Privacy policy

1. Our core beliefs regarding user privacy and data protection

User privacy and data protection are considered as a top priority by frePPLe.
Data is a liability, it should only be collected and processed when absolutely necessary.
We will never sell, rent or otherwise distribute or make public your personal information.

2. Relevant legislation

For any personal data you would communicate to frePPLe, we would comply with the following international legislation with regards to data protection and user privacy:

EU Data Protection Directive 1995 (DPD)
EU General Data Protection Regulation 2018 (GDPR)

FrePPLe’s compliance with the above legislation, all of which are stringent in nature, means that we are likely compliant with the data protection and user privacy legislation set out by many other countries and territories as well. If you are unsure about whether frePPLe is compliant with your own country of residences’ specific data protection and user privacy legislation you should contact us for clarification.

3. Personal information that frePPLe collects and why we collect it

This website collects and uses personal information for the following reasons:

3.1 Site visitation tracking

Like most websites, all the *.frepple.com websites use Google Analytics (GA) to track user interaction. We use this data to determine the number of people using our site, to better understand how they find and use our web pages and to see their journey through the website.

Although GA records data such as your geographical location, device, internet browser and operating system, none of this information personally identifies you to us. GA also records your computer’s IP address which could be used to personally identify you but Google do not grant us access to this. We consider Google to be a third party data processor (see section 5.0 below).

GA makes use of cookies, details of which can be found on Google’s developer guides.

Disabling cookies on your internet browser will stop GA from tracking any part of your visit to pages within this website.

In addition to Google Analytics, this website tracks current visitors through the Tawk dashboard (see https://www.tawk.to). Tawk is the chat tool used by frePPLe to interact with the people visiting either their website or any frePPLe instance. FrePPLe does not keep track of any history of connections nor visited pages using Tawk dashboard. Only current users are visible and no information is kept by frePPLe once they stop visiting our website.

3.2 Company information dwelling in the frePPLe instances

As part of our core business model, users having registered to a frePPLe instance (regardless of whether this instance is a paying or a free-tier instance) have to pouplate this instance with company data to model their supply chain.
FrePPLe makes no difference between personal data and company data. This company data is treated by frePPLe with the same confidentiality as the personal data.

3.3 Contact forms and email links

Should you choose to contact us using the contact form on our Contact us page or using a frePPLe alias emails (such as info@frepple.com, sales@frepple.com…), none of the data that you supply will be stored by frePPLe or passed to / be processed by any of the third party data processors defined in section 5.0. Instead the data will be collated into an email and sent to us over the Simple Mail Transfer Protocol (SMTP). Our SMTP servers are protected by TLS meaning that the email content is encrypted using SHA-2, 256-bit cryptography before being sent across the internet. The email content is then decrypted by our local computers and devices.

3.4 Email campaign

If you register for a free-tier environment, the email address that you submit to us will be registered in odoo.com who will send in the days following your registration a campaign of emails to help you discover key features of frePPLe. We consider Odoo to be a third party data processor (see section 6.0 below).

Your email address will remain within Odoo’s database for as long as we continue to use Odoo’s services or until you specifically request removal from the list. You can do this by unsubscribing using the unsubscribe links contained in any email that we send you or by requesting removal via email.

3.5 Support tickets

Support tickets are managed by Jira, a third party service desk application (see https://www.atlassian.com/software/jira/service-management/features/service-desk). We consider Jira to be a third party data processor (see section 5.0 below).

3.6 Source code and software downloads

All source code (both for the open source Community Edition, as well as the closed source Enterprise and Cloud Editions) is maintained on github (see https://github.com). This platform provides version control on the source code of the software, and also hosts the downloads of the software.

All discussions, collaboration and downloads for the open source Community Edition requires a github account. Downloads for the closed source Enterprise Edition of the software also requires a github account. We consider Jira to be a third party data processor (see section 5.0 below).

4. About frePPLe’s servers

The frePPLe website is hosted by Combell within a Belgian data center.

The frePPLe instances for both paying customers and free-trial users are hosted by Amazon Web Services, Inc (AWS) in their data center located in Ireland or in the United States of America. The frePPLe servers are configured with the following policies (the list is frequently being updated and revised to follow industry standards and best practices):

  • Data isolation: User data is stored in a dedicated database – no data is shared between different customers. The server configuration and the application guarantee no access is possible from one database to another.
  • Password security: User passwords are stored encrypted using the PBKDF algorithm with a SHA256 hash, a password stretching mechanism recommended by NIST. Nobody can access to your password or can retrieve it for you. The only option if a password is lost is to reset it through an reset request.
  • System Security: All cloud servers are running hardened Linux distributions with up-to-date security patches and a minimal set of services. Only FrePPLe support staff has clearance to remotely manage the servers – and access is only possible using 2048-bit SSH key pairs. All external network connections to the cloud servers are protected by state-of-the-art 256-bit SSL encryption.
  • Employee access: FrePPLe support staff may sign into your account to access settings related to a support issue (using special staff authorization, not with your password) or collect usage statistics. We only access files and settings needed to diagnose and resolve issues.

All traffic between any frePPLe website and your browser is encrypted and delivered over HTTPS.

5. OUR THIRD PARTY DATA PROCESSORS

We use a number of third parties to process personal data on our behalf. These third parties have been carefully chosen and all of them comply with the legislation set out in section 2.0. All 5 of these third parties are EU-U.S Privacy Shield compliant.

Google (Privacy policy)
Tawk (Privacy policy)
Amazon Web Services (Privacy policy)
Combell (Privacy policy)
Odoo (Privacy policy)
Atlassian (Privacy policy)
Github (Privacy policy)

6. Data breaches

We will report any unlawful data breach of this website’s database or the database(s) of any of our third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.

7. Changes to our privacy policy

This privacy policy may change from time to time inline with legislation or industry developments. We will not explicitly inform our clients or website users of these changes. Instead, we recommend that you check this page occasionally for any policy changes. Specific policy changes and updates are mentioned in the change log below.

7.1 Change log

31/03/2018:
– Privacy policy instigated

30/12/2023 :
– Include Amazon data center in the United States of America.
– Updated section 3.4 to refer to odoo rather than mailchimp.
– Added sections 3.5 and 3.6.
– Updated list of third party data processors.