Privacy Policy
Last updated 2026-09-25
This policy explains what [Company name] ("we"), [Registered address], does with personal data when you use Proceny. Questions: [contact e-mail].
What we process
- Your account: name, e-mail address, password (stored only as a one-way hash), and for each sign-in session the IP address and browser identifier.
- What your organisation puts in: catalogs, supplier price lists, quotations, RFQ answers, product data files, scanned documents, e-mails your suppliers send to your Proceny inbox addresses — and what Proceny derives from them (matches, prices, review decisions, comparisons, exports). Your team members' names and e-mail addresses, and invitations you send.
- Records of use: which files were processed and when, rows and pages counted against your plan, and actions such as approvals, exports and changes to settings (an audit trail for your organisation). Which product steps are used (for example "price list completed"), counted without names, file names, prices or text, kept in our own database. Problem reports you send, with the page, app version and error reference shown to you before sending.
- Billing: paid plans are sold by Polar (polar.sh) as merchant of record. We receive the plan and the subscription status; card details never reach us.
- Technical logs: request and job logs with identifiers and timings. They never contain file contents or prices.
Why
To provide the service your organisation signed up for (performance of a contract), to keep it secure and prevent abuse (legitimate interest), to bill for paid plans (contract), and where the law requires us to keep records.
What we do not do
- We do not sell personal data or use advertising trackers.
- No third-party AI service processes your files, and they are not used to train AI models. Scanned documents are read on our own servers.
- The free comparison tool runs in your browser and does not upload your files.
Who else processes data for us
- Hosting and database: [provider, purpose, location]
- File storage: [provider, location]
- Transactional e-mail: Resend — account e-mails and invitations
- Payments: Polar (merchant of record)
How long we keep it
- Your organisation's data: while the organisation exists.
- E-mails received at inbox addresses: the raw message for 30 days, the inbox entry for 365 days; imported files stay with the organisation.
- When an owner deletes the organisation (Settings), its data is erased within minutes; backups keep a copy for up to 14 days.
- Your account: until you ask us to delete it.
Security
Data travels over HTTPS. Every query is scoped to your organisation, and the database refuses links between organisations. Files are stored privately and downloaded only through signed-in, checked requests. Details: the Security section of our home page.
Your rights
You can ask for access to, correction, export or deletion of your personal data, and object to processing, by writing to [contact e-mail]. Organisation owners can delete their organisation themselves in Settings. You may also complain to your data protection authority.
Changes
We will announce material changes by e-mail or in the app before they apply.