What this is
During an engagement we handle data inside your systems — supplier records, invoices, approver names — and some of it is personal data. Where that happens you are the controller and we are the processor, and a Data Processing Addendum governs it.
This page summarises what that addendum says so you can assess it before a call. It is not the agreement itself. Ask for the executable version at hello@procuriva.com and we will send it, unsigned, without requiring an NDA first.
Scope and instruction
- We process personal data only on your documented instructions, and only for the services in the agreement.
- We tell you if an instruction appears to breach applicable data protection law, rather than carrying it out and raising it later.
- We do not use your data to train models, to build benchmarks, or for any purpose of our own.
Security measures
The technical and organisational measures are listed in full on the security page and are incorporated into the addendum by reference, so they are contractual rather than aspirational. In summary:
- Access is scoped by you, granted to named individuals, and revoked through your own joiner-leaver process.
- We work inside your systems rather than copying data into ours. Where a copy is unavoidable, its location is written into the addendum.
- Segregation of duties: the analyst who maintains supplier master data never processes that supplier's invoices.
- No one on our side can release a payment or action a change to a supplier's bank details.
Sub-processors
Our sub-processors are published and kept current on the sub-processors page. We give you at least 30 days' notice before adding one, and you may object; if we cannot resolve the objection you may terminate the affected services without penalty.
International transfers
Delivery is from India and the United Arab Emirates. Transfers out of the UK rely on the International Data Transfer Agreement, and out of the EEA on the standard contractual clauses, with a transfer risk assessment available on request. Where you require data to stay in a particular region, that is agreed in the addendum before access is granted rather than negotiated afterwards.
Breach notification
We notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data, with what we know at that point rather than waiting for a complete picture. We assist with your own notification obligations to regulators and data subjects.
Audit, assistance and deletion
- We assist you with data subject requests, impact assessments and regulator consultations.
- We make available the information needed to demonstrate compliance, and accept audits at reasonable notice.
- On termination we return or delete your personal data at your choice. Transition-out support is written into the agreement from day one, not negotiated at the point you leave.
Something here unclear, or missing what your security review needs? Email hello@procuriva.com and we will answer rather than send you a form.
Talk to us