1. Organisation-level data separation
Every record stored in the Service is scoped to the Customer organisation that created it. Data isolation is enforced at the database layer using row-level security.
2. Data controller and processor
In most scenarios the Customer organisation acts as the data controller for personal data it uploads, and Purchase Order Centre acts as the data processor handling that data on the Customer's behalf in order to operate the Service.
3. Customer ownership of data
Customers retain full ownership of all organisational data they upload. We do not sell Customer Data and we do not use Customer Data to train third-party systems.
4. Data storage
Customer Data is stored on managed cloud infrastructure with encryption in transit and at-rest protections provided by the underlying platform.
5. Data minimisation
We collect only the data required to deliver the Service: authentication, identity, organisational structure, and the operational records Customers choose to create.
6. Retention principles
Operational data is retained for as long as the Customer organisation maintains an active workspace. After termination, data may be exported within a reasonable period before deletion in accordance with our retention principles.
7. User deletion requests
Customers may request deletion of personal data at any time, subject to legal retention obligations. Requests can be submitted to support@purchaseorderhub.com.
8. Data export
Customers can request a structured export of their organisational data through the support team. We aim to fulfil reasonable export requests promptly.
9. Backup principles
Managed database backups are performed by our cloud infrastructure provider to support disaster recovery. Backup data is subject to the same access controls and retention policies as production data.
10. Incident response principles
In the event of a confirmed security incident affecting personal data, we will investigate, take reasonable steps to contain and remediate, and notify affected Customers and supervisory authorities where required by applicable law.
11. Contact for privacy enquiries
For data processing enquiries, contact support@purchaseorderhub.com.