Approvdit Approvdit.

Automate Your Bill Approvals & Workflows.

Privacy Policy

Effective Date: September 2026  •  Approvdit Technologies  •  [email protected]

This Privacy Policy describes how Approvdit Technologies ("Approvdit," "we," "us") collects, processes, stores, and protects data when organizations use our approval workflow platform. This policy applies to organizations that register on approvdit.com, users invited by those organizations, and anyone who contacts us for support.

1. Introduction & Scope

This Privacy Policy applies to organizations that register on approvdit.com, users invited by those organizations, and anyone who contacts us for support.

If you are an employee using Approvdit through your organization, your organization is the Data Controller for your data. Approvdit acts as the Data Processor.

2. Data Controller vs Data Processor

For organization-level data (registration, billing, integration credentials), Approvdit is the Data Controller — we determine why and how we process this data.

For employee and operational data (requests, approvals, vendor records, audit trail), the client organization is the Data Controller. Approvdit is the Data Processor. We process this data solely on the organization's instructions. Questions about employee data should be directed to the organization's administrator.

3. Data We Process

We process the following data:

Category Examples Protection
Organization dataCompany name, domain, industry, addressStandard
User profilesName, email, job title, phoneStandard
Approval dataRequests, amounts, invoicesStandard
Vendor bank detailsIBAN, SWIFT, account numberEncrypted (AES)
OAuth tokens / 2FA secretsIntegration keys, TOTP secretsEncrypted (AES)
Audit trailWho approved what, whenHash-chained

We do NOT collect passwords (stored as one-way hashed values), payment card numbers, government ID numbers, biometric data, or data from children (18+ only).

4. Legal Bases for Processing

Under UK GDPR and similar frameworks, we process data under these legal bases:

  • Providing the approval service — Contract
  • Security monitoring (login IPs, brute-force detection) — Legitimate Interest
  • Two-factor authentication — Contract
  • Audit trail (hash chain) — Legal Obligation
  • Backup & disaster recovery — Legitimate Interest
  • Email notifications (approvals, alerts) — Contract
  • Registration form data — Consent

5. How We Use Data

We use data ONLY to:

  • Run the approval workflow your organization has configured
  • Send notifications (approval emails, login alerts)
  • Connect integrations you explicitly set up
  • Maintain security (2FA, brute-force protection, tamper detection)
  • Back up data for recovery

We do NOT SELL or RENT or TRADE your DATA. We do NOT USE your data for advertising or marketing. We do NOT SHARE with analytics services. We do NOT MAKE automated decisions about individuals.

6. How We Protect Data

Approvdit implements the following technical and organizational security measures:

  • Mandatory two-factor authentication (TOTP) with encrypted secrets
  • Bank details encrypted at rest (AES)
  • OAuth tokens and 2FA secrets encrypted with key separation
  • Hash-chained, tamper-evident audit trail
  • Brute-force protection with automatic lockout
  • Instant session termination on account deactivation
  • Invitation links expire after 7 days
  • New-device login alerts
  • Weekly GPG-encrypted off-site backups
  • TLS encryption on all connections
  • Role-based access control (Administrator / Auditor / User)

7. Data Sharing & Sub-Processors

We share data with exactly three sub-processors, each bound by contractual data protection obligations:

Processor Service Data accessed
RenderHosting, databaseAll data
CloudflareCDN, file storage (R2)Uploaded files
ZohoEmail deliveryEmail addresses

Data is shared with QuickBooks or Google Sheets only when your organization explicitly connects those integrations.

8. International Data Transfers

Your data is hosted on infrastructure in the US and EU. All data in transit is TLS encrypted. Bank details, OAuth tokens, and 2FA secrets are additionally encrypted at rest. Backups are GPG-encrypted.

For UK/EU organizations: our sub-processors provide Standard Contractual Clauses for international transfers, available on request.

9. Data Retention & Deletion

  • Active account data retained while your subscription is active
  • Deleted data removed from live system immediately
  • Encrypted backup copies retained up to 30 days, then permanently deleted
  • Login attempt logs auto-expire after 15 days

On account closure, we provide a complete export of your organization's data upon request before deletion. Contact [email protected].

10. Your Rights

For organizations: access and export your data, correct any record, erase all data, disconnect integrations, cancel subscription.

For individual users: access your profile data, export your data, request corrections, request deletion (through your organization's administrator), lodge a complaint with your data protection authority.

To submit a request, contact [email protected] or your organization's administrator. We respond within 30 days.

11. Data Breach Notification

  • We will assess severity within 24 hours of detection
  • We will notify affected organizations within 72 hours of initial detection of a confirmed security breach
  • We will provide: what happened, data involved, our response, and recommended actions

12. Contact & Governing Law

Privacy contact: [email protected]

Entity: Approvdit Technologies

Registered office: Awaiting Incorporation

This policy is governed by the laws of the Islamic Republic of Pakistan. For organizations in the UK/EU, GDPR applies to the processing described above.

© 2026 Approvdit. All rights reserved.