Privacy Policy
Last updated: July 2025
1. Introduction
ERPilotAI ("we", "us", "our") is an AI-powered ERP selection platform operated from the United Kingdom. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy explains how we collect, use, store, and protect your personal data when you use our platform and services.
2. Data We Collect
Account data: Your name, email address, and organisation details when you register.
Business profile data: Information about your organisation's operations, systems, and requirements collected through the AI-guided interview and workshop process.
Project data: Vendor shortlists, RFI documents, scoring results, cost comparisons, and recommendation outputs generated through the platform.
Usage data: How you interact with the platform, including pages visited and actions taken, collected through analytics tools.
3. How We Use Your Data
- To provide and operate the ERPilotAI platform and deliver your ERP selection project
- To communicate project updates to your team members
- To generate AI-powered analysis, recommendations, and documents
- To improve our services and develop new features
- To comply with legal obligations
4. Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract: To deliver the services you have purchased
- Legitimate interests: To improve our platform and provide customer support
- Consent: For analytics and marketing communications (where applicable)
- Legal obligation: To comply with UK tax and regulatory requirements
5. Data Sharing
We do not sell your personal data. We share data only with:
- Your team members, for project collaboration purposes
- AI service providers (e.g., language model providers) to generate analysis and documents — data is processed under strict data processing agreements
- Cloud infrastructure providers hosting the platform
- UK authorities where legally required
We do not share your data with ERP vendors. Vendor data is only shared with vendors you choose to invite to your selection process.
6. Data Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews. Access to your project data is restricted to authorised team members within your organisation.
7. Data Retention
We retain your project data for the duration of your active project and for 12 months after project closure, after which it is permanently deleted. Account data is retained for the lifetime of your account.
8. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erasure ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with the Information Commissioner's Office (ICO)
9. Cookies
We use essential cookies for authentication and site functionality. We use analytics cookies to understand platform usage. You can manage your cookie preferences through the consent banner displayed on first visit.
10. Contact
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact Base44 support through the platform dashboard.
