Privacy Policy

1. Who we are

NEV Aftersales OS is operated by GreeSafe Limited (Hong Kong). For personal data processed through the Service, GreeSafe Limited is the controller; this policy explains what we collect and why.

2. Data we collect

Account data: name, work email, password (hashed), workshop country and time zone, WhatsApp/phone number, subscription edition and billing status.

Business data you enter: customers, vehicles, work orders, diagnostics, photos, quotes, invoices, inventory and communications.

Usage data: pages viewed, features used, device and browser type, approximate network location for security and localisation.

3. Purposes and legal bases

We process data to provide the Service (performance of contract), to secure and improve it (legitimate interests), to send service communications such as trial reminders and billing notices (contract or legitimate interests), and for optional marketing (consent, withdrawable). Where GDPR applies, these bases are set out per purpose as stated here.

4. AI features

AI assistance (diagnosis suggestions, drafting, translation) sends the minimum context needed for the request to model providers acting under our instructions. Customer data is not used to train third-party models by default, and high-risk outputs require human confirmation before actions are taken.

5. Payments

Payments (checkout, card charges, refunds and invoices) are handled by our payment provider — Airwallex as Merchant of Record — under its own privacy policy. We do not store full card numbers or equivalent payment credentials; we keep subscription and order status only for billing and settlement.

6. Processors and sharing

We share data with processors that help operate the Service under data-processing agreements, including: cloud hosting (AWS, EU region), payment and merchant-of-record services (Airwallex), communication providers (email, WhatsApp), the parts-catalogue service (epcparts.cn) and the Operator's ERP used to fulfil China supply-chain orders. We do not sell personal data.

7. International transfers

Data may be processed in the hosting regions above and, for fulfilment, in China. Where data is transferred out of the EEA or UK, we rely on adequacy decisions or standard contractual clauses with additional safeguards.

8. Retention

Account and business data are retained while your subscription is active and for a grace period after termination to allow export, after which they are deleted or anonymised, except where longer retention is required by law (for example accounting and audit records).

9. Your rights

Subject to applicable law (including GDPR where it applies), you can request access, correction, deletion, restriction, portability of your data, and object to certain processing. Workshop owners can manage member access in Settings. To exercise rights, contact us via in-app support or at support@greesafe.com.

10. Security

We apply technical and organisational measures including encryption in transit, tenant isolation, access control by role and data scope, audit logging of high-risk actions, and backups. No system is completely secure; we notify affected customers of qualifying incidents as required by law.

11. Cookies

The Service uses essential cookies and local storage for sign-in and preferences, and privacy-friendly analytics to understand feature usage. Optional analytics cookies are only set with consent where required.

12. Changes to this policy

We will announce material changes in the Service and update the date at the top of this document.