procurea.Book a call
Legal

GDPR Information Notice

Last updated: February 18, 2026

In accordance with Articles 13(1) and 13(2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR"), we inform you:

1Data Controller

The controller of your personal data is Procurea sp. z o.o., registered at ul. Pomorska 3/1, 85-050 Bydgoszcz, Poland.

Contact the Controller: hello@procurea.io.

3Categories of Data

We process the following categories of personal data:

  • Identification data: name, email address, phone number
  • Organizational data: company name, job title, industry, tax ID
  • Platform usage data: sourcing queries, results, supplier correspondence
  • Technical data: IP address, session identifiers, browser data

4Data Recipients

Your data may be shared with the following categories of recipients:

  • Google Cloud Platform / Firebase: IT infrastructure provider (hosting, application runtime, authentication), europe-west1 region (Belgium, EU).
  • Neon: managed PostgreSQL database provider, AWS eu-central-1 region (Frankfurt, Germany, EU).
  • Communication service providers: for SMS delivery (verification) and email (sequences, notifications).
  • Suppliers contacted via the Platform: User contact data included in requests for quotation.
  • Government authorities: in cases required by law.

5Data Transfers to Third Countries

As a general rule, personal data is stored and processed exclusively within the European Economic Area (EEA): the application on Google Cloud in the europe-west1 region (Belgium) and the database with Neon on AWS in the eu-central-1 region (Frankfurt, Germany).

Where data transfer outside the EEA is necessary, appropriate safeguards in accordance with Chapter V of the GDPR are applied, particularly the standard contractual clauses adopted by the European Commission.

6Data Subject Rights

Under the GDPR, you have the following rights:

  1. Right of access (Art. 15 GDPR): to obtain confirmation of data processing and access to your data.
  2. Right to rectification (Art. 16 GDPR): to request correction of inaccurate or completion of incomplete data.
  3. Right to erasure (Art. 17 GDPR): to request deletion of data (the "right to be forgotten") when:
    • data is no longer necessary for the purposes for which it was collected,
    • consent has been withdrawn and there is no other legal basis for processing,
    • a successful objection to processing has been raised.
  4. Right to restriction of processing (Art. 18 GDPR).
  5. Right to data portability (Art. 20 GDPR): to receive data in a structured, commonly used, machine-readable format.
  6. Right to object (Art. 21 GDPR): to processing based on the Controller's legitimate interest.
  7. Right to withdraw consent (Art. 7(3) GDPR): at any time, without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise the above rights, please contact us at: hello@procurea.io.

7Right to Lodge a Complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the relevant supervisory authority. For users in Poland:

President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
www.uodo.gov.pl

For users in other EU/EEA countries, you may lodge a complaint with your local data protection authority.

8Voluntary Nature of Data Provision

Providing personal data is voluntary but necessary to use the Procurea Platform. Failure to provide data will prevent Account registration and use of services.

9Automated Decision-Making

The Procurea Platform uses AI algorithms to discover and evaluate suppliers. Results generated by AI agents are solely informational and supportive in nature. They do not constitute automated decision-making within the meaning of Art. 22 GDPR. Final business decisions are always made by the User.

10Security Measures

The Controller has implemented appropriate technical and organizational measures to ensure the security of personal data, including:

  • Data encryption in transit (TLS) and at rest
  • Multi-factor authentication (OAuth 2.0 + SMS verification)
  • Data storage in certified Google Cloud data centers (EU region)
  • Regular security testing and backups
  • Access control based on the principle of least privilege
  • Access monitoring and logging

Controller Contact Information

Procurea sp. z o.o.
ul. Pomorska 3/1, 85-050 Bydgoszcz, Poland
Email: hello@procurea.io