Please read this document together with the other policies in the Legal Centre. If you use DeelosERP for a business, make sure your authorised Users understand the parts that apply to their work.
1. Our security approach
DeelosERP is designed with layered administrative, technical and physical safeguards appropriate to a hosted business platform. Depending on the feature and provider, safeguards may include authenticated access, role-based permissions, secure transmission, logging, backups, monitoring, access reviews and incident response procedures.
Security measures change as the Platform and threat environment change. No service, device, network or storage system can be guaranteed completely secure, and we do not claim that use of DeelosERP eliminates every business or cybersecurity risk.
2. Your security responsibilities
- Use strong, unique credentials and protect them from disclosure.
- Give each User only the access needed for their role and promptly remove access that is no longer needed.
- Protect devices, browsers, local storage and offline queues used to access DeelosERP.
- Keep Customer Data accurate, lawful and limited to what your business needs.
- Review audit activity, exports, payment records and synchronisation status for unusual or duplicate activity.
- Keep supported browsers and devices updated and use trusted networks where practical.
3. Offline and local data
Offline features may temporarily store information on a device before it synchronises. Protect that device from unauthorised use, theft and malware. Do not clear browser storage or uninstall a supported app until queued work has synchronised or been exported, unless you accept the risk of losing unsynchronised changes.
4. Reporting an incident
If you believe an Account, device, Customer Data set or Deelos service has been compromised, contact us promptly through the Contact page or sales@deeloserp.com. Include the affected business, approximate time, relevant User and a safe description of what happened. Do not include passwords or secret payment credentials in a report.
We will assess reported incidents, take reasonable containment and recovery steps, and provide notices required by applicable law or our agreements.
5. Responsible disclosure
If you discover a potential vulnerability, report it privately through the Contact page and allow us reasonable time to investigate and remediate it. Do not access, copy, alter or disclose another person's information, degrade availability, or test against live business data without our written permission.