Proquri Insight is in Demo Mode – Use With Care

Proquri
Back to home

Privacy Notice

Effective September 14, 2026

Who we are

Proquri is operated by Nastrond Harridsleff (org. nr. 936 340 369), made in Oslo, Norway. For anything in this notice, or to exercise any of the rights below, contact us at privacy@proquri.com.

The short version

Proquri helps you track, understand, and negotiate your company's SaaS contracts. To do that, we process the account details you give us, the contract documents you upload, and how you use the app — including sending contract text to a small number of AI providers to extract and analyze it. We never sell personal data. This notice explains what we collect, why, who we share it with, and the rights you have over it — including a dedicated section on GDPR, since it applies to us directly as a Norwegian (EEA) company, not only because some of our customers are in the EU.

What we collect

  • Account data: your name, work email, company name, and password (stored hashed, never in plain text) when you sign up.
  • Contract documents and their extracted content: the PDFs you upload, and every field our AI extracts from them — pricing, terms, renewal dates, and so on. This commonly includes personal data about people who aren't you or your organization — most notably the name of your vendor's sales representative, and sometimes signatory names or contact details appearing in the contract text itself.
  • Negotiation and usage records: notes and updates you log against a contract, messages you send to the AI Deal Copilot chat, and corrections you make to extracted fields.
  • Billing data: handled directly by Stripe when you subscribe to a paid tier — we never see or store your card number.
  • Technical data: standard connection logs (IP address, timestamps) our infrastructure generates automatically.
  • Cookies and similar technologies: see our Cookie Policy for the full detail — in short, a strictly-necessary login session and, once enabled, Google Analytics with your prior consent.

Why we process it, and on what legal basis

What we doWhyLegal basis
Run your account, extract and display your contractsDeliver the service you signed up forPerformance of a contract with you
Send contract text to Anthropic, LlamaParse, and Voyage AI for extraction, analysis, and the AI chatDeliver the core productPerformance of a contract with you
Pool anonymized/pseudonymized pricing data across customers for benchmarkingGive you peer pricing context — the product's core valueLegitimate interest, balanced against the anonymization safeguards described above
Process payments through StripeBill you for a paid tierPerformance of a contract with you; legal obligation (accounting/tax records)
Run Google AnalyticsUnderstand product usageYour consent, given through the cookie banner
Keep connection logs, detect abuseKeep the service secure and reliableLegitimate interest
Respond to legal requestsComply with the lawLegal obligation

Who we share it with

We share personal data only with the service providers that help us run Proquri, and only to the extent each one needs to do its job. See the table below for the full list, what each one does, where it processes data, and its data protection safeguards. We never sell personal data, and we never share contract documents with any other customer — the anonymized/pseudonymized benchmarking pool described above is the one place data crosses between customers, and it's built specifically so it can't be traced back to you or your contract.

SubprocessorUsed forData processing locationDPA / transfer safeguard
AnthropicContract extraction, AI Deal Copilot chatUSDPA + Standard Contractual Clauses auto-incorporated into Anthropic's commercial API terms on account creation. Anthropic does not use commercial API prompts/outputs to train its models by default.
LlamaIndex (LlamaParse / LlamaCloud)OCR / document parsingEU (configured on the EU region endpoint)DPA available (executed via DocuSign); does not use customer content to train models by default.
Voyage AIText embeddings for RAG chat and searchUSData processing terms under Voyage AI's commercial API agreement; submitted content is not used to train or improve Voyage AI's models (opted out).
Trigger.devBackground job orchestrationUS (AWS us-east-1)DPA incorporated into Trigger.dev's Terms of Service; Standard Contractual Clauses used for transfers outside the UK/EEA.
StripePayment processing, billingUS / EU (Stripe Payments Europe, Ltd. for non-Americas accounts)DPA incorporated into Stripe's terms; supports the EU-US Data Privacy Framework, UK IDTA, and Standard Contractual Clauses.
Google (Analytics)Product usage analytics (once live)USGoogle's standard data processing terms for Analytics apply; Analytics only runs with your prior consent (see our Cookie Policy).
HostingerVPS hosting (all self-hosted infrastructure runs here)EUDPA incorporating EU Standard Contractual Clauses (Module Two, controller-to-processor).
CloudflareDNS, and traffic routing/security once proxying is enabledGlobal networkDPA incorporating Standard Contractual Clauses.

International data transfers

Several of our service providers process data in the United States. Every transfer outside the EU/EEA relies on Standard Contractual Clauses as its primary safeguard — we don't rely on the EU-US Data Privacy Framework alone, given its currently uncertain status under active legal challenge. See the subprocessor table above for the safeguard used for each provider.

How long we keep data

We keep your account and contract data for as long as your account is active, plus a reasonable period afterward for backups and legal/accounting requirements. If you delete your account, we delete your account and contract data within 30 days of your request; residual copies in encrypted backups are purged on a rolling cycle within 90 days. We keep billing records for as long as we're required to by law. Anonymized benchmark data that no longer references you or your contract, described above, is retained indefinitely as aggregate market data, since it's no longer personal data about you specifically — with the one exception of the pseudonymized rep-name field noted above, which we'll address on request to the extent technically possible.

Your rights

Under GDPR, and wherever else applicable law gives you these rights, you can ask us to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Withdraw consent at any time, for anything we process based on consent (like analytics cookies), without affecting processing before that point

To exercise any of these, email privacy@proquri.com. You also always have the right to lodge a complaint with a supervisory authority — ours is Datatilsynet (the Norwegian Data Protection Authority, datatilsynet.no), or, if you're in the EU/EEA, your own country's data protection authority.

GDPR — how it applies to Proquri specifically

Nastrond Harridsleff is established in Oslo, Norway — an EEA state where GDPR applies as national law via the EEA Agreement. That means GDPR is our own primary data protection law from day one, for every user, not a rule that only attaches because a customer happens to be based in the EU.

A few specific points worth being explicit about:

  • Controller vs. processor: For your own account data, we're the data controller. For the personal data of third parties that appears inside contracts you upload — like a vendor sales rep's name — we also act as a controller for our own processing purposes (extraction, and anonymized/pseudonymized benchmarking), separately from your own relationship with your vendor.
  • Legal basis: see the table above for each processing activity.
  • International transfers: see the section above — Standard Contractual Clauses as the primary safeguard for every transfer outside the EEA.
  • Your rights: see the section above — the same rights apply regardless of where you or we are located, since GDPR is our own law, not a foreign standard we extend as a courtesy.

Children's privacy

Proquri is a business tool built for procurement and IT professionals. It isn't directed at, and we don't knowingly collect data from, anyone under 16.

Security

We use encryption in transit and at rest, isolate each customer's data from every other customer's, and run the PII-redaction pass described above before any data is pooled across customers. No system is perfectly secure, and we'll tell you if that ever matters to your data specifically.

Changes to this notice

We'll update the effective date above whenever we make a material change, and for significant changes, we'll make a reasonable effort to let active customers know directly.

Contact us

privacy@proquri.com — Nastrond Harridsleff, made in Oslo, Norway.