Legal & trust

Privacy Policy

How NextGenERP collects, uses, protects, exports and retains account, website and customer-submitted business data.

Policy architecture for product implementation and customer review. Indian legal counsel and a qualified accountant must approve final statutory wording and retention periods before commercial reliance.

Scope and processing roles

NextGenERP processes account, subscription, billing, sales, website, support and security information to operate its own service. For employee, customer and other business data uploaded by a customer, NextGenERP generally processes that data to provide the contracted service on the customer's instructions. The exact roles under India's Digital Personal Data Protection framework must be confirmed in the applicable agreement.

Information collected

We may collect account identity and contact details, company and tax details, subscription and payment references, support communications, device and security logs, consent records, cookies and website interaction data. Customers may upload business records such as leads, customers, vendors, invoices, GST records, employees, attendance, leave, bank details and documents.

  • Payment card or mandate details are handled by the enabled payment provider and should not be stored directly by NextGenERP unless expressly stated.
  • Passwords are stored as one-way hashes; secrets must not be included in support messages or exports.

Purposes

Information is used to create and secure accounts, provide requested modules, enforce access and subscriptions, process billing, deliver notifications, support customers, prevent abuse, investigate incidents, maintain auditability and comply with applicable obligations. Optional marketing messages require a separate choice and may be withdrawn.

Cookies, analytics and communications

Essential cookies support authenticated sessions and security. Tag-management or analytics tools are used only as configured in the deployed website. Mail delivery providers process destination addresses and message content required for invitations, password recovery, security alerts and service notices.

Customer business data and ownership

The customer retains ownership and control of the business data it submits, subject to the service agreement and applicable law. NextGenERP receives only the rights needed to host, process, back up, transmit, secure and provide the service. NextGenERP does not claim ownership of customer business data.

Security and sharing

NextGenERP uses tenant isolation, role-based access, authenticated private downloads, audit logging and other safeguards described in the product. Information is shared with authorized users, approved sub-processors and authorities only where contractually permitted or legally required. No security certification is claimed unless independently achieved and published.

Retention, expiry and deletion

After cancellation or expiry, the product is designed to provide a configurable read-only self-service export window, initially 30 days, followed by a controlled retention period, initially 90 additional days. Billing, tax, security, audit, consent or legal-hold records may require longer retention. Live data may be removed before encrypted backup copies age out through normal rotation. Backups are not restored for ordinary use after deletion except for disaster recovery, security or legal requirements.

Exports and rights requests

Authorized Company Owners and Admins can request a secure business-data export. Access, correction, update, erasure, consent-withdrawal and grievance requests are tracked in the Data & Privacy center and require appropriate identity verification. Employee requests may need to be handled by the employer customer; NextGenERP and the customer must determine responsibility for each request.

Transfers, updates and contact

Approved providers may process data from locations needed to deliver their services, subject to contractual and legal safeguards. Material policy changes will be dated and communicated where required. The final grievance and privacy contact, legal entity address and escalation timeline must be published after legal approval.

Last reviewed: 21 August 2026 · Version 2026-08-21