Privacy Policy
Last updated: [not set]
Scope
This Privacy Policy explains how we process personal data when you:
- visit erpdraft.com;
- request the POC checklist through the form on the website;
- book a call with us;
- correspond with us by email; or
- are contacted by us in your professional role at a company we believe may benefit from our service.
It does not cover personal data contained in purchase orders, master data, mailboxes or other business documents that we process on behalf of a customer during a proof of concept, a pilot or a production deployment. Such processing is governed by the customer agreement and a separate data processing agreement, under which we act as processor.
Who is responsible
The controller is:
[Legal entity name],
operating as an individual entrepreneur registered in Georgia
Identification number:
[xxx]
Registered address:
[Street, Tbilisi, Georgia], Georgia
Email:
hello@erpdraft.com
We are a Georgian business that offers its services to companies in the European Union. The General Data Protection Regulation (GDPR) therefore applies to the processing described in this Policy. As a Georgian entity we are also subject to Georgian data-protection law.
We are not required to appoint a data protection officer. Please direct all questions about this Policy to hello@erpdraft.com.
Cookies and similar technologies
This website does not:
- set cookies;
- use local storage or similar browser storage;
- use tracking pixels or browser fingerprinting;
- assign visitor or session identifiers; or
- load fonts, scripts, analytics tools or media from third-party servers.
All website assets, including fonts and the demo video, are delivered from our own infrastructure. Your browser does not contact a third-party content, analytics or advertising provider merely because you visit the website.
Where the website links to a third-party service, such as our call-booking page, nothing is loaded from that provider until you follow the link. The linked page is operated by that provider under its own privacy policy.
We therefore do not display a cookie consent banner. If we introduce a technology that requires consent, it will not be activated until the required information and consent mechanism are in place.
What we collect and why
POC checklist form
The checklist form asks for one item of information: your work email address.
We use it to:
- send the POC checklist you requested;
- process and respond to your request; and
- handle directly related business correspondence.
The legal basis is Article 6(1)(f) GDPR: our legitimate interest, and yours, in responding to a business enquiry you made in your professional role. Where you act as a sole trader and the enquiry concerns a potential contract with you personally, the legal basis is Article 6(1)(b) GDPR.
Providing an email address is optional, but we cannot send the checklist without it.
Your address is not:
- added to a newsletter;
- used for unrelated marketing;
- sold to data brokers; or
- disclosed to advertisers.
The form contains a second, hidden field used as a spam trap. Genuine visitors do not see or complete it. A value submitted through that field is processed only long enough to determine whether the submission is likely to be automated and is not retained as part of a genuine request. The legal basis for this spam protection is Article 6(1)(f) GDPR, based on our legitimate interest in protecting the form against automated abuse.
Normal technical information generated when the form is submitted may also appear in the web server logs described below.
Email correspondence
If you reply to the checklist email or contact us directly, we process the information normally contained in business correspondence, including:
- sender and recipient addresses;
- date and time;
- subject;
- message content;
- signature; and
- any attachments you choose to provide.
The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in responding to business enquiries and conducting business correspondence. Where the correspondence concerns a contract with you personally, the legal basis is Article 6(1)(b) GDPR.
Business contacts we approach
We contact people in their professional roles at companies that may benefit from our service. This is business-to-business communication; we do not contact private individuals.
For this purpose we process:
- your name, job title and the company you work for;
- your business email address and, where public, the address of your professional profile;
- the source from which we obtained the data;
- the history of our correspondence with you; and
- any objection you raise.
We obtain this data from company websites, job advertisements, professional networking platforms, public registers and directories, and from your own communications with us. This Policy provides the information required by Article 14 GDPR; our first message to you refers to it.
We use the data solely to offer our service to the company you work for, to a limited number of messages, and to record whether you wish to be contacted.
The legal basis is Article 6(1)(f) GDPR: our legitimate interest in offering our service to relevant companies, using professional contact data only and in a proportionate manner.
You may object at any time, simply by replying to our message or writing to hello@erpdraft.com. We will then stop contacting you. We keep your email address on a suppression list for the sole purpose of ensuring that your objection is respected.
Where we contact you through a professional networking platform, the platform processes the message under its own privacy policy.
Visit statistics
For each page view, our own statistics counter records the page path, the hostname of the referring website (not the full referring URL) and permitted campaign parameters if you arrived through a tagged link. The dataset contains no IP addresses, no full referring URLs, no browser user-agent strings, no cookies, no fingerprints and no visitor or session identifiers. It cannot be used to identify you or to reconstruct an individual visit.
Visit statistics are not linked to checklist requests, email correspondence or web server logs. They are not used to identify visitors or to create visitor profiles.
We process these records to understand which pages, referring websites and campaigns are useful and to improve the website. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in measuring the usefulness of the website in a privacy-preserving manner.
Web server logs
When your browser connects to the website, certain technical information must be processed to deliver the requested page. The server log contains:
- the IP address of the requesting device;
- date and time of the request;
- the requested URL and HTTP method;
- the HTTP status code and the size of the response;
- the referring URL, if your browser sends one; and
- the browser user-agent string.
Server logs are used only to:
- operate and maintain the website;
- diagnose technical faults;
- detect and investigate attacks or automated abuse; and
- protect the availability and integrity of the service.
The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in operating the website reliably and securely.
Logs are not used for advertising or routine visitor analytics. They may be compared with other technical records only where reasonably necessary to investigate a specific fault, abuse case or security incident.
Recipients and processors
Access to personal data is limited to authorised persons who need it for the purposes described above. At present that is the controller personally.
We use the following processors:
- [hosting provider], which hosts the website, the form storage, the visit statistics and the web server logs on a server located in Poland, within the European Union;
- Google Workspace, provided under our agreement with Google Cloud EMEA Limited, Ireland, for sending, receiving and storing email;
Each provider processes personal data under a data processing agreement.
We may also disclose information where required by law, a binding order or a competent authority, or where reasonably necessary to establish, exercise or defend legal claims.
We do not sell personal data or disclose it to advertisers or data brokers.
Where data is processed and who has access
The website, the form storage, the visit statistics and the web server logs are hosted on a server located in Poland, within the European Union. Email correspondence is stored in our email provider's systems as described above. The website does not send visitor information to third-party analytics, advertising or social-media services.
Our personnel access these systems remotely, which may include access from outside the European Economic Area. Such access is limited to authorised persons, takes place over encrypted connections with multi-factor authentication, and does not involve creating separate copies of the personal data described in this Policy outside the systems named above, beyond the ordinary use of encrypted work devices.
Registration in Georgia does not by itself involve any transfer of personal data to Georgia. Where a checklist request or correspondence leads to a customer relationship, invoicing and accounting records containing business contact details are kept as required by Georgian tax and accounting law.
Our email provider may use infrastructure or subprocessors outside the European Economic Area. Where this results in an international transfer, the provider applies the safeguards specified in its data processing terms, including an applicable adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism. The same applies to the call-booking provider where one is used.
You may request further information about applicable transfer safeguards by writing to hello@erpdraft.com.
How long data is kept
- Checklist requests, call bookings and related email correspondence are retained until you request deletion and, in any event, for no longer than 24 months after the last substantive contact.
- Contact data of business contacts we approached is deleted no later than 12 months after our last message if no business relationship results. Suppression-list entries are kept for as long as necessary to respect an objection.
- Visit statistics are retained for 12 months and then deleted automatically.
- Web server logs are retained for 14 days and then deleted automatically.
A particular record may be retained for longer where required by law or where reasonably necessary to establish, exercise or defend a legal claim. Access to information retained for these purposes is restricted.
Deleted information may remain in protected backups under our control for up to 30 days. Backup data is not used for ordinary business purposes and is overwritten through the normal backup cycle.
If a request results in a customer relationship, relevant business correspondence may become part of the customer record and may be retained for applicable statutory accounting, record-keeping or limitation periods.
Your rights
Subject to the conditions and exceptions in the GDPR, you may request:
- access to your personal data;
- correction of inaccurate or incomplete data;
- deletion of your personal data;
- restriction of processing; and
- receipt of your data in a portable, machine-readable format where Article 20 GDPR applies.
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. If you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims.
Where we contact you to offer our service, you may object at any time and without giving reasons. We will then stop contacting you.
We do not rely on consent for any processing described in this Policy, so there is no consent to withdraw.
To exercise a right, contact hello@erpdraft.com or, if one is named above, our representative in the European Union. We may request information reasonably necessary to confirm your identity.
We will respond without undue delay and normally within one month. Where permitted by the GDPR, this period may be extended by up to two additional months because of the complexity or number of requests. If an extension is required, we will inform you within the initial one-month period.
You may also lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live, where you work or where you believe an infringement occurred.
Automated decision-making
We do not use personal data collected through this website for profiling or for decisions based solely on automated processing that produce legal or similarly significant effects. The rejection of an apparent automated spam submission does not produce such effects.
Documents and customer data
The website does not provide a facility for uploading purchase orders, customer records or other business documents. Please do not enter customer personal data in the checklist form or in the booking note.
Business documents are exchanged only through the channels agreed with the customer. Before any proof of concept, pilot or live connection through which customer personal data may become available to us, a confidentiality agreement and a data processing agreement, including Standard Contractual Clauses where required, are put in place.
Further information is available in the pilot section.
Changes to this Policy
We may update this Policy when our processing activities, service providers or legal obligations change. The current version and its effective date will always be published on this page.