01Who we are and how to reach us
This Privacy Policy is issued by Nead, LLC, an Arkansas limited liability company doing business as DEV.co(“Nead,” “we,” “us,” or “our”). We operate the website at erp.io and provide the erp.io software service and related professional services.
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | [email protected], subject “Privacy” |
| Rights request appeals | [email protected], subject “Privacy Appeal” |
| Security reports | [email protected], subject “Security” |
| Postal | Nead, LLC, 1425 Broadway 22689, Seattle, WA 98112, United States |
1.1 Data Protection Officer
We have not appointed a Data Protection Officer. We have assessed that we are not required to under Article 37 GDPR: our core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor large-scale processing of special categories of data. Privacy matters are handled directly by our leadership team.
1.2 EU and UK representative
We have assessed that we are not currently required to appoint a representative under Article 27 GDPR or its UK equivalent, on the basis that our processing of EEA and UK personal data is occasional, does not include large-scale processing of special categories, and is unlikely to result in a high risk to individuals.
If that assessment changes we will appoint a representative and publish their details here. Until then, EEA and UK individuals and supervisory authorities may contact us directly at the addresses above, and we will respond within the periods required by law.
1.3 Response times
We acknowledge privacy requests within five business days and respond substantively within the statutory period — one month under GDPR, extendable by two months for complex requests with notice; 45 days under most US state laws, extendable by a further 45 days with notice.
02Definitions
| Term | Meaning |
|---|---|
| Personal information / personal data | Information that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable individual or household. |
| Controller / business | The party determining the purposes and means of processing. We are the controller for Site and Business Information. |
| Processor / service provider | A party processing on a controller’s documented instructions. We are the processor for Customer Data. |
| Customer Data | Information a customer organisation loads into, or connects to, the erp.io service — financial records, transactions, documents, and information about that customer’s own people, customers, and vendors. |
| Site and Business Information | Information we collect through our website, marketing, sales, support, and business operations. This policy governs it. |
| Sensitive personal information | As defined in the CCPA §1798.140(ae) and comparable state law — including government identifiers, precise geolocation, racial or ethnic origin, and account credentials. |
| Sale and share | As defined in the CCPA. We do neither. See Section 9. |
| Subprocessor | A third party we engage that may process Customer Data on a customer’s behalf. Listed at /trust/subprocessors. |
03Scope — what this policy does and does not cover
This distinction determines who you exercise your rights against, so it comes before everything else.
| Site and Business Information | Customer Data | |
|---|---|---|
| What it is | Enquiries, assessments, correspondence, website usage, billing contacts, job applications | Financial records and personal data inside a customer’s erp.io tenant |
| Our role | Controller / business | Processor / service provider |
| Governed by | This policy | The customer’s agreement with us, including the Data Processing Addendum |
| Who you contact for rights | Us, at [email protected] | The customer organisation that holds the relationship with you |
3.1 If your data is in a customer’s tenant
If you are an employee, customer, or vendor of a business that uses erp.io, your information may be in their tenant. We process it on their instructions and cannot lawfully act on your request without their authority.
Contact that organisation directly. If you contact us instead, we will promptly forward your request to them and, unless legally prohibited, tell you we have done so. We will assist them in responding as required by Article 28 GDPR and comparable US state law.
3.2 What this policy covers
- The erp.io website, including forms, assessments, calculators, and interactive tools;
- contact with us by email, telephone, or a form;
- administration of a customer relationship, including billing and support contacts;
- recruitment and job applications; and
- our business operations, including vendor management and marketing.
04Notice at collection
This section satisfies the notice-at-collection requirement under CCPA §1798.100(a) and comparable state law. It summarises what we collect, why, how long we keep it, and who we disclose it to. Detail follows in Sections 5 to 12.
| Category | Purpose | Retention | Disclosed to |
|---|---|---|---|
| Identifiers Name, email, phone, IP address, account identifier | Responding to enquiries, providing services, security, billing | 24 months from last contact; relationship + 7 years for customers | Hosting, email delivery, payment processing providers |
| Commercial information Services enquired about or purchased, transaction history | Providing services, billing, account management | Relationship + 7 years | Hosting, payment processing, professional advisers |
| Internet or network activity Pages viewed, interactions, referring URL, device data | Improving the site, security, abuse prevention | Up to 13 months (analytics); 12 months (security logs) | Hosting, analytics providers |
| Professional or employment information Job title, employer, organisation size, systems in use | Preparing a response to your enquiry, tailoring an assessment | 24 months from last contact | Hosting, email delivery |
| Inferences Likely fit, probable requirements | Preparing a written assessment you requested | 24 months from last contact | Not disclosed externally |
| Audio or visual Call or meeting recordings, where you consent | Accuracy of notes and follow-up | 12 months | Meeting platform provider |
4.1 What we do not collect
We do not knowingly collect through our website: biometric identifiers; precise geolocation; government identification numbers; payment card numbers; financial account credentials; or special categories of data under Article 9 GDPR such as health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sexual orientation.
We do not collect or process sensitive personal information as defined by the CCPA for any purpose that would trigger a right to limit its use.
05Information we collect
5.1 Information you provide
- Contact and business details. Name, work email, telephone, company, job title, submitted through assessment forms, demo requests, contact forms, or newsletter sign-up.
- Assessment and tool responses. Approximate revenue band, entity count, accounting system, other systems in your stack, and free-text descriptions of problems you are trying to solve.
- Engagement information. Correspondence, meeting notes, and documents you provide during an engagement.
- Support and correspondence. The content of emails, tickets, and other communications, together with our responses.
- Billing information. Billing contact, address, and purchase order references. Card details are handled by our payment processor and never reach us.
- Recruitment information. Application materials, employment history, and information from references you nominate.
Our website tools run locally. The total cost calculator, migration estimator, implementation risk score, AI readiness assessment, and chart of accounts generator all execute entirely in your browser and transmit nothing to us. Data reaches us only when you complete and submit a form.
5.2 Information collected automatically
- Device and connection data. IP address, browser type and version, operating system, screen characteristics, referring URL, language preference.
- Usage data. Pages viewed, time on page, links followed, navigation patterns.
- Approximate location. Derived from IP address at country or region level. We do not collect precise geolocation.
- Security and abuse-prevention data. Form submission records including timestamps and IP address, used to enforce rate limits and detect automated abuse.
5.3 Information from others
- Service providers. Aggregated or technical information about interactions with our communications and site.
- Publicly available sources. Company information such as industry, size, and public filings, used to prepare for a conversation you requested.
- Referrals. Contact information provided when a partner, adviser, or customer introduces you. Where a partner receives a referral fee, our partner terms require them to disclose that to you, and we will confirm it if you ask.
5.4 Records of processing
We maintain records of processing activities as required by Article 30 GDPR, covering both our controller and processor activities. These are available to a supervisory authority on request.
06How we use personal information
| Purpose | What this involves |
|---|---|
| Responding to enquiries | Preparing and sending the written assessment, proposal, or answer you requested, and following up. |
| Providing services | Delivering the software service and professional services, account administration, and support. |
| Billing and collection | Invoicing, payment processing, and recovery of amounts due. |
| Improving the site and product | Understanding which pages and tools are useful, identifying errors, prioritising work. |
| Marketing communications | Occasional updates about research, product, or services where requested or permitted by law. |
| Security and abuse prevention | Rate limiting, detecting automated abuse, investigating misuse, protecting our systems. |
| Legal and compliance | Meeting legal, accounting, tax, and regulatory obligations; establishing, exercising, or defending legal claims. |
| Recruitment | Assessing applications and communicating with candidates. |
| Corporate transactions | Evaluating, negotiating, or completing a merger, acquisition, financing, or sale of assets, subject to Section 9. |
6.1 What we do not do
- We do not sell personal information, and have not in the twelve months preceding the effective date.
- We do not share personal information for cross-context behavioural advertising.
- We do not use personal information collected through our website to train machine learning models.
- We do not engage in automated decision-making producing legal or similarly significant effects. See Section 19.
- We do not enrol you in a drip marketing sequence when you submit a form. Submitting a form results in a written reply from a person.
- We are not a data broker and are not registered as one in any state, because we do not sell data to third parties with whom the individual has no direct relationship.
07Legal bases for processing (EEA, UK, Switzerland)
| Legal basis | When we rely on it |
|---|---|
| Contract Art. 6(1)(b) | Providing contracted services, administering the account, billing, and support. |
| Legitimate interests Art. 6(1)(f) | Responding to business enquiries you initiate; improving our site and product; securing our systems and preventing abuse; direct marketing to business contacts; and defending legal claims. |
| Consent Art. 6(1)(a) | Non-essential cookies and analytics where consent is required; marketing email where consent is the applicable basis; call recording. Withdrawable at any time without affecting prior processing. |
| Legal obligation Art. 6(1)(c) | Retaining records for tax, accounting, and corporate purposes; responding to lawful requests from authorities. |
7.1 Our legitimate interests assessment
Where we rely on legitimate interests, we have carried out a balancing assessment considering the purpose, necessity, and impact on you. In summary: the processing is limited to business contact information in a business context; you initiated contact in most cases; the impact is minimal; and you can object at any time. A copy of the assessment is available on request.
You have the right to object to processing based on legitimate interests as described in Section 15. Where you object to direct marketing, we will stop without requiring a reason.
10Service providers and subprocessors
Each is bound by a written agreement requiring appropriate security, restricting use to providing services to us, and — where the GDPR applies — meeting Article 28 requirements.
| Category | Purpose | Data involved |
|---|---|---|
| Cloud hosting and infrastructure | Running the website and service | All categories, encrypted at rest and in transit |
| Content delivery and security | DNS, TLS, DDoS protection, WAF | Request metadata in transit |
| Transactional email delivery | Form submissions and service email | Name, email address, message content |
| Website analytics | Aggregated usage measurement | Device data, usage data, truncated IP |
| AI model providers | Powering product features | Content submitted to those features; see Section 20 |
| Payment processing | Collecting fees | Billing contact and transaction detail |
| Business productivity and storage | Internal operations and correspondence | Correspondence and business records |
Named subprocessors used in providing the service, with processing locations, are maintained at /trust/subprocessors. Customers receive 30 days’ notice of changes and may object as set out in the Data Processing Addendum.
11International data transfers
We are based in the United States and our infrastructure is primarily located there. If you are outside the United States, information you provide will be transferred to, stored in, and processed in the United States, which may not provide the same level of protection as your home jurisdiction.
Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on:
- the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum where the UK GDPR applies, and the Swiss adaptations where Swiss law applies;
- supplementary technical and organisational measures including encryption in transit and at rest and access controls enforced in the data layer; and
- the government-request commitments in Section 9.
We have conducted a transfer impact assessment. A copy, and copies of the safeguards we rely on, are available by writing to [email protected]. We may redact commercially sensitive terms.
If the SCCs or UK Addendum are invalidated or become insufficient, we will implement an alternative lawful mechanism without undue delay.
12How long we keep information
| Category | Retention period | Rationale |
|---|---|---|
| Enquiry and assessment submissions | 24 months from last contact | Legitimate interest in continuity of business conversation |
| Customer account and contact records | Relationship + 7 years | Statute of limitations and tax record requirements |
| Correspondence and support records | 36 months from last message | Service continuity and dispute defence |
| Marketing subscription records | Until unsubscribe | Consent-based |
| Unsubscribe suppression records | Indefinite | Legal obligation not to contact you again |
| Website analytics | Up to 13 months | Year-over-year comparison |
| Security and abuse-prevention logs | 12 months | Incident investigation |
| Financial and tax records | 7 years | Legal obligation |
| Recruitment records | 12 months after a decision | Discrimination claim limitation period; longer with consent |
| Call or meeting recordings | 12 months | Accuracy of notes |
Retention of Customer Data is governed by the customer agreement: deleted from live systems within 30 days of termination and from backups within 90 days, with written confirmation of dates on request.
Where we are subject to a legal hold, we retain relevant information for the duration of the hold notwithstanding the periods above, and process it only for the purpose requiring retention.
13Security
We maintain technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, and destruction. Full detail is in Annex II of the Data Processing Addendum. In summary:
- encryption in transit using TLS 1.2 or higher, and encryption at rest;
- access control enforced in the data access layer, with tenant isolation additionally enforced by row-level security in the database;
- one permission model governing people, automated agents, API credentials, and portal users identically;
- role-based, least-privilege access for our personnel, with production access requiring time-bound, dual-approved break-glass procedures that are logged and reported to affected customers;
- an append-only, hash-chained audit log with no update or delete path exposed to application code;
- network segmentation, logging, and anomaly monitoring;
- security assessment of vendors before engagement; and
- quarterly testing of backups and restoration procedures against production-sized data.
No system is completely secure and we do not claim otherwise. Our certification status, including the certifications we do not hold, is published at /trust/compliance.
14Data breach notification
If we become aware of a personal data breach, we will act as follows.
| Recipient | Timing | Basis |
|---|---|---|
| Affected customers (as controller) | Without undue delay, and within 72 hours of confirmation | Article 33(2) GDPR and our DPA commitment |
| Supervisory authority (where we are controller) | Within 72 hours of becoming aware, unless unlikely to result in risk | Article 33(1) GDPR |
| Affected individuals (where we are controller) | Without undue delay where high risk to rights and freedoms | Article 34 GDPR |
| US state notification | Within statutory periods, which vary by state | Applicable state breach notification law |
Notification will describe the nature of the breach, categories and approximate numbers affected, likely consequences, measures taken and proposed, and a point of contact. Where full information is not immediately available we provide it in phases rather than delaying the initial notification.
We will not delay notification in order to determine fault, and notification is not an acknowledgement of liability.
14.1 Reporting a vulnerability to us
Write to [email protected]with “Security” in the subject line. We acknowledge within one business day and will not pursue legal action against good-faith research conducted within the bounds set out in our Acceptable Use Policy.
15Your rights under GDPR and UK GDPR
If you are in the EEA, UK, or Switzerland, you have the following rights in respect of personal data for which we are the controller:
- Access. Confirmation of whether we process your data and a copy of it, with information about the processing.
- Rectification. Correction of inaccurate data and completion of incomplete data.
- Erasure. Deletion where a ground in Article 17 applies.
- Restriction. Restriction of processing in the circumstances in Article 18.
- Portability. Data you provided, in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible.
- Objection. To processing based on legitimate interests, and at any time to direct marketing.
- Withdrawal of consent. At any time, without affecting the lawfulness of prior processing.
- Rights relating to automated decisions. See Section 19.
- Complaint. To a supervisory authority in your country of residence, place of work, or the place of an alleged infringement.
15.1 Exercising these rights
Write to [email protected]. We may ask for information to verify your identity, using data already in our possession where possible — typically confirming control of the email address on the record. We will not request government identification unless the sensitivity of the request requires it.
We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies and why. There is no charge unless a request is manifestly unfounded or excessive, in which case we will explain the charge before proceeding.
16Your rights under US state privacy laws
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other states with comparable laws as they take effect have the rights below.
- Right to know or access. The categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties to whom it was disclosed.
- Right to delete. Deletion of personal information we collected from you, subject to statutory exceptions.
- Right to correct. Correction of inaccurate personal information.
- Right to data portability. A copy in a portable, readily usable format.
- Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We honour GPC signals regardless.
- Right to opt out of targeted advertising. We do not engage in targeted advertising.
- Right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do not conduct such profiling. See Section 19.
- Right to limit use of sensitive personal information. We do not collect or use sensitive personal information for purposes triggering this right.
- Right to non-discrimination. We will not deny services, charge different prices, or provide a different quality of service because you exercised a privacy right.
- Right to appeal. Where your state provides it, you may appeal a refusal. See 16.2.
16.1 Verification and authorised agents
We verify identity using information already in our possession, typically by confirming control of the email address associated with the record. For requests involving deletion or specific pieces of information we may require additional confirmation proportionate to the sensitivity.
An authorised agent may submit a request with written authorisation signed by you. We may contact you directly to confirm the authorisation and the request, unless the agent provides a valid power of attorney.
16.2 Appeals
If we decline a request, you may appeal by writing to [email protected]with “Privacy Appeal” in the subject line. We will respond within the statutory period — 45 days in most states — with a written explanation. If we deny the appeal, we will tell you how to contact your state attorney general.
16.3 Categories collected in the preceding 12 months
Identifiers; commercial information; internet or network activity; professional or employment-related information; inferences drawn for the limited purpose of preparing a response to your enquiry; and audio recordings where you consented. We have not collected biometric information, precise geolocation, or sensitive personal information through our website. We have not sold or shared any category.
17Additional California disclosures
17.1 Shine the Light — Civil Code §1798.83
California residents may request information about disclosure of personal information to third parties for their direct marketing purposes.
We do not disclose personal information to third parties for their direct marketing purposes, and have not in the preceding calendar year. To make a request anyway, write to [email protected]with “Shine the Light” in the subject line. We will respond within 30 days.
17.2 Financial incentives — §1798.125(b)
We do not offer financial incentives, price differences, or service-level differences in exchange for the retention or sale of personal information. There is no loyalty programme, no discount for providing data, and no premium charged for exercising a privacy right.
Our research benchmark programme, where customers may opt in to contribute aggregated de-identified statistics, is not a financial incentive programme. Participation has no effect on pricing, service level, support, or feature access, and opting out changes nothing.
17.3 Notice of right to opt out
Because we do not sell or share personal information, we are not required to and do not provide a “Do Not Sell or Share My Personal Information” link. If that ever changes, the link will appear on this page and in the site footer before any such processing begins.
17.4 Minors under 16
We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age, and we do not knowingly collect information from anyone under 16.
17.5 Data broker registration
We are not a data broker under California Civil Code §1798.99.80 or comparable law in any state, and are not registered as one, because we do not knowingly collect and sell personal information about consumers with whom we have no direct relationship.
18Other state-specific notices
18.1 Washington My Health My Data Act
We are physically located in Washington State. We do not collect, process, or share consumer health data as defined by the Washington My Health My Data Act, and our services are not designed to receive it. We therefore do not maintain a separate consumer health data privacy policy.
Our agreement restricts customers from submitting protected health information to the Services. If you believe consumer health data has reached us, write to [email protected] and we will investigate and delete it.
18.2 Nevada — NRS 603A
Nevada residents may submit a verified request directing us not to sell covered information. We do not sell covered information, but you may submit a request to [email protected] and we will respond within 60 days.
18.3 Colorado, Connecticut, Virginia, and universal opt-out
We honour universal opt-out mechanisms including Global Privacy Control as required by Colorado, Connecticut, and other state law, treating them as opt-outs of sale, sharing, targeted advertising, and non-essential analytics.
18.4 Illinois and Texas biometric laws
We do not collect, capture, purchase, or otherwise obtain biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act or the Texas Capture or Use of Biometric Identifier Act.
19Automated decision-making and profiling
19.1 In respect of Site and Business Information
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR.
We do not use automated lead scoring to decide whether to respond to you, and we do not price differently based on inferred characteristics. A person reads your enquiry and a person writes the reply.
19.2 In respect of the Services
The erp.io service includes automated agents that perform bookkeeping and operational work within an authority a customer configures. Where this processes personal data, the customer is the controller and their own privacy notice governs.
The Services are not designed to make, and must not be configured to make, decisions producing legal or similarly significant effects concerning individuals — including credit, employment, housing, insurance, or benefits decisions. Our Terms and Acceptable Use Policy prohibit such use.
19.3 Fixed limits on automation
Regardless of configuration, no automated agent may release payment, create a vendor or change vendor banking details, grant or modify permissions, close an accounting period, or make a statutory filing. These require a human actor and the limits are not configurable by customers or by us.
19.4 Explainability
Every automated action records the inputs read, the policy relied upon, the confidence assigned, and the alternatives rejected. This is intended to support meaningful information about the logic involved where a controller must provide it under Article 15(1)(h) or Article 22(3) GDPR.
20Artificial intelligence and model training
- We do not train models on Customer Data. We do not fine-tune, train, or otherwise use Customer Data to develop or improve machine learning models, whether our own or a third party’s. This is a contractual commitment in our Terms, not a policy statement we could quietly change.
- We do not train models on Site and Business Information either — enquiries, correspondence, and website interactions are not used for model development.
- Provider agreements prohibit training. Our agreements with AI model providers prohibit use of content submitted through our service to train their models, and provide for zero or limited retention solely for abuse monitoring.
- Content is transmitted only to generate a response for a feature the customer has enabled, and only the content that feature requires. There is no background process streaming data to a third party.
- Improvements come from elsewhere. We improve agent behaviour through prompts, policies, and evaluation sets built from our own synthetic and internal test data.
- Research aggregates are computed, not learned. Published benchmarks come from customers who opted in, aggregated so no customer is identifiable, and never from fewer than five contributing customers.
- AI features can be disabled entirely at tenant level, in which case no data is transmitted to a model provider and the rest of the service continues to function.
Further detail is published at /trust/ai-data, and the current model provider is listed at /trust/subprocessors.
21Financial information and GLBA
Because the Services process financial records, buyers reasonably ask about the Gramm-Leach-Bliley Act. This section states our position.
21.1 Our assessment
We are not a “financial institution” under the GLBA and its implementing regulations, including the FTC Safeguards Rule at 16 CFR Part 314. We do not engage in activities financial in nature under the Bank Holding Company Act: we do not lend, transfer, exchange, invest for others, safeguard money or securities, underwrite, broker, or provide financial advisory services.
We provide accounting and operational software to businesses. The financial records we process belong to our business customers and relate to their commercial transactions rather than to consumers obtaining financial products for personal, family, or household purposes.
21.2 Where a customer is a financial institution
If you are a financial institution subject to the GLBA and you use the Services to process nonpublic personal information about consumers, you remain responsible for your own compliance, including your obligations under the Safeguards Rule regarding service providers.
Tell us before contracting. We will discuss whether the Services are appropriate, what contractual commitments we can make, and where we cannot meet a requirement. We would rather decline than accept an engagement we cannot support compliantly.
21.3 Payment data
We do not store, process, or transmit cardholder data. Payment is handled by a PCI-DSS compliant processor under its own terms. We receive only confirmation of payment, the last four digits of the instrument, and billing contact details, and are therefore outside PCI scope.
22Marketing communications
Where you request an assessment, proposal, or answer, we reply directly. That reply is a business communication rather than marketing and comes from a person rather than an automated sequence.
Separately we may send occasional email about our research, product changes, or services. Every message includes a one-click unsubscribe that takes effect immediately. We keep a suppression record after you unsubscribe containing the minimum information needed to ensure we do not contact you again — that record is itself a use of your data, which is why we mention it rather than describing deletion as absolute.
- We do not sell or rent our mailing list, or share it with partners, sponsors, or event companies.
- We do not use behavioural triggers — we do not send different email because you visited a pricing page or opened a previous message.
- We do not run re-engagement campaigns. If you stop opening, we will eventually remove you.
- Marketing email complies with the CAN-SPAM Act, and with PECR and GDPR consent requirements where applicable.
23Job applicants and personnel
This section applies if you apply for a role with us.
- What we collect. Your application materials, employment and education history, information from references you nominate, notes from interviews, and the outcome of any paid work sample.
- Why. To assess your application and communicate with you. Legal basis: steps prior to entering a contract, and our legitimate interest in recruiting.
- Retention. 12 months after a decision, aligned to discrimination claim limitation periods, or longer with your consent so we can contact you about future roles.
- No automated screening. Applications are read by a person. We do not use applicant tracking systems that score or rank candidates algorithmically, and we do not use automated video or personality assessment.
- Background checks. Only where relevant to the role, only with your knowledge, and consistent with applicable law including the Fair Credit Reporting Act where a consumer report is obtained.
- Accommodations. If you need an adjustment at any stage, tell us. That information is used only to provide the accommodation and does not form part of the assessment.
Personnel data for people we employ or engage is governed by a separate internal privacy notice provided at the start of the engagement.
24Children's privacy
The Services are directed to businesses and are not intended for children. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of anyone under 16.
We do not operate a website or online service directed to children under 13 within the meaning of the Children’s Online Privacy Protection Act.
If you believe a child has provided us with personal information, write to [email protected] and we will delete it promptly.
25Third-party links and services
Our site links to third-party websites, including vendor sites referenced in our directory and research. We do not control those sites and are not responsible for their privacy practices. This policy does not apply to them.
Where the erp.io service connects to a third-party system at a customer’s direction — an accounting system, bank feed, payroll provider, or CRM — that provider’s handling of information within its own system remains governed by its own terms and privacy policy.
We do not embed third-party advertising, social media tracking pixels, or session recording tools on this site.
26Accessibility of this notice
We aim to make this policy accessible. It is structured with headings, uses tables with header cells, and is designed to work with screen readers and at increased zoom.
If you need this policy in an alternative format, or have difficulty exercising a privacy right because of a disability, write to [email protected]with “Accessibility” in the subject line. We will provide the information in an accessible format and assist with the request at no charge.
27Governing law
This Privacy Policy and any dispute arising out of or relating to it are governed by the laws of the State of Arkansas, without regard to its conflict of laws principles. The exclusive venue for any action arising out of or relating to this policy is the state or federal courts located in Benton County, Arkansas, and you consent to the personal jurisdiction of those courts.
Where you have accepted our Terms of Service, the dispute resolution provisions in those Terms — including the arbitration agreement and its 30-day opt-out — apply to disputes arising under this policy.
Nothing in this section limits your right to lodge a complaint with a supervisory authority in your jurisdiction, to contact your state attorney general, or any mandatory consumer protection right available under the law of your country of residence that cannot be derogated from by agreement.
28Changes to this policy
We may update this policy. When we do, we revise the “Last updated” date at the top. Where a change is material, we will provide additional notice — by email to customers and by a notice on the site — at least 30 days before it takes effect.
Where a change would permit a materially different use of personal information already collected, we will obtain consent where the law requires it rather than relying on continued use.
We maintain prior versions and will provide a copy on request. Material changes are logged in the changelog rather than applied silently.
Contacting us about privacy
Write to [email protected]with “Privacy” in the subject line, or to Nead, LLC, 1425 Broadway 22689, Seattle, WA 98112, United States. Include enough detail for us to identify the relevant information.
If you are dissatisfied with our response you may lodge a complaint with your local supervisory authority or, if you are a US state resident, with your state attorney general. We would prefer you raised it with us first, and we will tell you what we can and cannot do rather than routing you through a process.
Related documents: Terms of Service · Data Processing Addendum · Cookie Policy · Acceptable Use Policy · Subprocessors