erp.io
Pricing
Log inBook a demo
HomeLegalPrivacy Policy

Legal

Privacy Policy

What personal information Nead, LLC collects, why, who we share it with, how long we keep it, and the rights you have over it. Section 3 explains the distinction between information we control and customer data we merely process — that distinction determines who you exercise your rights against, and it is the first thing worth reading.

Effective
August 18, 2026
Last updated
August 18, 2026
Entity
Nead, LLC (d/b/a DEV.co)

Contents

  1. 01Who we are and how to reach us
  2. 02Definitions
  3. 03Scope — what this policy does and does not cover
  4. 04Notice at collection
  5. 05Information we collect
  6. 06How we use personal information
  7. 07Legal bases for processing (EEA, UK, Switzerland)
  8. 08Cookies and similar technologies
  9. 09When we share personal information
  10. 10Service providers and subprocessors
  11. 11International data transfers
  12. 12How long we keep information
  13. 13Security
  14. 14Data breach notification
  15. 15Your rights under GDPR and UK GDPR
  16. 16Your rights under US state privacy laws
  17. 17Additional California disclosures
  18. 18Other state-specific notices
  19. 19Automated decision-making and profiling
  20. 20Artificial intelligence and model training
  21. 21Financial information and GLBA
  22. 22Marketing communications
  23. 23Job applicants and personnel
  24. 24Children's privacy
  25. 25Third-party links and services
  26. 26Accessibility of this notice
  27. 27Governing law
  28. 28Changes to this policy

Questions about this policy?

Nead, LLC (d/b/a DEV.co)
1425 Broadway 22689
Seattle, WA 98112
United States

[email protected]

01Who we are and how to reach us

This Privacy Policy is issued by Nead, LLC, an Arkansas limited liability company doing business as DEV.co(“Nead,” “we,” “us,” or “our”). We operate the website at erp.io and provide the erp.io software service and related professional services.

PurposeContact
Privacy questions and rights requests[email protected], subject “Privacy”
Rights request appeals[email protected], subject “Privacy Appeal”
Security reports[email protected], subject “Security”
PostalNead, LLC, 1425 Broadway 22689, Seattle, WA 98112, United States

1.1 Data Protection Officer

We have not appointed a Data Protection Officer. We have assessed that we are not required to under Article 37 GDPR: our core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor large-scale processing of special categories of data. Privacy matters are handled directly by our leadership team.

1.2 EU and UK representative

We have assessed that we are not currently required to appoint a representative under Article 27 GDPR or its UK equivalent, on the basis that our processing of EEA and UK personal data is occasional, does not include large-scale processing of special categories, and is unlikely to result in a high risk to individuals.

If that assessment changes we will appoint a representative and publish their details here. Until then, EEA and UK individuals and supervisory authorities may contact us directly at the addresses above, and we will respond within the periods required by law.

1.3 Response times

We acknowledge privacy requests within five business days and respond substantively within the statutory period — one month under GDPR, extendable by two months for complex requests with notice; 45 days under most US state laws, extendable by a further 45 days with notice.

02Definitions

TermMeaning
Personal information / personal dataInformation that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable individual or household.
Controller / businessThe party determining the purposes and means of processing. We are the controller for Site and Business Information.
Processor / service providerA party processing on a controller’s documented instructions. We are the processor for Customer Data.
Customer DataInformation a customer organisation loads into, or connects to, the erp.io service — financial records, transactions, documents, and information about that customer’s own people, customers, and vendors.
Site and Business InformationInformation we collect through our website, marketing, sales, support, and business operations. This policy governs it.
Sensitive personal informationAs defined in the CCPA §1798.140(ae) and comparable state law — including government identifiers, precise geolocation, racial or ethnic origin, and account credentials.
Sale and shareAs defined in the CCPA. We do neither. See Section 9.
SubprocessorA third party we engage that may process Customer Data on a customer’s behalf. Listed at /trust/subprocessors.

03Scope — what this policy does and does not cover

This distinction determines who you exercise your rights against, so it comes before everything else.

Site and Business InformationCustomer Data
What it isEnquiries, assessments, correspondence, website usage, billing contacts, job applicationsFinancial records and personal data inside a customer’s erp.io tenant
Our roleController / businessProcessor / service provider
Governed byThis policyThe customer’s agreement with us, including the Data Processing Addendum
Who you contact for rightsUs, at [email protected]The customer organisation that holds the relationship with you

3.1 If your data is in a customer’s tenant

If you are an employee, customer, or vendor of a business that uses erp.io, your information may be in their tenant. We process it on their instructions and cannot lawfully act on your request without their authority.

Contact that organisation directly. If you contact us instead, we will promptly forward your request to them and, unless legally prohibited, tell you we have done so. We will assist them in responding as required by Article 28 GDPR and comparable US state law.

3.2 What this policy covers

  • The erp.io website, including forms, assessments, calculators, and interactive tools;
  • contact with us by email, telephone, or a form;
  • administration of a customer relationship, including billing and support contacts;
  • recruitment and job applications; and
  • our business operations, including vendor management and marketing.

04Notice at collection

This section satisfies the notice-at-collection requirement under CCPA §1798.100(a) and comparable state law. It summarises what we collect, why, how long we keep it, and who we disclose it to. Detail follows in Sections 5 to 12.

CategoryPurposeRetentionDisclosed to
Identifiers
Name, email, phone, IP address, account identifier
Responding to enquiries, providing services, security, billing24 months from last contact; relationship + 7 years for customersHosting, email delivery, payment processing providers
Commercial information
Services enquired about or purchased, transaction history
Providing services, billing, account managementRelationship + 7 yearsHosting, payment processing, professional advisers
Internet or network activity
Pages viewed, interactions, referring URL, device data
Improving the site, security, abuse preventionUp to 13 months (analytics); 12 months (security logs)Hosting, analytics providers
Professional or employment information
Job title, employer, organisation size, systems in use
Preparing a response to your enquiry, tailoring an assessment24 months from last contactHosting, email delivery
Inferences
Likely fit, probable requirements
Preparing a written assessment you requested24 months from last contactNot disclosed externally
Audio or visual
Call or meeting recordings, where you consent
Accuracy of notes and follow-up12 monthsMeeting platform provider

4.1 What we do not collect

We do not knowingly collect through our website: biometric identifiers; precise geolocation; government identification numbers; payment card numbers; financial account credentials; or special categories of data under Article 9 GDPR such as health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sexual orientation.

We do not collect or process sensitive personal information as defined by the CCPA for any purpose that would trigger a right to limit its use.

05Information we collect

5.1 Information you provide

  • Contact and business details. Name, work email, telephone, company, job title, submitted through assessment forms, demo requests, contact forms, or newsletter sign-up.
  • Assessment and tool responses. Approximate revenue band, entity count, accounting system, other systems in your stack, and free-text descriptions of problems you are trying to solve.
  • Engagement information. Correspondence, meeting notes, and documents you provide during an engagement.
  • Support and correspondence. The content of emails, tickets, and other communications, together with our responses.
  • Billing information. Billing contact, address, and purchase order references. Card details are handled by our payment processor and never reach us.
  • Recruitment information. Application materials, employment history, and information from references you nominate.

Our website tools run locally. The total cost calculator, migration estimator, implementation risk score, AI readiness assessment, and chart of accounts generator all execute entirely in your browser and transmit nothing to us. Data reaches us only when you complete and submit a form.

5.2 Information collected automatically

  • Device and connection data. IP address, browser type and version, operating system, screen characteristics, referring URL, language preference.
  • Usage data. Pages viewed, time on page, links followed, navigation patterns.
  • Approximate location. Derived from IP address at country or region level. We do not collect precise geolocation.
  • Security and abuse-prevention data. Form submission records including timestamps and IP address, used to enforce rate limits and detect automated abuse.

5.3 Information from others

  • Service providers. Aggregated or technical information about interactions with our communications and site.
  • Publicly available sources. Company information such as industry, size, and public filings, used to prepare for a conversation you requested.
  • Referrals. Contact information provided when a partner, adviser, or customer introduces you. Where a partner receives a referral fee, our partner terms require them to disclose that to you, and we will confirm it if you ask.

5.4 Records of processing

We maintain records of processing activities as required by Article 30 GDPR, covering both our controller and processor activities. These are available to a supervisory authority on request.

06How we use personal information

PurposeWhat this involves
Responding to enquiriesPreparing and sending the written assessment, proposal, or answer you requested, and following up.
Providing servicesDelivering the software service and professional services, account administration, and support.
Billing and collectionInvoicing, payment processing, and recovery of amounts due.
Improving the site and productUnderstanding which pages and tools are useful, identifying errors, prioritising work.
Marketing communicationsOccasional updates about research, product, or services where requested or permitted by law.
Security and abuse preventionRate limiting, detecting automated abuse, investigating misuse, protecting our systems.
Legal and complianceMeeting legal, accounting, tax, and regulatory obligations; establishing, exercising, or defending legal claims.
RecruitmentAssessing applications and communicating with candidates.
Corporate transactionsEvaluating, negotiating, or completing a merger, acquisition, financing, or sale of assets, subject to Section 9.

6.1 What we do not do

  • We do not sell personal information, and have not in the twelve months preceding the effective date.
  • We do not share personal information for cross-context behavioural advertising.
  • We do not use personal information collected through our website to train machine learning models.
  • We do not engage in automated decision-making producing legal or similarly significant effects. See Section 19.
  • We do not enrol you in a drip marketing sequence when you submit a form. Submitting a form results in a written reply from a person.
  • We are not a data broker and are not registered as one in any state, because we do not sell data to third parties with whom the individual has no direct relationship.

07Legal bases for processing (EEA, UK, Switzerland)

Legal basisWhen we rely on it
Contract
Art. 6(1)(b)
Providing contracted services, administering the account, billing, and support.
Legitimate interests
Art. 6(1)(f)
Responding to business enquiries you initiate; improving our site and product; securing our systems and preventing abuse; direct marketing to business contacts; and defending legal claims.
Consent
Art. 6(1)(a)
Non-essential cookies and analytics where consent is required; marketing email where consent is the applicable basis; call recording. Withdrawable at any time without affecting prior processing.
Legal obligation
Art. 6(1)(c)
Retaining records for tax, accounting, and corporate purposes; responding to lawful requests from authorities.

7.1 Our legitimate interests assessment

Where we rely on legitimate interests, we have carried out a balancing assessment considering the purpose, necessity, and impact on you. In summary: the processing is limited to business contact information in a business context; you initiated contact in most cases; the impact is minimal; and you can object at any time. A copy of the assessment is available on request.

You have the right to object to processing based on legitimate interests as described in Section 15. Where you object to direct marketing, we will stop without requiring a reason.

08Cookies and similar technologies

We use a deliberately small number of cookies. We do not use advertising cookies, retargeting pixels, or third-party tracking networks on this site. Full detail is in our Cookie Policy.

CategoryPurposeDurationConsent
Strictly necessarySecurity, load balancing, rate limiting, form integritySession to 12 monthsNot required
PreferenceLight or dark theme choice, stored in browser local storage rather than transmittedUntil clearedNot required
AnalyticsAggregated understanding of page and tool usage, configured to limit identifying detailUp to 13 monthsRequested where law requires

8.1 Global Privacy Control

We honour the Global Privacy Control signal where transmitted, treating it as a valid opt-out of sale and of sharing for cross-context behavioural advertising — notwithstanding that we engage in neither — and as an opt-out of non-essential analytics.

There is no common industry standard for Do Not Track browser signals, and we do not respond to them differently from GPC.

09When we share personal information

We share personal information only as described below. We do not sell, rent, or trade it.

  • Service providers. Vendors processing on our behalf under written contracts restricting their use to providing services to us. Categories in Section 10.
  • Professional advisers. Lawyers, accountants, auditors, and insurers, where reasonably necessary and subject to professional confidentiality.
  • Legal requirements. Where required by law, regulation, court order, subpoena, or valid legal process, or where necessary to establish, exercise, or defend legal claims.
  • Safety and enforcement. Where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Nead, our customers, or the public, including investigating fraud or security incidents.
  • Corporate transactions. In a merger, acquisition, reorganisation, financing, or sale of assets, personal information may transfer as a business asset. We will require the recipient to honour commitments in this policy and will notify affected individuals where required by law.
  • With your direction. Where you ask us to share information with an adviser or partner you nominate.

Government and law enforcement requests. We will not disclose Customer Data to a government authority unless legally compelled. Where compelled, we will — unless legally prohibited — notify the affected customer before disclosing, give them a reasonable opportunity to seek protective relief, challenge the request where there are reasonable grounds to consider it unlawful, and disclose only the narrowest responsive set. As of the effective date we have received no government requests for Customer Data.

10Service providers and subprocessors

Each is bound by a written agreement requiring appropriate security, restricting use to providing services to us, and — where the GDPR applies — meeting Article 28 requirements.

CategoryPurposeData involved
Cloud hosting and infrastructureRunning the website and serviceAll categories, encrypted at rest and in transit
Content delivery and securityDNS, TLS, DDoS protection, WAFRequest metadata in transit
Transactional email deliveryForm submissions and service emailName, email address, message content
Website analyticsAggregated usage measurementDevice data, usage data, truncated IP
AI model providersPowering product featuresContent submitted to those features; see Section 20
Payment processingCollecting feesBilling contact and transaction detail
Business productivity and storageInternal operations and correspondenceCorrespondence and business records

Named subprocessors used in providing the service, with processing locations, are maintained at /trust/subprocessors. Customers receive 30 days’ notice of changes and may object as set out in the Data Processing Addendum.

11International data transfers

We are based in the United States and our infrastructure is primarily located there. If you are outside the United States, information you provide will be transferred to, stored in, and processed in the United States, which may not provide the same level of protection as your home jurisdiction.

Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on:

  • the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum where the UK GDPR applies, and the Swiss adaptations where Swiss law applies;
  • supplementary technical and organisational measures including encryption in transit and at rest and access controls enforced in the data layer; and
  • the government-request commitments in Section 9.

We have conducted a transfer impact assessment. A copy, and copies of the safeguards we rely on, are available by writing to [email protected]. We may redact commercially sensitive terms.

If the SCCs or UK Addendum are invalidated or become insufficient, we will implement an alternative lawful mechanism without undue delay.

12How long we keep information

CategoryRetention periodRationale
Enquiry and assessment submissions24 months from last contactLegitimate interest in continuity of business conversation
Customer account and contact recordsRelationship + 7 yearsStatute of limitations and tax record requirements
Correspondence and support records36 months from last messageService continuity and dispute defence
Marketing subscription recordsUntil unsubscribeConsent-based
Unsubscribe suppression recordsIndefiniteLegal obligation not to contact you again
Website analyticsUp to 13 monthsYear-over-year comparison
Security and abuse-prevention logs12 monthsIncident investigation
Financial and tax records7 yearsLegal obligation
Recruitment records12 months after a decisionDiscrimination claim limitation period; longer with consent
Call or meeting recordings12 monthsAccuracy of notes

Retention of Customer Data is governed by the customer agreement: deleted from live systems within 30 days of termination and from backups within 90 days, with written confirmation of dates on request.

Where we are subject to a legal hold, we retain relevant information for the duration of the hold notwithstanding the periods above, and process it only for the purpose requiring retention.

13Security

We maintain technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, and destruction. Full detail is in Annex II of the Data Processing Addendum. In summary:

  • encryption in transit using TLS 1.2 or higher, and encryption at rest;
  • access control enforced in the data access layer, with tenant isolation additionally enforced by row-level security in the database;
  • one permission model governing people, automated agents, API credentials, and portal users identically;
  • role-based, least-privilege access for our personnel, with production access requiring time-bound, dual-approved break-glass procedures that are logged and reported to affected customers;
  • an append-only, hash-chained audit log with no update or delete path exposed to application code;
  • network segmentation, logging, and anomaly monitoring;
  • security assessment of vendors before engagement; and
  • quarterly testing of backups and restoration procedures against production-sized data.

No system is completely secure and we do not claim otherwise. Our certification status, including the certifications we do not hold, is published at /trust/compliance.

14Data breach notification

If we become aware of a personal data breach, we will act as follows.

RecipientTimingBasis
Affected customers (as controller)Without undue delay, and within 72 hours of confirmationArticle 33(2) GDPR and our DPA commitment
Supervisory authority (where we are controller)Within 72 hours of becoming aware, unless unlikely to result in riskArticle 33(1) GDPR
Affected individuals (where we are controller)Without undue delay where high risk to rights and freedomsArticle 34 GDPR
US state notificationWithin statutory periods, which vary by stateApplicable state breach notification law

Notification will describe the nature of the breach, categories and approximate numbers affected, likely consequences, measures taken and proposed, and a point of contact. Where full information is not immediately available we provide it in phases rather than delaying the initial notification.

We will not delay notification in order to determine fault, and notification is not an acknowledgement of liability.

14.1 Reporting a vulnerability to us

Write to [email protected]with “Security” in the subject line. We acknowledge within one business day and will not pursue legal action against good-faith research conducted within the bounds set out in our Acceptable Use Policy.

15Your rights under GDPR and UK GDPR

If you are in the EEA, UK, or Switzerland, you have the following rights in respect of personal data for which we are the controller:

  • Access. Confirmation of whether we process your data and a copy of it, with information about the processing.
  • Rectification. Correction of inaccurate data and completion of incomplete data.
  • Erasure. Deletion where a ground in Article 17 applies.
  • Restriction. Restriction of processing in the circumstances in Article 18.
  • Portability. Data you provided, in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible.
  • Objection. To processing based on legitimate interests, and at any time to direct marketing.
  • Withdrawal of consent. At any time, without affecting the lawfulness of prior processing.
  • Rights relating to automated decisions. See Section 19.
  • Complaint. To a supervisory authority in your country of residence, place of work, or the place of an alleged infringement.

15.1 Exercising these rights

Write to [email protected]. We may ask for information to verify your identity, using data already in our possession where possible — typically confirming control of the email address on the record. We will not request government identification unless the sensitivity of the request requires it.

We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies and why. There is no charge unless a request is manifestly unfounded or excessive, in which case we will explain the charge before proceeding.

16Your rights under US state privacy laws

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other states with comparable laws as they take effect have the rights below.

  • Right to know or access. The categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties to whom it was disclosed.
  • Right to delete. Deletion of personal information we collected from you, subject to statutory exceptions.
  • Right to correct. Correction of inaccurate personal information.
  • Right to data portability. A copy in a portable, readily usable format.
  • Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We honour GPC signals regardless.
  • Right to opt out of targeted advertising. We do not engage in targeted advertising.
  • Right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do not conduct such profiling. See Section 19.
  • Right to limit use of sensitive personal information. We do not collect or use sensitive personal information for purposes triggering this right.
  • Right to non-discrimination. We will not deny services, charge different prices, or provide a different quality of service because you exercised a privacy right.
  • Right to appeal. Where your state provides it, you may appeal a refusal. See 16.2.

16.1 Verification and authorised agents

We verify identity using information already in our possession, typically by confirming control of the email address associated with the record. For requests involving deletion or specific pieces of information we may require additional confirmation proportionate to the sensitivity.

An authorised agent may submit a request with written authorisation signed by you. We may contact you directly to confirm the authorisation and the request, unless the agent provides a valid power of attorney.

16.2 Appeals

If we decline a request, you may appeal by writing to [email protected]with “Privacy Appeal” in the subject line. We will respond within the statutory period — 45 days in most states — with a written explanation. If we deny the appeal, we will tell you how to contact your state attorney general.

16.3 Categories collected in the preceding 12 months

Identifiers; commercial information; internet or network activity; professional or employment-related information; inferences drawn for the limited purpose of preparing a response to your enquiry; and audio recordings where you consented. We have not collected biometric information, precise geolocation, or sensitive personal information through our website. We have not sold or shared any category.

17Additional California disclosures

17.1 Shine the Light — Civil Code §1798.83

California residents may request information about disclosure of personal information to third parties for their direct marketing purposes.

We do not disclose personal information to third parties for their direct marketing purposes, and have not in the preceding calendar year. To make a request anyway, write to [email protected]with “Shine the Light” in the subject line. We will respond within 30 days.

17.2 Financial incentives — §1798.125(b)

We do not offer financial incentives, price differences, or service-level differences in exchange for the retention or sale of personal information. There is no loyalty programme, no discount for providing data, and no premium charged for exercising a privacy right.

Our research benchmark programme, where customers may opt in to contribute aggregated de-identified statistics, is not a financial incentive programme. Participation has no effect on pricing, service level, support, or feature access, and opting out changes nothing.

17.3 Notice of right to opt out

Because we do not sell or share personal information, we are not required to and do not provide a “Do Not Sell or Share My Personal Information” link. If that ever changes, the link will appear on this page and in the site footer before any such processing begins.

17.4 Minors under 16

We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age, and we do not knowingly collect information from anyone under 16.

17.5 Data broker registration

We are not a data broker under California Civil Code §1798.99.80 or comparable law in any state, and are not registered as one, because we do not knowingly collect and sell personal information about consumers with whom we have no direct relationship.

18Other state-specific notices

18.1 Washington My Health My Data Act

We are physically located in Washington State. We do not collect, process, or share consumer health data as defined by the Washington My Health My Data Act, and our services are not designed to receive it. We therefore do not maintain a separate consumer health data privacy policy.

Our agreement restricts customers from submitting protected health information to the Services. If you believe consumer health data has reached us, write to [email protected] and we will investigate and delete it.

18.2 Nevada — NRS 603A

Nevada residents may submit a verified request directing us not to sell covered information. We do not sell covered information, but you may submit a request to [email protected] and we will respond within 60 days.

18.3 Colorado, Connecticut, Virginia, and universal opt-out

We honour universal opt-out mechanisms including Global Privacy Control as required by Colorado, Connecticut, and other state law, treating them as opt-outs of sale, sharing, targeted advertising, and non-essential analytics.

18.4 Illinois and Texas biometric laws

We do not collect, capture, purchase, or otherwise obtain biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act or the Texas Capture or Use of Biometric Identifier Act.

19Automated decision-making and profiling

19.1 In respect of Site and Business Information

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR.

We do not use automated lead scoring to decide whether to respond to you, and we do not price differently based on inferred characteristics. A person reads your enquiry and a person writes the reply.

19.2 In respect of the Services

The erp.io service includes automated agents that perform bookkeeping and operational work within an authority a customer configures. Where this processes personal data, the customer is the controller and their own privacy notice governs.

The Services are not designed to make, and must not be configured to make, decisions producing legal or similarly significant effects concerning individuals — including credit, employment, housing, insurance, or benefits decisions. Our Terms and Acceptable Use Policy prohibit such use.

19.3 Fixed limits on automation

Regardless of configuration, no automated agent may release payment, create a vendor or change vendor banking details, grant or modify permissions, close an accounting period, or make a statutory filing. These require a human actor and the limits are not configurable by customers or by us.

19.4 Explainability

Every automated action records the inputs read, the policy relied upon, the confidence assigned, and the alternatives rejected. This is intended to support meaningful information about the logic involved where a controller must provide it under Article 15(1)(h) or Article 22(3) GDPR.

20Artificial intelligence and model training

  • We do not train models on Customer Data. We do not fine-tune, train, or otherwise use Customer Data to develop or improve machine learning models, whether our own or a third party’s. This is a contractual commitment in our Terms, not a policy statement we could quietly change.
  • We do not train models on Site and Business Information either — enquiries, correspondence, and website interactions are not used for model development.
  • Provider agreements prohibit training. Our agreements with AI model providers prohibit use of content submitted through our service to train their models, and provide for zero or limited retention solely for abuse monitoring.
  • Content is transmitted only to generate a response for a feature the customer has enabled, and only the content that feature requires. There is no background process streaming data to a third party.
  • Improvements come from elsewhere. We improve agent behaviour through prompts, policies, and evaluation sets built from our own synthetic and internal test data.
  • Research aggregates are computed, not learned. Published benchmarks come from customers who opted in, aggregated so no customer is identifiable, and never from fewer than five contributing customers.
  • AI features can be disabled entirely at tenant level, in which case no data is transmitted to a model provider and the rest of the service continues to function.

Further detail is published at /trust/ai-data, and the current model provider is listed at /trust/subprocessors.

21Financial information and GLBA

Because the Services process financial records, buyers reasonably ask about the Gramm-Leach-Bliley Act. This section states our position.

21.1 Our assessment

We are not a “financial institution” under the GLBA and its implementing regulations, including the FTC Safeguards Rule at 16 CFR Part 314. We do not engage in activities financial in nature under the Bank Holding Company Act: we do not lend, transfer, exchange, invest for others, safeguard money or securities, underwrite, broker, or provide financial advisory services.

We provide accounting and operational software to businesses. The financial records we process belong to our business customers and relate to their commercial transactions rather than to consumers obtaining financial products for personal, family, or household purposes.

21.2 Where a customer is a financial institution

If you are a financial institution subject to the GLBA and you use the Services to process nonpublic personal information about consumers, you remain responsible for your own compliance, including your obligations under the Safeguards Rule regarding service providers.

Tell us before contracting. We will discuss whether the Services are appropriate, what contractual commitments we can make, and where we cannot meet a requirement. We would rather decline than accept an engagement we cannot support compliantly.

21.3 Payment data

We do not store, process, or transmit cardholder data. Payment is handled by a PCI-DSS compliant processor under its own terms. We receive only confirmation of payment, the last four digits of the instrument, and billing contact details, and are therefore outside PCI scope.

22Marketing communications

Where you request an assessment, proposal, or answer, we reply directly. That reply is a business communication rather than marketing and comes from a person rather than an automated sequence.

Separately we may send occasional email about our research, product changes, or services. Every message includes a one-click unsubscribe that takes effect immediately. We keep a suppression record after you unsubscribe containing the minimum information needed to ensure we do not contact you again — that record is itself a use of your data, which is why we mention it rather than describing deletion as absolute.

  • We do not sell or rent our mailing list, or share it with partners, sponsors, or event companies.
  • We do not use behavioural triggers — we do not send different email because you visited a pricing page or opened a previous message.
  • We do not run re-engagement campaigns. If you stop opening, we will eventually remove you.
  • Marketing email complies with the CAN-SPAM Act, and with PECR and GDPR consent requirements where applicable.

23Job applicants and personnel

This section applies if you apply for a role with us.

  • What we collect. Your application materials, employment and education history, information from references you nominate, notes from interviews, and the outcome of any paid work sample.
  • Why. To assess your application and communicate with you. Legal basis: steps prior to entering a contract, and our legitimate interest in recruiting.
  • Retention. 12 months after a decision, aligned to discrimination claim limitation periods, or longer with your consent so we can contact you about future roles.
  • No automated screening. Applications are read by a person. We do not use applicant tracking systems that score or rank candidates algorithmically, and we do not use automated video or personality assessment.
  • Background checks. Only where relevant to the role, only with your knowledge, and consistent with applicable law including the Fair Credit Reporting Act where a consumer report is obtained.
  • Accommodations. If you need an adjustment at any stage, tell us. That information is used only to provide the accommodation and does not form part of the assessment.

Personnel data for people we employ or engage is governed by a separate internal privacy notice provided at the start of the engagement.

24Children's privacy

The Services are directed to businesses and are not intended for children. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of anyone under 16.

We do not operate a website or online service directed to children under 13 within the meaning of the Children’s Online Privacy Protection Act.

If you believe a child has provided us with personal information, write to [email protected] and we will delete it promptly.

25Third-party links and services

Our site links to third-party websites, including vendor sites referenced in our directory and research. We do not control those sites and are not responsible for their privacy practices. This policy does not apply to them.

Where the erp.io service connects to a third-party system at a customer’s direction — an accounting system, bank feed, payroll provider, or CRM — that provider’s handling of information within its own system remains governed by its own terms and privacy policy.

We do not embed third-party advertising, social media tracking pixels, or session recording tools on this site.

26Accessibility of this notice

We aim to make this policy accessible. It is structured with headings, uses tables with header cells, and is designed to work with screen readers and at increased zoom.

If you need this policy in an alternative format, or have difficulty exercising a privacy right because of a disability, write to [email protected]with “Accessibility” in the subject line. We will provide the information in an accessible format and assist with the request at no charge.

27Governing law

This Privacy Policy and any dispute arising out of or relating to it are governed by the laws of the State of Arkansas, without regard to its conflict of laws principles. The exclusive venue for any action arising out of or relating to this policy is the state or federal courts located in Benton County, Arkansas, and you consent to the personal jurisdiction of those courts.

Where you have accepted our Terms of Service, the dispute resolution provisions in those Terms — including the arbitration agreement and its 30-day opt-out — apply to disputes arising under this policy.

Nothing in this section limits your right to lodge a complaint with a supervisory authority in your jurisdiction, to contact your state attorney general, or any mandatory consumer protection right available under the law of your country of residence that cannot be derogated from by agreement.

28Changes to this policy

We may update this policy. When we do, we revise the “Last updated” date at the top. Where a change is material, we will provide additional notice — by email to customers and by a notice on the site — at least 30 days before it takes effect.

Where a change would permit a materially different use of personal information already collected, we will obtain consent where the law requires it rather than relying on continued use.

We maintain prior versions and will provide a copy on request. Material changes are logged in the changelog rather than applied silently.

Contacting us about privacy

Write to [email protected]with “Privacy” in the subject line, or to Nead, LLC, 1425 Broadway 22689, Seattle, WA 98112, United States. Include enough detail for us to identify the relevant information.

If you are dissatisfied with our response you may lodge a complaint with your local supervisory authority or, if you are a US state resident, with your state attorney general. We would prefer you raised it with us first, and we will tell you what we can and cannot do rather than routing you through a process.

Related documents: Terms of Service · Data Processing Addendum · Cookie Policy · Acceptable Use Policy · Subprocessors

erp.io

ERP software with AI agents inside it — and the implementation, integration, and custom development that make it fit how you already work. We research and compare the rest of the market too, including the products we compete with.

AI
  • AI agents
  • ERP Copilot
  • Governance
  • Authority levels
  • Accuracy method
  • AI in ERP report
Platform
  • General ledger
  • Shadow ledger
  • Close
  • Reporting
  • Customer portals
  • API & MCP
Services
  • Implementation
  • Implementation rescue
  • Integration
  • Migration
  • Custom modules
  • Pricing
Research
  • ERP directory
  • Comparisons
  • Free tools
  • Guides
  • Glossary
  • Methodology
Company
  • About
  • Editorial policy
  • Partners
  • Trust center
  • Careers
  • Contact
© 2026 erp.io — a product of Nead, LLC (d/b/a DEV.co)We rank competitors honestly. No paid placement, ever.LegalPrivacyTermsDPASLACookiesStatus