This Privacy Policy ("Policy") explains how Global Chains ERP and its operating entity ("Global Chains ERP," "we," "us," or "our") collects, uses, discloses, stores, and protects information in connection with our cloud software platform and related services (collectively, the "Service"). The Service is designed as financial and business operations infrastructure, including without limitation: smart invoicing; accounts payable and receivable; vendor and client records; treasury, wallet, and payment-orchestration tooling; multi-currency and reconciliation features; M-Pesa and other payment-channel integrations where enabled; subscription billing; organization and workspace management; roles and approvals; APIs, webhooks, and third-party integrations; document and logo uploads; PDF ingestion where offered; email and messaging-related features; optional blockchain or digital-asset-related workflows including BTCPay Server hosting for merchants; optional push notifications; ledger or accounting-oriented exports/sync where offered; and administrative or compliance-oriented logging.
Important: This Policy is provided for transparency. It does not constitute legal advice. Financial, payroll, tax, sanctions, and data-protection requirements vary by jurisdiction and use case. Engage qualified counsel and, where applicable, execute a Data Processing Addendum (DPA) with us for enterprise deployments.
Last updated: August 2026
This Policy applies to visitors to our websites, registered users, organization administrators and members, payors or counterparties who interact with public or tokenized flows we host (such as hosted invoice or payment pages or vendor submission links), and individuals whose information is submitted into the Service by a customer (for example employees, vendors, or clients of our customers).
If you interact with the Service only as an employee or contact of our customer, that customer is typically responsible for informing you about processing and for honoring privacy requests for business data they control. We may still process certain information as an independent controller for security, billing, and platform integrity.
The Service is multi-tenant. In general:
Where laws require a lawful basis (such as under GDPR/UK GDPR), we rely on contract, legitimate interests (balanced against rights), legal obligation, or consent as appropriate to the activity. California and other U.S. state laws may classify certain processing differently; see Section 18.
Depending on how you use the Service, we may collect:
Where a workspace enables our POS service, we process operational records created at the till. Much of this concerns people who are not our users — a venue's staff and its walk-in customers — and the venue is the controller for it:
Where payroll features are enabled, a customer may store employee names, work email, job title, department, postal address, bank name and account number, mobile-money number and provider, and wallet address, together with salary, expense and payout records. This is sensitive employment data; the employing customer is the controller and is responsible for having a lawful basis to hold it and for telling its employees.
We may use rules-based systems or machine learning for fraud scoring, risk flags, categorization, suggestions, or workflow routing. Such processing may produce recommendations only; it does not replace your judgment unless you explicitly configure automation. Where required, you may have rights to human review or to object.
The AI assistant runs on infrastructure we operate. In our current production configuration the language model is self-hosted— prompts containing your business data are sent to a model running on our own servers, not to a third-party AI provider, and your content is not used to train anyone else's model.
So that you can judge this properly rather than take it on trust, here is exactly how it works:
Where GDPR, UK GDPR, Kenya Data Protection Act, Nigeria NDPA, South Africa POPIA, India DPDP Act, UAE frameworks, or comparable laws apply, we process personal data under one or more of: performance of a contract, legitimate interests (e.g. securing the Service, preventing fraud—balanced against individual rights), legal obligation, vital interests (rare), or consent where required (e.g. non-essential cookies or certain marketing). Public-sector or employment contexts may impose additional rules.
We may disclose information to:
Naming these is more useful than a category list. Several are engaged only if the relevant feature is switched onfor your workspace — a customer that does not use M-Pesa never touches Safaricom through us.
| Provider | Purpose | Engaged |
|---|---|---|
| MongoDB Atlas | Primary database for all application and POS data | Always |
| Vercel | Web application hosting, edge delivery, product analytics and performance metrics | Always |
| Sign-in with Google (identity verification and basic profile) | If you use Google sign-in | |
| Zoho Mail (SMTP) | Transactional email — invoices, invitations, password resets, notices | Always |
| Paystack | Subscription billing and card/bank collection | If you hold a paid subscription |
| Safaricom (Daraja) | M-Pesa STK push, payment pull and reconciliation | If M-Pesa is enabled |
| KCB | Bank collection and IPN settlement notifications | If KCB is enabled |
| Honeycoin | Treasury funding, payouts and settlement rails | If treasury payouts are enabled |
| Meta (WhatsApp Business) | WhatsApp messaging, receipts and the WhatsApp AI assistant | If WhatsApp is enabled |
| BTCPay Server | Self-hosted Bitcoin payment infrastructure for merchants | If Bitcoin payments are enabled |
| Blockchain RPC and wallet providers | Reading and broadcasting on-chain treasury transactions | If crypto treasury is enabled |
| ClickUp | Optional workflow integration | If you connect it |
Not on this list, deliberately:the AI model that powers the assistant. Under our current configuration it runs on infrastructure we operate, so it is not a subprocessor disclosure — see section 5A, including the fallback caveat.
This list may change. We will give enterprise customers notice where contractually required before engaging a new subprocessor that processes personal data on their behalf.
Where we host or operate BTCPay Server instances on behalf of merchants, we provide server software infrastructure only. We are not a payment processor, payment service provider (PSP), money transmitter, virtual asset service provider (VASP), or custodian in relation to Bitcoin or any other digital asset transactions processed through BTCPay Server.
BTCPay Server operates on a self-custodial model: merchants control their own Bitcoin private keys and wallets. We do not hold, custody, control, or have access to merchants' Bitcoin funds at any time.
In connection with BTCPay Server hosting, we may process:
On-chain transaction data is public by nature of the Bitcoin network. Transaction hashes, addresses, and amounts recorded on the blockchain are publicly visible and cannot be erased by us or by you. We may display or index this publicly available data to operate features you enable.
You (the merchant or operator) are solely responsible for all compliance obligations arising from your acceptance of Bitcoin payments, including applicable VASP registration, KYC/AML program requirements, tax reporting, and any licensing required in your jurisdiction.
We may process and store data in the United States, European Economic Area, United Kingdom, Kenya, and other regions depending on deployment and vendor locations. Where transfers from the EEA, UK, Switzerland, or other restricted jurisdictions occur, we implement appropriate safeguards such as Standard Contractual Clauses, the UK Addendum, or other lawful mechanisms. Copies of transfer assessments or DPAs may be available to enterprise customers upon request.
Application and POS data is held in a managed MongoDB Atlas cluster. The web application is served from Vercel's edge network, which means static assets and request routing are distributed by design. We will confirm the specific database region on request; enterprise customers can pin residency contractually.
Two components run on infrastructure we operate ourselves rather than being handed to a vendor: the AI model behind the assistant (section 5A) and, where a merchant enables Bitcoin, their BTCPay Serverinstance (section 7A). Payment-provider credentials that a workspace stores with us — M-Pesa and KCB API keys and secrets — are encrypted at rest under a key we hold separately from the database.
Some processing is unavoidably international: Safaricom and KCB operate in Kenya, Paystack and Meta operate regionally and globally, and public blockchains are worldwide by construction.
Specifics are more useful than adjectives. The measures below are the ones actually implemented in the platform today:
No system is perfectly secure.We do not represent that the Service is immune to compromise, "unhackable," or free from defects, and the list above is a description of current practice rather than a warranty. You are responsible for safeguarding credentials, API keys, and devices used to access the Service, and for removing access when a team member leaves.
We may record events such as authentication, role changes, configuration edits, approvals, exports, treasury or payout instructions initiated through the Service, webhook receipts, and administrative actions. Logs support security monitoring, dispute resolution, regulatory inquiries, and forensic investigations. Retention follows operational and legal requirements and may extend beyond account deletion where mandated for accounting or anti-fraud purposes.
We retain personal data for as long as necessary to provide the Service, comply with law (including tax, AML, and bookkeeping retention), resolve disputes, and enforce agreements. Where the platform enforces a schedule automatically, these are the periods:
Backups may persist for a limited period after a deletion request. Enterprise customers may negotiate schedules in a DPA.
You may request export or deletion subject to law and technical feasibility. Where we act as processor, requests may need to be routed through your organization's administrator. Some information must be retained by law or for legitimate interests (e.g. billing proofs, abuse prevention). Public blockchain records cannot be erased by us.
We keep this deliberately small. In normal use the Service sets:
next-auth.session-token, split across numbered parts when large). Strictly necessary — it is what keeps you signed in. HttpOnly, SameSite=Lax, Secure in production, and it expires after 30 days or when you sign out.We do not run advertising pixels or sell audience data. Blocking the session cookie will prevent sign-in.
We may send product updates or offers where permitted. You may opt out of marketing communications; transactional or security notices may continue.
The Service is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children.
We prohibit use of the Service for sanctions evasion, money laundering, terrorist financing, fraud, or other illegal financial activity. We may screen data where required, block activity, freeze features, or terminate accounts consistent with law and risk policies.
If you use Bitcoin, cryptocurrency, or other virtual asset features of the Service (including BTCPay Server hosting), you are solely responsible for complying with all applicable laws and regulations in your jurisdiction, including:
We screen for sanctioned addresses where technically feasible using available screening tools, but we make no representation that our screening is exhaustive or complete. You remain responsible for your own sanctions compliance program. We reserve the right to block, restrict, or report transactions associated with sanctioned addresses or persons.
Kenya is our primary market, so we call it out first. Under the Data Protection Act, 2019, data subjects in Kenya have the right to be informed of the use of their personal data, to access it, to object to its processing, to have inaccurate data corrected, and to have it deleted where there is no lawful reason to keep it. Complaints may be lodged with the Office of the Data Protection Commissioner (ODPC).
Two points specific to how the Service is used here. First, a venue that records a customer's name and phone number against a credit tab is a data controller under the Act and carries the duty to inform that customer. Second, M-Pesa transaction data reaches us through Safaricom under their own terms as well as ours.
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to processing, and to lodge a complaint with a supervisory authority. California residentsmay have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of certain "sales" or "sharing" (we do not sell personal information for money in the traditional sense; we may use cookies or analytics that could constitute "sharing" under some definitions—see our Cookie disclosures). Other U.S. states are adopting similar laws. We will verify requests as permitted by law.
If we determine a personal data breach requires notification under applicable law, we will notify regulators and affected individuals as required. Customers acting as controllers are responsible for notifying their own data subjects where their business data is affected and they have the relationship.
The Service may link to third-party sites or embed widgets. Their privacy practices are governed by their own policies. Wallet extensions, banking portals, or social login providers may collect data independently.
We may update this Policy to reflect product, legal, or operational changes. We will post the updated Policy with a new "Last updated" date and, where required, provide additional notice. Continued use after changes may constitute acceptance where permitted.
Privacy questions and requests:
Email: privacy@chains-erp.com
Data Protection Officer: dpo@chains-erp.com
Legal notices: legal@chains-erp.com
Address: Nairobi, Kenya. Full registered address available upon written request to legal@chains-erp.com.