Agreement
Before using the ERPECO website, please carefully read these Terms & Conditions. Your acceptance of and adherence to these terms will govern your access to and use of the Service. All users who intend to access or use the Service must adhere to these Terms.
You agree to be bound by these Terms by accessing or using the Service. You do not have the authorization to access the service if you disagree with any part of the terms.
Description of Service
Here at ERPECO, we offer a variety of enterprise resource planning services that can be used for both personal and business purposes or for internal business purposes in the organization you represent.
These services include accounting, sales, purchase, inventory, customer relationship management, point of sale, payroll, attendance, human resource management, and project management applications. You can access these services using any internet browser that the services support.
Modification of Terms of Service
We reserve the right to change the Terms of Service at any time. We will notify you by email or publishing the modified terms on the website. If the Terms are changed in a way that materially impacts your rights with regard to your use of the Services, you may stop using the Services.
Backups Recovery
- In our privacy policy, we specify the actual locations of our data centers.
- We keep backups of each ERPECO database for up to 1 month.
- Backups are being recreated in at least 3 data centers in 2 different locations.
- To restore any backups on your live database, contact our Helpdesk.
Disaster Recovery
We have a plan if the data center is entirely down or offline for a prolonged period, prohibiting the failover to our local hot standby.
- If the data cannot be recovered, we restore your daily backup so you won't lose your work.
- We offer a recovery time objective (RTO) which means 48h for free trials, education offers, 24h for paid subscriptions, freemium users, etc. If a disaster occurs and the data center is down, we repair the service in a different data center.
- Our daily backups are actively monitored and mirrored across many sites on various continents. With priority given to paying subscriptions, the data can be restored based on our backups from the previous day in a few hours.
- The daily backups and the provisioning scripts are regularly checked as part of the disaster recovery process and are tested continuously.
Database Security
- We store all the customer data in a secure database, and no data sharing is allowed between clients.
- No access is possible from one database to another. This is because we fully implement data access control rules.
Password Security
- Use industry-standard encryption to protect customer passwords.
- Our ERPECO team members do not have access to your password and cannot retrieve it. Therefore, when you lose it, you have to reset it.
- The customer database administrators have the right to configure the rate-limiting and the duration of repeated login.
- Securely transmitted the login credentials.
Password Policies
A built-in feature now allows database administrators to require a minimum user password length. In earlier versions, customization could be used to achieve the same outcome.
Staff Access
- For support issues, our helpdesk staff signs in to your account to access settings. However, they do not use your password; they have their own special staff credentials.
- Our staff can replicate the problem that you are facing, so you don’t need to share your password.
- Our Helpdesk staff makes every effort to preserve your privacy, only gaining access to files and settings necessary to identify and fix your problem.
Physical Security
ERPECO cloud servers are hosted in reputable data centers around the globe, and each one of them has to meet our strict physical security requirements:
- Physical access control with security badges.
- Security staff is available on site 24/7.
- 24/7 security cameras on data center locations.
- No outsider is allowed to access the data center, only authorized employees.
Credit Card Security
- We don’t store your credit card information on our systems.
- Securely transmit your credit card information.
Communications
- All our servers are kept under security.
- With state-of-the-art encryption (SSH), all internal data communication between our servers is also protected.
- With state-of-the-art 256-bit SSL encryption, all data communications to client instances are protected.
Network Defense
- All of the data center suppliers that ERPECO uses have huge network capacity and built their architecture to withstand the most powerful Distributed Denial of Service (DDoS) attacks. Their multi-continental networks' edge attack traffic can be detected and diverted by their automatic and manual mitigation systems before it has a chance to impair service availability.
- On servers running ERPECO, firewalls and intrusion prevention systems assist in identifying and stopping threats like brute-force password attacks.
Software Security
The complete codebase is under examination by ERPECO users. Community bug reports are a crucial source of security-related feedback. Developers are urged to review the code and report any security flaws.
For new and contributed pieces of code, the ERPECO R&D processes have code review steps that consider security considerations.
Secure by Design
- By using a higher-level API that doesn't require manual SQL queries, SQL injections are avoided.
- The framework forbids RPC access to secret methods, making it more difficult to introduce vulnerabilities that could be exploited.
- A high-level templating system that automatically escapes injected data stops XSS attacks.
Sample Data
To illustrate the possibility of using the Services successfully for particular objectives, ERPECO may offer sample data. Any such sample data and setup contains random data as its information. Regarding the quality, usefulness, completeness, or dependability of the information, as well as the example data and configurations, ERPECO provides no express or implied warranties.
Suspension and Termination
We reserve the right to suspend your user account or temporarily restrict access to all or a part of any Service in case of any alleged criminal activity, protracted periods of inactivity, or requests from law enforcement or other governmental authorities.
Additionally, we reserve the right to terminate your access to any Services in the event of unanticipated technical difficulties or the discontinuation of the Service, as well as to terminate your user account and refuse the Services if you violate the Terms. If your user account is terminated, all of the Services will be unavailable to you, and all the information in it, including your password and email address, will be deleted.