← Back to BuyerPro

Privacy Policy

1. Who we are

BuyerPro is a service operated by [COMPANY LEGAL NAME], a company registered in [JURISDICTION] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].

For questions about this policy or about your data, write to [email protected].

This policy is written to meet the UK GDPR and the EU GDPR. Where we say "personal data" we mean information that identifies a living individual, directly or indirectly.

2. Controller or processor

Which role we play depends on the data, and it changes what you should do if you want something removed.

DataOur roleWhat that means
Your account, billing and the emails we send you Controller We decide how this is used. Contact us directly.
Supplier email threads a customer BCCs to us Processor Our customer decides what goes in and why. We act on their instructions under a Data Processing Agreement.
Website visits and trial signups Controller We decide how this is used. Contact us directly.

If you are a supplier contact and you want your data removed from a thread, you can come to us and we will act — but we will normally need to tell our customer, because it is their record. Section 4 explains this.

3. What we collect

If you are a BuyerPro customer

  • Your email address and company email domain. We identify accounts by domain, so we know which threads belong to which customer.
  • Your supplier conversations. When you BCC [email protected], we receive the whole message: sender, recipients, subject, body, headers, and any attachments.
  • What we derive from those conversations. Commitments, dates, a risk level of green, yellow or red, and the coaching we draft for you.
  • Billing details. Handled by Stripe. We store the Stripe customer and subscription identifiers and your subscription status. We never see or store your card number.
  • Service records. An audit log of actions taken on your account, and operational metrics. These hold identifiers and timestamps, not message content.

If you asked for a sample coaching email

  • Your email address, so we can send it.
  • Your IP address, used only to stop the form being abused for spam. We erase it after 30 days.

If you just visit the website

Nothing. We run no analytics, no advertising pixels, and no third-party trackers, and the site sets no cookies. Our host, Cloudflare, keeps short-lived request logs for security and abuse prevention.

4. If you are a supplier contact

You may be reading this because you emailed one of our customers and noticed [email protected] in the thread, or because a BuyerPro coaching email quoted you. We want to be straightforward about it.

What happened. Our customer — the buyer you were corresponding with — copied your conversation to BuyerPro so our system could help them keep track of it. We did not obtain your details from you directly. Under Article 14 of the GDPR we have to tell you what we then do with them.

What we hold about you. Your name and email address as they appear in the correspondence, the content of messages you sent in that thread, any attachments, and the commitments and dates our system extracted from what you wrote.

Why we are allowed to. Our customer relies on their legitimate interests in keeping an accurate record of their supply chain commitments and managing delivery risk — the same interest that lets any business keep its correspondence. Our own legitimate interest is in providing the service they asked for. We have weighed this against your interests: the data is ordinary business correspondence you chose to send to that company, we do not use it to build a profile of you, we do not sell it, we do not enrich it from other sources, and we do not use it to market to you.

What you can do. You can ask us for a copy of what we hold, ask us to correct it, object to the processing, or ask us to delete it — see section 11. If you ask us to delete it, we will remove the messages you sent from our systems. We will normally need to notify the customer whose record it is, because they may have their own legal reason to keep a copy, and any copy in their own email system is theirs, not ours.

One honest limitation. Message bodies are encrypted individually, which is good for security but means we cannot search across them in bulk. If someone else in the thread mentioned you by name inside their own message, we cannot find that automatically. When you make a deletion request we review the affected threads by hand, and we will tell you what we found and what we removed.

5. Why we process it

PurposeLawful basis
Running your account and delivering coachingPerformance of a contract
Processing supplier correspondence to produce that coachingLegitimate interests — delivering a service our customer has asked for, and their interest in managing supply chain risk
Sending the sample coaching email you requestedConsent — withdraw it any time using the unsubscribe link
Service notices, trial reminders and billing emailsPerformance of a contract
Security, abuse prevention and rate limitingLegitimate interests — keeping the service available and safe
Keeping accounting and tax recordsLegal obligation

Where we rely on legitimate interests, you can object. Tell us and we will stop unless we have compelling grounds not to, which we would explain to you.

6. How AI is used

BuyerPro uses a large language model from Anthropic to read supplier threads and draft coaching. This means the content of the emails you BCC to us is sent to Anthropic's API to be processed.

  • Anthropic acts as our sub-processor under contract. Your content is not used to train AI models.
  • We do not send your data to any other AI provider.
  • We do not use your content to train any model of our own.

No automated decisions about you. The green, yellow and red risk levels are advice for a human buyer to read and act on. Nothing BuyerPro produces makes an automatic decision that has a legal or similarly significant effect on anyone, so the Article 22 restrictions on automated decision-making do not apply. A person always decides what to do next.

7. Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers, each under contract and each with access only to what they need:

ProviderWhat they doWhat they can see
AnthropicThe AI that reads threads and drafts coachingEmail content sent for analysis
DigitalOceanApplication hosting and the databaseEncrypted content, email addresses, account records
CloudflareWebsite hosting, email routing, DNS and securityInbound messages in transit, website request logs
PostmarkSending our outbound emailRecipient address and the message we send
StripeSubscription billingBilling contact and payment details, which they hold, not us
TelegramOperational alerts to our teamSignup notifications and error alerts

The current list, with locations and links to each provider's terms, is kept at buyerpro.ai/subprocessors. Customers can subscribe there to be told before we add a new one.

We may also disclose data if the law requires it, to enforce our terms, or to a buyer if the business is sold — in which case this policy continues to apply until you are told otherwise.

8. International transfers

Our systems run in the United States, and all of the providers above are US-based or process data in the US. If you are in the UK or the EEA, your data is transferred outside your home region.

We rely on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, in each case with the additional safeguards described in section 10 — most importantly that message content is encrypted with keys we control.

9. How long we keep it

We delete personal data once it has served its purpose. These periods are enforced by a job that runs every night and performs a permanent deletion — not an archive, and not a hidden flag.

WhatKept forCounted from
Email bodies, attachments, extracted commitments, coaching drafts24 monthsThe last message in that thread
Sample-request email addresses12 monthsThe request
IP addresses from the signup form30 daysThe request
Account audit log12 monthsThe event
Operational metrics12 monthsThe event
Shared summary and dashboard linksUntil they expireDeleted once no longer usable
Account and billing recordsDeleted within 30 days of your account closing, except records we must keep for taxAccount closure
Accounting records required by law6 yearsEnd of the financial year

If you close your account, ask us and we will delete everything sooner.

10. How we protect it

  • Every message body, attachment and extracted signal is encrypted before it is stored, using AES-256-GCM.
  • Each conversation has its own encryption key, derived from a master key that is held in the application environment and never written to the database. Compromising one thread's key does not expose any other.
  • If encryption fails, we discard the data. The system is built never to fall back to storing anything in plain text.
  • Inbound mail is cryptographically signed in transit between our mail router and our application, so forged messages are rejected.
  • Links we email you expire, and administrative access requires a separate secret that is never placed in a URL.
  • We defend against prompt injection — attempts to hide instructions inside an email to manipulate the AI — and we treat all incoming message content as untrusted.
  • All traffic is encrypted in transit with TLS, and the site is served with a strict Content Security Policy and HSTS.

No system is perfectly secure. If we suffer a breach that is likely to put your rights at risk, we will tell the relevant regulator within 72 hours of becoming aware of it, and tell you without undue delay where the risk to you is high.

11. Your rights

Wherever you are, we will honour these. Under the UK and EU GDPR you have the right to:

RightWhat it means
AccessGet a copy of the personal data we hold about you
RectificationHave inaccurate data corrected
ErasureHave your data deleted
RestrictionHave us pause processing while a dispute is resolved
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests, and to any direct marketing
Withdraw consentWithdraw consent at any time, where consent is the basis

How to exercise them. Email [email protected]. We will acknowledge within 5 working days and respond within one month. If your request is complex we may extend by a further two months, and we will tell you why within the first month. We do not charge for this.

We will ask you to confirm your identity before we act, so that nobody can use these rights to obtain someone else's data. Proving control of the email address in question is normally enough.

If the data sits inside a customer's account, we will pass your request to that customer and support them in answering it, as our agreement with them requires.

12. Cookies and tracking

This website sets no cookies. There is no analytics, no advertising network, no session tracking and no fingerprinting, which is why you have never seen a cookie banner here.

The coaching emails we send contain no tracking pixels — we do not record whether you opened them.

If we ever introduce anything that requires consent, we will ask first.

13. Children

BuyerPro is a business tool and is not directed at anyone under 16. We do not knowingly collect children's data. If you believe we have, tell us and we will delete it.

14. Changes

If we make a material change we will update the date at the top, and — if you are a customer — email you before it takes effect. Past versions are available on request.

15. Contact and complaints

Privacy questions and rights requests: [email protected]
Everything else: [email protected]
Post: [COMPANY LEGAL NAME], [REGISTERED ADDRESS]

We would rather hear a complaint directly so we can put it right. You also have the right to complain to a data protection regulator — in the UK, the Information Commissioner's Office at ico.org.uk; in the EEA, your national supervisory authority.