Terms of Service
Last updated 21 August 2026
These terms cover access to veloerp.com and to the VeloERP application. Where they conflict with a signed order form, master services agreement or Business Associate Agreement, the signed document wins.
The demo tenant
The demo hospital is seeded with synthetic data and contains no real protected health information by construction. Do not enter real patient, employee or financial data into it — it is a shared environment, sessions are watermarked and rate-limited, and its contents are reset periodically.
Subscription and pricing
Pricing is published by bed band on our pricing page and is charged on licensed capacity, never as a percentage of your collections. Your bill moves when your licensed bed or provider count moves.
Implementation is quoted as a fixed price before contract. Overrun on that scope is our cost, not yours. Scope changes you request are quoted separately before we start them.
What we commit to operationally
Production data does not load until the go-live gate passes: a countersigned BAA, verified SSO, enforced MFA, and reconciled integration test messages.
Recovery targets are an RTO of four hours and an RPO of fifteen minutes, with restore drills on a calendar and retained results.
We configure rather than fork. There are no per-customer code branches, which is what keeps your upgrade path intact.
Acceptable use
Do not attempt to access another tenant's data, probe the isolation boundary outside an agreed test, or use the platform to store data classes it is not designed for. Report anything that looks like a cross-tenant leak to us immediately — we treat it as a Sev-1 regardless of how it was found.
Termination and your data
On termination you get a full export of your data in a documented format before the tenant is decommissioned. Decommissioning ends with destruction of your tenant's encryption key.