Skip to main content

Privacy Policy

Last updated: 1 August 2026

1. Scope and Identity

ERPStack (“we”, “our”, “us”) is a systems engineering firm specializing in bespoke B2B applications. For our marketing website and tools (e.g., ROI Calculator, Architecture Grader), we act as the Data Controller. For client application hosting environments, we act strictly as a Data Processor under strict Statements of Work.

Controller of record: ERPStack. ERPStack is a remote-first software practice. It does not operate a public office, and its incorporation is in progress — registered entity details will be published here once that filing completes. Until that filing completes we publish no registered postal address rather than an unverified one; reach the controller at the address in Section 11. Section 4b sets out how transfers of EEA and UK personal data are protected in the meantime.

We have not appointed an Article 27 EU/UK representative. If you are in the EEA or UK and would prefer to raise a matter through a representative, tell us and we will nominate one for your matter at our cost. Contact our privacy officer at support@erpstack.io.

2. Data Acquisition & Categorization

We process the following data classes under secure parameters:

  • Identified Contact Information: Professional name, corporate email address, and project parameters supplied during form submission.
  • Tool & Form Submissions: Answers you give the Architecture Grader, ROI Calculator inputs, and anything you choose to write in a message — stored encrypted at rest (AES-256) in our database. We never ask for credentials or connection strings through this site.
  • Telemetry & Access Logs: IP address, routing parameters, and request timestamps compiled via server-side log routers. We do not correlate server logs with individual PII.
  • Performance Telemetry: Aggregated Core Web Vitals collected via Vercel Speed Insights, without cookies and without an individual identifier.
  • A/B Experiment Assignment: if — and only if — you allow optional cookies, we store a random identifier (es_vid) that keeps you in a consistent page variant between visits. It is a per-visitor record on this site, held for up to a year. It carries no name, email, or company, is never joined to your form submissions, is never shared, and no cross-site tracking is performed. Section 8 lists it in full.

3. Security & Database Infrastructure Safeguards

The controls below describe this website — not a generic aspiration:

  • Transit & Rest Security: All endpoints enforce TLS 1.3. The site database (serverless PostgreSQL) encrypts data at rest with AES-256.
  • Serverless Isolation: The site runs on immutable, per-deployment serverless functions — no long-lived servers to patch, no shells to compromise.
  • Least-Privilege Data Access: Every database interaction goes through parameterized queries via a typed ORM; credentials live in platform environment vaults, never in code or the repository.
  • Form Abuse Controls: Submissions pass honeypot checks and IP-based rate limiting before they are stored.

4. Subprocessors & Integrated Infrastructure

We use a small, fixed set of infrastructure subprocessors to host this site and its tools. Each one is listed here with what it does, where it runs, and the safeguards that bind it:

EntityPurposeLocationCompliance Safeguards
Vercel Inc.Serverless Edge compute and static page routingUnited States / Global CDNSOC 2 Type II, ISO 27001
Amazon Web Services (AWS)Relational data persistence and secure object backupsUS-East-1 (North Virginia) / EU-West-2 (London)SOC 1/2/3, ISO 27001, HIPAA BAA
Neon Inc.Serverless PostgreSQL for site content and form submissionsUS-East (AWS)SOC 2 Type II, GDPR Data Processing Agreement (DPA)
Resend (Plus Five Five, Inc.)Transactional email — your enquiry confirmation and our internal lead notificationUnited StatesSOC 2 Type II, GDPR DPA, EU Standard Contractual Clauses
Upstash, Inc.Redis used for form rate limiting — stores a hashed request counter keyed by IP for 10 minutesUnited States / EU regionsSOC 2 Type II, GDPR DPA
Google (Tag Manager, Ireland/LLC)Tag delivery for aggregate analytics. Loads only after you allow optional cookiesEU / United StatesEU Standard Contractual Clauses, EU–US Data Privacy Framework

4b. International Transfers of Personal Data

If you are in the EEA, the UK or Switzerland, submitting a form on this site transfers your personal data outside your jurisdiction — to us in India, and to the US-based subprocessors listed above. Neither India nor the United States benefits from a general EU adequacy decision covering these transfers, so we rely on the following safeguards under GDPR Chapter V (Articles 44–49):

  • Transfers to ERPStack in India: the European Commission’s Standard Contractual Clauses (Decision 2021/914, Module One, controller-to-controller), together with the UK International Data Transfer Addendum where UK data is involved. We will send you the executed clauses on request, free of charge.
  • Transfers to our subprocessors: each is bound by a Data Processing Agreement incorporating the Standard Contractual Clauses, as recorded in the table above.
  • Supplementary measures: data is encrypted in transit (TLS 1.3) and at rest (AES-256); access is limited to named personnel; and we have assessed the risk of third-country government access against the limited category of data involved — business contact details and what you choose to write in a message. We do not collect special-category data through this site and ask you not to send any.
  • Your alternative: if you would rather not transfer data at all, do not use the forms — email us, or ask for a call, and we will work from whatever you are comfortable sharing.

5. Legal Bases for Processing (GDPR)

We process personal data based on the following justifications:

  • Contract Performance: Delivering requested technical resources, project estimates, or executing contracted systems development.
  • Legitimate Interest: Protecting system integrity, preventing DDoS attacks via Edge rate-limiting, and managing active inquiries.
  • Explicit Consent: Optional communication preferences, which may be rescinded at any time via written notice.

6. Retention Policies

We enforce strict data minimization regimes. Contact record submissions are archived for up to 3 years to ensure operational continuity. Server metadata and aggregated performance telemetry are purged automatically after 12 months.

7. Data Subject Rights & Cryptographic Verification

Under GDPR and UK GDPR regimes, you possess the right to access, rectify, restrict, or purge your records. To execute a Data Subject Access Request (DSAR):

  • Submit your request directly to support@erpstack.io.
  • Before exporting data, we verify identity via email authentication or a matching cryptographic signature check.
  • DSAR reports are compiled and transmitted securely within 30 days of successful identity verification.
  • Object and restrict: where we rely on legitimate interest, you may object at any time and we will stop unless we can show compelling grounds that override your rights.
  • Portability: data you gave us under consent or contract will be provided in a structured, machine-readable format on request.
  • Withdraw consent: withdrawable at any time, without affecting processing already carried out. For cookies, use the Decline control described in Section 8.

Right to lodge a complaint. If you believe we have handled your personal data unlawfully, you have the right to complain to a data protection supervisory authority — in the EEA, the authority in your country of residence, place of work, or where the alleged infringement occurred; in the UK, the Information Commissioner’s Office. You do not have to contact us first, though we would rather you did — we would like the chance to fix it.

7b. California Residents (CCPA / CPRA)

If you are a California resident, the following applies in addition to the rights above:

  • Categories collected: identifiers (name, business email, company), commercial information (project parameters and budget band you select), and internet activity (server logs, aggregate performance telemetry). Collected directly from you, or generated by your use of the site.
  • Purpose: responding to your enquiry, preparing a proposal, and protecting the site from abuse.
  • We do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly collect personal information from anyone under 16.
  • No sensitive personal information is collected through this site, so there is no right to limit its use to exercise.
  • Your rights: to know, to delete, to correct, and not to be discriminated against for exercising them. Submit a request to support@erpstack.io; we respond within 45 days and will tell you if we need the permitted extension. An authorised agent may act for you with written permission.

8. Cookies — the complete list

This site sets two cookies. Both are first-party. There are no third-party advertising cookies, no cross-site tracking, and no data broker integrations.

CookiePurposeLifetimeLegal basis
es_consentRemembers whether you allowed or declined the optional cookie below, so we do not ask again180 daysStrictly necessary — required to honour your own choice
es_vidA random identifier that keeps you in the same A/B test group between visits, so page variants do not change under you. Not linked to your name, email, or any form you submit365 daysConsent — set only after you select “Allow”, and deleted when you decline

If you decline, no es_vid is written, any existing one is deleted, Google Tag Manager is not loaded, and you always see the default version of every page. Nothing else changes — no feature is withheld and no prompt is repeated.

To change your mind later, delete the es_consent cookie in your browser settings and reload; the prompt will reappear.

Aggregated Core Web Vitals are collected by Vercel Speed Insights without cookies and without an individual identifier.

9. Amendments & Contact

We update this policy periodically to reflect evolving regulatory frameworks. For inquiries regarding data protection policies, contact our systems engineering leads directly at support@erpstack.io.

Explore Custom ERP Solutions by Location, Industry, and Alternatives

Global Architectures