Privacy Policy
Effective Date: September 2026 • Approvdit Technologies • [email protected]
This Privacy Policy describes how Approvdit Technologies ("Approvdit," "we," "us") collects, processes, stores, and protects data when organizations use our approval workflow platform. This policy applies to organizations that register on approvdit.com, users invited by those organizations, and anyone who contacts us for support.
1. Introduction & Scope
This Privacy Policy applies to organizations that register on approvdit.com, users invited by those organizations, and anyone who contacts us for support.
If you are an employee using Approvdit through your organization, your organization is the Data Controller for your data. Approvdit acts as the Data Processor.
2. Data Controller vs Data Processor
For organization-level data (registration, billing, integration credentials), Approvdit is the Data Controller — we determine why and how we process this data.
For employee and operational data (requests, approvals, vendor records, audit trail), the client organization is the Data Controller. Approvdit is the Data Processor. We process this data solely on the organization's instructions. Questions about employee data should be directed to the organization's administrator.
3. Data We Process
We process the following data:
| Category | Examples | Protection |
|---|---|---|
| Organization data | Company name, domain, industry, address | Standard |
| User profiles | Name, email, job title, phone | Standard |
| Approval data | Requests, amounts, invoices | Standard |
| Vendor bank details | IBAN, SWIFT, account number | Encrypted (AES) |
| OAuth tokens / 2FA secrets | Integration keys, TOTP secrets | Encrypted (AES) |
| Audit trail | Who approved what, when | Hash-chained |
We do NOT collect passwords (stored as one-way hashed values), payment card numbers, government ID numbers, biometric data, or data from children (18+ only).
4. Legal Bases for Processing
Under UK GDPR and similar frameworks, we process data under these legal bases:
- Providing the approval service — Contract
- Security monitoring (login IPs, brute-force detection) — Legitimate Interest
- Two-factor authentication — Contract
- Audit trail (hash chain) — Legal Obligation
- Backup & disaster recovery — Legitimate Interest
- Email notifications (approvals, alerts) — Contract
- Registration form data — Consent
5. How We Use Data
We use data ONLY to:
- Run the approval workflow your organization has configured
- Send notifications (approval emails, login alerts)
- Connect integrations you explicitly set up
- Maintain security (2FA, brute-force protection, tamper detection)
- Back up data for recovery
We do NOT SELL or RENT or TRADE your DATA. We do NOT USE your data for advertising or marketing. We do NOT SHARE with analytics services. We do NOT MAKE automated decisions about individuals.
6. How We Protect Data
Approvdit implements the following technical and organizational security measures:
- Mandatory two-factor authentication (TOTP) with encrypted secrets
- Bank details encrypted at rest (AES)
- OAuth tokens and 2FA secrets encrypted with key separation
- Hash-chained, tamper-evident audit trail
- Brute-force protection with automatic lockout
- Instant session termination on account deactivation
- Invitation links expire after 7 days
- New-device login alerts
- Weekly GPG-encrypted off-site backups
- TLS encryption on all connections
- Role-based access control (Administrator / Auditor / User)
7. Data Sharing & Sub-Processors
We share data with exactly three sub-processors, each bound by contractual data protection obligations:
| Processor | Service | Data accessed |
|---|---|---|
| Render | Hosting, database | All data |
| Cloudflare | CDN, file storage (R2) | Uploaded files |
| Zoho | Email delivery | Email addresses |
Data is shared with QuickBooks or Google Sheets only when your organization explicitly connects those integrations.
8. International Data Transfers
Your data is hosted on infrastructure in the US and EU. All data in transit is TLS encrypted. Bank details, OAuth tokens, and 2FA secrets are additionally encrypted at rest. Backups are GPG-encrypted.
For UK/EU organizations: our sub-processors provide Standard Contractual Clauses for international transfers, available on request.
9. Data Retention & Deletion
- Active account data retained while your subscription is active
- Deleted data removed from live system immediately
- Encrypted backup copies retained up to 30 days, then permanently deleted
- Login attempt logs auto-expire after 15 days
On account closure, we provide a complete export of your organization's data upon request before deletion. Contact [email protected].
10. Your Rights
For organizations: access and export your data, correct any record, erase all data, disconnect integrations, cancel subscription.
For individual users: access your profile data, export your data, request corrections, request deletion (through your organization's administrator), lodge a complaint with your data protection authority.
To submit a request, contact [email protected] or your organization's administrator. We respond within 30 days.
11. Data Breach Notification
- We will assess severity within 24 hours of detection
- We will notify affected organizations within 72 hours of initial detection of a confirmed security breach
- We will provide: what happened, data involved, our response, and recommended actions
12. Contact & Governing Law
Privacy contact: [email protected]
Entity: Approvdit Technologies
Registered office: Awaiting Incorporation
This policy is governed by the laws of the Islamic Republic of Pakistan. For organizations in the UK/EU, GDPR applies to the processing described above.
© 2026 Approvdit. All rights reserved.