Ummigo ERP Logo
UMMIGO ERPEnterprise ERP
PricingSupport
Book a CallPortal
Enterprise Release v4.8 Live

Stay ahead with enterprise ERP innovations

Join 15,000+ operations leaders. Get product updates, security advisories, and architecture deep dives.

U
UMMIGO ERPENTERPRISE PLATFORM

Unified cloud ERP platform for modern retail, hospitality, manufacturing, and financial operations across 45+ countries. Built for extreme uptime and effortless compliance.

All Systems Operational SOC2 & ISO 27001

Products

  • Retail POS & Billing
  • Restaurant KDS & POS
  • Inventory & WMS
  • Accounting & Finance
  • HCM & Payroll
  • Integrations Hub

Solutions

  • Enterprise Chains
  • Franchise Networks
  • Manufacturing ERP
  • ROI Calculator
  • Pricing Plans

Company

  • About Us
  • Careers HIRING
  • Press & Media
  • Trust & Security
  • System Status

Support & Legal

  • Help Center
  • Documentation
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing (DPA)
© 2026 Ummigo ERP Technologies Inc. All rights reserved.
PrivacyTermsSecurityStatus
HomeLegal ComplianceData Processing Agreement
Enterprise Governance & Privacy

Data Processing Agreement

Formal DPA governing processor/controller roles, technical safeguards, sub-processor authorizations, and breach notification obligations for UMMIGO ERP enterprise tenants.

Effective Date & Last Revised: July 31, 2026

Table of Contents

1. Definitions & Scope2. Processor Obligations (UMMIGO ERP)3. Controller Obligations (Enterprise Tenant)4. Technical & Organizational Security Measures5. Approved Sub-Processors6. Personal Data Breach Notification Protocol7. Governing Law
Compliance Inquiries

Questions regarding our legal parameters or data safety practices?

Contact Legal Counsel

Definitions & Scope

This Data Processing Agreement ("DPA") governs the processing of personal and enterprise business data between:

  • Data Controller: The enterprise tenant entity (your company) who determines the purposes of data processing.
  • Data Processor: UMMIGO ERP Private Limited, who processes data on behalf of the Controller under written instruction.
  • Sub-Processors: Approved third parties (AWS, SendGrid, Twilio) engaged by UMMIGO ERP to deliver infrastructure services.

This DPA applies to all personal data processed through the UMMIGO ERP SaaS platform on behalf of the enterprise client.

Processor Obligations (UMMIGO ERP)

UMMIGO ERP as Data Processor commits to the following obligations:

  • Process personal data only on documented written instructions from the enterprise Controller.
  • Ensure all authorized staff processing personal data are bound by confidentiality obligations.
  • Implement and maintain technical safeguards as described in the Security Addendum (AES-256, TLS 1.3, RBAC).
  • Assist the Controller in responding to data subject access requests within legally mandated timeframes.
  • Notify the Controller of any personal data breach within 72 hours of confirmed discovery.
  • Delete or return all personal data to the Controller upon termination of services.

Controller Obligations (Enterprise Tenant)

As the Data Controller, the enterprise tenant accepts responsibility for:

  • Ensuring lawful basis for processing employee personal data (CNIC, biometrics, salary information).
  • Providing required disclosures and consents to employees whose data is processed through the platform.
  • Configuring role-based access controls appropriately to limit data access to authorized personnel.
  • Complying with applicable national laws (PECA 2016, PDPB) governing data collected through the platform.

Technical & Organizational Security Measures

UMMIGO ERP implements the following verified technical safeguards:

  • Encryption: AES-256 at rest; TLS 1.3 in transit across all network layers.
  • Access Control: Multi-factor authentication, IP whitelisting, role-based permission matrices (RBAC).
  • Data Isolation: Logical multi-tenant database schema isolation per enterprise account.
  • Logging: Immutable audit trails for all data modification events (GL vouchers, HR records, API calls).
  • Backup: Daily automated encrypted snapshots with 90-day point-in-time recovery.
  • Incident Response: Documented P1 breach escalation protocol with 72-hour Controller notification SLA.

Approved Sub-Processors

UMMIGO ERP currently engages the following approved sub-processors under binding data processing agreements:

Sub-ProcessorServiceData Location
Amazon Web Services (AWS)Database & Cloud Compute HostingAsia Pacific / EU Regions
SendGridTransactional Email DeliveryUSA (GDPR/SCC Covered)
TwilioSMS OTP & Alert NotificationsUSA (GDPR/SCC Covered)

Sub-processor updates are communicated via email notice 14 days in advance. Controllers may object to new sub-processors in writing within this window.

Personal Data Breach Notification Protocol

In the event of a confirmed personal data breach, UMMIGO ERP will notify the enterprise Controller within 72 hours via registered email and Admin Console alert. Notification will include: nature of breach, categories of data affected, estimated data subject count, and immediate containment measures taken.

Governing Law

This DPA is governed by the laws of Pakistan and shall be interpreted in accordance with applicable international data protection standards. Disputes are subject to arbitration in Lahore, Pakistan.

Official Legal Contact Details

UMMIGO ERP Operations & Legal Governance Team
Email: legal@ummigoerp.com | Phone: +92 321 8272999
Corporate Address: UMMIGO Tower, Tech District, Lahore / Karachi, Pakistan