Skip to main content

Legal

Privacy Policy

How ORVYNEX handles information in ORVYNEX POS.

Last updated September 2026.

1. Scope

This policy covers the ORVYNEX POS marketing website and the ORVYNEX POS application. It describes what information is collected, why, and what is done with it.

2. Information collected on this website

If you submit the contact or demo request form, we store the details you provide: your name, business name, email address, phone number, the number of shops you indicated, the plan you expressed interest in, and your message. We also record the IP address and browser user agent of the submission, solely to investigate abuse of the form.

We use these details to respond to your enquiry. We do not sell them, and we do not pass them to third parties for marketing.

3. Information in the application

When your business uses ORVYNEX POS, the data you enter — your products, stock, sales, customers, suppliers, staff accounts and related records — belongs to your business. We process it in order to provide the service to you.

Each business is a separate tenant, and that separation is enforced on the server at the query layer. One customer's data is not visible to another.

4. Account and access records

The application records authentication events and administrative actions — who changed what, and when. These records exist so that you can audit activity within your own organisation, and are visible to your own administrators.

5. Cookies

The application uses a session cookie to keep you signed in and a CSRF token cookie to protect form submissions. These are necessary for the service to function. The marketing website does not use advertising or cross-site tracking cookies.

6. Retention

Enquiries submitted through this website are retained while they are commercially relevant and then removed. Business data inside the application is retained for as long as your account is active, and is handled according to your agreement with us on termination.

7. Security

Access to the application requires authentication, and every action is checked against the permissions granted to the acting user and the branches they are assigned to. Transport is encrypted. Administrative access to production data is limited to the personnel who need it to operate the service.

8. Your choices

You can ask us what enquiry details we hold about you and ask us to delete them. If you are a customer, requests relating to data held inside your own account should come from an administrator of that account.

9. Contact

Questions about this policy can be sent through the contact form.

10. Changes

If this policy changes materially, the updated version will be published on this page with a new revision date.