This Privacy Policy explains how the LeoCore ERP Mobile application (“the App”), published by SEK Solution (“we”, “us”), handles information. The App is a companion client for the LeoCore ERP platform: you connect it to your organization’s own ERP server by entering that server’s address and your account credentials. Your business data lives on, and is controlled by, that server — not by us.
1. Information the App handles
| Data | Purpose | Where it goes |
|---|---|---|
| Login credentials (username & password) | To sign you in to the ERP server you configure. | Sent over HTTPS to your ERP server. The password is never stored on the device or by us. |
| Authentication tokens | To keep you signed in and refresh your session. | Issued by your ERP server; stored in your device’s encrypted keystore. Cleared on sign-out/uninstall. |
| Device identifier | To identify and manage this device’s session and access. | A random ID generated on-device, stored locally, and sent to your ERP server at login. |
| Server address | To know which ERP server to connect to. | Stored locally on the device. |
| Business data (products, customers, suppliers, invoices, statements, stock, reports) | To display and, for supported actions, record your work. | Retrieved from and sent to your ERP server only. Owned and controlled by your organization. |
2. Camera
The App uses the camera only for scanning product barcodes and QR codes. Scanning is performed on your device (offline) — camera images are not stored, uploaded, or shared. Only the decoded code text is used to look up a product on your ERP server.
3. Fingerprint / biometric unlock
If you enable fingerprint unlock, authentication is handled entirely by your device’s operating system (Android BiometricPrompt). The App never accesses, stores, or transmits your fingerprint or any biometric data — it only receives a yes/no result from the device.
4. How information is shared
The App communicates only with the ERP server you configure. It contains no third-party advertising and no third-party analytics or tracking SDKs. We do not sell or rent any information.
For visual styling, the App may load fonts from Google’s font service on first launch; this standard web request may expose your device’s IP address to Google solely to deliver the font. No personal or business data is sent in that request.
5. Permissions
- Camera — barcode/QR scanning (optional; only when you open the scanner).
- Fingerprint / Biometric — optional app unlock.
- Internet / Network — to connect to your ERP server.
6. Data retention & security
- Locally stored items (tokens, server address, preferences, device ID) remain on your device until you sign out or uninstall the App. Signing out revokes the session and clears stored tokens.
- Communication with your ERP server uses HTTPS.
- Sensitive values are kept in the device’s encrypted storage (Android Keystore).
- An optional fingerprint lock can require your biometric to reopen the App.
7. Data controller & your rights
Your business data is controlled by your organization (the operator of the LeoCore ERP server you connect to). Requests to access, correct, export, or delete that data should be directed to your organization’s administrator. For questions about the App itself, contact us using the details below.
8. Children
The App is a business tool intended for authorized employees and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction).
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Effective” date at the top of this page.