How Abror Programming LLC collects, uses, stores and protects personal data on the AERP platform and the aerp.dev website.
This Privacy Policy explains what personal data we collect through the AERP platform, the aerp.dev website and related Telegram integrations, why we collect it, how it is used and protected, and the rights you have over it. It applies to visitors, registered users, organization administrators and employees whose data is entered into AERP by their employer. By using the Service you acknowledge this Policy; where required by law, we will additionally ask for your explicit consent (for example, for biometric attendance data).
The data controller is Abror Programming LLC, registered at Shota Rustaveli 1, house 1, Yakkasaray district, Tashkent 100070, Uzbekistan. For any privacy question or request, contact us at aerp.dev@gmail.com.
Account data: full name, surname, gender, date of birth, phone number and password (stored in hashed form).
Telegram sign-in data: when you sign in with Telegram, we receive your Telegram ID, username, first/last name and profile photo, as shared by Telegram's official OAuth login — we do not receive your Telegram password.
Verification data: one-time SMS/Telegram codes used to confirm your phone number, and the verification status of your account.
Profile and organization data: your avatar image, job title, role and permissions inside your organization's workspace, and the organizations you create or belong to.
Attendance and biometric data: if your organization enables the face-recognition attendance module, facial images captured at check-in/check-out points are processed to verify identity and record attendance for that organization's employees. This data is processed only for organizations that explicitly enable the module and is treated as a special category of personal data with additional safeguards described in Section 8.
Customer Data entered by your organization: HR records, sales, warehouse, financial and production data your organization stores in AERP, which may include personal data of your organization's employees or clients that your organization is responsible for as a data controller.
Usage and device data: log-in timestamps, IP address, browser and device type, pages visited and actions taken in the Service, collected for security, debugging and product-improvement purposes.
Communications: messages you send to our support team, Telegram bot conversations, and content of demo/quote requests submitted through the Contact page.
We use personal data to:
We process personal data on the following legal bases, as applicable: performance of the contract you enter into by using AERP (account provisioning, billing); your consent (e.g. for biometric attendance data or marketing communications, which you may withdraw at any time); our legitimate interest in securing and improving the Service; and compliance with legal obligations, including the Law of the Republic of Uzbekistan "On Personal Data".
We use strictly necessary cookies and browser storage to keep you signed in, remember your language preference, and protect the Service against fraud and abuse. We do not use third-party advertising cookies. You can control cookies through your browser settings, though disabling essential cookies may prevent you from signing in.
We do not sell personal data. We share it only in the following circumstances:
Personal data is primarily processed on servers located to serve customers in Uzbekistan and the CIS region. Where a service provider (e.g. a cloud host or Telegram) processes data outside Uzbekistan, we take reasonable steps to ensure an adequate level of protection consistent with applicable law.
Facial recognition for attendance is an opt-in module enabled only by an organization's administrator for its own employees, and is not enabled by default. Where this module is used:
We retain personal data for as long as your account or organization remains active and as needed to provide the Service. After account or organization closure, we retain data for a reasonable period to allow export and to meet legal, accounting or dispute-resolution obligations, after which it is deleted or anonymized.
We apply technical and organizational measures appropriate to the sensitivity of the data, including encrypted transport (HTTPS), hashed passwords, role-based access control, and restricted internal access to biometric and financial data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Subject to applicable law, you have the right to:
To exercise these rights, contact us at aerp.dev@gmail.com; we will respond within a reasonable time as required by applicable law.
The Service is intended for business use by adults and is not directed at individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it.
We may update this Privacy Policy to reflect changes in the Service or legal requirements. We will post the updated version here with a new "Last updated" date and, for material changes, provide additional notice through the Service, email or Telegram.
For any question, request or complaint about this Privacy Policy or your personal data, contact us at aerp.dev@gmail.com or by post at Shota Rustaveli 1, house 1, Yakkasaray district, Tashkent 100070, Uzbekistan.
Questions about this document? Write to aerp.dev@gmail.com
Back to top