Eileen Grays LLC ERP Privacy Policy
Effective Date: August 25, 2026
Eileen Grays LLC and its subsidiaries (“we”, “us”, “our”, or “Eileen Grays LLC”) are committed to protecting your privacy. This Privacy Policy (“Policy”) describes how we collect, use, disclose, store, and protect Personal Data processed through our enterprise resource planning system, related web interfaces, internal business applications, APIs, and connected business services (collectively, the “ERP Services”).
In this Privacy Policy, “Personal Data” means information that identifies, relates to, describes, or can reasonably be linked to an individual. “Business Data” means information processed through the ERP Services in connection with our business operations, including order, product, inventory, purchasing, supplier, customer, logistics, finance, reporting, and other operational records.
Where we process Personal Data on behalf of a customer, affiliate, supplier, or other business partner, that organization may determine the purposes and means of processing. In those situations, we process such Personal Data in accordance with the applicable agreement and the instructions of that organization.
What Personal Data We Collect
We collect only the information reasonably necessary to provide, secure, maintain, and improve the ERP Services and to support our business operations.
1. Information You or Your Organization Provides
- Account and Profile Data: name, business email address, phone number, username, job title, department, role, permissions, language preference, time zone, and authentication information.
- Business and Operational Data: information entered, uploaded, imported, generated, or synchronized through the ERP Services, such as order information, customer and supplier contact information, product and SKU data, inventory records, purchasing records, shipment and tracking information, invoices, payment-related business records, reports, and internal workflow data.
- Support and Feedback Data: information you provide when requesting technical support, reporting an issue, submitting feedback, or communicating with us regarding the ERP Services.
2. Information We Collect Automatically
- Device and Browser Information: IP address, browser type and version, operating system, device type, language settings, session identifiers, and similar technical information.
- Usage Data: login activity, pages or modules accessed, actions performed, features used, search activity, downloads, uploads, and other interactions with the ERP Services.
- Log and Security Information: system logs, audit trails, error logs, authentication events, access records, API request information, and other information used for troubleshooting, security, and compliance.
3. Information From Integrated Services
The ERP Services may connect with third-party platforms, marketplaces, logistics providers, payment or financial service providers, cloud services, email services, or other business systems. When an authorized integration is enabled, we may receive and process information from those services as necessary to provide the requested integration and related business functions.
Purposes and Legal Basis for Processing Personal Data
We may process Personal Data for the following purposes:
- Provide the ERP Services: to create and manage accounts, authenticate users, apply permissions, process business transactions, synchronize data, generate reports, and provide the functions requested by authorized users.
- Operate and Improve the ERP Services: to maintain system availability, diagnose problems, improve workflows and features, analyze performance, and optimize system operations.
- Security and Fraud Prevention: to monitor access, maintain audit trails, detect unauthorized or suspicious activity, protect accounts and systems, enforce permissions, and prevent misuse of the ERP Services.
- Business Communications: to send service notices, security alerts, administrative messages, account information, and other communications related to the ERP Services.
- Business Operations: to support order fulfillment, inventory management, purchasing, supplier management, logistics, customer service, financial reconciliation, analytics, reporting, and related internal or authorized business processes.
- Legal Compliance: to comply with applicable laws and regulations, respond to lawful requests and legal process, protect our rights and systems, enforce agreements, and pursue or defend legal claims.
Where required by applicable law, our legal basis for processing may include performance of a contract, compliance with legal obligations, our legitimate business interests, and consent where consent is required.
Who We Share Personal Data With
We may share Personal Data only as reasonably necessary for the purposes described in this Policy, including:
- Service Providers: providers of cloud hosting, infrastructure, security, analytics, IT support, communications, data processing, backup, and other services supporting the ERP Services.
- Authorized Business Partners and Integrated Services: customers, suppliers, logistics providers, marketplaces, payment or financial service providers, and other authorized business partners when sharing is necessary to complete a business process or provide an enabled integration.
- Affiliates: subsidiaries and affiliated entities within our corporate group where necessary for legitimate business operations.
- Corporate Transactions: a successor, purchaser, or other relevant party in connection with a merger, acquisition, restructuring, financing, sale of assets, or similar transaction.
- Legal and Safety Disclosures: public authorities, regulators, courts, law enforcement, or other parties where we believe disclosure is necessary or appropriate to comply with law, legal process, or to protect rights, safety, property, operations, or systems.
- Other Parties With Authorization: other parties where you, your organization, or another authorized data controller has directed or consented to the disclosure.
We do not use Personal Data processed through the ERP Services for unrelated consumer advertising or sell Personal Data processed through the ERP Services for monetary consideration.
International Transfer of Information Collected
To support our global operations, we may transfer, store, or process Personal Data in jurisdictions other than the jurisdiction in which you are located. Data protection laws in those jurisdictions may differ from those applicable in your place of residence or work. Where required, we use appropriate safeguards for such transfers.
Your Rights Relating to Your Personal Data
Depending on applicable law and the context in which we process your Personal Data, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing.
- Request access to Personal Data that we process about you;
- Request correction of inaccurate or incomplete Personal Data;
- Request deletion of Personal Data, where applicable;
- Request restriction of certain processing activities;
- Request a copy or transfer of certain Personal Data, where applicable; and
- Object to certain processing or withdraw consent where processing is based on consent.
Some ERP accounts are managed by your employer or another organization. In such cases, certain requests may need to be submitted through the organization that administers your account. We may verify your identity and authority before acting on a request. We aim to respond within the period required by applicable law.
Security
We use commercially reasonable physical, administrative, and technical safeguards designed to protect Personal Data and Business Data. Depending on the relevant system and use case, these measures may include role-based access controls, authentication, authorization, encrypted communications, secure credential handling, logging, auditing, data validation, backup, monitoring, and other controls intended to prevent unauthorized access, alteration, disclosure, or destruction.
Users are responsible for protecting their account credentials and for using the ERP Services in accordance with applicable company policies and access permissions. If you believe an ERP account or the ERP Services have been compromised, please contact us promptly at Supplier@EileenGrays.com.
Data Retention
We retain Personal Data and Business Data only for as long as reasonably necessary for the purposes described in this Policy, including providing the ERP Services, maintaining business and accounting records, complying with legal obligations, resolving disputes, enforcing agreements, and protecting our systems and business.
Retention periods may vary depending on the type of data, business need, contractual requirements, legal or regulatory obligations, security considerations, and technical constraints. When data is no longer required, we will delete, anonymize, or otherwise securely dispose of it where reasonably practicable.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the ERP Services, our business practices, legal requirements, or security practices. When appropriate, we will provide notice of material changes through the ERP Services, by email, or by another reasonable means. We encourage you to review this page periodically for the latest information on our privacy practices.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Eileen Grays LLCPostal Mailing Address: 218 Black Tie Lane, Chapel Hill, North Carolina 27514
Email: Supplier@EileenGrays.com