Legal

Privacy Policy

How Procista.io handles your data, and who our subprocessors are.

Last updated: 2 July 2026

1. Scope

This policy explains how Procista.io ("Procista") handles data for our marketing website and our procurement platform. It reflects how the product actually works today; where a capability is on our roadmap rather than live, we say so.

2. Data we process

Website: when you submit the contact or demo form, we process the name, email, company, and message you provide, in order to respond. These submissions are delivered to our team by email and are not stored in a marketing database.

Platform: for customer organizations, we process account information (names, emails, roles) and the procurement data your team enters (requirements, suppliers, quotations, approvals, purchase orders, and related email correspondence).

3. How we use data

We use data to provide and secure the service, to communicate with you, and to improve reliability. We do not sell your data, and we do not use your organization’s procurement data to train third-party AI models.

AI features process specific documents you submit (for example a quotation PDF) to extract structured values for your review. Processing is per request and in service of your own workflow.

4. Subprocessors

We rely on a small set of infrastructure providers to run the service: Supabase (managed PostgreSQL database, authentication, and file storage; data currently hosted in the ap-south-1 / Mumbai region); Vercel (application hosting); Resend (transactional and workflow email); and AI providers (for example OpenAI and Anthropic) used to power document extraction and drafting features.

We keep this list current and will update it as our infrastructure evolves. Enterprise agreements can include a formal subprocessor list and change-notification terms.

5. Data ownership and residency

Your organization owns its procurement data. Data is isolated per organization and access is controlled so that one organization cannot see another’s data.

Data is currently hosted in the ap-south-1 (Mumbai) region. Specific data-residency arrangements for enterprise or government customers can be discussed as part of an Enterprise agreement.

6. Security

Data is encrypted in transit and at rest. We follow a defense-in-depth approach and engineer to recognized standards (OWASP ASVS). We are building toward formal certification (SOC 2); we do not claim certifications we have not yet obtained.

7. Retention and deletion

We retain customer data for the life of your agreement. You can request an export of your organization’s data, and we will delete customer data following termination in line with our retention practices and any terms in your agreement. Audit records are kept as an immutable log for integrity and compliance purposes.

8. Your choices

You can contact us to access, correct, or delete personal data we hold about you, subject to applicable law and legitimate business or legal retention needs.

9. Contact

Privacy questions or requests: privacy@procista.io.

This is a plain-language summary provided for transparency and is not a substitute for legal advice. For questions, contact legal@procista.io.