Steersman Data Handling and Privacy Policy
Last updated: 2025-12-10
Steersman Company (“Steersman”) provides ERP implementation, software development, and systems integration services. This policy describes how Steersman collects, processes, stores, uses, shares, retains, and disposes of client data in connection with authorized services.
1. Scope
This policy applies to all Steersman employees, contractors, systems, and environments that may store or process client data.
2. Data Minimization and Purpose Limitation
Steersman collects and processes only the minimum data necessary to provide requested services. Data is processed solely for documented client business purposes and as required to operate, support, secure, and troubleshoot approved integrations and applications.
3. Data Collection
Data may be collected through: - client-authorized system connections and integration interfaces; - service configuration, support requests, and change requests; - operational logs required for reliability and security.
Steersman does not collect data unrelated to service delivery.
4. Data Use
Steersman uses client data only for: - implementation, operation, and support of client-authorized workflows; - monitoring, audit logging, and security controls; - legal, regulatory, and contractual compliance.
Steersman does not sell client data and does not use client data for advertising or independent marketing.
5. Data Storage and Security Controls
Steersman implements administrative, technical, and physical safeguards appropriate to the nature of the data and the services provided, including: - encryption in transit and at rest where supported; - role-based access control and least-privilege access; - multi-factor authentication for administrative access; - centralized logging and security monitoring; - managed endpoint controls for personnel with access to production systems; - PCI-aligned practices for payment-related data where applicable.
Access to PII is restricted to authorized personnel with a defined business need.
6. Data Sharing and Subprocessors
Steersman may share data only with service providers or platforms required to deliver client-authorized services. Such sharing is limited to the minimum necessary data and is subject to contractual confidentiality and security obligations.
Steersman does not disclose client data to third parties for their independent use.
7. Data Retention
Steersman retains data only for as long as necessary to: - provide and support the applicable service; - meet contractual retention requirements; - satisfy legal, regulatory, and audit obligations.
Retention periods may vary by data type and client agreement.
8. Data Disposal
Upon expiration of retention requirements or termination of the applicable service (subject to contractual terms), Steersman will securely dispose of data using reasonable, industry-standard methods, which may include: - deletion from active systems; - deletion or expiration of relevant backups according to backup retention schedules; - removal of access credentials and integration tokens no longer required.
9. Employee Access and Device Controls
Steersman requires security awareness training for personnel with access to client data. Access must be performed using company-managed devices and approved accounts. Endpoint controls are used to reduce the risk of unauthorized data transfer, including restrictions on unapproved removable storage where applicable.
10. Incident Response
Steersman maintains an incident response process designed to identify, contain, investigate, remediate, and document security incidents. Where required by contract or applicable law, Steersman will notify affected clients within appropriate timeframes.
11. Client Requests
Subject to contractual and legal limitations, clients may request information related to: - the categories of data processed for their services; - access, correction, or deletion of data within Steersman-controlled systems; - security and compliance documentation relevant to the engagement.
12. Contact
Questions regarding this policy or data handling practices may be directed through our Contact page.