Back to home
GDPRCCPALocal laws

Regional Privacy Addendum

Supplemental privacy terms for EU/UK, California-style laws, Iraq/KRG/GCC, and other markets.

Last updated: May 9, 2026

EU, EEA, UK, and Switzerland

  • Customers generally act as controllers for Customer Personal Data submitted to tenant modules.
  • Provider generally acts as processor for Customer Personal Data and as controller for account, billing, website, marketing, security, and business operations data.
  • International transfers require an applicable lawful mechanism where required, such as adequacy decisions, standard contractual clauses, UK transfer addenda, or another valid mechanism.

California and Similar U.S. Privacy Laws

  • Provider does not sell Customer Data or share Customer Data for cross-context behavioral advertising.
  • Provider may act as a service provider or processor for Customer Data.
  • If sale, sharing, targeted advertising, financial incentives, or non-essential tracking are introduced, notices and controls must be updated before launch.

Iraq, Kurdistan Region, GCC, and Other Markets

Local requirements may affect lawful basis, consent, notice, authorization, data localization, hosting, transfer, government access, payroll, tax, education, accounting, e-signature, and records obligations.

Sensitive and Regulated Data

Customers should not submit sensitive or regulated data unless the agreement, deployment, configuration, security controls, and applicable law support that use.

Regional Privacy Addendum — Hevra ERP