Privacy Policy
This policy explains what personal data Caspian ERP collects, why, and what you can do about it. It covers this website (caspianerp.com) and the Caspian ERP application (app.caspianerp.com).
Caspian ERP is operated by CaspianTools, Bursa, Türkiye ("we", "us"). For any privacy question, write to privacy@caspianerp.com.
Two different roles
As a controller. For our own website visitors, prospects and account holders, we decide why and how data is processed.
As a processor. For the records your organization puts into Caspian ERP — personnel files, incidents, invoices, contacts and so on — your organization is the controller and we process that data on its instructions, under our customer agreement. If you are an employee of a Caspian ERP customer and want your records changed, contact your own organization first.
What we collect
When you use this website
- Standard request data such as IP address, browser type and pages requested, used to keep the site available and secure.
- Anything you type into the contact form. The form opens your own email client — the message reaches us as an ordinary email, and the website does not store it.
When you use the application
- Account data: name, email address, authentication identifiers and the organizations you belong to.
- Membership data: your role, permissions, status and preferences within each organization.
- Content data: the records you and your colleagues create in the modules.
- Operational logs: security and audit records, including membership, role and permission changes.
Why we process it
- To provide the service — performance of our contract with you or your organization.
- To keep it secure — legitimate interest in preventing abuse, fraud and unauthorised access.
- To support and improve the product — legitimate interest in understanding faults and demand.
- To respond to enquiries — steps taken at your request before entering a contract.
- To meet legal obligations — accounting, tax and lawful requests.
We do not sell personal data, and we do not use your organization's content for advertising.
Cookies and similar technologies
This marketing site can use Google Analytics to count visits and see which pages are read, and it asks before it does. On your first visit a banner offers Accept or Reject. Nothing is loaded and no cookie is set until you accept — if you reject, or simply never answer, Google is not contacted at all and no measurement happens.
If you accept, it sets first-party cookies that tell one browser from another and group requests into a single visit, and it reports the pages you open, the site or search that sent you, your approximate location and your device type. We use that only to understand demand for the product. We set no advertising cookies, we do not build profiles, and we run no remarketing.
Your answer is remembered in your browser's own storage — not in a cookie — so clearing this site's data in your browser makes the banner ask again. Every page works normally either way.
The application uses strictly necessary storage to keep you signed in and to remember interface preferences such as your language. Blocking that storage will stop the application working.
Who we share it with
We use a small number of service providers, each bound by contract to process data only on our instructions:
- Google Cloud / Firebase — hosting, authentication and database.
- Google Analytics — visit measurement on this marketing site.
- Email delivery — sending invitations, notifications and replies.
- AI features — where you explicitly use an AI-assisted drafting feature, the text you submit is sent to our model provider to produce the response. It is not used to train third-party models.
We also disclose data where the law requires it, or to protect our rights, users and service.
International transfers
Our providers operate globally, so data may be processed outside your country. Where it is, transfers rely on recognised safeguards such as the European Commission's standard contractual clauses.
How long we keep it
- Organization content is kept while the account is active, and deleted on request after it closes.
- Security and audit records are retained for a limited period for accountability.
- Enquiry emails are kept only as long as needed to answer them and to keep a record of the conversation.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable format. Write to privacy@caspianerp.com and we will respond within the time the law allows. If your data sits inside a customer's organization, we will refer your request to that organization and support it.
You also have the right to complain to your local data protection authority.
Security
Access to your organization's data is enforced server-side against the permissions your administrators grant. See the security page for details. No system is perfect — if you believe you have found a vulnerability, please write to security@caspianerp.com.
Children
Caspian ERP is a workplace product and is not directed at children under 16.
Changes
If we change this policy materially we will update the date above and, for account holders, notify you in the application or by email before the change takes effect.