← Back to ProcureLite

Privacy Policy

Last updated 23 September 2026

Draft, not final. This is a good-faith, best-practice policy covering how ProcureLite actually handles data today. It has not yet been reviewed by counsel and will be replaced with a fully reviewed version before general availability. If anything here is unclear or you need a formal statement for procurement purposes, please get in touch.

Who we are

ProcureLite is a procurement platform (requisitions, purchase orders, contracts, invoices, payments and a supplier portal) built and operated by the ProcureLite team. This policy covers both the public marketing site (getprocurelite.com) and the ProcureLite application itself.

Information we collect

When you submit the demo request or "express interest" form, we collect your name, work email, company name, and anything else you choose to provide (phone, company size, plan interest, message).

When your organisation becomes a customer, the application stores the business data you and your team put into it -- requisitions, purchase orders, supplier records, contracts, invoices and payments -- along with account data (name, email, role) for each user, and system-generated activity logs (see "Security" below).

How we use it

Marketing-site submissions are used only to respond to your enquiry -- we do not sell this information or share it with third parties for their own marketing.

Application data is used to provide the service to your organisation: running your procurement workflows, sending the notifications and emails you've configured, and (only with your permission) dispatching documents to the ERP or e-invoicing connections you set up in Settings.

Who we share it with

We use a small number of subprocessors to run the service: a database and authentication provider to store and secure application data, an email delivery provider to send notifications, and a payments provider to process subscription billing. None of them use your data for their own purposes beyond providing that infrastructure to us.

We do not sell personal data, and we only share application data with a third party (like your own ERP or a PEPPOL access point) when you explicitly configure that connection.

Data retention

We keep account and business data for as long as your organisation has an active subscription, plus a reasonable period afterward in case you want to reactivate or need an export. Marketing-site enquiries that don't convert to a customer are kept only as long as needed to follow up, and deleted or anonymised after.

Your rights

If you're in the EU/UK or a similar jurisdiction, you have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. Application users can self-service most of this directly: an export and an erasure request tool are built into the product's data privacy settings. For anything else, or for marketing-site enquiries, contact us via the contact form.

Cookies

The marketing site and application use only the cookies strictly necessary to keep you signed in and remember basic preferences (like light/dark mode). We don't run third-party advertising or tracking cookies.

Security

Application access is protected by row-level authorization scoped to your organisation, optional multi-factor authentication (TOTP) for every user, and a centralized security event log covering sign-ins and sensitive actions. Data in transit is encrypted (TLS). No system is perfectly secure, but this is the real, current state of the platform, not aspirational copy.

Children's privacy

ProcureLite is a B2B product intended for business use and is not directed at, or knowingly used to collect data from, children.

Changes to this policy

As this policy moves from draft to final, and as the product evolves, we'll update this page and the "last updated" date above. Material changes will be communicated to active customers.

Contact

Questions about this policy, or requests relating to your data, can be sent via the contact form.