ReuseSystem — Privacy Policy

Effective date:9-14-2026

1. Who we are

ReuseSystem is operated by Telli Enterprises Ltd, a company incorporated in the Republic of Cyprus, with its registered office at:

Kiniras 4C, Geri-Dali, Nicosia 2540, Cyprus

Enquiries about this policy, and requests relating to personal data, should be addressed to Stavros Mylonas at info@tellienterprises.com.

This policy explains how we handle personal data in connection with the ReuseSystem website at www.thereusesystem.eu, the ReuseSystem mobile applications, and the ReuseSystem web applications and modules (together, "the Services").

2. Controller and processor

How we handle personal data depends on whose data it is.

We are the controller for data about visitors to our website, people who contact us, prospective customers, and the administrators and billing contacts of our business customers.

We are a processor for the personal data that our business customers enter into or generate within the Services — including records about their employees, drivers and operators, their own customers, their assets and materials, and photographs uploaded from the field. For that data the customer is the controller: they decide what is collected and why, and we process it on their documented instructions under a written agreement.

If you use ReuseSystem through your employer and want to access, correct or delete your data, contact your employer first. If you contact us, we will refer you to them and assist them in responding.

3. Personal data we handle

Account and identity data — name, work email address, telephone number, job title, employer, username, password (stored hashed), user role and permissions, language and preferences.

Data entered into the Services — records created by users in the course of their work, including contact details of customers and suppliers, collection and delivery records, asset and device records, serial numbers and condition notes, weights and material data, job notes and uploaded documents.

Attendance and time data — where the attendance module is in use: check-in and check-out times, shift records, and the record or site they relate to.

Photographs — images taken or selected through the app and attached to a record, together with the time taken and the record they belong to. The app accesses the camera or photo library only when you use that function.

Device and technical data — device model, operating system and version, app version, IP address, language and time zone, crash reports, diagnostic logs, and security and audit logs including sign-in times.

Usage data — screens viewed, features used, and dates and times of use.

Billing data — for our direct customers: company details, VAT number, billing contact, invoices and payment records. Card payments are processed by Stripe; we do not receive or store full card numbers.

We do not intentionally collect special categories of personal data, such as health or biometric data, through the Services.

4. Permissions requested by the mobile applications

Permission Purpose
Camera Taking photographs of assets, materials, documents and proof of collection or delivery
Photos, media and storage Attaching existing photographs and documents, and saving exported files
Network access Synchronising data with the ReuseSystem server

[Add any further permission the apps request, with its purpose. This table must match the Data safety declaration in Google Play Console.]

Optional permissions can be refused or withdrawn at any time in your device settings; the features that rely on them will then be unavailable.

5. Purposes and legal bases

Where we act as controller we rely on the following bases under the EU General Data Protection Regulation:

Purpose Legal basis
Providing, operating and supporting the Services; managing accounts Performance of a contract
Invoicing, payment collection and credit control Performance of a contract; legal obligation
Security, fraud prevention, audit logging and backup Legitimate interests in protecting our systems and our customers' data
Diagnosing faults and improving the Services Legitimate interests in maintaining a product our customers rely on
Responding to enquiries and support requests Performance of a contract; legitimate interests
Marketing to business contacts about our products Legitimate interests; consent where required by law
Meeting tax, accounting and regulatory obligations Legal obligation

Where we rely on consent you may withdraw it at any time, without affecting processing carried out before withdrawal.

6. Cookies

Our website uses cookies that are necessary for it to function and, subject to your choices where a consent banner is presented, cookies that help us understand how the site is used. The mobile applications use local storage and a session identifier to keep you signed in and to synchronise data. We do not use advertising identifiers, we do not sell personal data, and we do not use personal data for cross-app advertising.

7. Who we share personal data with

  • Our hosting and infrastructure provider
  • Odoo, as the platform the Services are built on
  • Providers used to deliver email and in-app notifications
  • Stripe, for payment processing
  • Our accountants, auditors and legal advisers, under confidentiality
  • Public authorities, where we are legally required to disclose
  • A buyer or successor, in the event of a merger, acquisition or restructuring

Providers acting as processors are engaged under written agreements and may process personal data only on our instructions. A current list of our sub-processors is available on request at info@tellienterprises.com.

We do not sell personal data.

8. International transfers

We are established in Cyprus. The Services are used in Cyprus, Greece, the United Arab Emirates, South Africa and other countries, so personal data may be transferred outside the European Economic Area.

Where that happens we rely on an adequacy decision of the European Commission where one applies, or otherwise on the European Commission's Standard Contractual Clauses together with any additional safeguards identified by a transfer risk assessment. A copy of the safeguards in place can be requested at info@tellienterprises.com.

Where UAE or South African law applies, we process personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and the South African Protection of Personal Information Act, 2013, as applicable.

9. How long we keep data

Customer account and content data is kept for the duration of the subscription and, after it ends, for the export period set out in our Terms and Conditions, after which it is deleted. Backups are overwritten on a rolling cycle. Security and audit logs are kept for as long as needed for security and accountability purposes. Invoicing and accounting records are kept for the period required by Cyprus tax and company law. Support correspondence and marketing contact records are kept until they are no longer needed for the purpose they were collected for, or until you unsubscribe.

Where we act as processor, retention is governed by our customer's instructions.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, hashed passwords, role-based access control, restricted administrative access, audit logging, regular backups, patching, and confidentiality obligations on our staff and contractors.

No system is completely secure. Where a personal data breach is likely to result in a risk to individuals, we will notify the competent supervisory authority and affected customers without undue delay and, where required, within 72 hours.

11. Your rights

Where we act as controller and the GDPR applies, you have the right to access your personal data and receive a copy, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict processing in certain circumstances, to object to processing based on legitimate interests and to direct marketing at any time, to receive your data in a portable format, and to withdraw consent where processing is based on it.

We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.

To exercise a right, contact Stavros Mylonas at info@tellienterprises.com. We will respond within one month, extendable by two further months for complex requests, and may ask for information to verify your identity.

You may complain to your supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia, commissioner@dataprotection.gov.cy. In the UAE and South Africa, the UAE Data Office and the Information Regulator respectively.

12. Deleting your account and your data

You can request deletion of your ReuseSystem account and the personal data associated with it at [DELETION REQUEST URL] or by emailing info@tellienterprises.com from your registered address.

If your account was created by your employer, we will pass the request to them, as they control that data.

On a valid request we delete the account profile, credentials and personal identifiers, and remove the data from backups as the backup cycle completes. We may retain records we are required by law to keep, such as invoicing records and logs needed to evidence security incidents, and anonymised statistics that cannot identify you.

Uninstalling the application does not by itself delete data already held on our servers.

13. Google Play

The mobile applications are distributed through Google Play. Google collects its own data in connection with app distribution and billing under the Google Privacy Policy; we do not control that processing.

14. Children

The Services are business tools intended for use by adults in a workplace setting. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If we become aware that we have, we will delete it.

15. Changes to this policy

We may update this policy. The current version is always published at www.thereusesystem.eu with the date it takes effect. Where a change materially affects your rights, we will notify customers by email or by notice in the application before it takes effect.

16. Contact

Telli Enterprises Ltd
Kiniras 4C, Geri-Dali, Nicosia 2540, Cyprus
info@tellienterprises.com
www.thereusesystem.eu