Privacy Policy
GPAC Software
Last Updated: July 24, 2026
GPAC Software (“GPAC,” “we,” “our,” or “us”) respects your privacy and is committed to handling personal information, business information, and data processed through our ERP and SaaS services responsibly.
This Privacy Policy explains how we collect, use, process, disclose, retain, and protect information when you access or use our websites, software applications, cloud ERP services, APIs, customer-support services, implementation services, training services, and related offerings collectively referred to as the “Services.”
By accessing or using the Services, you acknowledge that you have read this Privacy Policy. Where consent is required by applicable law, we will request consent separately before carrying out the relevant processing.
1. Who We Are
GPAC® Software is an ERP and business-management software platform developed by Generation-Next IT Solution Ltd.
GPAC Software provides accounting, inventory, sales, purchasing, point-of-sale, banking, payroll, HRM, CRM, distribution, manufacturing, reporting, business automation, and related cloud and SaaS services.
Global subscriptions, international billing, sales, marketing, customer onboarding, and international customer support are managed by GPAC Global LLC.
For international customers whose subscription, quotation, invoice, checkout page, order form, or service agreement identifies GPAC Global LLC, GPAC Global LLC is the applicable commercial and billing entity.
For customers whose quotation, invoice, order form, or service agreement identifies Generation-Next IT Solution Ltd., Generation-Next IT Solution Ltd. is the applicable contracting entity.
The entity responsible for a particular customer relationship may therefore depend on the applicable subscription, quotation, invoice, checkout page, order form, hosting arrangement, or written agreement.
2. Scope of This Privacy Policy
This Privacy Policy applies to information processed through:
- The GPAC Software website and related web pages
- GPAC ERP and related software applications
- Cloud-hosted ERP and SaaS subscriptions
- Product trials, demonstrations, quotations, and onboarding
- Live Chat Support and customer-support portals
- Training, implementation, configuration, and support services
- APIs, integrations, and connected third-party services
- Sales, billing, subscription, and customer communications
A separate written agreement, data-processing agreement, service contract, or customer-specific privacy notice may apply to certain Services. Where such an agreement conflicts with this Privacy Policy, the applicable written agreement will govern to the extent stated in that agreement.
3. Information We Collect
We collect and process information reasonably necessary to provide, operate, support, secure, bill, and improve the Services.
A. Contact and Account Information
- Full name
- Company or organization name
- Job title or designation
- Email address
- Telephone or mobile number
- Country, region, city, or business address
- Username and account identifiers
- Subscription and customer-account information
- Communication preferences
B. Sales, Subscription and Billing Information
- Selected product, edition, modules, users, and service plan
- Quotation, invoice, order, and payment status
- Subscription start, renewal, cancellation, and expiry information
- Billing contact and billing address
- Transaction reference and payment confirmation
- Applicable tax or business-identification information
Payments may be processed by authorized third-party payment processors. When payment is completed through a hosted third-party checkout, GPAC Software does not normally receive or store the complete payment-card number, card security code, or complete banking credentials.
We may receive limited payment information from the payment processor, such as payment status, transaction identifier, card type, masked card details, billing country, refund status, dispute information, or subscription status.
C. Customer Business and ERP Data
When customers use GPAC ERP or related Services, we may process data entered, uploaded, generated, imported, or maintained by authorized users, including:
- Accounting and ledger information
- Sales, purchase, receipt, payment, journal, and transaction records
- Inventory, item, warehouse, and stock-movement records
- Customer, supplier, and business-contact information
- Employee, attendance, payroll, and HRM information
- Banking and cash-management records entered by the customer
- Tax, VAT, and regulatory reporting information
- Invoices, quotations, purchase orders, and delivery records
- Documents and files uploaded by authorized users
- Financial statements and management reports
- Configuration, workflow, branch, project, and access-control data
Customers retain ownership of the business data they enter or upload into the Services. GPAC Software does not claim ownership of customer accounting records, inventory data, payroll records, reports, or uploaded business files.
Access, processing, retention, export, backup, and deletion of customer business data remain subject to the applicable subscription, hosting arrangement, payment status, customer instructions, legal requirements, backup procedures, and technical limitations.
D. Support and Communication Information
We may collect information submitted through Live Chat Support, the support portal, email, telephone, product demonstrations, training sessions, customer-service requests, feedback forms, and other communications.
This information may include message content, support history, screenshots, attachments, error descriptions, configuration information, account details, and other information voluntarily provided by the customer.
E. Automatically Collected Information
- IP address
- Browser type and browser version
- Device and operating-system information
- Approximate location derived from IP address
- Login date, time, and account activity
- Pages or functions accessed
- Session, cookie, and preference information
- Error logs and diagnostic information
- Security, authentication, and audit events
- Referral source and website-interaction information
F. Information Received from Third Parties
We may receive limited information from payment processors, hosting providers, referral partners, authorized resellers, analytics providers, communication platforms, or integrations enabled by the customer.
We process such information only where reasonably necessary for an authorized business purpose and subject to applicable legal and contractual requirements.
4. How We Use Information
We may use personal and business information to:
- Provide, operate, maintain, and deliver the Services
- Create, verify, and manage customer and user accounts
- Process quotations, subscriptions, invoices, payments, and refunds
- Provide product demonstrations, onboarding, training, and support
- Configure and implement selected software modules
- Respond to Live Chat, support, billing, and service requests
- Monitor system performance, availability, and technical errors
- Protect accounts, infrastructure, data, and users from security threats
- Detect, prevent, and investigate fraud, misuse, or unauthorized activity
- Maintain audit, security, billing, and operational records
- Improve functionality, usability, support processes, and performance
- Communicate service notices, updates, maintenance, and policy changes
- Send requested quotations, product information, or business communications
- Comply with tax, accounting, legal, regulatory, and contractual obligations
- Establish, exercise, or defend legal and contractual rights
- Resolve complaints, disputes, payment issues, and service incidents
We do not sell customer personal information or customer ERP data to third parties for their independent advertising or marketing purposes.
5. Legal Bases for Processing
Where applicable data-protection law requires a legal basis, we process personal information on one or more of the following grounds:
- Contract: processing necessary to provide a requested subscription, software service, quotation, support service, or other contractual service
- Legal obligation: processing required for tax, accounting, regulatory, fraud-prevention, security, or legal compliance
- Legitimate interests: operating, securing, supporting, improving, and protecting our Services and business operations
- Consent: where consent is requested for a particular communication, cookie, marketing activity, or optional processing
- Protection of rights and security: preventing misuse, responding to security risks, and protecting customers, users, systems, and legal rights
Where we rely on legitimate interests, we consider the purpose, necessity, and potential impact of the processing on individuals.
6. Customer Instructions and Data Processing
For customer ERP data, the customer generally determines what information is entered into the system, which users may access it, and how that information is used for the customer’s business operations.
In such circumstances, GPAC Software and the applicable service entity process customer data to provide, host, maintain, secure, support, and operate the Services according to the customer’s instructions and the applicable agreement.
Customers are responsible for ensuring that they have the lawful authority, permission, notices, and consents necessary to enter or upload personal information into the Services.
Customers should not upload personal information, confidential information, or regulated information that is unnecessary for their authorized use of the Services.
7. Cookies and Similar Technologies
Our website and Services may use cookies, local storage, session storage, pixels, log files, or similar technologies to:
- Maintain secure login sessions
- Remember preferences and settings
- Protect accounts and prevent fraud
- Maintain website and application functionality
- Analyze website traffic and technical performance
- Understand how visitors interact with our website
- Measure the performance of permitted marketing activities
Strictly necessary cookies may be used where required to operate, authenticate, secure, or provide the requested Services.
Where required by applicable law, non-essential analytics, advertising, or marketing cookies will be used only after appropriate notice or consent.
Users may manage available cookie preferences through our cookie notice, consent tool, or browser settings. Disabling necessary cookies may affect the operation of certain website or application functions.
8. How We Share Information
We may share limited information with authorized service providers where reasonably necessary to provide, secure, support, host, analyze, bill, or maintain the Services.
Categories of recipients may include:
- Cloud hosting and infrastructure providers
- Payment processors and banking-service providers
- Email, SMS, communication, and support-service providers
- Analytics, monitoring, security, and fraud-prevention providers
- Implementation, technical-support, and authorized service partners
- Professional advisers, accountants, auditors, insurers, and lawyers
- Government, regulatory, judicial, or law-enforcement authorities
- Successors or participants in an authorized corporate transaction
Service providers are expected to process information only for authorized purposes and subject to appropriate contractual, confidentiality, privacy, and security requirements where applicable.
We may disclose information where reasonably necessary to comply with law, respond to lawful requests, enforce agreements, protect legal rights, prevent fraud, investigate misuse, or protect the safety and security of customers, users, systems, or the public.
GPAC Software does not sell, rent, or trade customer ERP data.
9. Payment Processing
Global subscription payments may be processed by authorized third-party payment processors for GPAC Global LLC.
Payment processors process payment information according to their own legal terms, privacy policies, security standards, and regulatory obligations.
We may exchange limited information with a payment processor to create or manage a subscription, confirm payment, process an authorized refund, respond to a dispute, prevent fraud, maintain billing records, and comply with applicable financial requirements.
Customers should review the privacy notice presented by the applicable payment processor when completing a payment.
10. International Data Transfers
Because GPAC Software supports customers and business operations across different locations, information may be processed or stored in countries where GPAC Global LLC, Generation-Next IT Solution Ltd., cloud hosting providers, payment processors, or other authorized service providers operate.
Data-protection laws may differ between countries. Where required, we use reasonable contractual, technical, and organizational safeguards designed to protect information transferred across borders.
The applicable safeguards may depend on the customer’s location, hosting arrangement, service provider, type of information, and applicable law.
11. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to help protect information against unauthorized access, misuse, loss, disclosure, alteration, or destruction.
Depending on the selected service, deployment, infrastructure, and configuration, safeguards may include:
- SSL/TLS encrypted connections
- User authentication and account-access controls
- Role-based permissions
- Cloud-hosting security controls
- Firewall and infrastructure-monitoring controls
- Activity, error, and login monitoring
- Backup and recovery procedures based on the applicable service plan
- Security updates and vulnerability-response processes
- Access restrictions for authorized personnel
- Administrative and operational security procedures
No internet transmission, cloud platform, software application, or storage system can be guaranteed to be completely secure. Customers must also maintain appropriate security controls for their own users, devices, passwords, networks, and business processes.
Where required by applicable law, we will take appropriate steps regarding confirmed personal-data incidents, including notification to affected parties or authorities where legally required.
12. Password and Account Security
Customers are responsible for maintaining secure passwords, protecting account credentials, assigning appropriate user permissions, and preventing unauthorized account sharing.
Customers should:
- Use strong and unique passwords
- Avoid sharing credentials between users
- Remove access when a user no longer requires it
- Review user roles and permissions periodically
- Protect devices and networks used to access the Services
- Notify GPAC Software promptly about suspected unauthorized access
GPAC ERP may temporarily restrict or monitor access after repeated failed login attempts or suspected unauthorized activity.
13. Data Retention
We retain personal and business information only for as long as reasonably necessary to provide the Services, maintain customer accounts, satisfy contractual and legal obligations, resolve disputes, prevent fraud, maintain security, and protect legal rights.
Retention periods may vary depending on:
- The category and sensitivity of the information
- The customer’s subscription and payment status
- The applicable hosting and backup arrangement
- Contractual and customer-support requirements
- Tax, accounting, legal, and regulatory obligations
- Fraud-prevention, security, and dispute requirements
- Technical feasibility and backup cycles
Following cancellation or termination, customer data may remain available for a limited period according to the applicable subscription, hosting arrangement, and data-retention policy.
Customers should export or request required business data before their subscription or hosting service ends.
Certain information may be retained after account closure where required for billing, tax, accounting, legal compliance, security, backup, fraud prevention, dispute resolution, or the protection of legal rights.
Backup copies may remain for a limited period until they are overwritten or deleted through the normal backup cycle, subject to technical, contractual, and legal requirements.
14. Data Access, Export and Deletion
Authorized customers may access and export available business data using supported reports, functions, or service-request processes, subject to account permissions, payment status, subscription status, and technical limitations.
Data export assistance, custom formats, database services, migration work, or post-termination assistance may require additional service charges where such work is outside the standard subscription scope.
Deletion requests may be limited where information must be retained for contractual, legal, billing, tax, accounting, security, backup, fraud-prevention, or dispute-resolution purposes.
15. Privacy Rights
Depending on location and applicable law, individuals may have the right to:
- Request access to personal information
- Request correction of inaccurate or incomplete information
- Request deletion of certain personal information
- Request a portable copy of certain information
- Object to or restrict certain processing activities
- Withdraw consent where processing is based on consent
- Opt out of certain marketing communications
- Submit a complaint to an applicable data-protection authority
These rights are not absolute and may be subject to identity verification, contractual obligations, legal exemptions, the rights of other persons, and applicable retention requirements.
To protect customer and personal information, we may request reasonable verification before processing a privacy-rights request.
Where consent is the legal basis for processing, withdrawal of consent does not affect processing lawfully completed before the withdrawal.
Where GPAC Software processes personal information solely on behalf of a customer organization, individuals may need to submit their request directly to that customer. We may assist the customer as required by the applicable agreement and law.
16. Marketing Communications
We may send product information, quotations, service updates, training information, and other business communications where requested, contractually necessary, based on an existing business relationship, or otherwise permitted by applicable law.
Recipients may unsubscribe from optional marketing emails using the unsubscribe method provided in the message or by contacting us.
Even after opting out of marketing communications, customers may continue to receive necessary service, security, billing, subscription, support, and legal notices.
17. AI and Customer Data Usage
GPAC Software does not use customer ERP, accounting, inventory, payroll, employee, financial, or business data to train general-purpose artificial intelligence models without explicit customer authorization.
Customer business data is not used for independent advertising or sold for AI-model training.
Where an optional AI-powered feature or third-party AI integration is introduced, relevant information regarding data usage, providers, limitations, and available choices may be provided separately before activation or use.
18. Third-Party Services and Integrations
The Services may integrate with payment gateways, cloud platforms, email services, SMS gateways, analytics tools, banking services, APIs, reporting tools, or other external platforms.
Third-party services operate under their own terms, privacy policies, technical controls, and data-processing practices.
Customers should review the applicable third-party policies before enabling or using an external integration.
We are not responsible for third-party privacy or security practices that are outside our reasonable control.
19. External Links
Our website or Services may contain links to external websites or services. This Privacy Policy does not govern websites or services operated by unrelated third parties.
Users should review the privacy policy of an external website before providing personal information through that website.
20. Children’s Privacy
GPAC Software is designed for businesses and authorized business users. The Services are not directed to children and should not be used by a child without appropriate authorization and supervision from the responsible organization, parent, or legal guardian where applicable.
If you believe that personal information relating to a child has been submitted without appropriate authorization, please contact us so that the matter can be reviewed.
21. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our Services, technology, service providers, security practices, business operations, or legal requirements.
Updated versions will be published on the official GPAC Software website with a revised “Last Updated” date.
Where required or reasonably appropriate, material changes may also be communicated through the website, customer account, registered email, Live Chat Support, or another appropriate communication channel.
22. Contact Us
For privacy questions, data requests, complaints, or concerns, please contact:
GPAC Software
Privacy and Support Email: support@gpacsoftware.com
Sales and Billing Email: sales@gpacsoftware.com
Support Portal: https://support.gpacerp.com/
Website: https://gpacsoftware.com/
Privacy requests may also be submitted through the official GPAC Live Chat Support available on the GPAC Software website.
Global SaaS, Billing and Commercial Operations:
GPAC Global LLC
30 N Gould St, Suite N
Sheridan, WY 82801
United States
Global Sales: +1 307-445-3857
Email: sales@gpacsoftware.com
Software Development and Bangladesh Operations:
Generation-Next IT Solution Ltd.
Century Center, Kha 225 Pragati Sarani
Bir Uttam Rafiqul Islam Avenue
Dhaka 1212, Bangladesh
Email: info@gnisbd.com
Office: +880 16 1136 5897
Bangladesh Support: +880 19 7777 4722
Privacy and Support Email: support@gpacsoftware.com
Trust Statement
Your Business Data Stays Yours.
GPAC Software does not sell customer ERP or business data.
We use reasonable administrative, technical, and organizational safeguards, including encrypted connections and access controls, designed to help protect customer information.
Secure ERP. Private Data. Customer Control.
Copyright © 2026 GPAC Software. All rights reserved. GPAC Software is developed by Generation-Next IT Solution Ltd. Global subscriptions, international billing, sales, marketing, onboarding, and international customer support are managed by GPAC Global LLC.