 AS acts as a data processor.
3. Retention
- Invoice data and synchronization logs are retained for as long as the customer's integration is active, and are deleted upon termination of the agreement or on the customer's request.
- User accounts are deleted when access is revoked or the agreement ends.
4. Disclosure
Data is disclosed only to the accounting system the customer has explicitly connected and authorized. We do not sell or share personal data with any other third party. The Application is hosted on Microsoft Azure within the EU/EEA.
5. Security
All data is transferred over encrypted connections (TLS). API credentials are stored encrypted, passwords are stored as salted cryptographic hashes, and access to the Application requires authentication. Access to production data within Zigma360 AS is limited to personnel who need it to operate the service.
6. Your rights
Data subjects have the right to access, rectify, and erase their personal data, and to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet). Requests concerning invoice content should be directed to the customer (the data controller); we assist the customer in fulfilling them.
7. Contact
Zigma360 AS, Sandnes, Norway · zigmaerp.com
E-mail: info@zigma360.no · Phone: +47 62 11 72 05
8. Changes
We may update this policy from time to time. The current version is always available at this address; material changes are communicated to affected customers.