Enterprise Privacy Policy & Data Protection Standards

Understand how Great ERP protects enterprise business data, adheres to GDPR, CCPA, and data protection laws, and ensures complete tenant isolation and sovereignty.

Compliance & Data Sovereignty

Enterprise Privacy Policy & Sovereign Data Standards

Effective Date: January 1, 2026 | Last Comprehensive Legal Review: September 2026

Executive Privacy & Data Protection Pledge

At Great ERP (owned and operated by Greatzern Consulting), privacy, security, and data sovereignty are fundamental architectural tenets. We fully appreciate that your ERP system houses your organization's most sensitive records: financial general ledgers, corporate banking reconciliations, employee compensation figures, vendor contracts, confidential customer communications, and proprietary product cost structures.

Our Foundational Guarantee: We never sell, rent, commercialize, disclose, or train public third-party artificial intelligence models on your transactional enterprise data. You retain 100% legal ownership, custody, and sovereign control of all information processed within your Great ERP instance at all times.

1. Data Controller Identification & Official Contact Details

The legal data controller responsible for the governance, processing, and safeguarding of data collected through the Great ERP platform under this Privacy Policy is:

Corporate Entity: Greatzern Consulting (Great ERP)

Physical Headquarters: Section 9, Thika, Kiambu County, Republic of Kenya

Corporate Inquiries: info@greatzern.com

Data Protection Officer (DPO): privacy@greatzern.com

Telephone Hotline: +254 758 991 904

2. Classifications of Data Collected and Processed

To deliver comprehensive ERP software functionality, we process information categorized into distinct functional streams:

A. Administrative Account Information

Full legal names, business email addresses, telephone numbers, encrypted password digests (computed via Argon2id and Bcrypt with salt hashing), designated user role permissions, and billing administrative contacts required to establish and verify your organization's account.

B. Customer Operational & Transactional Records

All business records created, imported, or maintained by your personnel: customer invoice line items, purchase orders, general ledger journal entries, bank statement reconciliations, warehouse inventory valuations, product barcodes, employee payroll numbers, national tax identification numbers, CRM sales opportunities, and Taskly project deliverables.

C. System Telemetry, Audit Logs & Diagnostic Metrics

Originating IP addresses, browser specifications, operating system environments, timestamps of administrative user logins, API authentication requests, and error stack traces. This information is utilized strictly to ensure 99.9% uptime, detect unauthorized intrusion attempts, and debug technical anomalies.

3. Lawful Bases for Processing Under Global Regulations

In compliance with international data privacy frameworks, including the European Union General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the UK Data Protection Act 2018, and the Kenya Data Protection Act 2019, all processing activities rely upon explicit lawful bases:

  • Performance of a Contract (GDPR Art. 6(1)(b)): Processing necessary to provision your software environment, route transactional emails, compute accounting balances, process subscription payments, and deliver technical support under our Master Services Agreement.
  • Statutory & Legal Obligations (GDPR Art. 6(1)(c)): Retention of financial invoices, electronic fiscal compliance signatures, and audit trails required under corporate taxation, accounting, and anti-money laundering statutes.
  • Legitimate Interests (GDPR Art. 6(1)(f)): Protecting platform network security, investigating malicious access attempts, defending against distributed denial-of-service attacks, and optimizing system compute efficiency.
  • Explicit User Consent (GDPR Art. 6(1)(a)): Applicable exclusively to opt-in communications, such as product update digests or marketing webinars, which can be revoked at any moment via the unsubscribe link in the email footer.

4. Tenant Logical Isolation & Sovereign Infrastructure Architecture

Traditional multi-tenant cloud SaaS architectures pool thousands of competing businesses into shared database tables separated merely by a foreign key column, creating catastrophic risks of data leakage and cross-tenant vulnerability. In contrast, Great ERP implements strict logical and containerized workspace isolation. Each organization's database schemas, application sessions, and cryptographic keys are partitioned. For enterprise customers requiring maximum sovereignty, we deploy dedicated virtual private cloud (VPC) nodes or on-premise appliances with zero shared compute resources.

5. Third-Party Sub-processors & Infrastructure Partners

We partner with an elite, transparent roster of certified infrastructure providers who maintain SOC 2 Type II, ISO 27001, and PCI-DSS Level 1 compliance. All sub-processors execute strict Data Processing Agreements (DPAs) incorporating standard contractual clauses:

Partner Entity Primary Operational Role Data Center Region
Tier-1 Cloud Compute & Storage Virtual server infrastructure, encrypted block storage volumes, automated offsite snapshot backups European Union / Germany / Local Sovereign Regions
Payment Gateway Processors (Stripe / Local Bank Rails) PCI-DSS certified tokenized payment processing; credit card details are never stored on Great ERP servers Global / Pan-African
Dedicated SMTP Relays Transactional delivery of password resets, system alerts, and customer invoice emails European Union / North America

6. Cryptographic Protection & Technical Safeguards

Great ERP enforces multi-layered cybersecurity controls across the entire software application lifecycle:

  • Data in Transit: Mandatory TLS 1.3 encryption with Perfect Forward Secrecy across all web endpoints, REST APIs, and webhook transmissions, reinforced with HTTP Strict Transport Security (HSTS).
  • Data at Rest: Database files, transaction journals, and uploaded documents are encrypted using AES-256 GCM cryptographic ciphers.
  • Granular Role-Based Access Control (RBAC): Organization administrators have fine-grained authority to restrict view, edit, and export permissions by department, branch, or employee role.
  • Intrusion Mitigation: Automated fail2ban rate-limiting, IP reputation checks, and Web Application Firewalls (WAF) inspect incoming requests against SQL injection and cross-site scripting attempts.

7. Data Retention, Portability & Guaranteed Purging

We retain your operational data exclusively for the duration of your active software subscription. In the event of subscription cancellation, Great ERP provides a 30-day export grace window during which authorized administrators can download complete database backups in standardized formats (SQL dump, CSV files, and structured JSON). Following the 30-day window, all active database tables, file attachments, and secondary backup snapshots are permanently, irreversibly destroyed in compliance with NIST SP 800-88 standards.

8. Your Statutory Data Protection Rights

Regardless of your geographical location, Great ERP extends comprehensive statutory privacy rights to all registered users:

Right to Access & Inspection: Request an authoritative record of all personal and account data held within our systems.
Right to Rectification: Update inaccurate or incomplete employee, customer, or accounting contact records instantly.
Right to Erasure ("Right to Be Forgotten"): Request the total deletion of personal information where not mandated by tax laws.
Right to Data Portability: Export all commercial datasets in open, machine-readable formats without artificial lock-in.

9. Inquiries & Regulatory Contact

To exercise your statutory data privacy rights or submit a technical security question, contact our Data Protection Officer directly at privacy@greatzern.com or via postal dispatch to Greatzern Consulting, Section 9, Thika, Kenya. We acknowledge and address all verified privacy inquiries within 48 business hours.