ModApp

Data Governance & Compliance

Privacy Policy

Last Updated: September 30, 2026 • Effective Immediately

1 Commitment to Tenant Data Isolation

ModApp is an enterprise ERP and CRM platform engineered as a modular monolith. Unlike multi-tenant platforms that mingle records in shared tables without boundaries, ModApp enforces strict architectural isolation:

  • Dynamic Query Filtering: Every entity framework query is parameterized dynamically with the tenant identifier, preventing cross-tenant leakage.
  • 32 Isolated Data Stores: Each business module manages its own persistence context, ensuring that accounting ledgers, employee records, and customer pipelines remain segregated.
  • Self-Hosted Independence: When deployed on private dedicated infrastructure, your company retains 100% control of all database files, backups, and encryption keys.

2 Information We Collect

Depending on how you interact with our platform and services, we collect:

Account & Registration

Company name, admin user name, business email address, phone number, and encrypted authentication credentials.

Inquiry & Support Data

Contact form submissions, support ticket messages, and correspondence sent to our direct email channels.

Commercial Billing (Optional)

Payment gateway customer identifiers (Stripe, PayPal, Adyen). Payment credentials are processed directly by gateways; ModApp never stores raw credit card numbers.

System Audit & Logs

Immutable audit logs of administrative actions, user login timestamps, and error diagnostics for troubleshooting.

3 How We Use Your Information

We process collected information solely for legitimate enterprise operations:

  • To provision, initialize, and maintain your tenant instance and elected modules.
  • To authenticate authorized personnel and enforce role-based access permissions.
  • To send transactional emails, verification codes, invoice notifications, and workflow approval alerts via configured SMTP services.
  • To respond to technical inquiries and support requests within our guaranteed service levels.
  • We do not sell, rent, or monetize tenant data to advertising brokers or external third parties.

4 Data Security & Encryption Standards

We employ defense-in-depth security measures to protect business-critical assets:

  • Transport Security: All web traffic is strictly encrypted in transit using TLS 1.3 / HTTPS.
  • Secret Storage: Third-party API keys, payment webhook secrets, and SMTP credentials are encrypted at rest using industry-standard cryptographic algorithms.
  • Database Backups: Automated SQL Server backups can be scheduled and encrypted before transfer to secure cloud storage repositories (e.g. Google Drive enterprise adapters).

5 Your Rights & Regulatory Compliance (GDPR / CCPA)

In accordance with global privacy frameworks, tenant administrators and individual end-users possess the following rights:

  • Access & Export: Request a complete export of your organization's structured data across all 30 modules.
  • Rectification: Correct inaccurate employee, partner, product, or company profile records directly via self-service interfaces.
  • Data Deletion: Upon conclusion of your contract or written request, all associated database records, file attachments, and audit trails will be permanently purged in accordance with our data retention schedule.

6 Privacy Contacts & Inquiries

If you have questions regarding this Privacy Policy or wish to exercise your data rights, please contact our data governance officers directly:

Primary Officer
sameth@qq.com
Technical Governance
waqarhabibmit@yahoo.com