01
Who We Are
SIGNALSTACKS TECHNOLOGIES PRIVATE LTD owns and operates ProcureOS, the purchasing platform that the agent Nish runs inside. References to ProcureOS, we, us, or our mean SIGNALSTACKS TECHNOLOGIES PRIVATE LTD operating ProcureOS and related services.
Under India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data we process to run ProcureOS — the role other laws call the "controller". Our sub-processors are Data Processors acting on our documented instructions.
Where your organization uploads personal data about its own staff or its suppliers, your organization decides why that data is there; we process it to deliver the service. A Data Processing Agreement is available on request at privacy@trynishai.com.
02
Information We Collect
We collect account information such as your name, email address, authentication provider details, organization or role information, subscription status, support messages, and consent and audit records.
We collect content you provide or generate in the service, including uploaded documents, requisitions, RFQs, vendor and item records, vendor quotes, comparison decks, cost sheets, purchase orders, playbook rules, notes, comments, feedback, prompts, exported content, and analysis results.
We collect technical and usage information such as IP address, user agent, device and browser details, pages visited, actions taken, timestamps, security logs, anti-abuse signals, cookies, and diagnostics.
We process supplier communications you route through the service, price and index reference data, and third-party source material to provide procurement features. Supplier contact details you upload are personal data about people who are not our users — see Outbound Communications in the Terms of Service for who is responsible for contacting them.
03
How We Use Information
We use information to provide, maintain, secure, and personalize ProcureOS; authenticate users; run AI analysis; generate quote comparisons and cost estimates; process uploads; stage and send procurement emails you approve; provide customer support; prevent abuse; manage subscriptions; and comply with legal obligations.
We use legal acceptance records to document that the current Terms of Service and Privacy Policy were presented when you created or accessed an account.
We do not sell your personal data. We do not use your uploaded private documents to train our own general-purpose AI models. We do not run behavioural or targeted advertising.
04
Product Improvement and Enterprise Customer Content
For users who are not Enterprise customers, we may use account data, usage data, uploaded content, prompts, outputs, feedback, and derived analysis to maintain, debug, evaluate, improve, and develop ProcureOS, including product quality, retrieval, ranking, prompts, safety, reliability, and feature development.
Enterprise usage means use under an ENTERPRISE plan, an Enterprise organization or account, or a written enterprise agreement. Enterprise Customer Content means uploaded documents, prompts, notes, requisitions, RFQs, quotes, comparison decks, cost sheets, purchase orders, playbook rules, comments, and other customer-provided materials.
We do not use Enterprise Customer Content for platform improvement, model training, feature development, benchmarking, or analytics beyond providing and supporting that Enterprise customer's service, unless the Enterprise customer expressly permits it in writing.
We may still process Enterprise Customer Content and operational telemetry as needed for service delivery, security, reliability, debugging, support, billing, legal compliance, abuse prevention, and customer-requested troubleshooting.
05
Sub-processors and AI Providers
To run the service we share the minimum necessary data with the providers below. Each is bound by its own terms to process data only for the purposes we instruct.
| Provider | What it does for us | Where it processes |
|---|---|---|
| Vercel | Hosts and serves the application; collects page performance metrics. | United States, plus its global edge network |
| Supabase (managed PostgreSQL and file storage) | Stores accounts, organizations, requisitions, RFQs, quotes, comparisons, purchase orders and uploaded documents. | India (AWS ap-south-1, Mumbai) |
| OpenRouter | Routes prompts, document excerpts and record extracts to the AI models that draft RFQs, comparisons, cost estimates and emails for Nish. | United States |
| Cloudflare (Workers AI, Vectorize) | Generates embeddings and runs vector search so the agent can retrieve the right document passages. | Global edge network |
| Tavily and Serper | Web search for supplier discovery and price or index reference material. We send the search query, not your documents. | United States |
| Resend | Delivers transactional email and the supplier emails your team approves and sends. | United States and European Union |
| Trigger.dev | Runs background jobs: document processing, RFQ dispatch, deadline clocks and reminders. | United States |
| Upstash (serverless Redis) | Rate limiting, sign-in throttling and short-lived caches. No procurement documents are stored here. | Regional serverless Redis in the region we configure |
| Microsoft Clarity | Aggregate analytics, heatmaps and session replay on the public marketing pages, including this one. | United States |
| Google (via Auth.js) | Optional Google sign-in. We receive your name, email address and Google profile identifier. | United States |
| Langfuse | Traces AI calls so we can debug bad output and measure quality. Enabled only where configured. | United States |
The locations shown are the regions we have configured today. Providers operate global infrastructure and may fail over or replicate within it. We will update this table when a provider or a region changes.
AI providers and infrastructure providers have their own security, retention, and abuse-monitoring practices. Where a provider offers the setting, we configure it to exclude customer-uploaded documents from model training.
We will publish a change to this list on this page before a new sub-processor starts processing customer content. Enterprise customers under a written agreement receive advance notice by email.
06
Where Your Data Is Processed
Your account records, procurement data, and uploaded documents are stored in India, in the Mumbai region. Processing outside India happens where a sub-processor in the table above operates from another country — principally the United States and the European Union, for AI inference, email delivery, background jobs, and analytics.
Those transfers are made on the basis of the contractual terms in each provider's data processing agreement, and are permitted under section 16 of the DPDP Act, which allows transfers except to countries the Central Government restricts by notification. If a country we use is restricted, we will move that processing.
07
Cookies and Local Storage
We use a small number of cookies and one local-storage key. Here is all of them.
| Name | Kind | Why it exists | How long it lasts |
|---|---|---|---|
| authjs.session-token (__Secure- prefixed over HTTPS) | Cookie | Keeps you signed in. Strictly necessary — the app cannot work without it. | Rolling session, renewed daily while you stay active; cleared on sign-out |
| x-role, x-org-id | Cookie | Your role and organization, so a page can render the right workspace without a database round-trip. Strictly necessary. | Same as the session; cleared on sign-out |
| theme-mode | Local storage | Remembers whether you chose the light or dark appearance inside the app. | Until you clear your browser storage |
| _clck, _clsk (Microsoft Clarity) | Cookie | Analytics and session replay on public marketing pages. Not strictly necessary. | Up to 1 year (_clck) and 1 day (_clsk) |
Microsoft Clarity runs on the public marketing pages only, including this one, and records interactions such as mouse movement, clicks, scrolling, and page content to produce heatmaps and session replays. It is not loaded inside the signed-in application, so your procurement records are never in a replay. You can block it with your browser's cookie controls or a tracker blocker without affecting anything else on this site.
The session, role, and organization cookies are strictly necessary. Blocking them signs you out.
08
Retention
We keep personal data only as long as the purpose it was collected for is being served, then delete or de-identify it. Concretely:
| What | How long we keep it |
|---|---|
| Account and organization records | For as long as the account is open, then deleted or de-identified within 90 days of closure |
| Procurement records — requisitions, RFQs, vendor quotes, comparison decks, cost sheets, purchase orders and uploaded documents | For the term of your subscription and 12 months afterwards, unless you ask us to delete sooner or law requires longer |
| Staged and sent supplier emails, and their delivery status | 24 months |
| Security, access and audit logs | 12 months |
| Encrypted backups | A rolling 35 days, then overwritten |
| Legal acceptance records (which policy version you accepted, and when) | Retained after account closure, because their only purpose is to evidence the agreement |
Deletion propagates to backups as the rolling backup window turns over. We may keep specific records beyond these periods where we need them to comply with law, resolve a dispute, prevent fraud, or establish or defend a legal claim — and only for as long as that need lasts.
On account closure, ask us at privacy@trynishai.com and we will export your organization's procurement records before deletion. See the Terms of Service for the export window.
09
Your Rights and Choices
As a Data Principal under the DPDP Act you may ask us to:
- confirm what personal data of yours we are processing, and give you access to it
- correct data that is inaccurate, and complete data that is incomplete
- erase personal data where the purpose it was collected for is served
- withdraw a consent you gave us, as easily as you gave it
- nominate another person to exercise these rights on your behalf if you die or become incapacitated
Write to privacy@trynishai.com and we will respond within 30 days. We may need to verify your identity before acting, and we will tell you if we cannot act on a request and why.
Withdrawing consent or deleting data may limit or prevent use of ProcureOS where the relevant data is required for authentication, security, billing, legal compliance, or service delivery.
If you are an employee of a customer organization, some requests are for your employer to decide — for example, deleting a purchase order that is part of their records. We will route the request to them and tell you we have.
10
Grievance Officer
Section 13(3) of the DPDP Act gives you the right to an accessible grievance channel. Ours is a monitored desk rather than a personal mailbox, so a grievance does not sit unread when one person is away.
Grievance and data protection
privacy@trynishai.comThe desk handles access, correction, completion, erasure, consent withdrawal, nomination, and any complaint about how we have handled your personal data.
We acknowledge every grievance and respond substantively within 30 days of receiving it. Tell us what happened, what you would like us to do, and the email address associated with your account.
If you are not satisfied with our response, or we do not respond in time, you may complain to the Data Protection Board of India under section 13(4) of the Act.
11
Security and Breach Notification
We use reasonable technical and organizational safeguards designed to protect personal data, including encrypted transport, encryption at rest, role-scoped access controls, per-organization data isolation, audit logs, and monitoring. Passwords are stored only as a salted hash. No system can be guaranteed completely secure.
If we become aware of a personal data breach, we will notify the Data Protection Board of India and the affected Data Principals without undue delay, and in any event within 72 hours of becoming aware, with what happened, what data was involved, and what we are doing about it.
12
Children
ProcureOS is a workplace tool and is not intended for anyone under 18, which is the age the DPDP Act uses to define a child. We do not knowingly collect personal data from a child, and we do not track, behaviourally monitor, or run targeted advertising to children.
If you believe a child has an account, write to us and we will delete it.
13
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice before they take effect, and the date at the top of this page always reflects the current version. Continued use after an update means you accept the updated policy.
14
Contact
Three desks, so a statutory request never lands in a sales inbox.
Privacy, data protection, grievances
privacy@trynishai.comLegal notices and agreements
legal@trynishai.comProduct support
support@trynishai.com