Privacy Notice
Effective September 14, 2026
Who we are
Proquri is operated by Nastrond Harridsleff (org. nr. 936 340 369), made in Oslo, Norway. For anything in this notice, or to exercise any of the rights below, contact us at privacy@proquri.com.
The short version
Proquri helps you track, understand, and negotiate your company's SaaS contracts. To do that, we process the account details you give us, the contract documents you upload, and how you use the app — including sending contract text to a small number of AI providers to extract and analyze it. We never sell personal data. This notice explains what we collect, why, who we share it with, and the rights you have over it — including a dedicated section on GDPR, since it applies to us directly as a Norwegian (EEA) company, not only because some of our customers are in the EU.
What we collect
- Account data: your name, work email, company name, and password (stored hashed, never in plain text) when you sign up.
- Contract documents and their extracted content: the PDFs you upload, and every field our AI extracts from them — pricing, terms, renewal dates, and so on. This commonly includes personal data about people who aren't you or your organization — most notably the name of your vendor's sales representative, and sometimes signatory names or contact details appearing in the contract text itself.
- Negotiation and usage records: notes and updates you log against a contract, messages you send to the AI Deal Copilot chat, and corrections you make to extracted fields.
- Billing data: handled directly by Stripe when you subscribe to a paid tier — we never see or store your card number.
- Technical data: standard connection logs (IP address, timestamps) our infrastructure generates automatically.
- Cookies and similar technologies: see our Cookie Policy for the full detail — in short, a strictly-necessary login session and, once enabled, Google Analytics with your prior consent.
Why we process it, and on what legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Run your account, extract and display your contracts | Deliver the service you signed up for | Performance of a contract with you |
| Send contract text to Anthropic, LlamaParse, and Voyage AI for extraction, analysis, and the AI chat | Deliver the core product | Performance of a contract with you |
| Pool anonymized/pseudonymized pricing data across customers for benchmarking | Give you peer pricing context — the product's core value | Legitimate interest, balanced against the anonymization safeguards described above |
| Process payments through Stripe | Bill you for a paid tier | Performance of a contract with you; legal obligation (accounting/tax records) |
| Run Google Analytics | Understand product usage | Your consent, given through the cookie banner |
| Keep connection logs, detect abuse | Keep the service secure and reliable | Legitimate interest |
| Respond to legal requests | Comply with the law | Legal obligation |
Who we share it with
We share personal data only with the service providers that help us run Proquri, and only to the extent each one needs to do its job. See the table below for the full list, what each one does, where it processes data, and its data protection safeguards. We never sell personal data, and we never share contract documents with any other customer — the anonymized/pseudonymized benchmarking pool described above is the one place data crosses between customers, and it's built specifically so it can't be traced back to you or your contract.
| Subprocessor | Used for | Data processing location | DPA / transfer safeguard |
|---|---|---|---|
| Anthropic | Contract extraction, AI Deal Copilot chat | US | DPA + Standard Contractual Clauses auto-incorporated into Anthropic's commercial API terms on account creation. Anthropic does not use commercial API prompts/outputs to train its models by default. |
| LlamaIndex (LlamaParse / LlamaCloud) | OCR / document parsing | EU (configured on the EU region endpoint) | DPA available (executed via DocuSign); does not use customer content to train models by default. |
| Voyage AI | Text embeddings for RAG chat and search | US | Data processing terms under Voyage AI's commercial API agreement; submitted content is not used to train or improve Voyage AI's models (opted out). |
| Trigger.dev | Background job orchestration | US (AWS us-east-1) | DPA incorporated into Trigger.dev's Terms of Service; Standard Contractual Clauses used for transfers outside the UK/EEA. |
| Stripe | Payment processing, billing | US / EU (Stripe Payments Europe, Ltd. for non-Americas accounts) | DPA incorporated into Stripe's terms; supports the EU-US Data Privacy Framework, UK IDTA, and Standard Contractual Clauses. |
| Google (Analytics) | Product usage analytics (once live) | US | Google's standard data processing terms for Analytics apply; Analytics only runs with your prior consent (see our Cookie Policy). |
| Hostinger | VPS hosting (all self-hosted infrastructure runs here) | EU | DPA incorporating EU Standard Contractual Clauses (Module Two, controller-to-processor). |
| Cloudflare | DNS, and traffic routing/security once proxying is enabled | Global network | DPA incorporating Standard Contractual Clauses. |
International data transfers
Several of our service providers process data in the United States. Every transfer outside the EU/EEA relies on Standard Contractual Clauses as its primary safeguard — we don't rely on the EU-US Data Privacy Framework alone, given its currently uncertain status under active legal challenge. See the subprocessor table above for the safeguard used for each provider.
How long we keep data
We keep your account and contract data for as long as your account is active, plus a reasonable period afterward for backups and legal/accounting requirements. If you delete your account, we delete your account and contract data within 30 days of your request; residual copies in encrypted backups are purged on a rolling cycle within 90 days. We keep billing records for as long as we're required to by law. Anonymized benchmark data that no longer references you or your contract, described above, is retained indefinitely as aggregate market data, since it's no longer personal data about you specifically — with the one exception of the pseudonymized rep-name field noted above, which we'll address on request to the extent technically possible.
Your rights
Under GDPR, and wherever else applicable law gives you these rights, you can ask us to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time, for anything we process based on consent (like analytics cookies), without affecting processing before that point
To exercise any of these, email privacy@proquri.com. You also always have the right to lodge a complaint with a supervisory authority — ours is Datatilsynet (the Norwegian Data Protection Authority, datatilsynet.no), or, if you're in the EU/EEA, your own country's data protection authority.
GDPR — how it applies to Proquri specifically
Nastrond Harridsleff is established in Oslo, Norway — an EEA state where GDPR applies as national law via the EEA Agreement. That means GDPR is our own primary data protection law from day one, for every user, not a rule that only attaches because a customer happens to be based in the EU.
A few specific points worth being explicit about:
- Controller vs. processor: For your own account data, we're the data controller. For the personal data of third parties that appears inside contracts you upload — like a vendor sales rep's name — we also act as a controller for our own processing purposes (extraction, and anonymized/pseudonymized benchmarking), separately from your own relationship with your vendor.
- Legal basis: see the table above for each processing activity.
- International transfers: see the section above — Standard Contractual Clauses as the primary safeguard for every transfer outside the EEA.
- Your rights: see the section above — the same rights apply regardless of where you or we are located, since GDPR is our own law, not a foreign standard we extend as a courtesy.
Children's privacy
Proquri is a business tool built for procurement and IT professionals. It isn't directed at, and we don't knowingly collect data from, anyone under 16.
Security
We use encryption in transit and at rest, isolate each customer's data from every other customer's, and run the PII-redaction pass described above before any data is pooled across customers. No system is perfectly secure, and we'll tell you if that ever matters to your data specifically.
Changes to this notice
We'll update the effective date above whenever we make a material change, and for significant changes, we'll make a reasonable effort to let active customers know directly.
Contact us
privacy@proquri.com — Nastrond Harridsleff, made in Oslo, Norway.