GDPR Compliance
How ERPS X applies the EU and UK General Data Protection Regulation to account data we control and to the business data you process in your workspace.
1. Scope
This page explains how ERPS X LLC, St. Petersburg, Florida, USA, meets the requirements of Regulation (EU) 2016/679 (GDPR) and the UK GDPR for customers, users and website visitors in the European Economic Area, the United Kingdom and Switzerland. It supplements the Privacy Policy, which remains the primary description of our processing.
2. Roles
| Data | ERPS X role | Your role |
|---|---|---|
| Account, billing, support, marketing and website data | Controller | Data subject |
| Customer Data in your workspace (your customers, suppliers, employees, guests, transactions) | Processor, acting on your documented instructions | Controller |
| Reseller-managed accounts | Controller for the account; processor for workspace data | Controller for workspace data; the reseller is a separate controller for its own customer relationship |
3. Principles we follow
- Lawfulness, fairness and transparency: we process data on the legal bases set out in the Privacy Policy and explain what we do in plain language.
- Purpose limitation: account and workspace data are used to provide, secure and support the Service, not for unrelated purposes.
- Data minimisation: registration asks only for what is needed to create an account and provision a workspace.
- Accuracy: you can correct account details in the panel at any time.
- Storage limitation: retention periods are published in the Privacy Policy and Terms of Service.
- Integrity and confidentiality: technical and organisational measures are described in Section 7.
- Accountability: we keep records of processing activities and review our sub-processors.
4. Legal bases for processing account data
- Article 6(1)(b) — contract: creating your account, provisioning workspaces, billing and support.
- Article 6(1)(f) — legitimate interests: security, fraud prevention, service improvement and responding to enquiries.
- Article 6(1)(a) — consent: newsletters and optional communications, withdrawable at any time.
- Article 6(1)(c) — legal obligation: retaining billing records and answering lawful requests.
5. Your rights as a data subject
For data we control, you have the following rights, which you can exercise by emailing [email protected] with the subject "GDPR request":
- Right of access (Art. 15): confirmation of processing and a copy of your personal data.
- Right to rectification (Art. 16): correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): deletion where there is no overriding legal reason to keep the data.
- Right to restriction (Art. 18): limiting processing in defined circumstances.
- Right to data portability (Art. 20): receiving your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): objecting to processing based on legitimate interests or to direct marketing.
- Rights relating to automated decisions (Art. 22): we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
- Right to lodge a complaint with the supervisory authority in your EU member state, or with the UK Information Commissioner's Office.
We respond within one month, extendable by two further months for complex requests as the GDPR allows. We will verify your identity before acting. If your personal data is held inside a customer's workspace, please contact that customer; we will support them in responding.
6. Data Processing Agreement
Customers who process personal data of EEA, UK or Swiss residents in their workspace can request a Data Processing Agreement (DPA) that incorporates the Article 28 processor terms and, where relevant, the EU Standard Contractual Clauses and UK Addendum. The DPA covers the subject matter and duration of processing, the nature and purpose, types of personal data and categories of data subjects, our obligations as processor, sub-processor management, assistance with data subject requests, breach notification, audits and deletion or return of data at the end of the service. Request it at [email protected].
7. Security measures
- HTTPS/TLS on erpsx.com, every workspace subdomain and mapped custom domains.
- A separate set of databases per company workspace, so one customer's data is not mixed with another's.
- Passwords stored using one-way hashing; email verification for new accounts; password reset by time-limited code.
- Role-based permissions inside ERPS (department locks), POS (Admin, Manager, Cashier) and RMS (Manager, Server, Cashier).
- Rate limiting and CSRF protection on sensitive forms; a panel lock screen after inactivity.
- Card payments handled entirely by Stripe; no full card numbers on our systems.
- Production access limited to authorised ERPS X staff; support access to a workspace only when you request it or to investigate a security or abuse issue.
- Regular backups to support recovery.
8. Sub-processors
We use a limited number of sub-processors to run the Service: our hosting and infrastructure providers (servers, databases, backups), transactional email delivery, Stripe for payments, and our self-hosted live-chat platform. A current list with locations is available on request. We will notify customers who hold a DPA at least 30 days before adding or replacing a sub-processor that processes their Customer Data, and they may object on reasonable data protection grounds.
9. International transfers
ERPS X LLC is established in the United States and processes data there. For transfers of personal data from the EEA, UK and Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with the technical measures above. Copies of the clauses are provided with the DPA.
10. Personal data breach notification
If we become aware of a personal data breach affecting Customer Data we process on your behalf, we will notify you without undue delay and, in any case, in time for you to meet your 72-hour obligation under Article 33. Our notice will describe the nature of the breach, the likely consequences, the measures taken and a contact point. For breaches affecting account data we control, we will notify the competent supervisory authority and affected individuals where required.
11. Retention and deletion
Workspace data is retained for the life of the subscription and for 90 days afterwards so you can export it, then deleted from production and rotated out of backups. Account and billing data retention is described in the Privacy Policy. You can request early deletion of a workspace at any time through Support.
12. Contact for data protection matters
ERPS X has not appointed a statutory Data Protection Officer. Data protection enquiries are handled by our privacy team:
Related: Privacy Policy, Cookie Policy, Terms of Service, Do Not Sell My Personal Information.