Privacy Policy
Last updated: 29 July 2026
1. About This Policy
This policy explains how erps.one ("we", "us", "our") handles personal data. It covers two different situations, and the difference matters, so please read Section 2 first.
Questions, or to exercise any right described here, contact privacy@erps.one.
2. Our Two Roles
We are the controller of the data we collect to run our business and provide the platform to you: your account details, your billing details, and information about how your organisation uses the Service. This policy governs that data.
We are a processorfor everything your organisation puts into the Service — records about your employees, customers, suppliers, payroll, finances and operations ("Customer Data"). Your organisation is the controller of that data and decides why and how it is processed. We handle it only on your organisation's instructions, under our Terms of Service and our Data Processing Agreement.
If you are an employee or customer of a business that uses erps.one and you want to see, correct or delete data that business holds about you, please contact that business directly. We cannot act on your request without their instruction, but we will pass it on if you write to us.
3. Data We Collect as Controller
- Account data: name, work email address, company name, job role, and a securely hashed password. If you sign in with a third-party account, we receive your name and email address from that provider — never your password.
- Billing data: company billing address, tax identifiers, subscription and invoice history. Card details are entered directly with our payment processor and are never held by us.
- Usage data: pages viewed, features used, actions taken and their timestamps, IP address, and general browser and device information.
- Security data: sign-in attempts, session and device records, and audit records of significant actions, kept to protect accounts and investigate misuse.
- Communications: messages you send us, support requests, and demo or sales enquiries.
- Cookies and similar technologies: see our Cookie Policy.
4. Customer Data We Process on Your Behalf
Depending on which modules your organisation enables, the Service may hold sensitive categories of personal data about your people and your contacts — for example government identification and bank details used for payroll, salary and benefits information, health plan enrolment, absence records, and performance records.
We do not use Customer Data for our own purposes. We do not sell it, we do not share it for advertising, and we do not use it to train machine learning models. We access it only where necessary to operate, secure or support the Service, or where your organisation asks us to. Access by our staff is limited to those who need it and is recorded.
5. How We Use Data
As controller, we use personal data to:
- Provide, maintain, secure and improve the Service
- Create and administer accounts and manage permissions
- Take payment and manage subscriptions, invoices and trials
- Send service messages such as receipts, alerts, security notices and product notifications
- Send product news and marketing where you have consented or where permitted for existing customers, always with a way to opt out
- Provide support and respond to enquiries
- Detect, investigate and prevent fraud, abuse and security incidents
- Understand aggregate usage patterns to improve the product
- Meet our legal, tax and accounting obligations and enforce our Terms
6. Legal Bases (UK / EU GDPR)
- Contract: providing the Service, administering your account, and taking payment
- Legitimate interests: keeping the Service secure, preventing fraud and abuse, improving the product, and marketing to existing business customers — balanced against your rights in each case
- Consent: optional cookies and marketing to people who are not existing customers; you may withdraw consent at any time
- Legal obligation: tax, accounting, and responding to lawful requests
Where we act as processor, your organisation is responsible for identifying the legal basis for its own processing.
7. Sharing and Sub-Processors
We share personal data only with service providers who help us run the platform, each bound by a written contract requiring confidentiality, security, and processing only on our instructions. They fall into these categories:
- Cloud hosting, storage and content delivery
- Payment processing and subscription billing
- Email delivery for service and transactional messages
- Push and in-app notification delivery
- Error monitoring, logging and platform performance measurement
- Customer support tooling
A current list of our named sub-processors is available on request from privacy@erps.one, and customers may ask to be notified of changes to it. We may also disclose data where required by law or valid legal process, to establish or defend legal claims, or to a successor in connection with a merger, acquisition or sale of assets — in which case we will notify affected customers. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
8. International Transfers
We are based in the United States and our providers may process data in the United States and other countries. Where personal data is transferred out of the UK or European Economic Area, we rely on appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission and the UK Addendum, together with additional measures where needed. Customers with data residency requirements can ask us about hosting their data in a specific region.
9. Retention
We keep account data for as long as the account is active. After an account closes, we keep data for 30 days so it can be recovered or exported, after which it is deleted from our active systems; backups expire on their ordinary cycle. Billing and tax records are kept for seven years to meet financial and legal obligations. Security and audit records are kept for as long as needed for their purpose. Customer Data is kept and deleted according to the instructions and settings of the organisation that controls it.
10. Security
We use technical and organisational measures appropriate to the risk, including encryption of data in transit and of sensitive fields at rest, separation of each customer's data, role-based access controls, audit logging of significant actions, hashed passwords, and restricted internal access on a need-to-know basis. We review these measures as the platform develops.
No system can be guaranteed completely secure. If a personal data breach occurs that affects you, we will notify the relevant supervisory authority and affected customers as required by law and without undue delay. To report a vulnerability or a suspected incident, write to security@erps.one.
11. Your Rights
Depending on where you live, you may have some or all of the following rights over personal data we hold as controller:
- Access: ask for a copy of your personal data
- Correction: have inaccurate data corrected
- Deletion: ask us to delete your data, subject to obligations that require us to keep it
- Portability: receive your data in a commonly used machine-readable format
- Restriction and objection: ask us to pause processing or object to processing based on legitimate interests, including direct marketing
- Withdraw consent: at any time, without affecting earlier processing
- US state privacy rights: residents of California and other states with comparable laws may request disclosure, deletion or correction, may opt out of any sale or sharing (we do neither), may limit the use of sensitive personal information, and will not be discriminated against for exercising these rights. You may use an authorised agent.
Email privacy@erps.one. We respond within 30 days, or 45 days where US state law allows, and may need to verify your identity first. If you are unhappy with our response you may complain to your local data protection authority.
12. Automated Decisions
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Some modules present scores, rankings or suggestions — for example in recruitment or sales — to help our customers prioritise their work. These are aids, not decisions, and the customer using them is responsible for ensuring a person makes the final call.
13. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 as controller. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to This Policy
We may update this policy. We will change the "Last updated" date above and, for significant changes, give notice by email or in the Service at least 14 days before they take effect.