Legal · Document
Privacy Policy
Effective: 2026-07-27. This Privacy Policy describes the personal information that Galan ERP, LLC (“Galan,” “we,” “us,” or “our”) collects,how we use it, and the rights you have under US state privacy laws.
A summary of changes between versions lives in the changelog at the bottom of this page. To exercise your rights, see How to Exercise Your Rights below.
1. Scope of This Policy
This Policy applies to personal information that Galan processes in its capacity as a service provider (CCPA terminology) to its business customers (“tenants”) and the personal information of end-users who interact with Galan’s marketing site, galan.com, and any subdomain thereof. Tenants’ own customers (whose data lives on Galan’s infrastructure but is owned by the tenant) are addressed under the tenant’s own privacy practices; we process their data only on the tenant’s documented instructions under our subprocesser commitments.
This Policy is written for residents of the United States. If you are an EU, UK, or EEA resident, please refer to our separate EU compliance commitments described in CONTRACTSnDOCS/EU_COMPLIANCE.md.
2. Personal Information We Collect
We collect personal information in three categories: (a) information you provide directly, (b) information collected automatically when you visit our site or use our service, and (c) information provided by third parties (e.g., your bank when you connect a bank feed).
Categories collected
- Identifiers. Name, email, business postal address, phone, login credentials.
- Commercial information. Records of services purchased, invoice data, payment history, subscription tier.
- Internet activity. IP address, browser type, referring URL, pages visited, session timestamps.
- Professional information. Business role, employer name.
- Financial information. Bank account identifiers (obtained via Plaid), payment instrument identifiers (processed by Stripe; we do not store full card numbers), invoice line items.
- Inferences. Service usage patterns to surface product tips; product-fit scoring for sales outreach (if you have opted in).
We do not knowingly collect sensitive personal information as defined by CPRA §1798.140(ae), with one limited exception: bank account credentials you connect for ACH. See §5 Sensitive PI.
3. How We Use Personal Information
We use the personal information we collect for the following business purposes:
- Provide, operate, maintain, and secure the Service.
- Process transactions and render invoices (including US sales-tax computation through tenant-chosen providers; see Subprocessors).
- Authenticate users, prevent fraud, and enforce our Terms.
- Communicate with you about the Service: account notices, security alerts, billing notices, and (with consent) product tips.
- Respond to your support requests, comments, and feedback.
- Comply with legal obligations (e.g., tax filings, lawful information requests).
We do not use your personal information for automated decisions that produce legal effects concerning you (e.g., credit decisions, employment screening). Sales tax computation by subprocessers is deterministic and based on the inputs you provide.
5. Sensitive Personal Information
We collect the following categories of sensitive personal information as defined by CPRA §1798.140(ae) only as strictly necessary to provide the Service, and only with your explicit consent at the point of collection:
- Bank account credentials when you connect a bank feed, processed by Plaid end-to-end; Galan receives an opaque token, not your credentials.
You may limit our use of sensitive PI under §7 below. To the extent we process sensitive PI, we do so only for the purposes enumerated at the point of collection.
6. Your Privacy Rights
Subject to the jurisdictional scope of the right and your verification, you have the following rights under US state privacy laws:
- Right to know what personal information we have collected about you, the categories, the sources, the business purposes, and the categories of recipients.
- Right to delete personal information we have collected from you, subject to statutory exceptions (e.g., tax records we must retain for 7 years).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing. See §10 Do Not Sell or Share. We do not sell or share, so the practical effect is that there is nothing to opt out of; nevertheless, you may file the request and we will record your preference.
- Right to limit use of sensitive PI to that which is necessary to perform the service.
- Right to non-discrimination for exercising any of the above rights. We will not deny service, charge different prices, or provide a different level of quality because you exercised a privacy right.
- Right to appeal (under VCDPA, CPA, CTDPA) if your request is denied; see §11.3 Appeals.
7. How to Exercise Your Rights
The mechanism depends on whose customer you are:
7.1 If you are a customer of a Galan tenant
Submit your request via that tenant’s privacy intake surface on the tenant’s subdomain. For example, if the tenant uses acme as their subdomain, file your request at acme.galan.com/privacy. The tenant’s data-protection contact receives your submission through our admin queue and replies under their own privacy programme. Galan, as the tenant’s service provider, cooperates with the tenant’s response but does not respond directly to you.
7.2 If you are a Galan customer (direct)
Submit your request via our privacy intake form or by emailing privacy@galan.com. The intake form records your request, the timestamp, your W3C Global Privacy Control signal (if any), and routes the request into our admin queue for processing.
7.3 If you are a visitor of our marketing site
You may file a verifiable consumer request by emailing privacy@galan.com from the email address you used to interact with us. We will authenticate you using that address plus one additional data point you provide.
8. Verification Process
We verify all consumer requests to ensure that we respond to the person whose personal information is at issue, not to an imposter. Verification standards:
- Known users (log in to a tenant environment): session-based authentication.
- Marketing-site visitors: verification via the email address on file plus a piece of information only you could know (e.g., a recent invoice number, a sales-conversation transcript).
- Authorised agents: per CCPA regulations, an authorised agent may submit a request on your behalf with a signed authorisation; CCPA-compliant agent designation via the California Secretary of State’s process is required for opt-out requests submitted by agents.
- Children’s requests: a parent or guardian must verify parental or guardian relationship before we respond.
9. Response Timing and Authorised Agent Information
We respond to verifiable consumer requests within the time required by the relevant statute:
- California: 45 days, extendable by 45 days with notice.
- Colorado: 45 days.
- Connecticut: 45 days.
- Texas: 45 days.
- Virginia: 45 days.
- Utah: 45 days.
- Delaware: 60 days.
- Minnesota: 30 days.
- Most other states: 45 days.
To submit a request via an authorised agent in California, the agent must register with the California Secretary of State per California Code of Regulations §7063.
10. Do Not Sell or Share My Personal Information
We do not sell or share your personal information for cross-context behavioural advertising. We also honour the W3C Global Privacy Control (GPC) signal sent by your browser (Sec-GPC: 1) as a valid opt-out of any future sale or sharing. If you wish to file an opt-out request regardless, see §7.
11. State-by-State Disclosures
The following table summarises additional rights and disclosures required by active US state privacy statutes. Where a statute provides broader protection than this Policy, the statute controls.
| State | Citation | Notes |
|---|---|---|
| California (CCPA / CPRA) | Cal. Civ. Code §1798.100 et seq. | Right to know, delete, correct, opt out of sale/sharing, limit use of sensitive PI; non-discrimination; 45-day response. |
| Virginia (VCDPA) | Va. Code §59.1-575 et seq. | Right to know, delete, correct, opt out of targeted advertising; appeals process; 45-day response. |
| Colorado (CPA) | Colo. Rev. Stat. §6-1-1301 et seq. | Right to know, delete, correct, opt out, DPA; 45-day response; Universal Opt-Out Mechanism (UOOM) recognition. |
| Connecticut (CTDPA) | Conn. Gen. Stat. §42-515 et seq. | Right to know, delete, correct, opt out; sensitive data limitation; 45-day response. |
| Utah (UCPA) | Utah Code §13-61-101 et seq. | Right to know, delete, opt out; 45-day response. Notably narrower (no right to correct, no sensitive PI category). |
| Texas (TDPDPA) | Tex. Bus. & Com. Code §541.001 et seq. | Right to know, delete, correct, opt out; sensitive data; 45-day response; 30-day breach notification (see §14). |
| Oregon (OCPA) | Or. Rev. Stat. §646A.570 et seq. | Right to know, delete, correct, opt out; sensitive PI; consumer health data separate regime. |
| Montana (MCDPA) | Mont. Code §30-14-2801 et seq. | Right to know, delete, correct, opt out; sensitive PI; effective 2024-10-01. |
| Delaware (DPDPA) | Del. Code tit. 6, §1200 et seq. | Right to know, delete, correct, opt out; sensitive PI; 60-day response. |
| Iowa (Iowa SF 262) | Iowa Code §715C et seq. | Right to know, delete, correct, opt out; sensitive PI; effective 2025-01-01. |
| Tennessee (TIPA) | Tenn. Code §47-18-3301 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response. |
| Indiana (INCDPA) | Ind. Code §24-4-1 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response. |
| New Jersey (NJ OPRA) | N.J. Stat. §56:8-161.1 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response. |
| Kentucky (KCDPA) | Ky. Rev. Stat. §367.7811 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response. |
| Maryland (MODPA) | Md. Code Com. Law §14-4301 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response; opt-out profile universality. |
| Minnesota (MCDPA) | Minn. Stat. §325E.66 et seq. | Right to know, delete, correct, opt out; sensitive PI; 30-day response. |
| New Hampshire (NHCDPA) | N.H. Rev. Stat. §507-H:1 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response; right to close account. |
| Rhode Island (RIDTPPA) | R.I. Gen. Laws §6-13.1 et seq. | Right to know, delete, correct, opt out; sensitive PI; 45-day response. |
11.1 Nevada (NRS 603A)
Nevada residents have a right to opt out of the sale of certain covered information (NRS 603A.345). We do not sell such information, but if you wish to make the request, see §7.
11.2 California Shine the Light (Cal. Civ. Code §1798.83)
California residents may request information about categories of personal information disclosed to third parties for those third-parties’ direct-marketing purposes. We do not make such disclosures.
11.3 Appeals
If we deny your request, you may appeal by replying to our denial email. We will respond to the appeal within the time required by statute (45 days under VCDPA, CPA, CTDPA, etc.). If your appeal is denied, you may contact your state Attorney General to file a complaint.
12. Children's Privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it. If you believe we have collected information from a child under 13, please email privacy@galan.com.
13. International Data Transfers
Galan hosts tenant data in US-based infrastructure (see Subprocessors for locations). The Service is not targeted at, marketed to, or knowingly designed to accept personal information from, residents outside the United States. If, despite this, Galan receives personal information from outside the United States, Galan will implement appropriate safeguards for the transfer at the time and to the extent required by applicable law (which may include the EU Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or other approved mechanisms). Until such safeguards are in place, Galan’s policy is to delete or anonymise such information rather than retain it.
14. Data Security and Retention
14.1 Security
We employ administrative, technical, and physical safeguards designed to protect personal information. These include encryption at rest and in transit, role-based access control, segregated tenant data, audited access logs, and written information security policies reviewed at least annually. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
14.2 Retention
We retain personal information for as long as needed to provide the Service and comply with our legal obligations. Default windows are:
- Tenant account data: 30 days after cancellation, then hard-deleted except for records required to be retained by law.
- Invoices, journal entries, tax filings: 7 years (IRS recordkeeping under 26 CFR 1.6001-1; extended to 10 years for substantial-omission cases).
- Privacy request audit trail: 5 years (to demonstrate compliance across the rolling statutory window).
- Cookie consent records: 1 year (see Cookie Policy).
- Marketing-leads data: until you opt out or 24 months of inactivity, whichever comes first.
14.3 Breach Notification
In the event of a breach affecting personal information, we will provide notice in accordance with applicable state breach-notification statutes. California (§1798.29) requires notice to affected residents in the most expedient time possible without unreasonable delay; Texas (Bus. & Com. Code §521.053) requires notice within 60 days; New York (SHIELD Act) within 30 days; Florida (FIPA) within 30 days; and most other states within 30–60 days. We will notify the relevant state Attorneys General and consumer reporting agencies as required.
15. Changes to This Privacy Policy
We will update this Policy when our practices change, when statutes referenced here are amended, or when new state privacy laws take effect. We will post the revised version at this URL with an updated effective date. For material changes, we will provide additional notice via email or in-product banner at least 30 days before the effective date. A changelog of material revisions is included at the bottom of this page.
16. Contact Us
For privacy questions, requests, or complaints, contact us:
- Email: privacy@galan.com
- Mail: 8206 Louisiana Blvd, Albuquerque, NM 87113
- Entity: VisionQEFA LLC (d/b/a Galan ERP)
Document changelog
- 2026-07-27 (v0.1 draft). Initial authored version, counsel-confirmed 2026-07-28.