Skip to content
InSoftOnline

Privacy Policy — InSoft Reports

This privacy policy explains how InSoft Online processes personal data in connection with the InSoft Reports mobile application (package de.insoftonline.report_system) for Android and iOS. It supplements our website legal notice and Terms & Conditions.

Version 1.0 · Last updated 20 September 2026

1. Controller

Controller for the app and related InSoft Online cloud services is InSoft Online, Karlstraße 18, 72336 Balingen, Germany. Email: info@insoftonline.de. Phone: +49 151 16908778. Support and data-subject requests: https://support.insoftonline.de. Further company details are listed in the Impressum.

If your business uses InSoft POS under a customer contract, some data may also be processed under that agreement (controller / processor roles as defined in your InSoft contract).

2. Who the app is for

InSoft Reports is a business companion app for customers of the InSoft Odoo POS system. Authorised users can view sales and fiscal reports, manage cash expenses, perform TSE-related cash total corrections, export PDFs and manage app settings.

It is intended for business users (owners, managers, staff, accountants) who already have an InSoft customer account linked to a POS subscription. It is not intended for children under 16.

3. Purposes and legal bases

We process data to authenticate you and keep you signed in, provide app features (reports, expenses, Fix Orders, settings, PDF export), display company information where relevant, verify subscription / licence status, offer updates, improve reliability and support, and comply with legal obligations where applicable.

Where the GDPR applies, legal bases typically include Art. 6 (1) (b) (contract — providing the app and POS-related services you requested), Art. 6 (1) (f) (legitimate interests — secure operation, licence enforcement, product improvement and support), Art. 6 (1) (c) (legal obligation), and Art. 6 (1) (a) (consent where required for optional processing).

Where the merchant organisation processes business or staff data in the app, that organisation is usually the controller for that data; InSoft acts as processor under a data processing agreement where required (Art. 28 GDPR).

4. Categories of data

Account and authentication: email address / username, password (sent securely for authentication; not stored inside the app), access token after login, customer / account identifiers (for example user ID, owner number), and a support-account flag if applicable. Stored locally for session convenience: token, user ID, name, email, language preference and related session fields.

Business / company information: company name, business address, company logo, and linked POS devices / configuration needed for reports. Company name, address and logo may be cached on the device for Settings.

POS and operational data: sales reports (for example Z-Bericht / Z-report, product, tax, order, date and table reports), net / tax / gross totals, device and table information, cash / bank / printed / not-printed cash totals (TSE / Fix Orders), and cash-out / expense records. This is typically business data of your InSoft POS account and may include amounts, order references, product names, table names and tax rates.

Files you create: when you export a report, the app can create a PDF. On Android you may save it to a location you choose; on Android and iOS you may share it through the system share sheet. Files you save or share are under your control and subject to the privacy practices of the apps or services you use.

App settings and technical data: preferred language (English, German, Arabic), installed app version for update checks, download / update preferences where applicable (Android in-app update), and temporary files related to APK download/install when you choose to update.

Licence / subscription status: periodic checks whether your customer subscription for this product is active, including active / inactive status, available app version information and update download links. Inactive subscriptions may restrict access until resolved with InSoft support.

We do not use the app to track GPS location, access contacts, camera or microphone, sell personal data for advertising, or show third-party advertising networks inside the app.

5. Where data is stored

On your device: session and profile-related data (login token, account identifiers, language preference, cached company name, address and logo). Logging out, clearing app data or uninstalling removes locally stored session data.

On InSoft servers: feature requests go to InSoft backends (for example https://support.insoftonline.de and related InSoft / Odoo services), which process and store the business and account data needed to operate InSoft POS and companion apps.

If you share a PDF or open an update page in a browser, that action uses device OS features and/or third-party apps under their own privacy policies.

If InSoft or its providers process data outside the European Economic Area, we take steps required by applicable law (such as appropriate contractual safeguards) to protect personal data.

6. Data sharing

We do not sell your personal data. We may share data only as needed with InSoft Online systems and authorised staff (operate the app, POS services, support, billing, licence management), hosting / infrastructure providers under appropriate agreements, your organisation’s admins / owners of the InSoft customer account, authorities where required by law, and services you select when you share files or open external update links.

7. Retention

On device: retained while you remain signed in, or until you log out, clear app data or uninstall.

On InSoft servers: retained according to your customer relationship, InSoft service terms, fiscal / accounting needs and legal retention requirements (especially for POS / fiscal-related business records).

If you ask us to delete personal data, we will assess the request under applicable law. Some business / fiscal records may need to be retained even if app access is removed.

8. Security

We take reasonable technical and organisational measures to protect data, including authenticated API access (Bearer token), transmission to InSoft servers over HTTPS, and restricting app features to active licensed customers.

No method of transmission or storage is completely secure. Keep login credentials confidential and use device lock features.

9. Your rights

Depending on applicable law, you may have the right to access, rectify, erase (subject to legal exceptions), restrict or object to certain processing, request data portability, withdraw consent where processing is based on consent, and lodge a complaint with a supervisory authority (in Germany typically your state data protection authority / Landesdatenschutzbehörde).

To exercise these rights, contact InSoft support via https://support.insoftonline.de or email info@insoftonline.de. Much of the data shown in the app is business POS data belonging to the InSoft customer organisation; requests may need to be coordinated with the account owner / business administrator.

10. Children

The app is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data through the app, contact us so we can take appropriate action.

11. Device permissions

Internet: login, reports, expenses, licence checks and updates. Install packages (Android): install app updates you download in-app. Storage / file access (as provided by the OS): save or share PDF reports.

We request only what is needed for the feature you use.

12. Changes

We may update this privacy policy from time to time. The version date above will change when we do. Continued use of the app after changes means you acknowledge the revised policy, unless applicable law requires additional notice or consent.

13. Contact

Privacy questions and data-subject requests for InSoft Reports: https://support.insoftonline.de · info@insoftonline.de · InSoft Online, Karlstraße 18, 72336 Balingen, Germany · Phone: +49 151 16908778.