1. Introduction
ProcureAide ("we", "our", "us") operates the Contrack Contract Lifecycle Management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our platform, in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable data protection laws.
By using Contrack, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the platform.
2. Data Controller
ProcureAide Ltd is the data controller responsible for your personal data. For any data protection queries, contact our Data Protection Officer at: dpo@procureaide.com
3. Personal Data We Collect
We collect the following categories of personal data:
- Account Information: Name, email address, department, role, and password (stored as a salted bcrypt hash).
- Contract Data: Contract content, metadata, parties, values, dates, deliverables, KPIs, and obligations you create or manage on the platform.
- Usage Data: Login timestamps, actions performed (audit trail), IP addresses, and session information.
- Communication Data: Email notifications and reminder preferences.
4. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6):
- Consent (Art. 6(1)(a)): You provide explicit consent during registration for data processing necessary to provide the service.
- Contract Performance (Art. 6(1)(b)): Processing is necessary to deliver the contract management services you have subscribed to.
- Legitimate Interest (Art. 6(1)(f)): Security monitoring, fraud prevention, and service improvement.
- Legal Obligation (Art. 6(1)(c)): Compliance with applicable laws and regulations.
5. How We Use Your Data
- Provide, maintain, and improve the Contrack platform
- Authenticate users and manage access controls
- Process contract workflows, approvals, and notifications
- Generate analytics and reports on contract portfolios
- AI-assisted analysis of contract content (obligations, risks, KPIs)
- Send email notifications and compliance reminders
- Monitor security and prevent unauthorized access
- Maintain audit trails for compliance and accountability
6. Data Sharing and Third Parties
We may share your data with:
- AI Service Providers: Contract content is processed by OpenAI (GPT-4o) for obligation extraction, risk review, and deliverable analysis. Data is transmitted securely and not used for model training.
- Email Service Providers: Email addresses and notification content are processed by Resend for transactional emails.
- Infrastructure Providers: Data is stored on secure cloud infrastructure with encryption at rest and in transit.
We do not sell your personal data to any third party.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of all personal data we hold about you. Available via Settings > Security > "Download My Data".
- Right to Rectification (Art. 16): Update inaccurate personal data via your profile settings.
- Right to Erasure (Art. 17): Request deletion of your account and anonymization of personal data. Available via Settings > Security > "Delete My Account".
- Right to Restrict Processing (Art. 18): Request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON export).
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at dpo@procureaide.com or use the self-service tools in your account settings.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, personal data is anonymized within 30 days. Audit logs are retained for 7 years for compliance purposes. Contract data may be retained as required by applicable laws and contractual obligations.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Passwords hashed with bcrypt (salted)
- JWT-based authentication with token expiration
- Account lockout after 5 failed login attempts
- HTTPS/TLS encryption for all data in transit
- Security headers (HSTS, X-Frame-Options, CSP)
- Role-based access control (RBAC) with configurable permissions
- Comprehensive audit logging of all sensitive actions
10. Cookies
Contrack uses only essential cookies required for authentication and session management. We do not use tracking or advertising cookies. You can manage cookie preferences via the cookie consent banner.
11. International Data Transfers
Your data may be processed in countries outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
12. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33). Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay (GDPR Article 34).
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on the platform. Your continued use after changes constitutes acceptance of the updated policy.
14. Contact Us
For any questions about this Privacy Policy or our data practices:
- Data Protection Officer: dpo@procureaide.com
- ProcureAide Ltd, London, United Kingdom
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.