Privacy Policy
Protostar ERP is a business software service operated by Protostar AI, LLC ("we", "us"). This policy explains what personal data we collect when you use it, why, who else processes it, how long it is kept, and what you can do about it. It applies to the marketing site at protostarerp.com, the sign-in service, and every customer workspace (tenant) we host.
In one paragraph: we collect the account and activity data needed to run a secure, auditable ERP for your employer. We use an AI assistant that sends your questions and the data needed to answer them to Anthropic, only if your organisation turns it on. We do not sell personal data, we do not run advertising or analytics trackers, and you can ask for a copy of your data or its deletion from inside the product.
1. Who is responsible
For the sign-in service and the marketing site, Protostar AI, LLC is the data controller. Inside a customer workspace, the customer organisation that invited you decides what business data is entered and how long it is kept — it is the controller of that data, and we process it on its behalf under our agreement with it. Requests about business records inside a workspace should therefore go to your organisation's Protostar ERP administrator first; they can involve us as needed.
2. What we collect and why
We collect the following categories of personal data. We collect only what each purpose needs; none of it is collected for advertising.
| Category | What | Why |
|---|---|---|
| Account identity | to create your account, sign you in and apply your permissions | |
| Sign-in and session records | security, automatic logoff, and the attributable audit trail regulated tenants require | |
| Activity and audit trail | 21 CFR Part 11 accountability where a tenant uses it; incident investigation | |
| Business records you enter | this is the service; your organisation controls it and decides how long it is kept | |
| AI assistant conversations | to answer your question; see the AI section — this data leaves the platform | |
| Agent (MCP) access records | so your organisation can see which software agent read its data | |
| Support and error diagnostics | to fix defects; retained briefly and not used for any other purpose |
We do not collect payment card details in the product. We do not collect precise location, biometric or health data about you. If your organisation enters such data into its own business records, that is governed by its policies and our agreement with it.
3. Use of artificial intelligence
Protostar ERP includes an AI assistant that answers questions about your organisation's ERP data. When your organisation enables it and you use it:
- The messages you type, and the ERP records the assistant retrieves to answer them, are sent to Anthropic, PBC, the provider of the language model, and processed in the United States. The assistant is identified as AI in the product; you are never talking to a person.
- The assistant is read-only. It cannot create, change, submit or delete records, and it can only read what your own account is permitted to read.
- Its answers can be wrong. The product tells you to verify before acting on them, and no business decision in the product is taken by the assistant on its own.
- The assistant is off until an administrator of your organisation configures it. Until then, nothing you type in the product is sent to an AI provider.
Your organisation may also authorise software agents of its own to read (never write) its ERP data through an agent interface (MCP). We record which credential, and the client name and model the agent declares about itself, so your organisation can see what read its data. The model behind such an agent is chosen and operated by your organisation, not by us.
We never use your data to train AI models. The assistant uses Anthropic's commercial API, whose terms do not allow Anthropic to train its models on customer data.
4. Third parties that process your data
We share personal data only with the third-party processors below, each under a contract that limits its use to providing the service to us. We do not sell personal data and we do not share it with data brokers or advertisers.
| Processor | What it does | Where | When |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting, storage, backups, DNS and outbound email (SES) | United States (us-east-1) | always |
| Anthropic, PBC | Large-language-model provider for the AI assistant — receives your assistant messages and the ERP data the assistant retrieves to answer them | United States | only when your organisation enables the AI assistant |
| SequenceQMS (Protostar AI partner platform) | Quality-management integration — supplier qualification status, change orders and controlled-document revisions are exchanged | United States | only when your organisation connects a SequenceQMS workspace |
| Software agents your organisation connects (MCP) | AI agents that your organisation authorises can read (never write) ERP data through the agent interface; the model behind such an agent is chosen by your organisation, not by us | as configured by your organisation | only when your organisation issues an agent credential |
We may also disclose data when the law requires it, or to protect the rights or safety of our customers, our users or the public. We will tell your organisation about such a request unless we are legally prevented from doing so.
5. Cookies
The product sets only the cookies that are strictly necessary to keep you signed in. There are no advertising, analytics or cross-site tracking cookies, so no cookie consent is requested.
| Cookie | Purpose | Lifetime |
|---|---|---|
sid | your signed-in session | until sign-out or automatic logoff |
user_id, full_name, user_image, system_user | shows who is signed in without a server round-trip | session |
6. How long we keep data
- Your account and activity records are kept for as long as your organisation keeps your account, then handled as described in section 7.
- Business records are kept for as long as your organisation decides. Where a customer operates under 21 CFR Part 11 or similar rules, the audit trail and electronic signatures — which include the signer's name — must be retained by law and cannot be erased while that duty lasts.
- Backups are kept on the server for 14 days. Off-site copies are encrypted and versioned; superseded versions expire after 180 days. Data deleted from the live system therefore disappears from backups on that schedule.
- Error diagnostics are kept only as long as needed to fix the defect.
7. Your rights — access, correction, deletion
Wherever you are, you can ask us to see the personal data we hold about you, correct it, or delete it. Depending on where you live (for example under the EU and UK GDPR, or the California Consumer Privacy Act) you may also have rights to restrict or object to processing, to data portability, and to complain to a supervisory authority. We do not discriminate against anyone for exercising a right.
- Download your data: from the product, open Personal Data Download Request and save it. You receive an email with a file of the personal data linked to your account.
- Delete your account: open My Account and choose Delete account, then confirm from the email we send. Your organisation's administrator reviews the request — because some records must legally be kept (section 6) — and the deletion is completed within 30 days. Your personal identifiers are removed or anonymised; business records your organisation is required to keep remain, with your name replaced where the law allows.
- Uploaded files you attached to records are deleted when the record is deleted by your organisation, or when your organisation's workspace is closed, and leave backups on the schedule in section 6. All uploads are private by default and served only to signed-in users with permission to the record they belong to.
- Correct your details: your name and contact details can be changed in My Account, or by your organisation's administrator.
8. Security
All access is over TLS. Each customer organisation runs in its own isolated workspace with its own database. Sessions time out automatically after inactivity. Uploaded files are private by default. Backups and off-site storage are encrypted at rest and are not publicly accessible. Every change to a regulated record is attributed to a signed-in user with a timestamp.
9. Children
Protostar ERP is a workplace tool for organisations. It is not directed at children and we do not knowingly collect data from anyone under 16.
10. International transfers
The service is hosted in the United States. If you use it from elsewhere, your data is transferred to and processed in the United States by us and the processors in section 4.
11. Changes to this policy
When we change this policy we update the version and effective date at the top, and for material changes we notify your organisation's administrator before they take effect. Earlier versions are available on request.
12. Contact
Privacy questions and requests: through your organisation's Protostar ERP administrator, or your Protostar AI account representative.