Skip to content

Privacy Policy

Effective date: [DATE] · Last updated: [DATE]

Draft pending legal review. This is a comprehensive template. Replace the bracketed fields ([LEGAL ENTITY NAME], [REGISTERED ADDRESS], [JURISDICTION], [DATE]) and have it reviewed by counsel before launch.

This Privacy Policy explains how [LEGAL ENTITY NAME] (“BSuit”, “we”, “us”) collects, uses, discloses and safeguards personal data when you visit our website, sign up for a trial, or use the BSuit cloud ERP (the “Service”). It applies to personal data we process as a controller. When you operate the Service for your organization, your organization is the controller of the data it stores, and we act as a processor under our customer agreement and Data Processing Addendum (DPA).

1. Who we are (Controller)

The data controller for this website and account data is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [JURISDICTION]. For privacy questions or to exercise your rights, contact privacy@bsuiterp.com. [If applicable: our EU/UK representative and Data Protection Officer can be reached at the same address.]

2. Data we collect

  • Account & signup data: your name, work email, company name, and password (stored only as a salted hash).
  • Workspace content: the business data you enter into your ERP tenant. We process this on your behalf as a processor.
  • Communications: messages you send via our contact, support, and newsletter forms.
  • Technical data: IP address, device/browser type, and security logs needed to operate the Service reliably and prevent abuse.
  • Cookies: strictly-necessary cookies for authentication and CSRF protection (see Section 9).

3. How we use data & legal bases (GDPR Art. 6)

  • To provide and operate the Service, including provisioning your workspace — performance of a contract.
  • To communicate about your account and respond to support requests — performance of a contract / legitimate interests.
  • To send product updates you opt into — consent (withdrawable at any time).
  • To keep the platform secure, prevent fraud and abuse, and maintain audit logs — legitimate interests / legal obligation.
  • To comply with legal, tax and accounting obligations — legal obligation.

4. How we share data

We do not sell personal data. We share it only with: (a) sub-processors that help us run the Service (e.g. cloud hosting, email delivery) under contract and appropriate safeguards; (b) professional advisors and authorities where required by law; and (c) a successor entity in the event of a merger or acquisition, subject to this Policy. A current list of sub-processors is available on request.

5. International transfers

Where personal data is transferred outside your region, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. Enterprise customers may request data residency in a specific region.

6. Data retention

We keep account data for as long as your account is active and as needed to provide the Service. After termination, workspace data is retained for a limited wind-down period so you can export it, then deleted or anonymized, except where longer retention is required by law. Specific retention periods are set out in our DPA.

7. Your data, isolated & secure

Each company's data is logically isolated per tenant and encrypted in transit; Enterprise plans can run on a dedicated database. See our Security page for details. We do not sell your data or use your workspace content to train models without your instruction.

8. Your rights

Depending on your location, you have the right to access, correct, delete, restrict or object to processing, and to data portability (GDPR). California residents have rights to know, delete, correct, and to opt out of “sale”/“sharing” — which we do not do (CCPA/CPRA). To exercise any right, contact privacy@bsuiterp.com. You may also lodge a complaint with your supervisory authority. We respond within the timeframes required by applicable law (generally 30 days).

9. Cookies

We use only strictly-necessary cookies to keep you signed in (an httpOnly session cookie) and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies on this site. If that changes, we will request consent before setting non-essential cookies.

10. Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted here with an updated effective date, and where required, communicated to you directly.

12. Contact

Questions or requests? Email privacy@bsuiterp.com or reach us via the Contact page.