erp.io
Pricing
Log inBook a demo
HomeLegalData Processing Addendum

Legal

Data Processing Addendum

This DPA forms part of the Terms of Service and governs our processing of personal data on your instructions. It incorporates the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and the service-provider terms required by US state privacy law. Annexes I to III set out the processing details, our technical and organisational measures, and our subprocessors.

Effective
August 18, 2026
Last updated
August 18, 2026
Entity
Nead, LLC (d/b/a DEV.co)

Contents

  1. 01Parties, incorporation, and precedence
  2. 02Definitions
  3. 03Roles of the parties
  4. 04Processing on documented instructions
  5. 05Confidentiality and personnel
  6. 06Security of processing
  7. 07Sub-processors
  8. 08Assistance with Data Subject rights
  9. 09Assistance with impact assessments and consultation
  10. 10Personal Data Breach notification
  11. 11Audits and information rights
  12. 12International transfers
  13. 13Government access requests
  14. 14Return and deletion
  15. 15US State Privacy Law terms
  16. 16Liability and general
  17. 17Annex I — Description of processing
  18. 18Annex II — Technical and organisational measures
  19. 19Annex III — Sub-processors

Questions about this policy?

Nead, LLC (d/b/a DEV.co)
1425 Broadway 22689
Seattle, WA 98112
United States

[email protected]

01Parties, incorporation, and precedence

This Data Processing Addendum (“DPA”) is entered into between Nead, LLC, an Arkansas limited liability company doing business as DEV.co(“Processor,” “we,” or “us”), and the customer identified in the Agreement (“Controller,” “Customer,” or “you”).

Address: Nead, LLC, 1425 Broadway 22689, Seattle, WA 98112, United States. Contact for data protection matters: [email protected].

1.1 Incorporation

This DPA is incorporated into and forms part of the Terms of Serviceor other written agreement between the parties (the “Agreement”). It takes effect on the effective date of the Agreement and continues for as long as we process Personal Data on your behalf.

No signature is required for this DPA to apply. If your procurement process requires an executed counterpart, write to [email protected] and we will provide one, including a version incorporating your own paper where the substance is equivalent.

1.2 Order of precedence

In the event of conflict, the following order applies to the subject matter of data protection: (i) the Standard Contractual Clauses or UK Addendum, where applicable; (ii) this DPA; (iii) the Agreement. In all other respects the Agreement controls.

02Definitions

TermMeaning
Data Protection LawAll laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US State Privacy Laws.
US State Privacy LawsThe California Consumer Privacy Act as amended by the CPRA, the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon, Montana, Delaware, and comparable state laws as they take effect.
Personal DataAny information relating to an identified or identifiable natural person contained in Customer Data, and “personal information” as defined under US State Privacy Laws.
Data SubjectThe identified or identifiable natural person to whom Personal Data relates, and “consumer” under US State Privacy Laws.
ProcessingAny operation performed on Personal Data, whether or not by automated means.
Sub-processorAny third party engaged by us to process Personal Data on your behalf.
Personal Data BreachA breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
SCCsThe Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
UK AddendumThe International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018, version B1.0.
Supervisory AuthorityAn independent public authority established under Article 51 GDPR or its UK equivalent.

Terms not defined here have the meaning given in the Agreement or, failing that, in Data Protection Law.

03Roles of the parties

3.1 Controller and Processor

For Personal Data contained in Customer Data, you are the Controller(or, where you act on behalf of another controller, the processor) and we are the Processor (or sub-processor).

Under US State Privacy Laws, you are the business or controller and we are the service provider or processor.

3.2 Where we act as controller

We act as an independent controller for a limited category of data that is not Customer Data: account administration and billing contacts, support correspondence, website and marketing interactions, and security and abuse-prevention logs. That processing is governed by our Privacy Policy rather than by this DPA.

3.3 Your responsibilities as Controller

You are responsible for, and warrant that:

  • you have a valid lawful basis for the processing you instruct;
  • you have provided all required notices to Data Subjects and obtained any required consents;
  • your instructions comply with Data Protection Law;
  • the Personal Data you provide is accurate and was lawfully obtained; and
  • you have assessed the suitability of the Services for your processing, including any data protection impact assessment required by Article 35 GDPR.

04Processing on documented instructions

4.1 Scope of instructions

We will process Personal Data only on your documented instructions, which comprise: this DPA; the Agreement; the configuration choices you make within the Services, including agent authority grants and connected systems; and any further written instructions you give.

Processing is limited to what is necessary to provide, support, secure, and improve the Services for you, and to comply with law.

4.2 Unlawful instructions

We will immediately inform you if, in our opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is withdrawn, amended, or confirmed. We are not obliged to conduct a legal review of your instructions.

4.3 Legally required processing

Where we are required by Union, Member State, or other applicable law to process Personal Data beyond your instructions, we will inform you of that requirement before processing unless the law prohibits it on important grounds of public interest.

4.4 Restrictions on our use

We will not, and this is a material term:

  • sell or share Personal Data as those terms are defined under the CCPA/CPRA;
  • retain, use, or disclose Personal Data outside the direct business relationship with you, or for any purpose other than the business purposes specified in the Agreement;
  • combine Personal Data received from you with personal information received from another source, except as permitted for a service provider under US State Privacy Laws;
  • use Personal Data to train, fine-tune, or develop machine learning models, whether our own or a third party’s; or
  • use Personal Data for our own marketing or profiling purposes.

We certify that we understand these restrictions and will comply with them. We will notify you if we determine we can no longer meet these obligations.

05Confidentiality and personnel

We ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that the commitment survives the end of their engagement.

Personnel measures include:

  • access limited to personnel who require it to perform their duties, on a least-privilege basis;
  • background screening consistent with applicable law and the sensitivity of the role;
  • data protection and security training on joining and periodically thereafter;
  • documented offboarding revoking all access; and
  • production access only under time-bound, dual-approved break-glass procedures that are logged in the same audit trail as customer activity and reported to affected customers.

Routine support does not include access to Customer Data. We do not maintain a standing administrative capability to read customer records.

06Security of processing

Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects, we implement appropriate technical and organisational measures as set out in Annex II.

We regularly test, assess, and evaluate the effectiveness of those measures, and will not materially decrease the overall security of the Services during the term of the Agreement.

You are responsible for security within your own control, including the configuration choices you make, the permission grants you issue, the strength of your identity provider controls, and the security of endpoints your Users operate.

07Sub-processors

7.1 General authorisation

You give general written authorisation for us to engage Sub-processors. Current Sub-processors are listed in Annex III and maintained at /trust/subprocessors.

7.2 Obligations we impose

Each Sub-processor is engaged under a written contract imposing data protection obligations at least as protective as those in this DPA, and meeting the requirements of Article 28(3) GDPR. We remain fully liable to you for the performance of each Sub-processor’s obligations.

7.3 Notice of changes

We will give at least 30 days’ advance notice before adding a Sub-processor or materially expanding the role of an existing one. Notice is given by email to the account contact and by updating the subprocessor page with a revised date. Subscribe by writing to [email protected].

7.4 Your right to object

You may object on reasonable, good-faith data protection grounds within the notice period. We will work with you to find an alternative, which may include configuring your tenant so the Sub-processor is not used where technically feasible.

Where no reasonable alternative exists, you may terminate the affected Services without penalty and receive a pro-rata refund of prepaid unused fees.

7.5 Emergency replacement

We may engage a replacement Sub-processor without advance notice where necessary to maintain continuity or security — for example where an existing provider fails — and will notify you as soon as practicable afterwards with an explanation.

08Assistance with Data Subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to Data Subject requests to exercise rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.

8.1 Self-service

The Services provide functionality enabling you to access, correct, export, restrict, and delete Personal Data within your tenant without our involvement. In most cases you will be able to respond to a request without contacting us.

8.2 Requests received by us

If we receive a request directly from a Data Subject relating to Personal Data we process on your behalf, we will not respond substantively. We will promptly forward the request to you and, unless legally prohibited, direct the Data Subject to you.

8.3 Additional assistance

Where you require assistance beyond the self-service functionality, we will provide it within a reasonable period and at no charge for a reasonable volume of requests. We may charge our reasonable costs for assistance that is unreasonable in volume or complexity, and will tell you before incurring any charge.

09Assistance with impact assessments and consultation

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with:

  • data protection impact assessments under Article 35 GDPR;
  • prior consultation with a Supervisory Authority under Article 36 GDPR;
  • your obligations under Articles 32 to 36 GDPR; and
  • equivalent obligations under US State Privacy Laws, including data protection assessments.

Our published security documentation, this DPA including its Annexes, our subprocessor list, and our compliance page are intended to provide most of the information a DPIA requires. Where you need more, write to [email protected].

9.1 Automated decision-making

The Services include automated processing. They are not designed to make, and must not be configured to make, decisions producing legal or similarly significant effects concerning Data Subjects. Automated actors cannot release payment, change banking details, grant permissions, close an accounting period, or make a statutory filing, and those limits are not configurable.

Every automated action records the inputs read, the policy relied upon, the confidence assigned, and the alternatives rejected, which is intended to support any explanation you must give a Data Subject under Article 22(3) GDPR.

10Personal Data Breach notification

10.1 Notification to you

We will notify you without undue delay and in any event within 72 hoursof becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf.

10.2 Content of notification

To the extent information is available, notification will describe:

  • the nature of the breach, including categories and approximate number of Data Subjects and records concerned;
  • the likely consequences;
  • measures taken or proposed to address it and to mitigate adverse effects; and
  • the name and contact details of our point of contact.

Where information is not available at once, we will provide it in phases without further undue delay rather than withholding the initial notification.

10.3 Cooperation

We will reasonably cooperate with you in investigating and remediating the breach and in meeting your notification obligations to Supervisory Authorities and Data Subjects. We will not notify a Supervisory Authority or Data Subject on your behalf unless you instruct us to or we are independently required to do so.

10.4 No admission

Our notification is not an acknowledgement of fault or liability. We will not delay notification in order to determine fault.

11Audits and information rights

We will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or another auditor you mandate.

11.1 Standard process

In the first instance, we will satisfy audit requests by providing: our current security documentation; completed responses to a reasonable security questionnaire; this DPA and its Annexes; our subprocessor list; and, where available, third-party audit reports or penetration test summaries. We will respond within 30 days.

11.2 On-site audits

Where the above is genuinely insufficient, or following a Personal Data Breach affecting your Personal Data, or where a Supervisory Authority or regulator requires it, you may conduct an on-site audit subject to:

  • at least 30 days’ written notice, except where a regulator requires shorter;
  • no more than once in any twelve-month period, other than following a breach or at regulatory direction;
  • conduct during business hours, without unreasonably disrupting our operations;
  • the auditor being bound by confidentiality obligations and not being our competitor; and
  • protection of other customers’ data, our Confidential Information, and our security architecture.

On-site audits are at your expense unless they reveal our material non-compliance, in which case we bear reasonable costs.

12International transfers

We are established in the United States and our infrastructure is primarily located there. Personal Data transferred to us from the EEA, the UK, or Switzerland is transferred to a third country.

12.1 Standard Contractual Clauses

Where the GDPR applies and no adequacy decision covers the transfer, the parties agree that the SCCs apply and are incorporated into this DPA by reference, as follows:

ElementPosition
ModuleModule Two (controller to processor). Where you act as a processor for another controller, Module Three (processor to processor) applies instead.
Clause 7 (docking)Applies.
Clause 9 (sub-processors)Option 2, general written authorisation, with a 30-day notice period as set out in Section 7.3.
Clause 11 (redress)The optional independent dispute resolution paragraph does not apply.
Clause 17 (governing law)The law of Ireland.
Clause 18 (forum)The courts of Ireland.
Annex ICompleted by Annex I to this DPA below.
Annex IICompleted by Annex II to this DPA below.
Annex IIICompleted by Annex III to this DPA below.

12.2 UK transfers

Where the UK GDPR applies, the UK Addendumapplies to the SCCs. Table 1 is populated with the parties’ details in Section 1; Tables 2 and 3 refer to the SCCs and Annexes as set out above; and in Table 4, neither party may end the Addendum as set out in Section 19 of the Mandatory Clauses.

12.3 Swiss transfers

Where Swiss law applies, the SCCs apply with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and Switzerland as the forum, and with “Data Subject” extended to legal entities until Swiss law provides otherwise.

12.4 Supplementary measures and transparency

We have conducted a transfer impact assessment, available on request. Supplementary measures include encryption in transit and at rest, access controls enforced in the data layer, and the government-request commitments in Section 13.

12.5 Alternative mechanisms

If the SCCs or UK Addendum are invalidated, superseded, or become insufficient, the parties will cooperate in good faith to implement an alternative lawful transfer mechanism without undue delay.

13Government access requests

If we receive a legally binding request from a public authority for disclosure of Personal Data, we will, unless legally prohibited:

  • notify you promptly and, where possible, before disclosing;
  • provide you a reasonable opportunity to seek protective relief;
  • challenge the request where there are reasonable grounds to consider it unlawful under applicable law, including by seeking interim measures;
  • disclose only the minimum amount of Personal Data responsive to the request; and
  • document our assessment and the steps taken, and make that documentation available to you and to a Supervisory Authority on request.

Where we are prohibited from notifying you, we will use reasonable efforts to obtain a waiver of the prohibition and will notify you as soon as permitted.

We will publish aggregate statistics on government requests where we are permitted to do so. As of the effective date of this DPA, we have received no government requests for Customer Data.

14Return and deletion

On termination of the Agreement, and at your election, we will return or delete Personal Data as follows:

  • Export during the term. You may export Personal Data at any time, on a schedule you configure, in open documented formats, without a support request or fee.
  • Post-termination export. For 30 days after termination, we will on written request provide a final export at no charge.
  • Deletion. Following that period, we will delete Personal Data from live systems within 30 days and from backups within 90 days.
  • Confirmation. We will provide written confirmation of deletion and the dates on request.

We may retain Personal Data where required by Union, Member State, or other applicable law, or where subject to a legal hold. Retained data remains subject to this DPA and to the confidentiality obligations in the Agreement, and will not be processed for any purpose other than the one requiring retention.

15US State Privacy Law terms

This Section applies to Personal Data subject to US State Privacy Laws and supplements the rest of this DPA.

15.1 Service provider status

We act as a service provider under the CCPA/CPRA and as a processor under other US State Privacy Laws. Personal Data is disclosed to us solely for the limited and specified business purposes set out in the Agreement.

15.2 Our certifications

We certify that we will:

  • not sell or share Personal Data;
  • not retain, use, or disclose Personal Data for any purpose other than performing the Services, or as otherwise permitted by the CCPA;
  • not retain, use, or disclose Personal Data outside the direct business relationship between us;
  • not combine Personal Data with personal information from another source, except as permitted for a service provider;
  • comply with applicable obligations under US State Privacy Laws and provide the same level of protection they require;
  • notify you promptly if we determine we can no longer meet these obligations; and
  • grant you the right to take reasonable and appropriate steps to stop and remediate unauthorised use of Personal Data.

15.3 Sensitive personal information

We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA §1798.121 and its regulations. The Services are not designed to receive sensitive personal information, and the Agreement restricts what you may submit.

15.4 Deidentified data

Where we process deidentified data, we will take reasonable measures to ensure it cannot be associated with an individual, publicly commit to maintaining and using it only in deidentified form, and contractually obligate any recipient to the same.

16Liability and general

16.1 Liability

Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations in the Agreement, including the enhanced cap applicable to breaches of data protection and security obligations. Nothing in this DPA limits liability that cannot be limited under Data Protection Law, including liability to Data Subjects under the SCCs.

16.2 Changes to this DPA

We may update this DPA where required by a change in Data Protection Law, in transfer mechanisms, or in our processing. We will give at least 30 days’ notice of any material change and will not make a change that materially reduces the protections afforded to Personal Data.

16.3 Severability

If any provision is held invalid, the remainder continues in effect. The SCCs and UK Addendum are severable from the rest of this DPA and remain effective independently.

16.4 EU and UK representative

We have assessed that we are not currently required to appoint a representative under Article 27 GDPR or its UK equivalent, on the basis that our processing of EEA and UK Personal Data is occasional, does not include large-scale processing of special categories of data, and is unlikely to result in a high risk to Data Subjects.

We will appoint a representative and publish their details here if that assessment changes. Until then, EEA and UK Data Subjects and Supervisory Authorities may contact us directly at [email protected] or at the postal address in Section 1, and we will respond within the periods required by Data Protection Law.

17Annex I — Description of processing

A. List of parties

Data exporter: the Customer identified in the Agreement, acting as controller. Contact details and activities are as set out in the Agreement.
Data importer: Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States. Contact: [email protected]. Activities: provision of a cloud-based financial management and automation platform and related professional services. Role: processor.

B. Description of transfer

ItemDetail
Categories of Data SubjectsCustomer’s employees, contractors, and other Users; Customer’s customers and their staff; Customer’s vendors, suppliers, and their staff; Customer’s portal users; auditors and external advisers granted access.
Categories of Personal DataIdentity and contact data (name, business email, telephone, business address, job title); employment data (department, location, cost centre, employment or contractor status, loaded cost inputs where payroll is connected); commercial data (transactions, invoices, payments, contracts, projects, approvals); authentication and access data (user identifiers, authentication events, permission grants, IP address); audit records (actions taken, timestamps, actor identity, reasoning for automated actions); and content of documents Customer submits.
Sensitive dataNone is intended or required. The Agreement restricts submission of protected health information, cardholder data, biometric identifiers, and government identification numbers other than tax identifiers required for statutory reporting. Where Customer nonetheless submits such data, no additional restrictions beyond those in Annex II are applied.
Frequency of transferContinuous, for the duration of the Agreement.
Nature of processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, alignment, combination, restriction, erasure, and destruction, together with automated classification, matching, reconciliation, and generation of Output.
Purpose of processingProviding, supporting, and securing the Services; performing Professional Services; complying with law.
Retention periodFor the duration of the Agreement, plus 30 days for post-termination export, plus up to 90 days for deletion from backups. Audit records are retained for seven years by default where Customer configures that retention.
Sub-processor transfersAs set out in Annex III, for the duration of their engagement, for the purposes stated.

C. Competent Supervisory Authority

Determined in accordance with Clause 13 of the SCCs — the supervisory authority of the Member State in which the data exporter is established, or where the exporter is not established in the EEA, the authority of the Member State in which its Article 27 representative is established or in which the relevant Data Subjects are located.

18Annex II — Technical and organisational measures

The following measures are implemented and maintained. They apply to all Personal Data processed under this DPA.

AreaMeasures
Pseudonymisation and encryptionEncryption in transit using TLS 1.2 or higher with modern cipher suites. Encryption at rest using AES-256 or equivalent. Encryption keys managed by the cloud provider’s key management service with access restricted and logged.
ConfidentialityAccess control enforced in the data access layer: every query carries an actor and a scope, and a query without them fails rather than returning data. Row-level security in the database as defence in depth. One permission model governing people, automated agents, API credentials, and portal users identically. Field-level exposure control.
IntegrityAppend-only, hash-chained audit log with no update or delete path exposed to application code. Atomic, idempotent writes so no transaction posts partially and retries cannot duplicate. Property-based testing asserting accounting invariants. Release gates blocking any change that regresses correctness or calibration on held-out evaluation sets.
Availability and resilienceContinuous replication with a recovery point objective of 5 minutes. Recovery time objective of 4 hours for regional failure. Defined degradation ordering under partial failure. Availability target of 99.9% monthly, published including months below target.
RestorationBackups encrypted at rest. Restore procedures exercised quarterly against production-sized data rather than assumed.
Testing and evaluationPeriodic security testing, dependency and vulnerability scanning, and code review. Penetration testing where a current engagement exists, with summaries available under NDA.
User identification and authorisationSAML 2.0 and OIDC single sign-on, SCIM provisioning on applicable plans, enforced named individual accounts, segregation-of-duties conflicts rejected at grant time rather than reported afterwards, expiring grants for auditors and temporary access.
PersonnelConfidentiality commitments surviving engagement. Least-privilege access. Security and data protection training. Documented offboarding. Production access only via time-bound, dual-approved, logged break-glass procedures reported to affected customers.
Logging and monitoringAccess, administrative action, and security event logging. Anomaly alerting. Audit records available to Customer, including reasoning recorded for every automated action.
Physical securityProcessing takes place in cloud provider data centres with physical access controls, environmental protection, and independent third-party certification. We operate no data centre of our own.
SegregationLogical tenant isolation enforced in the data layer and again by row-level security. Separation of production, staging, and development environments. Production data is not used in non-production environments.
Sub-processor governanceSecurity assessment before engagement, written Article 28 terms, and ongoing review. Smallest defensible subprocessor list rather than a comprehensive one.
Incident responseDocumented procedure with defined roles, severity classification, 72-hour customer notification commitment, and published post-mortems for customer-affecting incidents.
Data minimisation and accuracyProcessing limited to what the Services require. Customer-controlled correction and deletion. Continuous reconciliation surfacing inconsistencies rather than absorbing them.

Certification status, stated honestly. As of the effective date we do not hold a SOC 2 Type I or Type II report, and do not hold ISO 27001. Controls are designed against the Trust Services Criteria but have not been subject to an independent examination. We state this rather than describing designed controls as though they were certified.

19Annex III — Sub-processors

The following Sub-processors are authorised as of the effective date. The current list is maintained at /trust/subprocessors and changes are notified under Section 7.3.

Sub-processorPurposePersonal DataLocation
Amazon Web Services, Inc.Compute, database, object storage, backupAll categories in Annex IUnited States
Cloudflare, Inc.DNS, TLS termination, CDN, DDoS protection, WAFRequest metadata and content in transit; no persistent storageGlobal edge; US for any logging
Anthropic, PBCLanguage model inference for agent and copilot featuresContent submitted to those featuresUnited States
Twilio SendGridTransactional and notification emailRecipient name, email address, message contentUnited States
Stripe, Inc.Payment processingBilling contact and transaction detail; card data handled by Stripe, never by usUnited States
Google LLCBusiness email, calendaring, document storageCorrespondence and business records only; not Customer Data from the ServicesUnited States

Model provider terms prohibit training on content submitted through the Services and provide for zero or limited retention solely for abuse monitoring. Agent and copilot features can be disabled at tenant level, in which case no Personal Data is transmitted to the model provider.

Requesting an executed copy

This DPA applies without signature. If your procurement process requires an executed counterpart, or you need it on your own paper, write to [email protected] and we will turn it around promptly.

Related documents: Terms of Service · Privacy Policy · Subprocessors · Compliance · Security

erp.io

ERP software with AI agents inside it — and the implementation, integration, and custom development that make it fit how you already work. We research and compare the rest of the market too, including the products we compete with.

AI
  • AI agents
  • ERP Copilot
  • Governance
  • Authority levels
  • Accuracy method
  • AI in ERP report
Platform
  • General ledger
  • Shadow ledger
  • Close
  • Reporting
  • Customer portals
  • API & MCP
Services
  • Implementation
  • Implementation rescue
  • Integration
  • Migration
  • Custom modules
  • Pricing
Research
  • ERP directory
  • Comparisons
  • Free tools
  • Guides
  • Glossary
  • Methodology
Company
  • About
  • Editorial policy
  • Partners
  • Trust center
  • Careers
  • Contact
© 2026 erp.io — a product of Nead, LLC (d/b/a DEV.co)We rank competitors honestly. No paid placement, ever.LegalPrivacyTermsDPASLACookiesStatus