Privacy Policy

Effective Date: 01-01-2026 
Brand Name: ERPURL 
Service Provider: Sawaftech Co. 

ERPURL (“ERPURL,” “we,” “our,” or “us”) is committed to protecting the privacy, confidentiality, and security of personal and business data processed through our ERP solutions, including our cloud-hosted services, self-hosted deployments, mobile applications, website, implementation services, support services, and related integrations. 

This Privacy Policy explains what information we collect, how we use it, how it is protected, how backups are handled, how customers can access or export their data, and how ERPURL supports data portability without vendor lock-in. 

This Privacy Policy does not replace any signed contract, service agreement, SLA, data processing agreement, quotation, proposal, subscription plan, or written commercial agreement between ERPURL/Sawaftech Co. and the customer. In case of conflict, the signed agreement, active subscription plan, or approved quotation will apply to the extent permitted by law. 

1. Scope of This Policy 

This Privacy Policy applies to: 

  • ERPURL cloud-hosted ERP services.  
  • ERPURL self-hosted or on-premise deployments.  
  • ERPURL mobile applications.  
  • ERPURL website, contact forms, and newsletter subscriptions.  
  • Implementation, training, migration, support, maintenance, backup, and consulting services.  
  • Integrations with third-party systems when configured for a customer.  

This policy applies to both personal data and business/operational data processed through ERPURL. 

2. Data Ownership and Processing Roles 

Customer business data entered into ERPURL remains the property of the customer. 

ERPURL and Sawaftech Co. do not claim ownership over customer operational, financial, accounting, inventory, HR, sales, customer, supplier, uploaded files, or other business records entered into the system. 

For cloud-hosted ERPURL customers, the customer remains the data owner and, where applicable, the data controller for the business data entered into ERPURL. Sawaftech Co. acts as a service provider/data processor for the purpose of hosting, implementation, support, maintenance, backup, troubleshooting, and other contracted services. 

For self-hosted customers, the customer controls where and how their data is stored. ERPURL/Sawaftech Co. does not access self-hosted customer data unless access is explicitly authorized by the customer for support, implementation, maintenance, troubleshooting, or other agreed services. 

Customers are responsible for ensuring that the data they enter into ERPURL is collected, processed, and stored lawfully, especially where the data relates to their own customers, suppliers, employees, contractors, or other third parties. 

3. Information We Collect 

a. Account, Contact, and Billing Information 

We may collect information provided directly by customers, users, or website visitors, including: 

  • Name.  
  • Email address.  
  • Phone number.  
  • Company name.  
  • Job title or department.  
  • Billing and payment-related information.  
  • Account registration details.  
  • User credentials required for account access.  
  • Subscription, package, and service-related details.  
b. Usage and Technical Data 

When users access ERPURL platforms, mobile applications, or website services, we may collect technical and usage information such as: 

  • IP address.  
  • Browser type and version.  
  • Device type, operating system, and device information.  
  • Login times and access logs.  
  • Error logs and system logs.  
  • Usage patterns and performance data.  
  • Security and authentication logs.  
  • Geolocation data, only where enabled or required for specific functionality.  
c. Business and Operational Data 

When customers use ERPURL for business operations, we process the data entered into the system by the customer and their authorized users, such as: 

  • Customer and supplier records.  
  • Sales, quotations, orders, invoices, and payment records.  
  • Inventory, warehouse, and stock data.  
  • Accounting and financial records.  
  • Employee, HR, payroll, and attendance information, where used.  
  • Project, task, workflow, and operational data.  
  • Product, pricing, and service information.  
  • Documents, files, attachments, and correspondence uploaded into the system.  
  • Reports, dashboards, and transaction history.  
d. Support and Implementation Data 

When customers request implementation, training, migration, support, troubleshooting, consultation, or maintenance, we may process information necessary to provide the service, including: 

  • Support requests and messages.  
  • Screenshots, files, or examples shared by the customer.  
  • System configuration details.  
  • Error logs.  
  • Backup or migration files.  
  • Remote-session information, where applicable.  
  • Communication history through WhatsApp, email, ticketing system, phone, or other support channels.  
  • Support plan, subscription plan, or service-level details.  
e. Mobile Application Data 

When using ERPURL mobile applications, the app may process: 

  • Login and authentication details.  
  • Device information.  
  • ERP server connection details.  
  • App usage and error logs.  
  • Camera, file storage, photo, contact, location, or notification permissions only where required for app functionality and only when enabled by the user or device settings.  

The mobile application connects to the customer’s selected ERPURL server, whether cloud-hosted or self-hosted. 

f. Website, Cookies, and Newsletter Data 

When using our website, contact forms, or newsletter forms, we may collect: 

  • Name and contact details submitted through forms.  
  • Company information submitted by the visitor.  
  • Email newsletter subscription details.  
  • Website usage and analytics data.  
  • Cookies or similar technologies, where enabled.  

Users may unsubscribe from marketing or newsletter communications where such option is available. 

4. How We Use Information 

We use personal and business data only for legitimate service, operational, contractual, technical, and legal purposes, including: 

  • Providing, operating, and maintaining ERPURL services.  
  • Hosting customer ERP systems.  
  • Creating and managing user accounts.  
  • Authenticating users and securing access.  
  • Implementing, configuring, and customizing ERPURL according to customer requirements.  
  • Providing technical support, troubleshooting, training, consultation, and maintenance according to the customer’s active plan or agreement.  
  • Performing backups and recovery operations according to the customer’s active plan or agreement.  
  • Improving platform performance, reliability, and user experience.  
  • Sending service-related notifications, alerts, updates, or administrative messages.  
  • Managing billing, subscriptions, invoices, and payments.  
  • Responding to customer inquiries and support requests.  
  • Monitoring system security and preventing unauthorized access.  
  • Complying with legal, regulatory, accounting, or contractual obligations.  
  • Enforcing service agreements and protecting ERPURL, Sawaftech Co., customers, and users.  

We do not sell, rent, or trade customer personal or business data. 

5. Legal Basis for Processing 

Where applicable under relevant data protection laws, we process personal data based on one or more of the following legal bases: 

  • Performance of a contract or preparation to enter into a contract.  
  • Customer consent, where consent is required.  
  • Compliance with legal, tax, accounting, regulatory, or security obligations.  
  • Legitimate business interests, such as service operation, security, fraud prevention, support, system improvement, and customer communication.  
  • The customer’s instructions, where Sawaftech Co. acts as a data processor/service provider.  

6. Cloud vs. Self-Hosted Deployments 

Cloud-Hosted ERPURL 

For cloud-hosted customers, ERPURL is hosted on ERPURL-managed infrastructure. Sawaftech Co. manages the hosting environment, server maintenance, backup processes, standard updates, monitoring, and related infrastructure services according to the customer’s active package, plan, contract, or service agreement. 

Self-Hosted ERPURL 

For self-hosted or on-premise customers, the customer controls the hosting environment, server access, backup procedures, security policies, and infrastructure. Sawaftech Co. accesses self-hosted systems only when authorized by the customer for implementation, support, maintenance, troubleshooting, or other contracted services. 

Backup, update, and support responsibilities for self-hosted deployments depend on the agreed service plan or support contract. 

7. Backups and Backup Retention 

Backup frequency, retention period, backup storage method, and backup availability depend on the customer’s active hosting plan, subscription package, quotation, contract, or service agreement. 

For hosted ERPURL customers, Sawaftech Co. performs scheduled backups according to the subscribed plan. Depending on the selected plan, backups may include one or more of the following: 

  • Daily database backups.  
  • Weekly database backups.  
  • Monthly database backups.  
  • Uploaded file backups or file archives.  
  • External cloud backup synchronization.  
  • Extended backup retention.  
  • Additional backup storage or backup delivery options.  
  • Disaster recovery or restoration support.  

The exact backup schedule and retention period are defined in the customer’s active plan or agreement. For example, some plans may include only standard backup retention, while higher plans may include longer retention, additional backup copies, external cloud synchronization, or enhanced recovery support. 

Backups are used for business continuity, disaster recovery, system recovery, and data protection. Backup files may include database backups and, where applicable, uploaded file archives or system files required for restoration. 

ERPURL may allow authorized users to download the latest available database backup directly from the ERP system itself in SQL format, subject to the customer’s active plan, system configuration, user permissions, and system access rights. 

CSV or Excel exports may be available for selected modules, lists, reports, or business records. However, CSV and Excel exports are intended for reporting, review, or partial data portability and are not considered a full system restore backup. The SQL database backup is the proper format for a full database backup. 

For self-hosted or on-premise deployments, backup responsibility depends on the agreed support plan. If no hosted backup service or managed support agreement is active, the customer is responsible for implementing, monitoring, securing, and testing their own backups. 

8. Data Portability and No Vendor Lock-In 

ERPURL does not impose vendor lock-in. 

Customers may download or request access to their business data and backups according to their permissions, package, plan, and agreement. Authorized users may take the available SQL database backup from ERPURL, where enabled under the customer’s plan and permissions, and may use it to migrate to another system, another hosting environment, or another qualified service provider. 

ERPURL is based on ERPNext, a global open-source ERP system. This means the core ERP platform is not strictly proprietary to Sawaftech Co. and may be hosted, maintained, or supported by other qualified providers if the customer chooses to move in the future. 

Business records may also be exported to CSV or Excel where required for reporting, migration, review, or analysis. 

Uploaded files and attachments may be included in file backups or accessed through the system where permissions allow. 

Any Sawaftech-specific branding, custom applications, custom reports, custom workflows, custom integrations, scripts, or private custom development will be handled according to the final contract scope, source-code terms, and commercial agreement signed with the customer. 

9. Data Retention and End of Service 

We retain personal and business data only for as long as needed to provide ERPURL services, maintain customer accounts, comply with contractual obligations, meet legal/accounting requirements, resolve disputes, support security, and maintain backups according to the customer’s active plan and backup retention policy. 

Customer business data is generally retained while the customer subscription or service agreement is active. 

Upon termination or expiry of service, the customer may request or download a final available backup, subject to system access rights, active plan terms, contract terms, and any outstanding commercial obligations. 

After service termination, customer data may be deleted, archived, or made inaccessible according to the agreed contract terms and operational retention procedures. Backup copies may remain temporarily within scheduled backup cycles until they are automatically replaced or deleted according to the backup retention period applicable to the customer’s plan. 

Some records may be retained for a longer period where required by law, accounting requirements, tax obligations, dispute resolution, fraud prevention, security investigation, or contractual obligations. 

10. Support Services and Plan-Based Support Terms 

Support availability, support channels, support response times, included support hours, chargeable services, and support pricing depend on the customer’s active plan, quotation, contract, SLA, or service agreement. 

Depending on the subscribed plan, support may include one or more of the following: 

  • Simple questions and answers during working hours.  
  • Basic troubleshooting.  
  • System issue investigation.  
  • Configuration support.  
  • Consultation.  
  • Training.  
  • Data import or migration assistance.  
  • Custom report support.  
  • Custom workflow support.  
  • Integration support.  
  • Custom development support.  
  • Priority response options.  
  • Remote support sessions.  

Simple support questions and answers during working hours may be included in some plans. Other services, such as configuration, troubleshooting, consultation, training, custom reports, workflows, integrations, data migration, or custom development, may be charged separately, billed hourly, deducted from included support hours, or covered by the subscribed support plan. 

Any paid support, hourly rate, prepaid support hours, monthly support allowance, or priority support level will be defined in the customer’s active plan, quotation, SLA, or signed agreement. 

ERPURL/Sawaftech Co. may provide support through WhatsApp group, email, phone, remote session, ticketing system, or other agreed support channels. Support channels may change over time as service operations improve, including moving support requests to a ticketing system for better tracking and follow-up. 

Response and resolution times depend on the urgency, severity, support plan, service availability, third-party involvement, required access, and complexity of the issue. 

Urgent issues that cause the production system to stop working are treated with the highest priority according to the customer’s active support plan. High, medium, and low-priority issues are handled according to the response times and support scope defined in the applicable plan or SLA. 

Final resolution time may depend on the complexity of the issue, whether the issue is related to third-party services, hosting infrastructure, user configuration, data issues, custom development, integrations, or client-side access/environment problems. 

11. Data Sharing and Third-Party Service Providers 

We do not sell, rent, or trade customer personal or business data. 

We may share limited information only where necessary for service operation, legal compliance, or contracted services, including with: 

  • Cloud hosting providers.  
  • External backup storage providers.  
  • Payment processing providers.  
  • Email, notification, or communication service providers.  
  • Support, ticketing, or collaboration tools.  
  • Professional advisors such as accountants, auditors, or legal advisors.  
  • Government, regulatory, or legal authorities where required by law.  
  • Third-party integration providers authorized by the customer.  

Where we use third-party service providers, we take reasonable steps to ensure that they process data only for the required service purpose and apply appropriate confidentiality, security, and data protection obligations. 

If a customer enables or requests integration with a third-party platform, such as email services, shipping/logistics platforms, payment gateways, e-commerce platforms, or other business tools, the customer acknowledges that data may be exchanged with that third-party provider according to the integration configuration and that provider’s own terms and privacy policy. 

12. International Data Storage and Transfers 

Customer data may be stored and processed in the hosting region, server location, or cloud infrastructure selected or agreed with the customer. 

Because ERPURL may use external cloud hosting, backup storage, support tools, communication tools, or other service providers, data may be processed or stored outside the customer’s country where necessary to provide the service. 

Where international transfer or cross-border processing applies, ERPURL/Sawaftech Co. will take reasonable steps to apply appropriate technical, contractual, and organizational safeguards. 

13. Data Security 

We apply reasonable technical and organizational measures to protect personal and business data against unauthorized access, loss, misuse, alteration, disclosure, or destruction. 

Security measures may include: 

  • SSL/TLS encryption for data in transit.  
  • Role-based access control.  
  • User permission management.  
  • Optional two-factor authentication where enabled.  
  • Password-protected user accounts.  
  • Server-level firewall and infrastructure security controls.  
  • Restricted administrative access.  
  • System monitoring and error logging where applicable.  
  • Access logs where applicable.  
  • Regular backup procedures according to the active plan.  
  • External backup synchronization where included in the active plan.  
  • Encryption at rest where supported by the hosting or storage infrastructure.  
  • Security updates and maintenance according to the hosted service scope and active plan.  

Customers are responsible for managing their own users, passwords, permissions, internal access policies, device security, and appropriate use of administrator accounts. 

Customers should ensure that only authorized employees or representatives are given access to ERPURL and that user accounts are disabled when no longer required. 

14. Support Access to Customer Systems 

Sawaftech Co. support or technical staff may access customer systems or data only when required for: 

  • Implementation.  
  • Setup and configuration.  
  • Support and troubleshooting.  
  • Maintenance.  
  • Backup or recovery.  
  • Migration.  
  • Training.  
  • Contracted technical services.  
  • Investigation of errors, performance issues, or security issues.  

Such access is limited to authorized personnel and is handled under confidentiality obligations. 

Support access may be performed through admin access, remote sessions, system logs, shared screenshots, backup files, or other information provided by the customer. 

Customers should avoid sharing unnecessary sensitive information during support requests unless it is required to resolve the issue. 

15. Customer Responsibilities 

Customers are responsible for: 

  • Ensuring that their use of ERPURL complies with applicable laws and regulations.  
  • Ensuring that business data entered into ERPURL is lawful and accurate.  
  • Obtaining necessary consents from their employees, customers, suppliers, or other data subjects where required.  
  • Managing user access and permissions.  
  • Keeping passwords confidential.  
  • Enabling two-factor authentication where appropriate.  
  • Notifying ERPURL/Sawaftech Co. of suspected unauthorized access or security issues.  
  • Downloading and storing their own backup copies where required by their internal policy.  
  • Reviewing third-party integrations before enabling them.  
  • Understanding the backup, support, and retention limits of their subscribed plan.  

16. Mobile Applications 

ERPURL mobile applications are designed to connect users securely to their selected ERPURL server. 

Mobile permissions such as camera, storage, files, contacts, location, or notifications are requested only when needed for app functionality, such as uploading attachments, scanning codes, taking photos, receiving notifications, or using location-based features. 

Users may control mobile permissions through their device settings. 

No personal or business data is shared with third parties through the mobile application except as required to operate the service, connect to the selected ERPURL server, provide support, comply with law, or process an authorized third-party integration. 

17. Cookies, Analytics, and Website Forms 

ERPURL may use cookies or similar technologies on its website to operate the website, improve performance, analyze visitor activity, remember preferences, and manage forms or newsletter subscriptions. 

Website visitors may control cookies through their browser settings. 

Information submitted through website forms may be used to respond to inquiries, provide quotations, arrange demonstrations, send requested information, or communicate about ERPURL services. 

Newsletter subscribers may unsubscribe from marketing emails where an unsubscribe option is provided. 

18. User Rights 

Depending on applicable law and the nature of the data, users may have the right to: 

  • Access their personal data.  
  • Correct inaccurate personal data.  
  • Request deletion of personal data.  
  • Restrict or object to processing.  
  • Request data portability.  
  • Withdraw consent where processing is based on consent.  
  • Request information about how their data is processed.  

For customer business data hosted inside ERPURL, requests from the customer’s employees, customers, suppliers, or other third parties should normally be directed to the customer, because the customer controls the business data entered into the system. 

Where Sawaftech Co. acts as a service provider/data processor, we may assist the customer in responding to valid requests according to the contract, technical feasibility, and applicable law. 

19. Security Incidents 

In the event of a confirmed security incident affecting customer data, ERPURL/Sawaftech Co. will take reasonable steps to investigate, contain, mitigate, and resolve the issue. 

Where required and appropriate, affected customers will be notified without undue delay with available information about the nature of the incident, affected services or data, recommended actions, and remediation steps. 

Customers are responsible for notifying their own users, employees, customers, regulators, or other third parties where legally required and where the customer is the data controller. 

20. Automated Processing 

ERPURL may include workflow automation, notifications, approvals, reports, dashboards, and system rules configured by the customer or during implementation. 

ERPURL does not use personal data for automated decisions that produce legal or similarly significant effects on individuals unless such workflows or rules are specifically configured by the customer as part of their business process. 

Customers are responsible for reviewing and approving any automated workflows that affect their own users, employees, customers, suppliers, or other third parties. 

21. Children’s Privacy 

ERPURL services are intended for business use and are not directed toward individuals under the age of 16. 

We do not knowingly collect personal data from children. If we become aware that personal data from a child has been collected without proper authorization, we will take reasonable steps to delete it or restrict its processing where required. 

22. Policy Updates 

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, security practices, backup procedures, support plans, subscription packages, or business operations. 

Updates may be published on our website and/or communicated by email or service notification where appropriate. 

Continued use of ERPURL after the updated policy becomes effective means that the updated policy applies from that date. 

Scroll to Top