Processor terms for customer-controlled personal data handled through the hosted service.

Data processing addendum — ERPipe

How this DPA applies

This Data Processing Addendum forms part of the ERPipe Terms when a customer uses ERPipe to process personal data for which that customer is controller. "Customer" is the workspace owner or organization accepting the Terms; "ERPipe" is the processor. If a signed copy or customer-specific information is required, contact hello@erpipe.com before production use.

Processing instructions and confidentiality

ERPipe will process customer personal data only to provide and secure the service, on documented instructions in the Terms, workspace configuration, and tool requests, or as required by law. Persons authorized to process the data are subject to appropriate confidentiality obligations.

Security

ERPipe maintains measures appropriate to the beta's risk, including encrypted transport, per-workspace envelope encryption for Odoo credentials, server-side sessions, tenant and connection gates, write approvals, configurable policies, rate limits, and redacted audit details. Current controls and limitations are published on the Security page.

Subprocessors

Customer gives general authorization for the providers on the published Subprocessor list. ERPipe remains responsible for imposing appropriate data-protection obligations on subprocessors. Material changes will be reflected on that page; a customer may object by contacting us before the changed provider is used for its workspace, where commercially practicable.

Assistance, incidents, and requests

Taking into account the nature of processing and available information, ERPipe will reasonably assist Customer with data-subject requests, security obligations, impact assessments, and regulator consultations. ERPipe will notify Customer without undue delay after confirming a personal-data breach affecting Customer data and will provide available information needed for Customer's response.

Return, deletion, and audits

On termination or verified request, ERPipe will disable access and delete or return customer personal data according to the Privacy Notice, except data retained for security, legal, or dispute purposes. Customer may request information reasonably necessary to demonstrate compliance. Audits must protect other customers, avoid service disruption, and first use available documentation before an on-site review.

International transfers

Customer acknowledges that the beta has no fixed-region commitment. Where transfer safeguards are legally required, the parties will use the applicable standard contractual clauses or another lawful mechanism, including safeguards incorporated through provider agreements.

Processing details

This DPA is intended to cover the processor terms described in GDPR Article 28. Customer remains responsible for the lawfulness, accuracy, and scope of its instructions.

Last updated: 2026-07-18

Open the full page