Skip to main content

Privacy Policy

Last updated: 18 August 2026

Who we are

ProcuLink is a product operated by Diip Solutions OÜ, registry code 17527757, registered at Uus-Sadama tn 15-2, 10120 Tallinn, Estonia. In this policy, "ProcuLink", "we", "us", and "our" refer to Diip Solutions OÜ as operator of the ProcuLink procurement automation platform at proculink.eu.

What data we collect

  • Account data — name, work email, organisation name, collected via Clerk authentication on sign-up.
  • Order data — purchase order files you upload, canonical order data derived from those files, mapped and transformed output files.
  • Usage data — page views, feature interactions, error events, collected via product analytics.
  • Billing data — subscription plan and status, handled by Stripe. We never store your card numbers or payment credentials.
  • Email configuration — IMAP server credentials (host, port, username, password) for email ingestion features. Passwords are encrypted at rest using AES-256-GCM authenticated encryption.
  • Delivery credentials — webhook URLs and authentication tokens for supplier delivery configurations, encrypted at rest.

How we use your data

  • To provide the ProcuLink service: parse, map, transform, and deliver your purchase orders.
  • To send transactional emails such as order status notifications and billing receipts.
  • To improve the product via aggregated, pseudonymous product analytics.
  • To comply with legal obligations, including tax records for invoiced subscriptions.

We do not sell your data to third parties. We do not use your order content to train AI models.

Data storage and residency

These providers hold your order files, the database, and the API that serves them:

  • File storage: Cloudflare R2 (EU-region bucket)
  • Database: PostgreSQL hosted on Neon (EU region)
  • API hosting: Railway (EU region)
  • Error monitoring: Sentry (EU region instance)
  • Frontend: Vercel (global CDN — order files do not pass through it)

Some processing happens outside the EEA, under Standard Contractual Clauses. These providers are not a rare exception — they sit on the normal path an order takes:

  • Authentication: Clerk (US-based, EU data residency available on request)
  • AI document extraction and mapping suggestions: OpenAI (US) — receives purchase-order content, unless we have turned AI extraction off for your organisation
  • Payments: Stripe (US, EU establishment) — billing data only, no order content
  • Email in and out: Postmark (US) — carries orders emailed to your ProcuLink address, and the purchase orders we email to your suppliers, as attachments

Where your data is stored and the route it travels to reach your supplier are two different questions. The outbound network path is chosen by our hosting provider and is not pinned to a region by us, so we cannot tell you today which country an outbound delivery leaves from. The Security page explains this in full.

Data retention

  • Active account data is retained while your account is active.
  • Order files and output artifacts are retained for the life of the account by default. We delete order data on written request — see "Deleting your data" below for what that covers.
  • A shorter automatic window can be set on a workspace, so that stored order files are removed once they reach the age you choose. It is off unless you ask us for it.
  • Account and billing data is deleted within 30 days of account closure on written request.
  • Audit log entries are retained for the life of the account, except where they belong to an order you have asked us to delete — those go with the order.

Your rights under GDPR

As an EU/EEA data subject you have the right to:

  • Access the personal data we hold about you
  • Rectification of inaccurate data
  • Erasure ("right to be forgotten") where no overriding legal basis exists
  • Data portability — receive your data in a structured, machine-readable format
  • Objection to processing based on legitimate interests
  • Restriction of processing where accuracy is contested or objection is pending

To exercise any of these rights, email privacy@proculink.eu. We respond within one month, which is the period the GDPR sets. If a request is complex we may extend that by up to two further months, and we will tell you inside the first month if we need to.

Deleting your data

To have order data deleted, email privacy@proculink.eu from the address on your account and tell us which orders — a list of PO numbers, a number prefix, or a date range. We check that the address belongs to the workspace you name, and we confirm the scope with you in writing before anything is deleted. Deletion is run by us rather than from a button in the product, and it cannot be undone.

What gets deleted

  • The document you sent us, as held in our file storage.
  • The order content we extracted from it — line items, quantities, prices, and the names, addresses and contact details captured from the document.
  • The output files we generated for your supplier.
  • The processing and delivery history for those orders, and the mapping decisions recorded against them.

What we keep, and why

  • A note that the deletion happened — the date, who ran it, and how much it covered. It holds none of your order content. We keep it because we have to be able to demonstrate what we did and when, which is what GDPR Article 5(2) asks of us.
  • Workspace configuration — suppliers, buyers, mappings, validation rules, output templates, and delivery settings with their stored credentials. These are settings rather than order content, so deleting orders leaves them in place and the workspace keeps working. Ask us if you want them removed as well; we do that by hand.
  • Billing and tax records — kept for as long as accounting law requires us to keep them.
  • A marker for orders collected from your own systems — where we picked a file up from your SFTP server or S3 bucket, we keep a note that the file was already handled, with its link to the deleted order cut. The file itself stays yours and we never remove it. Without that marker your file would simply be collected again and turned into a new order.
  • Backup copies — until they age out on their normal rotation. We do not restore deleted order data from a backup.

Two things sit outside this. Your sign-in account is held by our authentication provider, and deleting order data does not remove it — ask us and we will. And a purchase order we have already sent to your supplier is in your supplier's systems from that point on, which we have no way to reach.

Cookies

We use only functional cookies (authentication session, CSRF protection) and analytics cookies (product usage — pseudonymous). We do not use advertising or cross-site tracking cookies.

Subprocessors

The authoritative list of subprocessors is maintained at /subprocessors with a 30-day change-notification commitment. The current snapshot:

ProcessorPurposeLocation
RailwayAPI and background-worker hostingEU region
NeonPostgreSQL database hostingEU region
CloudflareR2 object storage (order files and the output files we generate) and DNSEU-region bucket
VercelWebsite and app hosting (order files do not pass through it)Global CDN
ClerkAuthentication and session managementUS, EU data residency available
OpenAIAI document extraction and mapping suggestions (API data is not used for model training under OpenAI's API terms)US
StripePayment processing and subscription managementUS, EU establishment
PostmarkEmail in and out: orders emailed to your ProcuLink address, and the purchase orders we email to your suppliersUS
PostHogPseudonymous product analyticsEU (eu.posthog.com)
SentryError monitoring and diagnosticsEU region

Contact and DPO

For privacy questions or to exercise your rights: privacy@proculink.eu
General support: support@proculink.eu
Registered address: Diip Solutions OÜ, Uus-Sadama tn 15-2, 10120 Tallinn, Estonia