Back to Home
Privacy & Security Architecture

Enterprise Data Privacy Policy

Effective Date: August 18, 2026 • Version 5.0 • BIZERP Platform Architecture

1. Core Privacy Commitments

At BIZERP, we believe enterprise business data is confidential, proprietary, and must remain under the exclusive control of the subscribing enterprise. This Privacy Policy details our operational data handling, encryption standards, and isolation controls.

Zero Data Monetization
We do not sell, rent, or trade your company data, financial books, or employee records.
Complete Tenant Isolation
All records are partitioned by immutable tenant identifiers at the database and API query levels.

2. Information We Collect & Process

Account Credentials: Full name, corporate email address, hashed passwords (bcrypt), and Multi-Factor Authentication (MFA) tokens for authorized users.

Commercial & Operational Data: Chart of accounts, invoices, purchase orders, BOM formulas, batch numbers, employee payroll records, and inventory balances submitted by Customer during the routine operation of the ERP.

System Telemetry: Anonymized request logs, response times, IP access logs, and audit trails required for security monitoring and fraud detection.

3. Data Encryption & Security Standards

In Transit: All HTTP traffic is secured via TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) and modern cipher suites.

At Rest: PostgreSQL database partitions, Redis cache layers, and document storage use industry-standard AES-256 encryption.

Private Cache Headers: All authenticated ERP pages and API endpoints strictly serve Cache-Control: private, no-store, no-cache, must-revalidate, max-age=0 to eliminate intermediate proxy caching.

4. Subprocessors & Service Providers

BIZERP utilizes select infrastructure subprocessors to provide cloud hosting, DNS management, and optional payment processing:

  • Hostinger VPS Infrastructure (Secure Tier-3 Data Centers)
  • Cloudflare & Caddy Proxy (TLS Termination, DDoS Mitigation, Automated Certificate Management)
  • Stripe & Regional Banking Gateways (Optional Payment Gateways, where explicitly configured by Customer)

5. Data Retention & Deletion Rights

Customer may export complete business ledger data, product catalogs, and transaction histories at any time. Upon formal contract termination, customer data is scheduled for permanent cryptographic erasure following the standard 30-day post-termination transition window.

6. Contact Data Protection Officer

For privacy inquiries, data subject access requests, or security audits, contact our Data Protection Officer at dpo@bizerp.us.

BIZERP Architecture & Security Governance Team