Privacy Policy

Last updated: 1 June 2026

How Procoflow collects, uses and protects personal data across the marketing site and the product.

Who we are

This policy describes how Neetu AI Solutions LLP (“Procoflow”, “we”, “us”) handles personal data when you visit our website, request a demo, or use the Procoflow product as a user within a customer's tenant.

For product data, the customer (your employer or the company that invited you) is the data controller and Procoflow acts as a processor on their behalf. For the marketing site and sales enquiries, Procoflow is the controller.

Data we collect

Depending on how you interact with us, we may collect:

How we use it

We use personal data to:

Legal bases

Where applicable law requires a legal basis, we rely on your consent (for marketing email), the performance of a contract (to provide the service), and our legitimate interests (to secure and improve the product), balanced against your rights.

Sharing and subprocessors

We do not sell personal data. We share it only with vendors that help us run the service (for example hosting and email delivery), under contract and only as needed. A current list is on the Subprocessors page.

Retention

We keep personal data for as long as needed for the purposes above, then delete or anonymise it. Product data is retained per the customer's settings and our agreement with them. Cancelled records inside the product are closed, not deleted, so the audit trail stays intact.

Your rights

Subject to local law, you may request access, correction, deletion, a copy of your data, or object to certain processing. For product data, we will route your request to the relevant customer (controller) and assist them. Contact us to exercise any right.

Account and data deletion

Procoflow accounts are provisioned and managed by your organisation. Your organisation's administrator can remove your user account at any time, which revokes your access.

To delete your account or request deletion of your personal data, contact your organisation's administrator, or email us at [email protected] and we will action the request or route it to your organisation (the data controller). We will respond within 30 days. Records you created inside the product (such as requests and orders) may be retained in your organisation's tenant for audit and legal purposes even after your user account is removed.

Security

We protect data with tenant isolation, role-based access, encryption in transit and an audit trail. See the Security page for more, and report any concern to our security contact.

Changes and contact

We will post any change here and update the date above. Questions about this policy can go to [email protected].