Procurea is committed to maintaining the highest standards of data protection and regulatory compliance. This page outlines our compliance framework and data handling practices.
1GDPR
Procurea is fully GDPR compliant. When processing customer data on behalf of our clients, we act as a data processor under Article 28 GDPR. A Data Processing Agreement (DPA) is available upon request for all enterprise customers.
2Data Residency
Customer data is stored on EU infrastructure: the application on Google Cloud europe-west1 (Belgium) and the database with Neon on AWS eu-central-1 (Frankfurt, Germany). No customer data leaves EU infrastructure, and database backups are held in the same region as the database.
3Data Retention
Campaign data (sourcing results and supplier lists, and offer responses where they exist from before that feature was paused) is retained for 12 months from the date of creation. Account data is retained for the duration of service plus 30 days after account deletion to allow for data recovery if needed.
4Data Deletion
Users can request a full data export and deletion at any time via account settings or by contacting our support team. Upon receiving a deletion request, all personal data is permanently removed within 30 days, in accordance with GDPR Article 17 (Right to Erasure).
5Sub-processors
We use the following sub-processors to deliver our services:
- Google Cloud Platform: cloud infrastructure, database hosting, and compute
- Resend: transactional email delivery (account notifications and reports)
- Serper.dev: web search API for supplier discovery
- Google AI Studio: AI processing for supplier analysis and enrichment
6Contact
For compliance inquiries, data protection questions, or to request a DPA, please contact us.