Privacy policy
Last updated 28 September 2026
ERPSetu is business software. You (the business) decide what goes into it; we keep it so the software works and for no other purpose. This page is the notice the Digital Personal Data Protection Act, 2023 asks for, in plain words.
What we keep about you
Your account: name, email, mobile number and a one-way hash of your password (we cannot read your password).
Your business records: whatever you and your staff enter — customers, bills, stock, staff. You are the data fiduciary for your customers' data; we process it on your instructions.
Sign-in records: the device, IP address and time of each sign-in, so you can see and end sessions from Settings, Sign-in & Security.
Why we keep it
To run the software you signed up for, to bill for a paid plan, to send the messages you ask the system to send, and to keep the service secure. We do not sell data and we do not use your business records to advertise to anyone.
Who else sees it
Only the providers the service needs: the hosting company, the payment gateway for plan payments, and — only when you switch them on with your own keys — your email, SMS, WhatsApp or AI provider. AI can be switched off for your whole organisation, and then no business data leaves ERPSetu for it.
ERPSetu support can open your account only to help you, and every such sign-in is recorded.
How long it is kept
While your account is open. After cancellation your data stays read-only for the period stated in the terms so you can export it, and is then deleted. Tax records your business must keep by law are your responsibility to export before then.
Your rights
You can see and correct your account details in the app, export your business data from Import & Export, and ask us to delete your account. Write to us from the contact page; we answer within 30 days.
If you think your data has been exposed, tell us through the contact page marked 'Data breach'. We will investigate and tell you and the Data Protection Board what the law requires.