Features Compliance Pricing Industries
Automotive Real Estate POS & Retail Business Services Professional Services Logistics Tourism & Hospitality Bodycare & Fitness Learning Transportation Construction
Resources

Privacy Policy

What we collect, why, who sees it, and what you can ask us to do - for this website and for the application.

Last updated 11 September 2026

This policy explains what personal data VISIONS ERP collects, why, and what you can do about it. It covers this website (visionserp.com) and the software at app.visionserp.com. "We", "us" and "our" mean VISIONS ERP, Dubai, United Arab Emirates. We have kept it short on purpose; if a question is not answered here, write to hello@visionserp.com and a person will reply.

1. Two kinds of data

There is a distinction that runs through everything below.

  • Data about you - the person or business dealing with us. Your name, work email, phone number, company, the messages you send us, and the account you open. For this we are the controller: we decide what is collected and why, and this policy is about that.
  • Data inside your ERP - your customers, suppliers, employees, transactions and documents. That is your data. You decide what goes in and who sees it; we process it only to run the service for you. Our obligations for it are in the terms and conditions, and your own privacy obligations to the people in it stay with you.

2. What we collect on this website

  • Contact and demo requests - name, email, and whatever you choose to add: phone or WhatsApp number, company, a message. We also record the page you sent it from and your IP address, which is how we tell a real enquiry from a bot.
  • The pop-up form - the same fields, from the short form that appears after you have read a page for a while.
  • Newsletter - your email address and the page you signed up from. Every email we send carries a one-click unsubscribe link.
  • Server logs - the ordinary web-server record of requests: IP address, browser, time, page. Kept for a short period for security and to diagnose faults.

We do not run Google Analytics, advertising pixels or any other third-party tracking on this website. There is no cookie banner because there is nothing to consent to: the only cookies are the ones the site needs to work (see section 6).

3. What we collect in the application

  • Account details - the business name, the account owner's name and email, and the name and email of each user you add. Users choose their own passwords; we store only a one-way hash and cannot read them.
  • Billing - your plan, billing period and invoice history. Card details are handled by the payment provider and are never stored on our systems.
  • Usage and audit records - who did what and when inside your company's account. This is a feature: it is the audit trail your accountant and auditor rely on, and it is visible to you.
  • Support conversations - what you tell us by phone, WhatsApp or email when you ask for help, so that the next person you speak to has the context.

4. Why we use it

  • To answer you when you write, call or book a demo - and to follow up on that request. Enquiries from this website are passed into our own customer records at app.visionserp.com so that the person who calls you back has what you sent.
  • To run your account: sign you in, bill you, back up your data, restore it if something goes wrong, and tell you about changes that affect you.
  • To keep the service safe - spotting abuse, blocking attacks, and investigating faults.
  • To send the newsletter, only if you asked for it, and only when something in the UAE actually changes.
  • To improve the product, using usage information in aggregate. We do not read the contents of your ledger to do this.

We do not sell personal data, and we do not share it with advertisers. We contact you about the product you are using or asked about, not about other people's products.

5. Who else sees it

As few parties as possible, and each only for a reason:

  • Hosting - the cloud infrastructure that runs the website and the application and holds its backups. Your data is stored in isolated tenancies on those systems.
  • Email delivery - the mail service that sends transactional email and the newsletter on our behalf.
  • WhatsApp - if you choose to message us there, Meta's terms apply to that conversation.
  • Fonts and icons - the website loads typefaces and icon fonts from Google Fonts and jsDelivr. Your browser sends its IP address to those services to fetch the files, as it does for any public asset.
  • Accountants and other users you invite - anyone you give a login sees what the role you assign allows. That is your choice, and you can withdraw it at any time.
  • Authorities - if the law requires us to disclose something, we will, and we will tell you unless we are legally prevented from doing so.

We do not use your data to train artificial-intelligence models, ours or anyone else's. Where we use an AI service to draft our own website content, no customer data is sent to it.

6. Cookies and local storage

  • Session cookie - keeps you signed in to the application, and on the website lets a form you submit be tied to the page that showed it. Expires when your session ends.
  • CSRF token - a security cookie that stops another site from submitting forms on your behalf.
  • Pop-up preference - if you close or send the pop-up form, the website remembers that in your browser's local storage so it does not ask again. This never leaves your browser.

No advertising, analytics or cross-site cookies are set by this website.

7. How long we keep it

  • Enquiries - as long as the conversation is live, then as part of our customer records if you become a customer. If you do not, we delete them within two years.
  • Newsletter - until you unsubscribe. We keep a record that you unsubscribed so that we never email you again by mistake.
  • Account data - for the life of the account, then 30 days after closure so that it can be exported or recovered, then deleted from live systems and from backups as they rotate. Invoices we issued to you are kept for the period UAE tax law requires.
  • Server logs - a matter of weeks.

8. Your rights

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies to you, other data-protection law, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct it if it is wrong;
  • delete it, where we have no continuing need or legal duty to keep it;
  • stop sending you marketing - the unsubscribe link does this instantly, or write to us;
  • restrict or object to a particular use.

Email hello@visionserp.com from the address we hold for you. We will answer within 30 days and will not charge for a reasonable request. If we refuse, we will tell you why. You also have the right to complain to the UAE Data Office.

For data inside your ERP - a customer of yours asking to be deleted, for example - the request goes to you, and the application gives you the tools to act on it.

9. Security

Connections are encrypted in transit. Passwords are hashed, not stored. Each company's data is isolated from every other customer's, and access inside a company is controlled by the roles you set. Backups are taken automatically. Access to production systems is limited to the people who need it to run and support the service, and their actions are logged. If we ever discover a breach that affects your data, we will tell you promptly and honestly what happened and what we are doing about it.

10. Children

The website and the application are for businesses. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete it.

11. Changes

When this policy changes, the date at the top changes with it. If a change materially affects how we use your data, we will email the account owner before it takes effect.

12. Contact

VISIONS ERP, Dubai, United Arab Emirates · hello@visionserp.com · +971 56 887 0500.