Privacy Policy — BOCP ERP connector for AI assistants
1. Who we are
The connector is operated by the provider of BOCP ERP: SC REAL LIFE SRL, CIF: 23310817.
- Service: BOCP ERP — https://www.bocp.ro
- Contact for privacy questions: office@reallife.solutions
- Support: office@reallife.solutions
2. What this connector does
It gives an AI assistant chosen by you read-only access to company-level aggregated business indicators already calculated inside your own BOCP ERP account — for example daily invoiced value, or sales totals for a period together with comparisons against the previous period and the same period a year earlier.
The connector cannot create, change or delete anything in your ERP.
3. What data the AI assistant can receive
Only the following leaves BOCP, and only for the indicators an administrator of your account has explicitly enabled:
- Indicator metadata — the identifier, unit and goal direction of each enabled indicator.
- Aggregated values — daily totals, period sums, percentage changes and data-coverage counts for those indicators.
- Connector context — the name and identifier of the connector, its rate limit, which indicators it is allowed to read, and the endpoint addresses.
- Your company name, as the title of the connection (shown as “BOCP ERP — your company”).
What is never sent
The following are excluded by design, and no setting, grant or request can expose them through this connector:
- Customer, supplier, contact or employee records; names, addresses, e-mail addresses, phone numbers.
- Individual documents (invoices, orders, receipts) or any row-level data.
- Passwords, API keys, access tokens, encryption keys or bank/authority credentials.
- Payment card data.
- National identification numbers and copies of identity documents.
- Health data or any other special category of personal data under Article 9 GDPR.
- Per-employee or per-user performance figures.
- Any data belonging to another BOCP account.
4. Legal roles
BOCP acts as a processor on behalf of your company, which is the controller of the data in its ERP account. We process it only on your documented instructions.
Your recorded permission grant is that instruction. When an administrator enables the connection and selects which indicators may be read, BOCP stores that decision together with the user and the time. Nothing is disclosed to an AI assistant without such a grant, and the default state of a new connector is access to nothing.
The AI provider is your processor, not our sub-processor. You connect your own account with the AI provider (for example Anthropic) and agree that provider's terms directly. What the AI provider does with the data it receives, including whether it is transferred outside the EEA, is governed by your relationship with them — please review their privacy terms. We recommend confirming that you hold an appropriate data processing agreement and transfer mechanism with them before enabling access to anything beyond aggregated figures.
5. What we store, and for how long
To operate and secure the connection, BOCP stores the following inside your own account or in its central service database:
| Data | Purpose | Retention |
|---|---|---|
| Access log: date/time, connector, request route and method, HTTP status, response size, permission level applied, and the IP address of the requesting AI service | Security, abuse detection, rate limiting, and your own audit view inside BOCP | 90 days, then deleted automatically |
| Access and refresh tokens, stored only as irreversible hashes — never the token itself | Authenticating the connection and detecting reuse of a stolen token | 90 days after expiry, then deleted automatically |
| A routing record per token: which account and service it belongs to, its expiry, and whether it was revoked | Routing a request to the correct account, and revoking access immediately | 90 days after expiry, then deleted automatically |
| Registration details of the AI application: its generated identifier, its name and its redirect addresses | Completing the standard OAuth authorisation flow | For as long as the registration exists |
| Your permission grants (which indicators are enabled) and the connector's settings | Enforcing your choices on every request | Until you change or delete them |
The IP address recorded in the access log is that of the AI provider's servers, not of an individual end user.
We do not collect the content of your conversations with the AI assistant, and the connector never requests an assistant's chat history, memory or files.
6. Sharing with third parties
We do not sell your data and we do not share it for advertising.
Data is transmitted only to the AI provider you connected, and only as described in section 3. We disclose nothing else to third parties except where required by law.
7. Your control and your rights
- You choose the scope. An administrator selects each indicator individually. New indicators are never enabled automatically.
- You can withdraw access at any time — deactivate or delete the connector in BOCP, or remove the connection in the AI product. Deactivating a connector immediately revokes its tokens.
- You can see what was accessed. Every request, including refused ones, is visible in the access log inside BOCP (Integrări → Conectori AI → Agenți AI → the connector → Jurnal accesări).
- As a data subject under GDPR you have rights of access, rectification, erasure, restriction, objection and portability. Because BOCP acts as a processor for your company, please direct such requests to the company operating the ERP account; we assist controllers in responding to them.
8. Security
- The connection uses HTTPS only.
- Authorisation uses OAuth 2.1 with PKCE; approval requires a recent, deliberate login by an administrator of the account, and cannot be granted from a BOCP support session.
- Tokens are short-lived, rotate on use, and are stored only as hashes.
- Each account's data is held in a separate database, and a token issued for one account cannot be used to read another.
- Requests are rate limited per connector, and every request is logged.
9. Children
BOCP ERP is business software and is not directed at children.
10. Changes to this policy
If we change what the connector discloses, we will update this policy and the in-product data declaration shown when permissions are granted, before the change takes effect.
11. Contact
Questions about this policy or about data handled through the connector: office@reallife.solutions
Was this article helpful?