1. Scope
This policy applies to the Hesba platform, website, sign-up and help pages, and the information a customer adds while managing invoices, inventory, customers, collections, and its online store.
Hesba provides operational software. The subscribing company is responsible for the accuracy of its data and for having the right to use it in the platform.
2. Data we collect
We collect the information needed to create an account, operate the service, improve it, and support customers.
- Account data: name, email, phone number, company name, and securely stored password credentials.
- Operational data entered by a company: products, invoices, customers, inventory, collections, returns, and attachments.
- Technical usage data: sign-in logs, device and browser information, network identifiers, and error logs used to secure and diagnose the service.
3. How we use data
We use data to provide the service requested by the company, not to sell the company data or use it for unrelated marketing.
- Operate the account, apply plan limits, and send registration, security, or subscription communications.
- Display invoices, inventory, and reports inside the company account and enforce permissions chosen by its administrator.
- Protect accounts, prevent misuse, and improve product performance using aggregated, non-identifying operational insights when needed.
4. Company isolation and permissions
Each company has a logically separated data space. Data from one company is not shown to users of another company.
A company administrator controls who can see or edit information. Sensitive values such as cost and profit are protected by server-side permissions, not only hidden in the interface.
5. Sharing and service providers
We do not sell company data. We may use hosting, email, backup, or payment providers to operate the service, and they only receive the minimum data needed for their role.
We may disclose data when required by law, to protect the platform and customers, or on the explicit instruction of the account-owning company.
6. Retention and deletion
We retain information while an account is active and as needed to operate records. When an account ends, its owner can request an export or deletion subject to support procedures and applicable legal or accounting obligations.
Backup copies may remain for a limited period for recovery and security before they are removed through the normal backup cycle.
7. Account security and policy updates
Use a strong, unique password, assign staff roles carefully, and disable users who no longer work for the company. Do not share sign-in details. If you suspect unauthorised access, change the password and notify support promptly.
We may update this policy as the service or legal requirements evolve. The current version and date will appear on this page, and material changes may be communicated to the account owner.

