Enterprise Data Privacy Policy
Effective Date: August 18, 2026 • Version 5.0 • BIZERP Platform Architecture
1. Core Privacy Commitments
At BIZERP, we believe enterprise business data is confidential, proprietary, and must remain under the exclusive control of the subscribing enterprise. This Privacy Policy details our operational data handling, encryption standards, and isolation controls.
2. Information We Collect & Process
Account Credentials: Full name, corporate email address, hashed passwords (bcrypt), and Multi-Factor Authentication (MFA) tokens for authorized users.
Commercial & Operational Data: Chart of accounts, invoices, purchase orders, BOM formulas, batch numbers, employee payroll records, and inventory balances submitted by Customer during the routine operation of the ERP.
System Telemetry: Anonymized request logs, response times, IP access logs, and audit trails required for security monitoring and fraud detection.
3. Data Encryption & Security Standards
In Transit: All HTTP traffic is secured via TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) and modern cipher suites.
At Rest: PostgreSQL database partitions, Redis cache layers, and document storage use industry-standard AES-256 encryption.
Private Cache Headers: All authenticated ERP pages and API endpoints strictly serve Cache-Control: private, no-store, no-cache, must-revalidate, max-age=0 to eliminate intermediate proxy caching.
4. Subprocessors & Service Providers
BIZERP utilizes select infrastructure subprocessors to provide cloud hosting, DNS management, and optional payment processing:
- Hostinger VPS Infrastructure (Secure Tier-3 Data Centers)
- Cloudflare & Caddy Proxy (TLS Termination, DDoS Mitigation, Automated Certificate Management)
- Stripe & Regional Banking Gateways (Optional Payment Gateways, where explicitly configured by Customer)
5. Data Retention & Deletion Rights
Customer may export complete business ledger data, product catalogs, and transaction histories at any time. Upon formal contract termination, customer data is scheduled for permanent cryptographic erasure following the standard 30-day post-termination transition window.
6. Contact Data Protection Officer
For privacy inquiries, data subject access requests, or security audits, contact our Data Protection Officer at dpo@bizerp.us.