1. Who this covers
This Privacy Policy explains how Recovra (“we”) handles personal data when you visit our websites, create an account, or use the Recovra platform (the “Service”). For data inside a customer’s workspace (invoices, contracts, shipment records) we act as a processor on the customer’s instructions; for account, billing and website data we act as a controller.
2. Data we collect
- Account data: name, work email, hashed password or sign-in tokens, organization membership and role.
- Customer Data you upload: invoices, rate sheets, contracts and operational files. These are commercial records and may incidentally contain names, addresses or contact details of vendor or shipping personnel.
- Activity and audit logs: who uploaded, verified, approved, submitted or closed each item, with timestamps. These logs exist so financial decisions are traceable and cannot be disabled by users.
- Technical data: IP address, browser and device information, and diagnostic logs needed to run and secure the Service.
We do not sell personal data and do not use Customer Data to train machine-learning models.
3. How we use it
- To provide the Service: store documents, compute findings, run approval workflows and display dashboards to authorised members of your organization.
- To secure the Service: authentication, tenant isolation, abuse and fraud prevention, incident investigation.
- To operate our business: billing, support, service notices and legally required record-keeping.
- With your consent or where permitted: product updates and marketing, which you can opt out of at any time.
4. Document transcription by AI models
When a customer enables PDF transcription, the PDF is sent to the configured model provider (Anthropic or OpenAI, under our API agreement with them) solely to convert the printed content into structured rows. The provider name, model and read confidence are stored with the document, and findings derived from transcribed rows are marked for human verification. API-based providers process the content to return the result and, under their API terms, do not use it to train their models. Spreadsheet uploads are parsed entirely within our infrastructure and never leave it.
6. Security
Data is encrypted in transit (TLS) and at rest. Files live in a private bucket with per-organization folder policies; database access is governed by row-level security and role checks; only owners and admins can delete records. Secret keys are never shipped to browsers. Every automated decision and every human workflow step is written to an audit log. Our database provider takes daily backups, and restores are tested as part of our operations runbook. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
7. Retention
Customer Data is retained while your organization uses the Service and deleted from production within 60 days of account closure or a verified deletion request, subject to backup rotation (up to 30 additional days) and legal obligations. Audit logs relating to financial approvals may be retained for up to 7 years where required for accounting or tax purposes, in which case they are restricted to that purpose.
8. International transfers
Our infrastructure is located in the United States. If you access the Service from other regions, your data is transferred to and processed there. Where required we rely on standard contractual clauses or an equivalent lawful mechanism and will enter into a data processing agreement on request.
9. Your rights
Depending on where you live you may have rights to access, correct, delete, restrict or port your personal data, or to object to certain processing. Workspace members can update their own profile and password in Settings; organization admins can remove members and delete documents. For anything else, or if you are a vendor employee whose details appear in a customer’s invoice, contact us and we will respond within 30 days or refer the request to the relevant customer where we act as processor.
11. Contact and changes
Privacy questions and requests: alaidaroosawad@gmail.com. We may update this policy; material changes are announced inside the Service or by email, and the date at the top reflects the latest revision. See also our Terms of Service.