Privacy Policy

Last updated: September 5, 2026

1. Who we are

Megorix is a product developed and operated by MegaPC Informática e Software, Lda., Portuguese tax ID (NIPC) 504125931, registered at Rua Álvaro Teles nº 221, Alburitel, 2490-020 Ourém, Santarém, Portugal. We are the data controller for the personal data collected through the website, the web app, and the Megorix mobile app (together, the “Service”).

The Megorix mobile app (com.megorix.app) is a native app that gives access to the same web app — admin.megorix.com — used in the browser, with a few additional phone capabilities described in section 2.5.

2. What data we collect

2.1 Account data

Name, work email, password (encrypted), organization/company, job title, and language preferences, collected when you create an account or are invited to an existing organization.

2.2 Billing data

Name/company name, billing address, and subscription history. Payment processing is handled by Stripe — we don't store your full card details on our servers.

2.3 Data you enter into the ERP

The business data you and your organization enter into Megorix (customers, invoices, inventory, HR, etc.) belongs to your organization. We process it only as a data processor, to provide the Service — we never sell it or use it for advertising.

2.4 Usage and technical data

IP address, device and browser type, pages visited, actions taken in the app, and error logs — used for security, abuse detection, and product improvement.

2.5 Mobile app permissions

The mobile app requests the following native permissions, always at the moment a specific feature needs them — never at startup — and you can decline any of them and keep using the rest of the app normally:

  • Camera and microphone — to attach photos (or, in the future, video/audio) to records in your business (e.g., a repair, an item, a material request).
  • Location — for features that depend on where you are (e.g., linking a trip to a record).
  • Push notifications — if you allow it, we store a device identifier (token) linked to your account, via Firebase Cloud Messaging (Google), solely to send you the notifications your organization has configured. The token is removed when you uninstall the app or revoke the permission.

You can revoke any of these permissions at any time in your phone's operating system settings.

2.6 Cookies

We use essential cookies (session, authentication) and, with your consent, analytics cookies. You can manage your preferences at any time via the website's cookie notice.

3. What we use your data for

  • Creating and managing your account and your organization's account;
  • Providing, maintaining, and improving the Service;
  • Processing payments and billing;
  • Sending operational communications (e.g., a change in support ticket status) and, with consent, marketing communications;
  • Preventing fraud and abuse, and keeping the platform secure;
  • Complying with legal and tax obligations.

4. Legal basis (GDPR)

We process your data based on the performance of the subscription contract (Terms of Service), compliance with legal obligations (e.g., invoicing), our legitimate interest in keeping the platform secure and functional, and, where applicable, your consent (e.g., analytics cookies, push notifications).

5. Who we share data with

We only share data with subprocessors that help us provide the Service, including:

  • Stripe — payment processing;
  • Google / Firebase — sending push notifications in the mobile app;
  • Hosting/cloud provider — hosting the infrastructure and database;
  • Email delivery service — transactional emails (password recovery, invoices, support notifications).

We do not sell your personal data or your organization's data to third parties. We only share data with authorities when required by law.

6. How long we keep data

We keep account data for as long as the subscription is active, plus any additional period required by tax and legal obligations after it ends. You can request deletion of your account at any time — see section 7.

7. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate data;
  • Request erasure of your data (the “right to be forgotten”);
  • Request portability of your data;
  • Object to processing or request that it be restricted;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with the Portuguese national data protection authority (CNPD).

To exercise any of these rights, contact us at [email protected].

8. Security

Each organization's data is isolated at the database level (Row Level Security), passwords are encrypted, and connections to the Service are always made over HTTPS. No system is 100% secure, but we work actively to protect your data.

9. Minors

The Service is intended for professional/business use and is not directed at anyone under 16.

10. Changes to this policy

We may update this policy periodically. Material changes will be communicated by email or via an in-app notice, with the “last updated” date at the top of this page revised accordingly.

11. Contact

Questions about this policy or your data: [email protected].