procurea.Book a call
Legal

Privacy Policy

Last updated: February 18, 2026

1Data Controller

The controller of your personal data is Procurea sp. z o.o., registered at ul. Pomorska 3/1, 85-050 Bydgoszcz, Poland (hereinafter: the "Controller" or "we").

Contact the Controller: hello@procurea.io.

2What Data We Collect

When using the Procurea Platform, we collect the following categories of data:

2.1. Registration Data

  • Full name (from your Google or Microsoft account)
  • Email address
  • Phone number (provided during verification)
  • Profile picture (if available from OAuth account)

2.2. Organizational Data

  • Company / organization name
  • Job title
  • Industry
  • Tax identification number (optional)

2.3. Data Generated During Platform Use

  • Sourcing queries and their parameters
  • Search results and supplier lists
  • Correspondence with suppliers, requests for quotation and submitted offers, where such data exists from a period when those features were offered. They are paused as of 8 September 2026 and no new data of this kind is created.
  • Activity logs and operation history

2.4. Technical Data

  • IP address
  • Browser type and operating system
  • Session identifiers
  • Cookie data (details in section 7)

3Purposes of Data Processing

We process your personal data for the following purposes:

  • Service delivery: operating Platform functionality, including running AI sourcing processes (legal basis: Art. 6(1)(b) GDPR, performance of a contract). Sending requests for quotation and email sequences is paused and no longer a purpose of processing.
  • Registration and Account management: authentication, identity verification (legal basis: Art. 6(1)(b) GDPR).
  • Billing and invoicing: processing payments for Credits (legal basis: Art. 6(1)(b) and (c) GDPR).
  • Communication: responding to inquiries, handling complaints, system notifications (legal basis: Art. 6(1)(b) and (f) GDPR).
  • Security: protection against unauthorized access, fraud prevention (legal basis: Art. 6(1)(f) GDPR, legitimate interest).
  • Analytics and service improvement: analyzing Platform usage to improve functionality (legal basis: Art. 6(1)(f) GDPR).

4Data Sharing

Your data may be shared with the following categories of recipients:

  • IT service providers: Google Cloud Platform (hosting, databases), Firebase (authentication), to the extent necessary for service provision.
  • Communication service providers: SMS delivery services (phone verification) and email services (sequences).
  • Suppliers discovered by the Platform: none. The Platform reads public web pages and does not contact suppliers on the User's behalf. Where requests for quotation were sent before that feature was paused, User contact information was visible in them.
  • Government authorities: as required by applicable law, upon request from authorized bodies.

We do not sell personal data to third parties. We do not share data for third-party marketing purposes.

5Data Transfers Outside the EEA

The application runs on Google Cloud servers in the europe-west1 region (Belgium, EU), and the database is hosted by Neon on AWS in the eu-central-1 region (Frankfurt, Germany). As a general rule, data does not leave the European Economic Area.

When using services from providers located outside the EEA (e.g., AI services), we apply appropriate safeguards, including standard contractual clauses approved by the European Commission.

6Data Retention Period

  • Account data: for the duration of the active Account and for 30 days after deletion.
  • Billing data: for the period required by tax regulations (5 years).
  • Analytical data: in anonymized form, indefinitely.
  • System logs: up to 12 months.

7Cookies

The Platform uses cookies for the following purposes:

  • Essential cookies: required for the proper operation of the Platform (session, authentication).
  • Analytical cookies: collecting anonymous usage statistics (Google Analytics).

You can manage cookie settings in your browser. Disabling essential cookies may limit Platform functionality.

8Your Rights

In relation to data processing, you have the following rights:

  • Right of access: to obtain information about processed data (Art. 15 GDPR).
  • Right to rectification: to correct inaccurate data (Art. 16 GDPR).
  • Right to erasure: to request deletion of data, i.e., the "right to be forgotten" (Art. 17 GDPR).
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability: to receive data in a structured format (Art. 20 GDPR).
  • Right to object: to processing based on legitimate interest (Art. 21 GDPR).
  • Right to lodge a complaint: with the relevant data protection authority.

To exercise these rights, contact us at: hello@procurea.io.

9Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Data encryption in transit (TLS/SSL) and at rest
  • OAuth 2.0 authentication with identity providers (Google, Microsoft)
  • Two-factor verification (SMS)
  • Regular backups
  • Role-based access control
  • Activity monitoring and logging

10Changes to the Privacy Policy

We reserve the right to update this Privacy Policy. Users will be notified of significant changes electronically. The current version is always available at procurea.io.

Contact Information

Procurea sp. z o.o.
ul. Pomorska 3/1, 85-050 Bydgoszcz, Poland
Email: hello@procurea.io