← AXON · HR · EN

Working copy. Confirm the legal text with the controller (Leonard) or a lawyer before relying on it in production.

Privacy and GDPR

This is a working draft for AXON. Confirm the legal wording with the controller (Leonard) or a lawyer before relying on it in production.

Who

The controller is the company you signed into (tenant schema · company_id). AXON is a tool in that database — not an external DPO portal.

What is processed

  • Partners (contacts, tax ID, attachments)
  • Employees (dossier, HR files, GDPR_CONSENT document)
  • Loyalty members (loyalty_member_consents)
  • RAC renters (ID documents, card consent)
  • POS and Apps (same database, same record)

The session cookie is necessary to stay signed in. There is no marketing tracker in the ERP.

Consents

The register is Administration → GDPR. Loyalty consents stay in the existing table and appear in the same register. New partner / HR / RAC consents go to gdpr_consents.

Rights (DSAR)

Per person: JSON export and an erasure request. Erasure anonymises contact fields and deletes attachments. Accounting journals are not deleted (legal archive).

Retention

Partner, HR and RAC attachments by day count on the GDPR hub. Job: php artisan axon:gdpr-retention.

Audit

Who opened a partner, employee, loyalty or renter dossier is listed on the GDPR page.