01 Our respective roles
Axera is a trading name of EJ Global Limited, company number 17231331, registered in
England and Wales. This notice applies to Axera’s hosted ERP, warehouse management and CRM service.
The customer is normally the controller
The organisation subscribing to Axera normally decides why and how personal data in its workspace
is used. This can include data about its workers, customers, suppliers, prospects, drivers and other
business contacts. The customer is responsible for having a lawful basis, giving required privacy
information, configuring appropriate access and responding to individuals’ rights.
Axera is normally the processor
Axera processes that customer-controlled data on the customer’s behalf to host, operate, secure,
maintain and support the service. We follow the customer’s documented instructions, the customer
agreement and the applicable data-processing terms, unless UK law requires otherwise.
The role depends on the purpose of a particular activity, not only the label in a contract. Axera can be a
processor for ERP records and a controller for separate information it needs for its own business purposes.
This notice summarises those roles. A separate written Data Processing Addendum should accompany the
customer agreement and set the binding processing instructions and Article 28 responsibilities.
02 Data the product can handle
The exact information depends on which modules and fields the customer chooses to use. It can include:
Users and access
Names, work contact details, job titles, departments, roles, permissions, account status, supplier-portal links and authentication or security settings.
Business contacts
Customer, supplier, prospect and contact names, business addresses, email addresses, telephone numbers, job information, notes and communication preferences.
Orders and warehouse operations
Orders, purchase orders, delivery details, bookings, stock and picking movements, returns, vehicles, location activity, barcodes and records of who performed an action.
Finance and commercial records
Invoices, transactions, payment status, credit information, quotations, proposals, pricing, billing references and supporting documents uploaded by authorised users.
Tasks, support and content
Tasks, comments, notifications, support tickets, guided-help feedback, messages, notes and files that users choose to upload.
Audit and technical records
Stock and finance audit trails, user-attributed changes, feature usage, request and diagnostic identifiers, IP-derived security controls, errors and other service logs.
The data normally comes from the customer and its authorised users, is generated through their use of the
product, or is imported through an integration the customer chooses to configure. Customers should not enter
special-category or criminal-offence data unless its use has been agreed, is lawful and appropriate safeguards
are in place.
03 How Axera processes customer-controlled data
As processor, we use customer-controlled data only as needed to:
- provide the ERP, WMS, CRM, finance, reporting and related features selected by the customer;
- authenticate users and apply the customer’s roles and permissions;
- host, store, back up, transmit and retrieve information;
- provide requested implementation, maintenance, troubleshooting and support;
- protect the service, investigate incidents and prevent misuse; and
- comply with documented instructions or a legal requirement that applies to us.
We do not sell, rent or trade customer-controlled data. We do not use it for third-party advertising or to
build advertising profiles, and we do not use it to train our own general-purpose AI models.
Axera does not determine the customer’s lawful basis for ordinary ERP processing. The customer must identify
and document the appropriate basis for its own purposes and use of the product.
04 When Axera acts as a controller
Axera acts as a separate controller where we decide an independent business purpose for limited personal
information. Depending on the relationship, this can include:
- customer representatives and commercial contacts used to administer contracts, accounts and billing;
- support correspondence and service communications with people who contact us directly;
- security, authentication, abuse-prevention and diagnostic records needed to protect the platform;
- records needed to establish or defend legal claims or meet accounting and regulatory obligations; and
- service and AI-usage records, including the user, feature, model, token totals and estimated cost, used to operate, control and account for enabled features.
Our usual lawful bases for these activities are performance of a contract, our legitimate interests in
administering and securing the service, and compliance with legal obligations. We retain this information
only for as long as needed for those purposes and applicable record-keeping requirements.
Public website visits, demo enquiries and prospect communications are covered separately by our
website privacy notice.
05 Service providers, integrations and AI
We may use contracted service providers for infrastructure, database hosting, backups, security, monitoring,
support and email delivery. Where they handle customer-controlled data, they act as subprocessors and are
subject to data-protection obligations. The applicable Data Processing Addendum should identify the current
subprocessor information and any notification process for changes.
Optional OpenAI features
AI features remain unavailable unless an organisation enables them and configures an API key. An
explicit user action may then send a bounded prompt and relevant, permission-scoped context to the
configured OpenAI API. Axera records feature, model and usage totals for control and accounting. We do
not make automatic per-keystroke or background OpenAI calls.
Optional email delivery
If a customer configures Mailgun-backed marketing features, recipient addresses, message content and
delivery events may be sent to or received from Mailgun to deliver mail and enforce suppression,
opt-out and bounce rules. Sending remains under customer configuration and authorised user actions.
A customer may also configure its own integrations. That customer is responsible for assessing the integration,
authorising the transfer and informing affected individuals. Some providers may process information outside the
United Kingdom; where we arrange such a transfer, we use an applicable lawful mechanism and safeguards.
06 Security, permissions and human access
We use technical and organisational measures appropriate to the service and risk. These include authenticated
access, customer-configured roles and permissions, protected credentials and secrets, encrypted transport,
audit trails for material operations, rate limiting, backups and diagnostic monitoring.
Customer data is available to the customer’s authorised users according to their permissions. Axera personnel
may access it only where needed to provide requested support, operate or secure the service, comply with law,
or otherwise follow documented customer instructions. Personnel with access are subject to confidentiality
obligations.
No system can guarantee absolute security. Customers must manage their user accounts, permissions, devices and
authentication methods appropriately and notify us promptly of suspected compromise.
07 Retention, return and deletion
The customer controls how long its operational records are required, subject to product capabilities, the
customer agreement, documented instructions and applicable law. Some stock, finance and other audit records are
intentionally preserved to maintain an accurate history and should not be altered or removed without a lawful,
authorised process.
At the end of the service, return and deletion of customer-controlled personal data should be handled under the
Data Processing Addendum and the customer’s instructions. Copies may remain temporarily in protected backups
until they age out through the normal backup cycle, or longer where UK law requires retention.
Axera-controlled commercial, security, support and legal records follow retention periods based on their purpose,
risk and applicable limitation or record-keeping requirements. Data that is no longer required is deleted or
anonymised.
08 Individual rights and requests
For data in a customer workspace
Contact the organisation that provided your account, employs you, or entered your information into
Axera. It is normally the controller and decides how to respond. If you contact Axera about customer-
controlled data, we will normally refer or pass the request to the relevant customer and assist it as
required by our processing terms.
For data controlled by Axera
Contact hello@axera.uk.
Depending on the circumstances, you may have rights of access, correction, erasure, restriction,
objection and portability. These rights are not absolute, and we may need to confirm your identity.
Axera’s AI features provide advisory, search or drafting assistance and do not make solely automated decisions
about individuals that produce legal or similarly significant effects. Operational changes remain subject to
authorised user action and server-side controls.