Legal
Privacy Policy
Last updated: 29 July 2026
This Privacy Policy explains how Connecticut Co Ltd ("we", "us", "our") collects, uses, and protects personal data in connection with ConnectERP (the "Service"). It's written with the Mauritius Data Protection Act 2017 in mind, and applies to visitors of our public pages, prospects who sign up for a trial, and the individual users of a Customer's account.
1. Two Kinds of Personal Data
It's useful to separate two different roles we play:
- Account & billing data - information about the Customer company and the individuals who use the Service on its behalf (name, work email, password, role, login activity). For this data, we act as the controller.
- Customer Data - whatever a Customer chooses to store inside their own tenant account (their customers' and suppliers' names, contact details, transactions, etc.). For this data, the Customer is the controller and we act as a processor, handling it only to provide the Service and on the Customer's instructions. If you are an individual whose data appears inside someone else's ConnectERP account, requests about that data should generally go to that business directly, not to us.
2. Information We Collect
- Account information: company name, admin name, work email, password (stored hashed, never in plain text), and chosen subscription plan.
- Usage and log data: login timestamps and IP address (used for our Login History security feature), and general application logs used to diagnose faults.
- Communications: messages you send us for support or billing queries.
- Customer Data: as described in Section 1 - not collected by us directly, but stored on the Customer's behalf as part of the Service.
We do not use third-party advertising trackers or sell personal data to anyone.
3. How We Use Information
We use account and billing data to:
- Provide, maintain, and secure the Service, including authentication and the Login History feature;
- Send transactional email (verification, password resets, billing/trial notices, and documents you ask us to email on your behalf, e.g. an invoice to your customer);
- Respond to support requests;
- Comply with legal and tax obligations.
4. Legal Basis for Processing
We process account and billing data on the basis that it is necessary to perform our contract with you (providing the Service you signed up for), to comply with legal obligations (e.g. tax records), and, in limited cases such as service announcements, on the basis of our legitimate interest in running the business - always in a way that doesn't override your own rights and interests.
5. Sharing and Third Parties
We share personal data only where necessary to run the Service: with infrastructure and email-delivery providers who process data on our behalf under confidentiality obligations, and where required by law or to protect our legal rights. We do not sell personal data or share it for third-party marketing.
6. Data Security
Each Customer's data is isolated to its own tenant account and is not accessible from other Customers' accounts. Passwords are hashed, not stored in plain text, and Two-Factor Authentication is available on every account. We take regular backups of Customer Data. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable technical and organizational measures appropriate to the sensitivity of the data involved.
7. Data Retention
We retain account and billing data for as long as your account is active, and for a reasonable period afterward to comply with legal, accounting, or tax obligations. Customer Data is retained for as long as the Customer's account is active; if an account is cancelled or terminated, Customer Data may be retained for a limited period to allow export before deletion.
8. Your Rights
Subject to the Mauritius Data Protection Act 2017, you may have the right to request access to, correction of, or deletion of your personal data, to object to or restrict certain processing, and to lodge a complaint with the Data Protection Office of Mauritius. To exercise any of these rights over account or billing data we hold about you, contact us using the details in Section 11. If your request concerns data stored inside a specific Customer's tenant account (see Section 1), we will direct you to that Customer, as they control that data.
9. Cookies
We use only the cookies necessary for the Service to function: a session cookie to keep you signed in, and a CSRF token to protect form submissions from cross-site attacks. We do not use third-party advertising or analytics cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice before they take effect.
11. Contact
Questions about this Privacy Policy, or requests relating to your personal data, can be sent to postmaster@connecticutcoltd.mu.
See also our Terms of Service and Refund & Cancellation Policy.