Product schedules Huberway LLC — Updated 5 October 2026 — HW-LEGAL-2026-10-05 Service boundaries, data responsibilities and purchasing context across the ecosystem. Esdra ERP, POS and EVA Esdra provides business catalogue, inventory, pricing, orders, invoicing and retail operations in the enabled configuration. The business customer controls its operational, workforce, customer and supplier records; Huberway processes entrusted records under the DPA. The customer validates fiscal settings and business inputs. Stock, transaction and POS rules belong to the deterministic Esdra domain; EVA recommendations require the relevant permissions and review. Availability of a plugin does not mean it is enabled for every tenant. Merchant ecommerce and portals For a merchant storefront, the seller, total price, tax, delivery, payment, withdrawal and guarantees are identified by the merchant before purchase. Huberway’s software terms do not replace the merchant’s sales terms. Paprika’s existing storefront identifies an independent merchant. Merchant customers contact that seller about their order; Huberway handles its own software relationship and processor assistance. Developer, dropshipping and supplier portals require scoped authorisation; access does not grant rights to unrelated tenant data. Shared marketing CRM research, a valid email, an imported list, a public source or a subscribed flag is not sufficient proof of permission to send marketing. The campaign owner must document the applicable purpose/channel, source, consent or other permitted exception, notice, withdrawals and suppression lists. Permission must still be valid at dispatch. Tracking opens or clicks is a separate purpose and can require separate consent. Login, purchase and transactional notifications must not be bundled with optional marketing. Expandigo research and enrichment Expandigo supports business discovery, observations, enrichment and datasets from selected sources. Its customer controls its uploaded records and intended uses; independent sourcing and provision of a contact dataset require analysis of Huberway’s own role and notices. Source/date/quality/licence limitations accompany permitted use; accuracy, exhaustive coverage and sales outcomes are not guaranteed. Export or CRM handoff does not grant marketing permission. Individuals can request correction, objection or erasure through the Privacy Policy contact, identifying the relevant record where possible. Sales360 / Concord CRM The CRM manages commercial relationships, pipelines, opportunities, activities, documents and connected correspondence. The deploying business controls prospect/customer records and permissions. Mailbox authorisation permits the selected service operation, not unrestricted reuse or recipient tracking. Third-party CRM components remain subject to their licences. Huberway’s common runtime does not override customer ownership or the CRM’s record permissions. Orion agent coordination Orion coordinates configured goals, tools, approvals, execution history and costs. Available capabilities depend on the deployed runtime. Python V1 read/draft capability does not imply enabled real-world effects. A model suggestion is not an approval. Consequential operations require authorised parameters, tenant/actor, current permissions and resource versions, expiry and execution reconciliation. Private mode must not silently route data to a cloud model. My Huberway and identity My Huberway provides enabled account, organisation, identity, contacts, documents, inbox and workspace functions. Huberway controls its account/security administration; the organisation controls entrusted business content. SSO connects authorised identity mappings, not general data sharing. A catalogue tile does not prove that a purchase, reseller entitlement, provider synchronisation or provisioning is available. Domains and cloud purchases require their actual seller, registrar/provider terms and transparent order before activation. Huberway Analytics Analytics processes configured website visits, events, goals, heatmaps, replay and declared visitor information for the website owner. That owner controls visitor purposes and notices; Huberway provides the contracted processor service. Consent must be wired to the actual tracker; a cookie-less identifier can still be personal data. Replay must minimise sensitive input; visitor identification requires a specific signal and notice. Analytics data does not itself authorise marketing, cross-site identity graphs or financial accounting. Retention and erasure settings require operational execution, including providers and backups. Huberway Meet / MeetingPro Meet provides enabled rooms, invitations, audio/video, chat, files and appointment integrations. The organiser controls invitation recipients and meeting purposes and must inform participants of any recording or transcript before it starts and meet local requirements. Camera/microphone permission is not blanket recording consent. Availability of media or embedded participation depends on actual configuration. Huberway account administration and service security remain separate from organiser-controlled content. BID verification Where enabled, BID supports separate person, company, affiliation and authority checks with manual review and protected evidence. A verification badge is scoped to its verified assertion; it does not certify creditworthiness, marketing permission, every company claim or government identity integration. Use only requested evidence and avoid unnecessary sensitive data. Sharing, marketing preferences and partner discounts require their own choices and applicable terms; a proposed benefit is not an activated entitlement. For the BID verification workflow in My Huberway, the attachment retention rule is 90 days from the first terminal outcome. It is not measured from submission. Unfinished drafts, profile information and review/audit records have distinct lifecycles; this attachment rule does not claim that every record or backup has been erased.