Privacy Policy

Last updated: 24 June 2026

This policy explains what personal data we process when you use elorun, why we use it, and what rights you have. In plain language, with no fine print — because respect for your data is at the heart of the product.

1. Data controller

The data controller for your personal data is Higimax - Soluções de Higiene e Limpeza, Unipessoal Lda, with its registered office at Zona Industrial, Rua L, Lote 5, 5370-565 Mirandela, Portugal, tax ID (NIF) 510115381, operating the «elorun» service.

For any data protection matter, you may contact us by email at geral@higimax.pt.

2. Data we process

We process only the data necessary to provide you with the service:

  • Account data: name and email address; your password is stored in encrypted form (never in plain text).
  • Subscription and billing data: the plan you have chosen and the billing details required to issue an invoice.
  • Technical data: IP address, access logs, and status indicators for your installation (online/offline status, API activity) — for support, security, and service operation.
  • Strictly necessary cookies (see section 9).

3. Your business data stays with you

This is a key point: elorun is a bridge. Your Sage 50c data — customers, suppliers, invoices, stock — remains on your server and in your database. We do not copy it to our cloud or store it.

When you use the API or the AI assistant, requests pass through the bridge securely, but the business content is not retained by us. You remain the sole owner and controller of your Sage data.

4. Purposes and legal bases for processing

  • Providing and managing the service (account creation, licence activation, support) — performance of a contract.
  • Billing and compliance with tax and accounting obligations — legal obligation.
  • Security, abuse prevention, and diagnostics (logs) — legitimate interests.
  • Service communications (technical notices, changes) — performance of a contract; marketing communications only with your consent.

5. Who we share data with (sub-processors)

We do not sell your data. We engage trusted providers solely to operate the service:

  • Cloudflare — infrastructure, network, and secure access tunnel.
  • Resend — sending transactional emails (account verification, documents).
  • Payment processor (e.g. Stripe) — where applicable, to process subscription payments.
  • Each sub-processor is contractually bound to process data only on our behalf and in accordance with the GDPR.

6. International transfers

Some sub-processors may process data outside the European Economic Area. In such cases, we ensure appropriate safeguards as provided for under the GDPR (adequacy decisions or Standard Contractual Clauses adopted by the European Commission).

7. Retention periods

We retain account data for as long as your subscription is active. Upon closure, we delete or anonymise your data, except for data we are legally required to keep (for example, billing records, for the statutory retention period applicable in Portugal).

8. Your rights

Under the GDPR, you have the right to:

  • Access your data and obtain a copy;
  • Rectify inaccurate or outdated data;
  • Erase your data (the «right to be forgotten»), within legal limits;
  • Restrict or object to certain processing activities;
  • Data portability;
  • Withdraw consent at any time, where processing is based on consent.

9. Complaints to the supervisory authority

To exercise your rights, simply send an email to geral@higimax.pt. We will respond within the statutory time limit.

If you believe that our processing does not comply with applicable law, you have the right to lodge a complaint with the CNPD (the Portuguese data protection authority) — www.cnpd.pt.

10. Cookies

We use only cookies that are strictly necessary for the website to function, which do not require prior consent:

  • Session cookie — keeps you authenticated in your customer area;
  • Language cookie («lang») — remembers the language you have selected;
  • Cloudflare Turnstile cookie — anti-bot protection on forms.

11. Security

We apply appropriate technical and organisational measures to protect your data: encryption in transit, encrypted passwords, access via independent credentials, and a tunnel with no open ports. No system is infallible, but we treat security as a priority.

12. Changes to this policy

We may update this policy to reflect changes to the service or to applicable law. The version in force is always the one published on this page, with the update date at the top. Material changes will be communicated with reasonable advance notice.