E1 ERP1.ORG
  • Overview
  • Modules
  • Deployment (PKR)
  • About
  • Contact
Sign In Request Demo

Privacy Policy

Last Updated: September 10, 2026 | Effective Immediately

At ERP1.ORG ("we", "our", or "the Platform"), accessible from https://erp1.org, the privacy and security of our institutional clients, educational administrators, educators, students, guardians, and charitable donors are paramount. This Privacy Policy outlines our strict policies regarding the collection, safeguarding, processing, and disclosure of information when you utilize our website, software platform, and associated API endpoints.

1. Information We Collect

A. Institutional & Administrative Account Information

When an educational institution, seminary, or trust registers for ERP1, we collect administrative contact information, including organization legal name, campus addresses, administrative representative names, official email addresses, billing coordinates, and telephone/WhatsApp contact numbers.

B. Student, Faculty & Employee Data (Stored on Behalf of Institutions)

In operating the ERP, customer institutions input records regarding their enrolled students, academic faculty, and administrative staff. This includes student identification numbers, academic grade levels, attendance records, Quran memorization progress (Sabq, Sabqi, Manzil), fee voucher receipts in PKR, examination results, staff payroll details, and biometric attendance logs. The subscribing institution acts as the primary Data Controller for this information, and ERP1 processes it strictly as a Data Processor pursuant to institutional authorization.

C. Philanthropic & Donor Records

When institutions manage donations through our platform, records may include donor names, contact information, donation categories (e.g., Zakat, Sadaqah, General), pledged amounts, sequential receipt identifiers, and transaction references. Payment details processed through third-party gateways are encrypted and never stored in plain text on our servers.

2. How We Use Collected Information

We process collected data solely for legitimate institutional purposes:

  • To provision, maintain, and secure the ERP1 software platform.
  • To facilitate automated administrative notifications, such as student absence alerts, fee vouchers, and donor receipts dispatched via WhatsApp or email.
  • To generate double-entry financial ledgers, audit trails, and examination report cards.
  • To process authorized subscription payments in PKR, account billing, and fraud prevention.
  • To deliver priority technical support and critical security updates.

3. Zero Commercial Exploitation of Data

We never sell, rent, monetize, or trade student, institutional, or donor data to third parties, advertisers, or data brokers. Data stored within an institution's database is solely the property of that subscribing organization.

4. Data Security & Encryption Standards

We employ enterprise-grade technical and organizational safeguards to protect institutional records:

  • Encryption in Transit: All data transmitted between user browsers and ERP1 servers is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Role-Based Access Control (RBAC): Granular capability matrices restrict user access so staff can only view records explicitly authorized for their branch and department.
  • Audit Logging: System transactions, logins, and permission changes are recorded in immutable system logs to prevent unauthorized alterations.
  • Scheduled Off-site Backups: Institutional databases are backed up systematically to prevent catastrophic data loss.

5. Cookies & Session Management

ERP1 uses strictly necessary session cookies (e.g., PHPSESSID) to authenticate users, maintain secure active login sessions, and prevent cross-site request forgery (CSRF). We do not deploy invasive third-party tracking cookies or behavioral advertising scripts inside the ERP application.

6. Third-Party Service Providers

We may partner with vetted third-party infrastructure providers to support platform functionality:

  • Payment Processors: Compliant payment gateways for subscription settlements.
  • Messaging Providers: Authorized WhatsApp API gateways (e.g., GreenAPI) utilized strictly for outbound administrative notifications requested by the institution.
  • Cloud Infrastructure: Certified hosting data centers adhering to international physical and digital security standards.

7. Data Retention & Institutional Ownership

Institutions retain full ownership of their data. Subscribing organizations can export their database schemas, records, and student files at any time. Upon verified cancellation of an institutional subscription, customer data will be retained for 60 days to allow manual export, after which it will be permanently expunged from primary production servers.

8. Contact Our Data Protection Team

If you have questions regarding this Privacy Policy, your institutional data, or wish to exercise data subject rights (access, correction, or deletion), please contact:

ERP1 Data Governance Officer
Email: privacy@erp1.org / support@erp1.org
Website: https://erp1.org
Address: Jamia Darul Taqwa Institutional Complex, Lahore, Pakistan

ERP1.ORG

The dedicated institutional resource planning system for educational institutions, Islamic seminaries, and charitable trusts.

Platform

  • Overview
  • All 15 Modules
  • Deployment Tiers (PKR)
  • Sign In

Organization

  • About Us
  • Contact & Support
  • Privacy Policy
  • Terms of Service
  • Refund & Cancellation

Compliance

  • GDPR / CCPA Compliant
  • Support: support@erp1.org
  • XML Sitemap
© 2026 ERP1.ORG. All rights reserved.
Privacy Policy Terms of Service Refund Policy