AcuSpend legal

Privacy Policy

This notice explains the personal-information flows implemented in AcuSpend's pilot workspace and the information that must still be completed before a public production launch.

Last reviewed: July 18, 2026

1. Who is responsible for your information

For the AcuSpend service, the data controller is the AcuSpend operator identified in the relevant pilot agreement or account communications. A public production notice must name the controller, state its registered address, provide a privacy contact email, and identify a Data Protection Officer or EU representative where one is required. Until then, pilot users should use their agreed AcuSpend contact channel for privacy requests.

2. Information AcuSpend processes

AcuSpend processes account and authentication information; profile and workspace membership details; procurement requests and structured sourcing briefs; supplier, RFQ, quotation, and comparison information; recommendation and buyer-decision records; collaboration messages and activity history; and documents uploaded to the workspace. Depending on how you use the service, that information may include business contact details and other personal data contained in user-provided content.

3. Why we process it and the legal basis

Where the GDPR applies, AcuSpend processes information to create and secure accounts, provide workspace features, manage access, store and retrieve user content, and support requested procurement workflows. The expected legal bases are performance of a contract or steps taken at your request before a contract; legitimate interests in security, fraud prevention, service reliability, and improving the service; compliance with legal obligations where applicable; and consent only where AcuSpend specifically asks for it. The final controller must validate and document the applicable basis for each processing activity before production launch.

4. How access is limited

The application separates buyer workspaces from staff operations. Access is controlled through authenticated accounts, organisation membership, platform roles, tenant-aware access checks, and database Row Level Security. Buyers do not automatically receive internal sourcing notes, quotation data, supplier source documents, or comparison drafts. These controls reduce access but do not remove the need for users to manage their workspace memberships carefully.

5. Service providers and disclosures

AcuSpend is configured to use Supabase for database, authentication, and private file storage, and may use Vercel to host the application. Controlled email workflows can use Resend when explicitly enabled. Optional assisted features can use OpenAI only when an administrator enables the relevant feature and server-side configuration. AcuSpend may also disclose information to professional advisers, competent authorities, or another party where required by law or necessary to protect rights and safety. Before each live provider is enabled, the controller must confirm an appropriate processor agreement and the provider's current processing terms.

6. International transfers

Processing locations and transfer mechanisms depend on the region and service-provider configuration selected for the relevant environment. The repository does not record those contractual or regional choices. Before public use, the controller must publish the countries involved, the applicable transfer mechanism, and a way to obtain information about safeguards for transfers outside the EEA or United Kingdom where data-protection law requires this.

7. Retention and deletion

AcuSpend retains information while an account or workspace is active and for as long as reasonably necessary to provide the service, preserve security and audit records, resolve disputes, meet legal obligations, or enforce agreements. Exact retention periods, deletion workflows, and backup handling are not yet published and must be completed before general availability. Deleting a workspace member does not necessarily remove records that the workspace must retain for its legitimate business history or legal obligations.

8. Security

AcuSpend uses authenticated access, role and organisation checks, Row Level Security, private document storage, and server-side secrets for configured integrations. These measures are designed to reduce unauthorised access; no online service can promise absolute security. Users must protect credentials and report suspected security incidents through the applicable AcuSpend support channel.

9. Your privacy rights

Subject to applicable law, you may have rights to request access, correction, erasure, restriction, objection, portability, and information about processing. Where processing relies on consent, you may withdraw it. You may also complain to the competent data-protection authority. AcuSpend must implement and publish a verified identity-checking and request-handling process before public launch; do not send sensitive identity documents through ordinary workspace messages unless specifically instructed by the controller.

10. Cookies, local storage, and automated processing

The application uses necessary authentication session cookies and may use local browser storage for preferences such as theme selection. The source reviewed for this notice does not include an advertising or analytics consent system. AcuSpend must inventory any cookies, pixels, analytics, or similar technologies added later and provide any notice or consent required before activating them. The product supports human-reviewed procurement workflows and does not make an automated decision that independently selects a supplier, enters a contract, or awards a purchase.

11. Children and updates to this notice

AcuSpend is designed for business procurement use and is not intended for children. Do not knowingly submit children's personal data through the service. This notice may be updated as the service, legal operator, providers, or data practices change. The production notice must include a reliable privacy contact and an effective date for each material revision.