ERPat System ERPat System
  • Home
  • App Library
  • Tools Hub
  • User Guide
  • Community
  • Job Portal
  • Learn
  • Blog
  • Contact
Sign In
Legal

GDPR Compliance

For individuals in the European Union, the EEA, and the United Kingdom: this statement explains how ERPat aligns with the General Data Protection Regulation (GDPR), alongside our compliance with the Philippine Data Privacy Act.

Last Updated: June 28, 2026 EU 2016/679 (GDPR)

On this page

  1. Our Commitment
  2. When the GDPR Applies
  3. Controller & Processor Roles
  4. Lawful Bases for Processing
  5. Your GDPR Rights
  6. International Data Transfers
  7. Data Protection by Design
  8. Sub-Processors & DPAs
  9. Records of Processing
  10. Breach Notification
  11. DPO & EU Matters
  12. Supervisory Authority
  13. Relationship to the DPA

ERPat, operated by BytesCrafter IT Solutions, is built primarily for the Philippine market and complies with the Data Privacy Act of 2012 (Republic Act No. 10173). Where we process the personal data of individuals in the European Union (EU), the European Economic Area (EEA), or the United Kingdom (UK), we also align our practices with the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the UK GDPR.

This statement complements our Privacy Policy. It does not replace it. For our full description of what we collect and why, please read the Privacy Policy. The GDPR principles below apply in addition to your rights under the Philippine DPA.

1. Our Commitment

We process personal data lawfully, fairly, and transparently; collect it for specified, explicit, and legitimate purposes; keep it accurate and limited to what is necessary; retain it no longer than needed; and protect it with appropriate security. These principles (GDPR Article 5) mirror the data privacy principles of transparency, legitimate purpose, and proportionality under the Philippine DPA.

2. When the GDPR Applies

The GDPR may apply to our processing where we offer the Service to, or monitor the behavior of, individuals located in the EU/EEA or UK (GDPR Article 3), regardless of where ERPat is established. If you are such an individual, the protections in this statement apply to you.

3. Controller & Processor Roles

Consistent with our Privacy Policy, ERPat acts as a controller for the personal data of individuals who register directly with us, and as a processor for personal data that a Customer processes through the Service about its own employees and data subjects. As a processor, we act only on the documented instructions of the controller (GDPR Article 28) and make available the information necessary to demonstrate compliance.

4. Lawful Bases for Processing

Where the GDPR applies, we rely on one or more lawful bases under Article 6: your consent; performance of a contract; compliance with a legal obligation; protection of vital interests; or our (or a third party's) legitimate interests, balanced against your rights and freedoms. Special categories of data (Article 9) are processed only where an additional condition applies, such as explicit consent or obligations in the field of employment and social security law.

5. Your GDPR Rights

Subject to the conditions and exemptions in the GDPR, you have the right to:

  • Access your personal data and obtain a copy (Article 15);
  • Rectification of inaccurate or incomplete data (Article 16);
  • Erasure (“right to be forgotten”) in certain circumstances (Article 17);
  • Restriction of processing (Article 18);
  • Data portability — receive your data in a structured, commonly used, machine-readable format (Article 20);
  • Object to processing based on legitimate interests or direct marketing (Article 21);
  • Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects (Article 22); and
  • Withdraw consent at any time, without affecting prior lawful processing.

To exercise these rights, contact our Data Protection Officer at [email protected]. If your data is held by a Customer (controller) using ERPat, we will refer your request to them and assist in responding. We do not charge a fee for most requests and aim to respond within one (1) month, as the GDPR provides.

6. International Data Transfers

If we transfer personal data from the EU/EEA or UK to a country that has not received an adequacy decision, we implement appropriate safeguards under Chapter V of the GDPR — typically the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable) — together with supplementary technical and organizational measures. A copy of the relevant transfer mechanism is available on request.

7. Data Protection by Design & Default

We integrate data protection into how the Service is built and operated (Article 25): data minimization, role-based access controls, tenant isolation, encryption in transit, secure credential storage, and security middleware. By default, only the personal data necessary for each purpose is processed.

8. Sub-Processors & Data Processing Agreements

We engage vetted sub-processors (for example, hosting, storage, email, and SMS providers) under written contracts that impose data-protection obligations consistent with Article 28. We remain responsible for their performance. Where ERPat acts as a processor for a Customer, we make a Data Processing Agreement (DPA) available on request, which includes the required Article 28 terms and details of approved sub-processors.

9. Records of Processing

We maintain records of our processing activities (Article 30) describing the categories of data and data subjects, purposes, recipients, transfers, retention, and security measures, and we make them available to supervisory authorities on request.

10. Breach Notification

We maintain a breach response procedure. Where a personal data breach is likely to result in a risk to individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33), and we will inform affected individuals when the breach is likely to result in a high risk to their rights and freedoms (Article 34). As a processor, we notify the relevant controller without undue delay. This aligns with the 72-hour notification standard under NPC Circular 16-03.

11. Data Protection Officer & EU Matters

Our Data Protection Officer oversees compliance and serves as your contact point for data protection questions and rights requests. Where required, we will cooperate in the appointment of a representative for EU/UK matters. Contact: [email protected].

12. Right to Lodge a Complaint

If you are in the EU/EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority (for UK residents, the Information Commissioner's Office). We would, however, appreciate the opportunity to address your concerns first — please contact our DPO. Individuals in the Philippines may also contact the National Privacy Commission.

13. Relationship to the Philippine Data Privacy Act

This GDPR statement operates alongside, and does not diminish, your rights under the Philippine Data Privacy Act of 2012. Where both frameworks apply, we apply the protection that provides the greater safeguard to your personal data. For the complete picture of our practices, read our Privacy Policy and Terms of Service.

Privacy Policy Terms of Service

This GDPR Compliance statement is provided for general informational purposes and as a starting template. It does not constitute legal advice. We recommend review by qualified legal counsel or a Data Protection Officer to reflect your specific processing activities and obligations.

ERPat System

All-in-One Business Platform.
Made for Every Filipino Business.

Quick Links

  • Job Portal
  • Tools Hub
  • Community
  • Blog

Resources

  • Support Center
  • Knowledge Base
  • Documentation
  • User Guide

Contact Us

  • https://erpat.app
  • [email protected]
  • +63 968 882 4423
  • 24/7 Support Available

© 2026 ERPat System. All rights reserved.

  • Privacy Policy
  • Terms of Service
  • GDPR Compliance

Delete?

Are you sure? In some cases, you won't be able to undo this action!

Delete?

Are you sure? You can undo this action for a short period of time after confirming.