Privacy Policy
Last updated: 1 August 2026
1. Scope and Identity
ERPStack (“we”, “our”, “us”) is a systems engineering firm specializing in bespoke B2B applications. For our marketing website and tools (e.g., ROI Calculator, Architecture Grader), we act as the Data Controller. For client application hosting environments, we act strictly as a Data Processor under strict Statements of Work.
Controller of record: ERPStack. ERPStack is a remote-first software practice. It does not operate a public office, and its incorporation is in progress — registered entity details will be published here once that filing completes. Until that filing completes we publish no registered postal address rather than an unverified one; reach the controller at the address in Section 11. Section 4b sets out how transfers of EEA and UK personal data are protected in the meantime.
We have not appointed an Article 27 EU/UK representative. If you are in the EEA or UK and would prefer to raise a matter through a representative, tell us and we will nominate one for your matter at our cost. Contact our privacy officer at support@erpstack.io.
2. Data Acquisition & Categorization
We process the following data classes under secure parameters:
- Identified Contact Information: Professional name, corporate email address, and project parameters supplied during form submission.
- Tool & Form Submissions: Answers you give the Architecture Grader, ROI Calculator inputs, and anything you choose to write in a message — stored encrypted at rest (AES-256) in our database. We never ask for credentials or connection strings through this site.
- Telemetry & Access Logs: IP address, routing parameters, and request timestamps compiled via server-side log routers. We do not correlate server logs with individual PII.
- Performance Telemetry: Aggregated Core Web Vitals collected via Vercel Speed Insights, without cookies and without an individual identifier.
- A/B Experiment Assignment: if — and only if — you allow optional cookies, we store a random identifier (
es_vid) that keeps you in a consistent page variant between visits. It is a per-visitor record on this site, held for up to a year. It carries no name, email, or company, is never joined to your form submissions, is never shared, and no cross-site tracking is performed. Section 8 lists it in full.
3. Security & Database Infrastructure Safeguards
The controls below describe this website — not a generic aspiration:
- Transit & Rest Security: All endpoints enforce TLS 1.3. The site database (serverless PostgreSQL) encrypts data at rest with AES-256.
- Serverless Isolation: The site runs on immutable, per-deployment serverless functions — no long-lived servers to patch, no shells to compromise.
- Least-Privilege Data Access: Every database interaction goes through parameterized queries via a typed ORM; credentials live in platform environment vaults, never in code or the repository.
- Form Abuse Controls: Submissions pass honeypot checks and IP-based rate limiting before they are stored.
4. Subprocessors & Integrated Infrastructure
We use a small, fixed set of infrastructure subprocessors to host this site and its tools. Each one is listed here with what it does, where it runs, and the safeguards that bind it:
| Entity | Purpose | Location | Compliance Safeguards |
|---|---|---|---|
| Vercel Inc. | Serverless Edge compute and static page routing | United States / Global CDN | SOC 2 Type II, ISO 27001 |
| Amazon Web Services (AWS) | Relational data persistence and secure object backups | US-East-1 (North Virginia) / EU-West-2 (London) | SOC 1/2/3, ISO 27001, HIPAA BAA |
| Neon Inc. | Serverless PostgreSQL for site content and form submissions | US-East (AWS) | SOC 2 Type II, GDPR Data Processing Agreement (DPA) |
| Resend (Plus Five Five, Inc.) | Transactional email — your enquiry confirmation and our internal lead notification | United States | SOC 2 Type II, GDPR DPA, EU Standard Contractual Clauses |
| Upstash, Inc. | Redis used for form rate limiting — stores a hashed request counter keyed by IP for 10 minutes | United States / EU regions | SOC 2 Type II, GDPR DPA |
| Google (Tag Manager, Ireland/LLC) | Tag delivery for aggregate analytics. Loads only after you allow optional cookies | EU / United States | EU Standard Contractual Clauses, EU–US Data Privacy Framework |
4b. International Transfers of Personal Data
If you are in the EEA, the UK or Switzerland, submitting a form on this site transfers your personal data outside your jurisdiction — to us in India, and to the US-based subprocessors listed above. Neither India nor the United States benefits from a general EU adequacy decision covering these transfers, so we rely on the following safeguards under GDPR Chapter V (Articles 44–49):
- Transfers to ERPStack in India: the European Commission’s Standard Contractual Clauses (Decision 2021/914, Module One, controller-to-controller), together with the UK International Data Transfer Addendum where UK data is involved. We will send you the executed clauses on request, free of charge.
- Transfers to our subprocessors: each is bound by a Data Processing Agreement incorporating the Standard Contractual Clauses, as recorded in the table above.
- Supplementary measures: data is encrypted in transit (TLS 1.3) and at rest (AES-256); access is limited to named personnel; and we have assessed the risk of third-country government access against the limited category of data involved — business contact details and what you choose to write in a message. We do not collect special-category data through this site and ask you not to send any.
- Your alternative: if you would rather not transfer data at all, do not use the forms — email us, or ask for a call, and we will work from whatever you are comfortable sharing.
5. Legal Bases for Processing (GDPR)
We process personal data based on the following justifications:
- Contract Performance: Delivering requested technical resources, project estimates, or executing contracted systems development.
- Legitimate Interest: Protecting system integrity, preventing DDoS attacks via Edge rate-limiting, and managing active inquiries.
- Explicit Consent: Optional communication preferences, which may be rescinded at any time via written notice.
6. Retention Policies
We enforce strict data minimization regimes. Contact record submissions are archived for up to 3 years to ensure operational continuity. Server metadata and aggregated performance telemetry are purged automatically after 12 months.
7. Data Subject Rights & Cryptographic Verification
Under GDPR and UK GDPR regimes, you possess the right to access, rectify, restrict, or purge your records. To execute a Data Subject Access Request (DSAR):
- Submit your request directly to support@erpstack.io.
- Before exporting data, we verify identity via email authentication or a matching cryptographic signature check.
- DSAR reports are compiled and transmitted securely within 30 days of successful identity verification.
- Object and restrict: where we rely on legitimate interest, you may object at any time and we will stop unless we can show compelling grounds that override your rights.
- Portability: data you gave us under consent or contract will be provided in a structured, machine-readable format on request.
- Withdraw consent: withdrawable at any time, without affecting processing already carried out. For cookies, use the Decline control described in Section 8.
Right to lodge a complaint. If you believe we have handled your personal data unlawfully, you have the right to complain to a data protection supervisory authority — in the EEA, the authority in your country of residence, place of work, or where the alleged infringement occurred; in the UK, the Information Commissioner’s Office. You do not have to contact us first, though we would rather you did — we would like the chance to fix it.
7b. California Residents (CCPA / CPRA)
If you are a California resident, the following applies in addition to the rights above:
- Categories collected: identifiers (name, business email, company), commercial information (project parameters and budget band you select), and internet activity (server logs, aggregate performance telemetry). Collected directly from you, or generated by your use of the site.
- Purpose: responding to your enquiry, preparing a proposal, and protecting the site from abuse.
- We do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly collect personal information from anyone under 16.
- No sensitive personal information is collected through this site, so there is no right to limit its use to exercise.
- Your rights: to know, to delete, to correct, and not to be discriminated against for exercising them. Submit a request to support@erpstack.io; we respond within 45 days and will tell you if we need the permitted extension. An authorised agent may act for you with written permission.
8. Cookies — the complete list
This site sets two cookies. Both are first-party. There are no third-party advertising cookies, no cross-site tracking, and no data broker integrations.
| Cookie | Purpose | Lifetime | Legal basis |
|---|---|---|---|
| es_consent | Remembers whether you allowed or declined the optional cookie below, so we do not ask again | 180 days | Strictly necessary — required to honour your own choice |
| es_vid | A random identifier that keeps you in the same A/B test group between visits, so page variants do not change under you. Not linked to your name, email, or any form you submit | 365 days | Consent — set only after you select “Allow”, and deleted when you decline |
If you decline, no es_vid is written, any existing one is deleted, Google Tag Manager is not loaded, and you always see the default version of every page. Nothing else changes — no feature is withheld and no prompt is repeated.
To change your mind later, delete the es_consent cookie in your browser settings and reload; the prompt will reappear.
Aggregated Core Web Vitals are collected by Vercel Speed Insights without cookies and without an individual identifier.
9. Amendments & Contact
We update this policy periodically to reflect evolving regulatory frameworks. For inquiries regarding data protection policies, contact our systems engineering leads directly at support@erpstack.io.