Legal
Privacy Policy
This policy explains what personal data Procapy collects, why we collect it, how we protect it, and the choices and rights you have. We have tried to keep it plain.
Effective 6 September 2026 · See also our Terms of Service
1. Who we are and what this policy covers
Procapy ("Procapy", "we", "us" or "our") provides AI-powered software for accounts payable, procurement, expense management and finance automation. This Privacy Policy applies to personal data we process when you:
- visit procapy.com or any site that links to this policy (the "Website");
- contact us, request a demo or quote, or subscribe to our communications;
- use the Procapy platform, applications, APIs and related services as a customer or as an authorised user of a customer (the "Service");
- interact with us as a supplier, partner, job applicant or business contact.
Personal data means any information relating to an identified or identifiable individual.
This policy does not cover the practices of third parties, including our customers and the third-party services you connect to the Service, which have their own privacy policies.
2. Our role: controller or processor
We act in two different capacities, and your rights depend on which one applies.
- Controller. For data about visitors to the Website, prospects, customer account holders and billing contacts, and business contacts, we decide why and how the data is processed and we are the controller. Sections 3 to 11 of this policy describe this processing.
- Processor. When a customer uploads invoices, receipts, purchase orders, vendor records, employee expense claims and similar content into the Service ("Customer Content"), the customer decides why and how that data is processed and is the controller. We process Customer Content only on the customer's documented instructions, as set out in our Terms of Service and any Data Processing Agreement with that customer. Section 12 describes this processing.
If you are an employee, vendor or other individual whose data appears in Customer Content, the customer (typically your employer or the company you do business with) is responsible for that data. Please direct requests about it to them. We will help our customers respond to such requests as required by law and our agreement with them.
3. Personal data we collect
Data you give us directly:
- Contact and demo requests: name, work email, phone number, company, job title, country, how you heard about us, the urgency of your request, your message, and any file you attach (for example a sample invoice or process document).
- Account data: name, work email, role, password (stored as a salted hash), profile photo, language and notification preferences, and the organisation you belong to.
- Billing data: billing contact details, company registration and tax identifiers, and invoicing history. Card payments, where offered, are handled by a payment provider; we do not store full card numbers.
- Communications: the content of emails, chat messages, support tickets and calls with us, and feedback or survey responses.
- Recruitment data: CVs, cover letters and application details if you apply for a job with us.
Data collected automatically when you use the Website or Service:
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language, time zone and referring URLs.
- Usage data: pages viewed, features used, actions taken in the Service, timestamps, session duration and error logs.
- Cookies and similar technologies, as described in section 9.
Data from other sources:
- Business information from public sources, data providers and social networks such as LinkedIn, used to verify company details and to understand which organisations are interested in Procapy.
- Data from third-party services you choose to connect to the Service, such as accounting systems, ERPs, banks, email and storage providers, to the extent needed for the integration.
- Data from partners and resellers who introduce you to us.
We do not intentionally collect sensitive personal data (such as health, religious, biometric or genetic data, or data about children) as a controller. Customers should not upload such data to the Service unless it is genuinely necessary for the finance process concerned, in which case the customer is responsible for having a lawful basis for it.
4. How we use personal data and our legal bases
We use personal data for the following purposes. Where a law such as Indonesia's Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") or the EU/UK General Data Protection Regulation ("GDPR") requires a legal basis, the basis is indicated.
- To respond to your enquiries, demo and quote requests, and to provide customer support. Basis: performance of a contract or steps taken at your request before entering a contract; our legitimate interest in responding to business enquiries.
- To create and administer accounts, authenticate users, provide the Service, process billing and collect payment. Basis: performance of a contract.
- To operate, maintain, secure and monitor the Service, detect and prevent fraud, abuse and security incidents, and enforce our terms. Basis: legitimate interests in keeping the Service secure and reliable; legal obligation.
- To analyse how the Website and Service are used, and to develop, test and improve our products, including the accuracy of AI features. Basis: legitimate interests in improving our products; consent where required for cookies and similar technologies.
- To send service communications such as onboarding information, release notes, security notices, renewal reminders and invoices. Basis: performance of a contract; legitimate interests.
- To send marketing communications about products, features, events and content we think will interest you. Basis: consent, or legitimate interests where permitted for existing business contacts. You can opt out at any time (section 8).
- To comply with legal obligations, including tax, accounting, anti-money-laundering and sanctions requirements, and to respond to lawful requests from authorities. Basis: legal obligation.
- To establish, exercise or defend legal claims, and in connection with a merger, acquisition or reorganisation. Basis: legitimate interests.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights, and you may object as described in section 8.
5. How AI features use data
The Service uses machine learning and generative AI to read documents, extract and match data, flag anomalies, draft content and automate routine tasks. To provide these features we process the Customer Content that customers submit, together with related metadata.
We may use third-party AI model providers as sub-processors. Where we do, data is sent under contractual terms that prohibit the provider from using it to train their models or for any purpose other than providing the service to us, and we select providers that offer enterprise data protection commitments.
We do not use Customer Content to train models that are made available to other customers unless the customer has opted in in writing. We may use de-identified and aggregated data, and data from customers who have opted in, to improve extraction accuracy, detection rules and product quality.
AI outputs can be wrong. Customers remain responsible for reviewing outputs and for the decisions they make, and we design the Service so that consequential actions require human review.
We do not use AI to make automated decisions that produce legal or similarly significant effects about individuals as a controller.
7. International transfers
We are based in Indonesia and our service providers may be located in other countries, including Singapore, the United States and the European Union. This means personal data may be transferred to, stored and processed in countries other than the one in which you are located, which may have different data protection laws.
Where we transfer personal data across borders we take steps required by applicable law to protect it, including transferring only to countries that provide an adequate level of protection, using contractual safeguards such as standard contractual clauses or equivalent terms, obtaining your consent where required, and applying the security measures described in section 10.
Customers may request information about the locations in which their Customer Content is hosted, and we offer regional hosting options where stated in the Order Form.
8. Your rights and choices
Depending on where you are located and the law that applies, you may have the right to:
- access the personal data we hold about you and receive a copy of it;
- ask us to correct inaccurate or incomplete personal data;
- ask us to delete your personal data, subject to legal retention requirements;
- restrict or object to our processing, including processing based on legitimate interests and processing for direct marketing;
- receive your personal data in a portable, machine-readable format, where processing is based on consent or contract;
- withdraw consent at any time where we rely on consent;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you;
- lodge a complaint with a supervisory authority, including Indonesia's personal data protection authority or the authority in your country of residence.
To exercise your rights, email hello@procapy.com or use the settings in your account. We may need to verify your identity before acting on a request. We will respond within the period required by applicable law, and in any event within 30 days, and we will not charge a fee unless the law allows it for excessive or repeated requests.
If your data was uploaded to the Service by one of our customers (see section 2), we will refer your request to that customer where appropriate, and assist them in responding.
Marketing choices. You can opt out of marketing emails by using the unsubscribe link in any email or by contacting us. We will still send service and transactional messages that are necessary to operate your account.
Cookie choices. See section 9.
10. How we protect personal data
We maintain administrative, technical and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include encryption in transit (TLS) and at rest, role-based access controls and least-privilege principles, multi-factor authentication, logging and monitoring, regular backups, vulnerability management and security testing, secure development practices, confidentiality obligations for staff, and staff training.
No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to individuals, we will notify affected customers without undue delay (and within 72 hours for confirmed breaches affecting Customer Content) and notify authorities and individuals where required by law.
You can help by using a strong, unique password, enabling multi-factor authentication, and letting us know promptly if you suspect any unauthorised access to your account.
11. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law. In general:
- Enquiry and demo-request data: up to 24 months after our last contact with you, unless you become a customer.
- Account and usage data: for the life of the customer relationship and up to 12 months afterwards, except where a shorter period is agreed.
- Customer Content: for the subscription term, then made available for export for 30 days and deleted from live systems within 90 days after termination, with backups expiring on a rolling schedule of up to 12 months, unless the customer instructs otherwise or law requires retention.
- Billing, tax and accounting records: 10 years, as required by Indonesian law.
- Security and access logs: typically 12 to 24 months.
- Marketing data: until you opt out or after 24 months of inactivity.
- Recruitment data: up to 12 months after the recruitment decision, unless you agree to be considered for future roles.
When data is no longer needed we delete it or anonymise it so that it can no longer be linked to you.
12. Customer Content and our role as processor
When we process Customer Content on behalf of a customer, we:
- process it only on the customer's documented instructions, including as set out in the Terms of Service, the Order Form and any Data Processing Agreement, unless required by law to do otherwise;
- keep it confidential and ensure our personnel are bound by confidentiality obligations;
- apply the security measures described in section 10;
- engage sub-processors only under written terms that impose data protection obligations equivalent to ours, and inform customers of changes;
- assist the customer in responding to data subject requests and in meeting its security, breach notification and impact assessment obligations;
- delete or return Customer Content at the end of the service, as described in section 11 and the Terms of Service;
- make available the information necessary to demonstrate compliance and allow for audits as agreed in the Data Processing Agreement.
Customers are responsible for ensuring that they have a lawful basis to collect Customer Content and to share it with us, for providing any required notices to their employees, vendors and other individuals, and for not uploading data that is not needed for the finance process concerned.
Customers who need a Data Processing Agreement, including for GDPR purposes, can request one at hello@procapy.com.
13. Children
The Website and Service are intended for businesses and are not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will delete it.
14. Third-party websites
The Website and Service may contain links to third-party websites, products and services. We are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any site you visit.
15. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology or legal requirements. We will post the updated policy on the Website and update the effective date at the top. If the changes are material, we will notify customers by email or through the Service at least 30 days before they take effect, and we will seek consent where required by law.
Previous versions of this policy are available on request.
16. Contact us
If you have questions, concerns or requests about this policy or our handling of your personal data, contact us at hello@procapy.com or write to Procapy, Jakarta, Indonesia. Please include "Privacy" in the subject line so we can route your message promptly.
If you are not satisfied with our response, you have the right to complain to the competent data protection authority in your country. We would appreciate the chance to resolve your concern first.
