Privacy Policy
This Privacy Policy explains how RESM CORP collects, uses, stores, and shares information through its Odoo-based business platform, including accounting, invoicing, banking synchronization, and Enable Banking integrations.
1. Scope
This policy applies to users, customers, suppliers, banking users, and authorized representatives who use or interact with this application.
2. Information We Process
- Account, company, and contact information
- Accounting records, invoices, bills, and payment references
- Bank account metadata, balances, and transaction history authorized by the user
- Technical logs, audit history, import payloads, and reconciliation activity
- Communications and documents uploaded to the platform
3. Banking Data
Where bank synchronization is enabled, banking data is accessed only after user authorization through the relevant banking provider or open banking intermediary, including Enable Banking where configured. Banking data is used to import transactions, support reconciliation, maintain accounting records, and operate internal controls.
4. Purpose of Processing
- Operate accounting, invoicing, and payment workflows
- Import and reconcile bank transactions
- Maintain ledgers, statements, and audit trails
- Detect duplicate imports, fraud indicators, and operational errors
- Meet legal, tax, regulatory, and contractual obligations
5. Legal Basis
We process data based on contract performance, legitimate business interests, legal obligations, and where applicable, user consent for bank connectivity and related services.
6. Data Sharing
Data may be shared with service providers, regulated banking connectivity providers, hosting providers, accountants, auditors, regulators, and payment or banking institutions where required to deliver services or comply with law. We do not sell personal data.
7. Retention
Data is retained for as long as needed for operational, contractual, accounting, tax, audit, legal, and security purposes. Banking and accounting records may be retained for the statutory period applicable to the relevant jurisdiction.
8. Security
We use administrative, organizational, and technical controls to protect data, including authentication controls, role-based access, audit logging, and infrastructure security measures.
9. Data Subject Rights
Where applicable, individuals may request access, correction, deletion, restriction, objection, or portability of personal data, subject to legal and operational limitations.
Effective URL base: crm.kelani.tech