Privacy Policy
Effective August 29, 2026. This policy explains how IGFirstERP handles personal and business information across its web, iPhone, support, integration, and assisted-service channels.
1. Information We Collect
- Identity and account details, including names, usernames, email addresses, phone numbers, roles, and business details.
- Operational records entered by a business, including products, inventory, sales, purchases, expenses, contacts, staff actions, documents, and audit trails.
- Subscription and transaction references from Apple, Google Play, Paystack, banks, or other payment providers. We do not require full payment-card numbers to be stored in IGFirstERP.
- Integration records from services a business connects, such as ecommerce, messaging, shipping, email, or APIs.
- Device, diagnostic, security, usage, and support records needed to operate and protect the service.
2. How We Use Information
- Provide the contracted service, authenticate users, maintain one controlled operational record, and deliver reports, notifications, integrations, and support.
- Verify subscription status, reconcile provider events, prevent duplicate entitlements, and manage account access.
- Protect accounts, investigate misuse, diagnose failures, and maintain service reliability.
- Respond to requests, improve the product, and meet legal, tax, security, and audit obligations.
3. Data Sharing
We do not sell personal data. We disclose the minimum necessary information to service providers acting for us, to integrations enabled by the business, or where disclosure is legally required. Provider categories may include cloud hosting and storage, email and messaging delivery, monitoring and security, customer support, AI processing, Apple and Google store billing, Paystack and other payment providers, and professional advisers.
4. Cortex Hosted Analysis
Some Cortex workflows may process the minimum authorized operational records or files needed for an analysis through an approved external AI service provider. By using IGFirstERP and those Cortex workflows, the business instructs IGFirstERP to perform this processing under these terms and this Privacy Policy. IGFirstERP applies the business's existing access controls and does not use hosted analysis to bypass approvals or make disciplinary findings.
Provider working files and isolated analysis environments may be retained for up to 30 days and are scheduled for deletion within that boundary. Where hosted analysis is unavailable, supported deterministic ERP inspection remains available.
5. Cortex Evidence and Case Files
Files supplied to Cortex are treated as untrusted supporting evidence until they are validated and, where possible, checked against authorized ERP records. Secured case files, their versions, evidence references, and audit receipts follow the business's normal record-retention obligations. Short-lived export links are rechecked against the current user's business and access before download.
6. International and Cross-Border Processing
IGFirstERP serves businesses that may operate across countries. Some processors may handle data outside Nigeria. Where this occurs, we use contractual, access, security, and vendor controls appropriate to the service and applicable law.
7. Data Retention
Account and operational data is normally kept while the service is active. After a verified deletion or termination request, eligible data is deleted or de-identified according to the request, backup cycle, contractual commitments, and applicable law. Tax, accounting, security, fraud-prevention, dispute, and operational audit records may be retained for the period legally or reasonably required, with personal identity minimized where appropriate.
8. Security
We apply reasonable technical and organizational controls to protect data. No system is 100% risk-free, but we continuously improve safeguards and monitoring.
9. Your Rights and Deletion Requests
Subject to applicable law, you may request access, correction, portability, restriction, objection, or deletion of eligible personal data. Start a verified deletion request from Account settings or the public account deletion page. Staff may request deletion of their login and eligible personal data. A verified owner may request deletion of an entire business account.
10. Store Billing
Apple or Google may process store subscription purchases under their own privacy policies. IGFirstERP receives transaction identifiers, product, storefront, subscription state, renewal dates, and related lifecycle data needed to verify access. Deleting IGFirstERP data does not automatically cancel a store subscription.
11. Third-Party Platforms
When you connect third-party services (including Meta/WhatsApp), their own policies and terms also apply to data processed through those platforms.
12. Children
IGFirstERP is a business service and is not directed to children. Account administrators should not create user accounts for anyone who cannot lawfully use the service.
13. Questions and Complaints
Contact [email protected] for a privacy request or complaint. You may also contact the appropriate data protection authority where applicable.
14. Policy Updates
We may update this policy as the service, processors, or legal requirements change. A new effective date will be published here, and material changes may also be communicated through the service or registered contact channel.