AcuSpend legal
Privacy Policy
This notice explains the personal-information flows implemented in AcuSpend's pilot workspace and the information that must still be completed before a public production launch.
Last reviewed: September 18, 2026
1. Who is responsible for your information
For the AcuSpend service, the data controller is the AcuSpend operator identified in the relevant pilot agreement or account communications. A public production notice must name the controller, state its registered address, provide a privacy contact email, and identify a Data Protection Officer or EU representative where one is required. Until then, pilot users should use their agreed AcuSpend contact channel for privacy requests. Section 2 explains the split between workspace content and service-operation data.
2. Controller and processor roles
Your buying organisation controls the procurement content in its workspace: requests, briefs, supplier and quotation information, messages, documents, and decisions. AcuSpend processes that workspace content only to provide the service to your organisation, on its behalf and under the pilot agreement; the organisation's instructions are expressed through its workspace members' ordinary use of the product and its administrator settings. For account, access-control, security, and service-operation data such as authentication records, audit logs, and support correspondence, the AcuSpend operator acts as controller as described in section 1. If your personal data sits inside a customer workspace, address access, correction, or deletion requests to that organisation first; AcuSpend assists workspace administrators with verified requests.
3. Information AcuSpend processes
AcuSpend processes account and authentication information; profile and workspace membership details; pre-launch pilot-access requests (contact details plus sourcing-profile answers submitted before signup); procurement requests and structured sourcing briefs; supplier, RFQ, quotation, and comparison information; recommendation and buyer-decision records; collaboration messages and activity history; and documents uploaded to the workspace. Depending on how you use the service, that information may include business contact details and other personal data contained in user-provided content.
4. Why we process it and the legal basis
Where the GDPR applies, AcuSpend processes information to create and secure accounts, provide workspace features, manage access, store and retrieve user content, and support requested procurement workflows. The expected legal bases are performance of a contract or steps taken at your request before a contract; legitimate interests in security, fraud prevention, service reliability, and improving the service; compliance with legal obligations where applicable; and consent only where AcuSpend specifically asks for it. The final controller must validate and document the applicable basis for each processing activity before production launch.
5. How access is limited
The application separates buyer workspaces from staff operations. Access is controlled through authenticated accounts, organisation membership, platform roles, tenant-aware access checks, and database Row Level Security. Buyers do not automatically receive internal sourcing notes, quotation data, supplier source documents, or comparison drafts. These controls reduce access but do not remove the need for users to manage their workspace memberships carefully.
6. Service providers and disclosures
Supabase provides database, authentication, and private file storage; Vercel hosts the application. These processors handle personal data as part of providing the service. The following processors are used only when an administrator explicitly enables them: Resend for controlled RFQ, support, and buyer-notification email; OpenAI for assisted features (see section 7); Exa for live supplier-discovery search; Cloudflare for the staging monitor scheduler and optional Turnstile abuse protection; Sentry for error monitoring when a DSN is configured. Each processor acts only on AcuSpend's instructions under its processing terms; the controller must confirm processor agreements before enabling a provider for personal data. Staff VAT checks query the EU's public VIES registry, which is a verification lookup rather than a processor: only the VAT number itself is transmitted. AcuSpend may also disclose information to professional advisers, competent authorities, or another party where required by law or necessary to protect rights and safety. AcuSpend does not sell personal data, does not buy contact lists or enrichment data, and sets no advertising trackers.
7. AI processing and no-training commitment
Assisted features such as request analysis, clarification help, quote extraction, supplier-discovery search, and buyer Acu answers run on the configured provider. The default local provider processes content inside AcuSpend and sends nothing externally. Where an administrator enables OpenAI-backed features, only the minimum content needed for the task is sent through the OpenAI API; OpenAI's API terms state that API content is not used to train models, and AcuSpend does not permit training on workspace content. Supplier-discovery queries sent to Exa contain only the search terms derived from the sourcing brief. AI output is advisory and human-reviewed: no automated step selects a supplier, enters a contract, or awards a purchase (see section 12). If a new AI provider is introduced, this notice will name it and fresh consent or agreement will be obtained where required before activation.
8. International transfers
Processing locations and transfer mechanisms depend on the region and service-provider configuration selected for the relevant environment. The repository does not record those contractual or regional choices. Before public use, the controller must publish the countries involved, the applicable transfer mechanism, and a way to obtain information about safeguards for transfers outside the EEA or United Kingdom where data-protection law requires this.
9. Retention and deletion
AcuSpend retains information while an account or workspace is active and for as long as reasonably necessary to provide the service, preserve security and audit records, resolve disputes, meet legal obligations, or enforce agreements. Exact retention periods, deletion workflows, and backup handling are not yet published and must be completed before general availability. Deleting a workspace member does not necessarily remove records that the workspace must retain for its legitimate business history or legal obligations.
10. Security
AcuSpend uses authenticated access, role and organisation checks, Row Level Security, private document storage, and server-side secrets for configured integrations. These measures are designed to reduce unauthorised access; no online service can promise absolute security. Users must protect credentials and report suspected security incidents through the applicable AcuSpend support channel.
11. Your privacy rights
Subject to applicable law, you may have rights to request access, correction, erasure, restriction, objection, portability, and information about processing. Where processing relies on consent, you may withdraw it. You may also complain to the competent data-protection authority. AcuSpend must implement and publish a verified identity-checking and request-handling process before public launch; do not send sensitive identity documents through ordinary workspace messages unless specifically instructed by the controller.
12. Cookies, local storage, and automated processing
Strictly-necessary cookies keep you signed in (Supabase session cookies) and protect access to non-public environments such as staging. Your theme choice and your cookie decision are stored in your browser's local storage on your own device; the cookie decision is never sent to AcuSpend. AcuSpend sets no analytics, advertising, or cross-site tracking cookies. On your first visit you will see an Accept / Decline banner: accepting records consent for optional cookies should any ever be introduced, while declining keeps the platform on necessary-only storage. Browsers broadcasting a Global Privacy Control signal are treated as Decline. You can change your choice at any time with the “Cookie preferences” control in the page footer, which re-opens the banner. If non-essential cookies, pixels, or analytics are ever added, this notice will be updated and fresh consent requested before they are activated. The product supports human-reviewed procurement workflows and does not make an automated decision that independently selects a supplier, enters a contract, or awards a purchase.
13. Children and updates to this notice
AcuSpend is designed for business procurement use and is not intended for children. Do not knowingly submit children's personal data through the service. This notice may be updated as the service, legal operator, providers, or data practices change. The production notice must include a reliable privacy contact and an effective date for each material revision.
