[DRAFT — pending legal review] This document is a placeholder template and is not yet legally binding. It will be replaced before general availability.
Privacy Policy
Last updated: 19 July 2026
1. Scope
This Privacy Policy explains what personal data Paytrol collects when your organization uses the Service, how we use it, and the choices available to you. It applies to the Paytrol application and website.
2. Data we collect
- Account data — name, work email, phone number, job title, and role within your organization.
- Organization data — company name, registration details, registered address, country, currency, and timezone.
- Operational data — payment requests, payee records, invoices and supporting documents you upload, approval decisions, comments, and the audit trail of those actions.
- Technical data — sign-in events, IP address, browser and device information, and application logs used to operate and secure the Service.
3. How we use it
- to provide, operate, and support the Service;
- to route approvals and maintain the audit trail your organization relies on;
- to authenticate users and protect against unauthorized access, fraud, and abuse;
- to send transactional notifications, such as approval requests and status changes;
- to meet legal, accounting, and regulatory obligations.
We do not sell personal data, and we do not use your operational data to advertise to you.
4. Legal basis
We process personal data to perform our contract with your organization, to pursue our legitimate interests in operating and securing the Service, and to comply with legal obligations. Where consent is required, we obtain it.
5. Sharing
We share data only with service providers that help us run the Service — for example cloud hosting, database, email delivery, payment-processing for subscriptions, and document-reading services — each acting under contract and only as needed to provide their function. We may also disclose data where required by law.
Data belonging to one organization is segregated from other organizations by row-level security enforced in the database.
6. Retention
Invoice and audit records are retained for the period stated in your plan (currently seven years) so they remain available for accounting and audit purposes. The audit trail is append-only by design and cannot be edited or deleted, including by administrators. Account data is retained while your organization uses the Service and for a reasonable period afterwards.
7. Security
We use encryption in transit, access controls, row-level data isolation, and least-privilege access for our own staff. No system is perfectly secure, but we work to protect data proportionately to its sensitivity — bank details in particular are restricted to finance roles.
8. International transfers
Data may be processed in a region other than your own, including by our hosting providers. Where data is transferred internationally we rely on appropriate safeguards.
9. Your rights
Depending on your jurisdiction you may have the right to access, correct, export, or request deletion of your personal data, and to object to or restrict certain processing. Because we process most data on behalf of your organization, please raise these requests with your organization’s Paytrol administrator, who can contact us.
Note that deletion requests may be limited where records must be retained for accounting, audit, or legal reasons — in particular the append-only audit trail.
10. Cookies
We use strictly necessary cookies to keep you signed in and to protect the session. We do not use advertising cookies.
11. Changes and contact
We may update this policy from time to time and will provide reasonable notice of material changes. A formal data-protection contact address will be published alongside the reviewed version of this document.