Welcome to CPALS ERP (“we,” “our,” “Platform,” or “System”). We deeply understand that your enterprise data—ranging from cash flow metrics and inventory levels to logistics and sensitive employee files—is your company’s most valuable asset. We are fully committed to utilizing world-class encryption, strict access controls, and absolute transparency to ensure your data remains secure and confidential
B2B Data Relationship Statement (SaaS)
In compliance with applicable global data protection regulations (including the GDPR and regional PDP laws), our Corporate Client acts as the Data Controller, while CPALS ERP acts strictly as the Data Processor. We process your organizational data solely based on your written instructions and service agreements.
1. Information We Process
To deliver a seamless, fully integrated ERP experience, our Platform processes the following categories of data based on the modules you activate:
Full names of employees, corporate email addresses, roles, job titles, department assignments, system activity logs, and digital logs (e.g., if you integrate attendance devices).
Inventory records, purchase and sales histories, supplier and customer databases managed by you, payroll databases, financial statements, and supply chain records.
IP addresses, device metadata, browser types, security incident logs (for detecting unauthorized activities), and secure session cookies to keep system sessions authenticated.
2. How We Use Your Information
We process information strictly to ensure the smooth operation of your business dashboards:
- To provide active core ERP functionalities (Finance, HR, Supply Chain, CRM, Procurement, and Payroll).
- To generate and display real-time business intelligence and operational reports on your corporate dashboard.
- To log all system changes for internal audit trail purposes (*Audit Trail*), protecting against internal unauthorized modifications.
- To transmit vital system notifications, facilitate multi-factor authentication (MFA/2FA), and perform essential infrastructure maintenance.
3. Security & Storage Infrastructure
Securing your enterprise data is our absolute baseline. We enforce the following protocols across all system endpoints:
All data in transit is protected using TLS 1.3 encryption. At rest, database files and operational storage are encrypted using AES-256 standards.
Each corporate client is provisioned with logically isolated database tenant layers to prevent any cross-tenant data visibility or leaks.
4. Data Sharing & Third-Party Integrations
We will never sell, lease, or distribute your proprietary business databases to third-party advertisers. Your operational data is shared only with certified sub-processors required to run our cloud architecture:
- Cloud Infrastructure Providers: High-performance, firewalled data centers holding ISO 27001 certifications.
- Integrated Payment Gateways: Secure transaction networks used to manage invoicing and automatic payroll distributions (if enabled).
- Transactional Communication APIs: External servers sending automated SMS/Email OTP codes and push notification alerts to your workforce.
5. Data Ownership & Retention Policies
You maintain absolute, unconditional ownership of all records, files, and data entered into CPALS ERP. You can safely export your databases in structured formats at any point during your subscription. Upon subscription termination or non-renewal, your databases will be systematically decommissioned and permanently purged from our active databases and backup logs after a standard 30-day grace period, unless extended retention is required for legal audits or financial compliance.
Have Questions Regarding ERP Data Security?
Contact our dedicated Data Protection Officer (DPO) for comprehensive compliance documentation and security audits.