Eileen Grays LLC ERP Privacy Policy

Effective Date: August 25, 2026

Eileen Grays LLC and its subsidiaries (“we”, “us”, “our”, or “Eileen Grays LLC”) are committed to protecting your privacy. This Privacy Policy (“Policy”) describes how we collect, use, disclose, store, and protect Personal Data processed through our enterprise resource planning system, related web interfaces, internal business applications, APIs, and connected business services (collectively, the “ERP Services”).

In this Privacy Policy, “Personal Data” means information that identifies, relates to, describes, or can reasonably be linked to an individual. “Business Data” means information processed through the ERP Services in connection with our business operations, including order, product, inventory, purchasing, supplier, customer, logistics, finance, reporting, and other operational records.

Where we process Personal Data on behalf of a customer, affiliate, supplier, or other business partner, that organization may determine the purposes and means of processing. In those situations, we process such Personal Data in accordance with the applicable agreement and the instructions of that organization.

What Personal Data We Collect

We collect only the information reasonably necessary to provide, secure, maintain, and improve the ERP Services and to support our business operations.

1. Information You or Your Organization Provides

2. Information We Collect Automatically

3. Information From Integrated Services

The ERP Services may connect with third-party platforms, marketplaces, logistics providers, payment or financial service providers, cloud services, email services, or other business systems. When an authorized integration is enabled, we may receive and process information from those services as necessary to provide the requested integration and related business functions.

Purposes and Legal Basis for Processing Personal Data

We may process Personal Data for the following purposes:

Where required by applicable law, our legal basis for processing may include performance of a contract, compliance with legal obligations, our legitimate business interests, and consent where consent is required.

Who We Share Personal Data With

We may share Personal Data only as reasonably necessary for the purposes described in this Policy, including:

We do not use Personal Data processed through the ERP Services for unrelated consumer advertising or sell Personal Data processed through the ERP Services for monetary consideration.

International Transfer of Information Collected

To support our global operations, we may transfer, store, or process Personal Data in jurisdictions other than the jurisdiction in which you are located. Data protection laws in those jurisdictions may differ from those applicable in your place of residence or work. Where required, we use appropriate safeguards for such transfers.

Your Rights Relating to Your Personal Data

Depending on applicable law and the context in which we process your Personal Data, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing.

Some ERP accounts are managed by your employer or another organization. In such cases, certain requests may need to be submitted through the organization that administers your account. We may verify your identity and authority before acting on a request. We aim to respond within the period required by applicable law.

Security

We use commercially reasonable physical, administrative, and technical safeguards designed to protect Personal Data and Business Data. Depending on the relevant system and use case, these measures may include role-based access controls, authentication, authorization, encrypted communications, secure credential handling, logging, auditing, data validation, backup, monitoring, and other controls intended to prevent unauthorized access, alteration, disclosure, or destruction.

Users are responsible for protecting their account credentials and for using the ERP Services in accordance with applicable company policies and access permissions. If you believe an ERP account or the ERP Services have been compromised, please contact us promptly at Supplier@EileenGrays.com.

Data Retention

We retain Personal Data and Business Data only for as long as reasonably necessary for the purposes described in this Policy, including providing the ERP Services, maintaining business and accounting records, complying with legal obligations, resolving disputes, enforcing agreements, and protecting our systems and business.

Retention periods may vary depending on the type of data, business need, contractual requirements, legal or regulatory obligations, security considerations, and technical constraints. When data is no longer required, we will delete, anonymize, or otherwise securely dispose of it where reasonably practicable.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the ERP Services, our business practices, legal requirements, or security practices. When appropriate, we will provide notice of material changes through the ERP Services, by email, or by another reasonable means. We encourage you to review this page periodically for the latest information on our privacy practices.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Eileen Grays LLC
Postal Mailing Address: 218 Black Tie Lane, Chapel Hill, North Carolina 27514
Email: Supplier@EileenGrays.com