Privacy in one sentence
Procuraz uses personal data to operate a business procurement platform, administer accounts, route enquiries, secure the service and support customer-directed workflows; it does not independently use customer procurement data for unrelated purposes.
Because Procuraz may process data for a buying company, privacy requests sometimes need to be handled by that company rather than by Procuraz alone.
This Privacy Policy explains how Procuraz collects, uses, discloses, stores and protects personal data through www.procuraz.com, the company application, vendor portal, seller-partner portal, contact and support channels, and related services.
It applies to website visitors, prospective customers, company users, vendor users, seller-partner users and other individuals who interact with Procuraz. A customer company may provide a separate privacy notice for data it controls through its Procuraz workspace.
This Policy is intended to align with applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as their provisions become applicable and in force, together with other applicable information-technology and privacy obligations.
Procuraz may act in different roles depending on the data and relationship:
- Website and business relationship: Procuraz determines why and how it processes website enquiries, account administration, billing, security and its own business records.
- Customer workspace: the Customer generally determines the purpose of employee, vendor and procurement data, and Procuraz processes that data to provide the Services under the Customer’s instructions.
- Vendor onboarding: the inviting Customer determines which supplier information and documents are required and how the onboarding decision is made. Procuraz provides the collection and review workflow.
- Seller partner relationship: Procuraz and the Seller Partner may each process relevant contact, team, customer and commercial information for their respective contractual purposes.
Where Indian law uses the terms “Data Fiduciary” and “Data Processor,” the applicable role depends on who determines the purpose and means of processing for the relevant personal data.
| Category | Examples | Why it may be collected |
|---|---|---|
| Identity and contact | Name, work email, phone number, job title, organization, address | Account creation, invitations, communication and support |
| Account and organization | User ID, role, department, permissions, organization relationship, login status | Authentication, access control and workspace administration |
| Vendor and compliance | Business name, GSTIN, PAN, bank proof, registration records, authorized-signatory details and supplier categories | Customer-directed vendor onboarding, verification and supplier management |
| Procurement records | Requisitions, approvals, RFQs, quotations, catalogs, purchase orders, receipt records, comments and attachments | Provide the procurement workflow requested by the Customer |
| Commercial and billing | Plan, subscription, invoice, tax and payment-status information | Contract administration, billing and accounting |
| Support and communications | Contact-form content, emails, support history, screenshots and feedback | Respond, troubleshoot, improve service and maintain records |
| Technical and usage | IP address, browser, device, time, page, session, logs, errors and security events | Operate, secure, diagnose and improve the Services |
Do not submit passwords, OTPs, private keys, complete card numbers, health data or other highly sensitive information unless a specific Procuraz workflow lawfully requires it and provides appropriate notice.
We collect information directly from you; from the organization that creates or administers your account; from a Customer that invites a Vendor; from a Vendor or Seller Partner that creates team users; from connected services authorized by the organization; from service providers supporting authentication, hosting, email, payment or security; and automatically through logs and browser interactions.
A Customer may upload or enter information about employees, approvers, vendor contacts or other business representatives. The Customer is responsible for providing required notices and having a lawful basis for that disclosure.
- create, authenticate and administer accounts and organization workspaces;
- provide requisition, approval, vendor, sourcing, catalog, purchase-order and receipt workflows;
- send invitations, transactional notices, security alerts and support responses;
- route website enquiries to sales, support, vendor, technical or partner teams;
- process subscriptions, invoices and payment status;
- protect accounts, detect abuse, investigate incidents and enforce terms;
- monitor reliability, diagnose errors, plan capacity and improve usability;
- comply with law, court orders, lawful government requests and contractual obligations;
- establish, exercise or defend legal claims; and
- create aggregated or de-identified insights that do not reasonably identify an individual or organization.
Depending on the context and applicable law, Procuraz processes personal data with consent; to take steps requested before entering a contract; to perform a contract; for legitimate uses or business purposes recognized by law; to comply with legal obligations; to protect security, prevent fraud or respond to emergencies; and on the documented instructions of a Customer.
Where consent is required, it should be specific, informed and capable of withdrawal. Withdrawal does not affect processing already completed lawfully and may limit the ability to provide the requested account or workflow.
For personal data contained in a Customer workspace, the Customer usually decides why the data is collected, which users can access it, how long it should be retained and which vendor documents are required. Procuraz processes that data to host and operate the Services.
Questions or rights requests concerning Customer-controlled data should generally be directed first to the relevant Customer. Procuraz will provide reasonable assistance as required by law and the customer agreement.
Vendor approval or rejection is a Customer decision. Procuraz does not independently determine whether a supplier should be accepted, selected or awarded business.
Information may be shared:
- within the organization and with Authorized Users according to roles and workflow permissions;
- between a Customer and invited Vendor where necessary for onboarding, RFQs, quotations, orders and receipt collaboration;
- with Seller Partners only within the scope of the partner relationship and authorized customer activity;
- with service providers that host, secure, send email, process payments, monitor errors or support the Services;
- with professional advisers, auditors, insurers or financing partners under confidentiality duties;
- in connection with a merger, financing, reorganization or sale, subject to appropriate protection;
- when required by law or reasonably necessary to protect rights, safety, security or prevent fraud; and
- with your consent or at the direction of the relevant organization.
Procuraz does not sell personal data as a standalone data-broker activity.
Procuraz may engage hosting, database, email, payment, analytics, monitoring, customer-support and security providers. They may process limited data only to deliver contracted services and are expected to apply appropriate confidentiality and security obligations.
The exact provider set may change as the platform develops. Enterprise customers may request available subprocessor information or contractual data-processing terms through support. Procuraz remains responsible for selecting providers appropriate to the service and applicable contract.
Procuraz and its service providers may process information in India or other locations where infrastructure or support is operated. When personal data is processed outside India, Procuraz will apply contractual, technical and organizational measures required by applicable law and will observe any government restrictions on transfer.
Customers are responsible for confirming that their use and instructions comply with sector-specific localization or transfer requirements that apply to them.
We retain information for as long as reasonably necessary to provide the Services, maintain the account, satisfy the Customer’s instructions, support security and continuity, comply with tax and legal obligations, resolve disputes and enforce agreements.
Retention varies by category. Active account and procurement records may remain for the subscription term and a reasonable export or recovery period. Support, security, billing and legal records may be retained longer where needed. Backups may persist until their normal rotation or secure deletion cycle completes.
When data is no longer required, Procuraz will delete, anonymize or restrict it subject to technical feasibility, legal holds and contractual obligations.
Procuraz uses a combination of technical and organizational measures designed to protect personal data, including authenticated access, role and organization boundaries, secure transport, secret management, logging, backups, vulnerability management and incident response appropriate to the production environment.
No online service can guarantee absolute security. Users and organizations must protect credentials, maintain supported devices and browsers, assign minimum necessary permissions and report suspected compromise promptly.
Security reports should be sent to tech@procuraz.com and should not be publicly disclosed before Procuraz has had a reasonable opportunity to investigate.
Subject to applicable law and the role in which data is processed, you may have rights to:
- receive information about personal data processing;
- access information about personal data and processing activities;
- correct inaccurate or incomplete data;
- request erasure when retention is no longer lawful or necessary;
- withdraw consent where processing relies on consent;
- raise a grievance and receive a response;
- nominate another person to exercise rights in circumstances recognized by law; and
- complain to the competent data-protection authority after using the available grievance process.
Rights may be limited by legal obligations, other individuals’ rights, fraud prevention, security, legal claims, contractual records or exemptions under applicable law.
Email support@procuraz.com with the subject “Privacy Request” and identify the account, organization and data involved. Do not send identity documents until Procuraz explains a secure verification method.
We may verify identity and authority before acting. When the data is controlled by a Customer, we may forward or direct the request to that Customer and assist it. We will respond within the period required by applicable law or communicate if additional information is needed.
The Services are designed for business organizations and are not directed to children under 18. Procuraz does not knowingly invite children to create accounts or submit personal data for independent use.
If you believe a child’s personal data has been submitted improperly, contact support. Procuraz may seek confirmation from the relevant organization and delete or restrict the data where appropriate.
The public marketing website is designed to function without advertising cookies. Essential browser storage or cookies may be used for security, session management or preferences when required by an authenticated application.
If Procuraz introduces non-essential analytics, advertising or cross-site tracking, it will update this Policy and deploy an appropriate preference or consent mechanism before activating those technologies where required.
You can control cookies through your browser, but blocking essential session technologies may prevent login or authenticated functions.
Transactional messages—such as invitations, approval notices, password or security alerts, subscription notices and support responses—are necessary to operate the account or requested workflow.
Marketing communications may be sent where permitted. You can unsubscribe using the message link or contact support. Opting out of marketing does not stop necessary service communications.
The website or Services may link to third-party sites or portals. Their privacy practices are governed by their own notices. Review them before providing personal data. Procuraz is not responsible for content or processing outside services it controls.
We may update this Policy when the product, providers, law or business practices change. The current version will display the effective date. Material changes will be communicated through the website, application or account email where appropriate.
Historical versions may be retained for governance and contractual records.
Privacy questions, requests and grievances may be sent to support@procuraz.com. Security incidents should be sent to tech@procuraz.com.
Please include the relevant organization and account context. The Procuraz Privacy and Grievance Team receives requests through the support address above and may ask for appropriate verification before acting.