Snapshot 58333
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Approveit Solutions Resources Use Cases Integrations Pricing How It Works Log In Request a Demo Home Privacy Policy Approveit Privacy Policy Approveit Privacy Policy Approveit Privacy Policy Last updated: September 21, 2026 Introduction Introduction Introduction Approveit, Inc. is committed to protecting your privacy and ensuring you have a positive experience when using the services we provide, which we generally refer to as Approveit or the Approveit Service. Approveit, Inc. is committed to protecting your privacy and ensuring you have a positive experience when using the services we provide, which we generally refer to as Approveit or Approveit services. Scope of this Privacy Policy Scope of this Privacy Policy This Privacy Policy explains how we handle data: what we collect, how we obtain it, how we use it, when and if we disclose it, and your options for managing it. It covers: This Privacy Policy explains how we handle data: what we collect, how we obtain it, how we use it, when and if we disclose it, and your options for managing it. It covers: • The Approveit Service, including the Approveit AI Assistant and the Approveit MCP server • Our website approveit.today • Our sales, support and marketing activities • The Approveit Service, including the Approveit AI Assistant and the Approveit MCP server • Our website approveit.today • Our sales, support and marketing activities • The Approveit Service, including the Approveit AI Assistant and the Approveit MCP server • Our website approveit.today • Our sales, support and marketing activities Who are we and how to contact us? Who are we and how to contact us? Who are we and how to contact us? Personal data described in this policy is processed by Approveit, Inc., a company incorporated in the State of Delaware with its principal place of business at 455 Valencia Street, San Francisco, CA 94103, USA. The words “we”, “our” and “us” refer to Approveit, Inc. Contact: support@approveit.today, or Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA. Data protection contact: Serge Gusev, Chief Executive Officer, serge@approveit.today. Personal data described in this policy is processed by Approveit, Inc., a company incorporated in the State of Delaware with its principal place of business at 455 Valencia Street, San Francisco, CA 94103, USA. The words “we”, “our” and “us” refer to Approveit, Inc. Contact: support@approveit.today, or Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA. Data protection contact: Serge Gusev, Chief Executive Officer, serge@approveit.today. Personal data described in this policy is processed by Approveit, Inc., a company incorporated in the State of Delaware with its principal place of business at 455 Valencia Street, San Francisco, CA 94103, USA. The words “we”, “our” and “us” refer to Approveit, Inc. Contact: support@approveit.today, or Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA. Data protection contact: Serge Gusev, Chief Executive Officer, serge@approveit.today. Our two roles: processor and controller Our two roles: processor and controller Our two roles: processor and controller Most of the data inside the Approveit Service belongs to our customers. For that data we are a processor: our customers are the controllers, they decide what is processed and why, and we act on their instructions. If you are an employee or contractor of one of our customers and you want to exercise a right over your approval data, contact your employer first. We will refer such requests to them and assist them in responding. For a smaller set of data we are the controller: our website visitors, prospects, billing contacts, marketing contacts and the people we speak to on sales and support calls. Our processing as a processor is governed by our Data Processing Addendum, which takes effect automatically when a customer accepts our Terms of Service. No signature is required. If your organization needs a countersigned copy for its records, email support@approveit.today. Most of the data inside the Approveit Service belongs to our customers. For that data we are a processor: our customers are the controllers, they decide what is processed and why, and we act on their instructions. If you are an employee or contractor of one of our customers and you want to exercise a right over your approval data, contact your employer first. We will refer such requests to them and assist them in responding. For a smaller set of data we are the controller: our website visitors, prospects, billing contacts, marketing contacts and the people we speak to on sales and support calls. Our processing as a processor is governed by our Data Processing Addendum, which takes effect automatically when a customer accepts our Terms of Service. No signature is required. If your organization needs a countersigned copy for its records, email support@approveit.today. Most of the data inside the Approveit Service belongs to our customers. For that data we are a processor: our customers are the controllers, they decide what is processed and why, and we act on their instructions. If you are an employee or contractor of one of our customers and you want to exercise a right over your approval data, contact your employer first. We will refer such requests to them and assist them in responding. For a smaller set of data we are the controller: our website visitors, prospects, billing contacts, marketing contacts and the people we speak to on sales and support calls. Our processing as a processor is governed by our Data Processing Addendum, which takes effect automatically when a customer accepts our Terms of Service. No signature is required. If your organization needs a countersigned copy for its records, email support@approveit.today. What we process as a processor, on our customers’ behalf What we process as a processor, on our customers’ behalf Personal data processed in the Approveit Service on our customers’ instructions may include: name, display name and username; email address and company; workplace information such as team or department; identifiers from integrated platforms such as a Slack or Microsoft Teams user ID; the content of approval requests, attachments, comments and workflow messages; the content of instructions submitted to AI features; timestamps such as creation and approval time; and usage logs, audit trails, session recordings and technical metadata needed for the Service to function and stay secure. Our Data Processing Addendum sets out the full description of this processing. Personal data processed in the Approveit Service on our customers’ instructions may include: name, display name and username; email address and company; workplace information such as team or department; identifiers from integrated platforms such as a Slack or Microsoft Teams user ID; the content of approval requests, attachments, comments and workflow messages; the content of instructions submitted to AI features; timestamps such as creation and approval time; and usage logs, audit trails, session recordings and technical metadata needed for the Service to function and stay secure. Our Data Processing Addendum sets out the full description of this processing. Where we rely on legitimate interests, you may object at any time by contacting support@approveit.today. Providing the personal data needed to create and administer an account is a requirement of our contract with the customer. Without it we cannot provide the Approveit Service. Providing marketing contact details is optional. Processing Processing Processing Purpose Purpose Purpose Legal basis (GDPR) Legal basis (GDPR) Legal basis (GDPR) Account creation and administration Account creation and administration Account creation and administration Providing the Service under our Terms Providing the Service under our Terms Art. 6(1)(b) contract, or Art. 6(1)(f) legitimate interests where the individual is not the contracting party Art. 6(1)(b) contract, or Art. 6(1)(f) legitimate interests where the individual is not the contracting party Billing, invoicing and tax records Billing, invoicing and tax records Billing, invoicing and tax records Taking payment and meeting accounting obligations Taking payment and meeting accounting obligations Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation Error monitoring and security logging for our own systems Error monitoring and security logging for our own systems Error monitoring and security logging for our own systems Debugging and securing the Service Debugging and securing the Service Art. 6(1)(f) legitimate interests; balancing assessment available on request Art. 6(1)(f) legitimate interests; balancing assessment available on request Sales and support calls, including recording and transcription where notified Sales and support calls, including recording and transcription where notified Sales and support calls, including recording and transcription where notified Selling and supporting the Service Selling and supporting the Service Art. 6(1)(f) legitimate interests; consent where required by local law Art. 6(1)(f) legitimate interests; consent where required by local law Marketing emails to business contacts Marketing emails to business contacts Marketing emails to business contacts Promoting the Service Promoting the Service Art. 6(1)(f) legitimate interests, or Art. 6(1)(a) consent where required Art. 6(1)(f) legitimate interests, or Art. 6(1)(a) consent where required Non-essential cookies and similar technologies Non-essential cookies and similar technologies Non-essential cookies and similar technologies Website analytics and advertising measurement Website analytics and advertising measurement Art. 6(1)(a) consent Art. 6(1)(a) consent Security monitoring, fraud prevention and audit logging Security monitoring, fraud prevention and audit logging Security monitoring, fraud prevention and audit logging Protecting the Service and its users Protecting the Service and its users Art. 6(1)(f); Art. 6(1)(c) Art. 6(1)(f); Art. 6(1)(c) Responding to legal and regulatory requests Responding to legal and regulatory requests Responding to legal and regulatory requests Legal compliance Legal compliance Art. 6(1)(c) Art. 6(1)(c) Where we rely on legitimate interests, you may object at any time by contacting support@approveit.today. Providing the personal data needed to create and administer an account is a requirement of our contract with the customer. Without it we cannot provide the Approveit Service. Providing marketing contact details is optional. Where we rely on legitimate interests, you may object at any time by contacting support@approveit.today. Providing the personal data needed to create and administer an account is a requirement of our contract with the customer. Without it we cannot provide the Approveit Service. Providing marketing contact details is optional. We do not use inferences to build profiles for advertising or to make decisions about individuals. Apart from account log-in credentials, which we use only to authenticate users and secure accounts, we do not intentionally collect sensitive personal information, and we do not use sensitive personal information to infer characteristics about anyone. For the preceding twelve months: Categories of personal information (California) Categories of personal information (California) Category Category Category Examples Examples Examples Sources Sources Sources Business purpose Business purpose Business purpose Disclosed to Disclosed to Disclosed to Sold Sold Sold Shared Shared Shared Identifiers Identifiers Name, email, workspace ID, Slack or Teams user ID, IP address, cookie identifiers Name, email, workspace ID, Slack or Teams user ID, IP address, cookie identifiers You; your employer; platforms you connect on your instruction; automatically from your device You; your employer; platforms you connect on your instruction; automatically from your device Providing and securing the Service; advertising measurement on our marketing website Providing and securing the Service; advertising measurement on our marketing website Hosting, support, analytics and AI sub-processors; advertising partners (marketing website only) Hosting, support, analytics and AI sub-processors; advertising partners (marketing website only) No No Yes, online identifiers through marketing website cookies only Yes, online identifiers through marketing website cookies only Yes, online identifiers through marketing website cookies only Commercial information Commercial information Subscription, billing and purchase history Subscription, billing and purchase history You; our payment processor You; our payment processor Billing, tax and accounting Billing, tax and accounting Payment processor, accounting Payment processor, accounting No No No No No Internet or network activity Internet or network activity Usage events, session recordings, error logs, cookie data Usage events, session recordings, error logs, cookie data Automatically from your device Automatically from your device Analytics, debugging, advertising measurement on our marketing website Analytics, debugging, advertising measurement on our marketing website Analytics and error monitoring vendors; advertising partners (marketing website only) Analytics and error monitoring vendors; advertising partners (marketing website only) No No Yes, marketing website cookies only Yes, marketing website cookies only Yes, marketing website cookies only Professional or employment information Professional or employment information Employer, team, role, approval authority Employer, team, role, approval authority Your employer Your employer Operating approval workflows Operating approval workflows Hosting and AI sub-processors Hosting and AI sub-processors No No No No No Audio and visual information Audio and visual information Sales and support call recordings and transcripts Sales and support call recordings and transcripts You, with notice at the start of the call You, with notice at the start of the call Sales and support Sales and support Transcription and conferencing vendors Transcription and conferencing vendors No No No No No Inferences Inferences None None - - - - - - No No No No No Sensitive personal information Sensitive personal information Account log-in credentials Account log-in credentials You You Authenticating you and securing your account Authenticating you and securing your account Hosting sub-processor Hosting sub-processor No No No No No We do not use inferences to build profiles for advertising or to make decisions about individuals. Apart from account log-in credentials, which we use only to authenticate users and secure accounts, we do not intentionally collect sensitive personal information, and we do not use sensitive personal information to infer characteristics about anyone. We do not use inferences to build profiles for advertising or to make decisions about individuals. Apart from account log-in credentials, which we use only to authenticate users and secure accounts, we do not intentionally collect sensitive personal information, and we do not use sensitive personal information to infer characteristics about anyone. Restricted data Restricted data The Approveit Service is not designed for special categories of personal data under Article 9 of the GDPR, protected health information, full payment card numbers, or government identification numbers. Unless we have agreed otherwise in writing, our customers are contractually responsible for not submitting them, under our Terms of Service and our Data Processing Addendum. Where such data is submitted contrary to that prohibition, we do not use or disclose it for any purpose that would give rise to a right to limit its use under the CPRA. The Approveit Service is not designed for special categories of personal data under Article 9 of the GDPR, protected health information, full payment card numbers, or government identification numbers. Unless we have agreed otherwise in writing, our customers are contractually responsible for not submitting them, under our Terms of Service and our Data Processing Addendum. Where such data is submitted contrary to that prohibition, we do not use or disclose it for any purpose that would give rise to a right to limit its use under the CPRA. Where we get data from Where we get data from We collect most personal data directly from you, from your employer where you use Approveit as part of your work, and from platforms you connect on your instruction. We also obtain business contact details for prospective customers from public sources, referral partners and business data providers. We collect most personal data directly from you, from your employer where you use Approveit as part of your work, and from platforms you connect on your instruction. We also obtain business contact details for prospective customers from public sources, referral partners and business data providers. Who we share data with Who we share data with We use third-party service providers to operate parts of the Approveit Service and to run our business. We share with each provider the data reasonably needed for the service it provides. Where a provider processes data on our customers’ behalf, it is engaged under a written contract that restricts its use of that data to performing the services for us, and prohibits it from retaining, using or disclosing it for any other purpose or combining it with personal information from other sources. Some providers we engage for our own business operations, such as our payment processor, act as independent controllers for limited purposes such as fraud prevention and regulatory compliance; their own privacy notices govern that processing. We maintain the current list of sub-processors that process customer data on our customers’ behalf, with each one’s purpose and processing location, in Exhibit 2A of our Data Processing Addendum. That list is the authoritative record. We give customers advance notice of new sub-processors, and customers may object on reasonable data protection grounds, as set out in that Addendum. Hosting, session replay, in-product analytics and error monitoring are performed by sub-processors listed in Exhibit 2A. We also use service providers for our own business operations, including payment processing, CRM and marketing, call recording and transcription, and website analytics; those are listed in Exhibit 2B of the same document. We use third-party service providers to operate parts of the Approveit Service and to run our business. We share with each provider the data reasonably needed for the service it provides. Where a provider processes data on our customers’ behalf, it is engaged under a written contract that restricts its use of that data to performing the services for us, and prohibits it from retaining, using or disclosing it for any other purpose or combining it with personal information from other sources. Some providers we engage for our own business operations, such as our payment processor, act as independent controllers for limited purposes such as fraud prevention and regulatory compliance; their own privacy notices govern that processing. We maintain the current list of sub-processors that process customer data on our customers’ behalf, with each one’s purpose and processing location, in Exhibit 2A of our Data Processing Addendum. That list is the authoritative record. We give customers advance notice of new sub-processors, and customers may object on reasonable data protection grounds, as set out in that Addendum. Hosting, session replay, in-product analytics and error monitoring are performed by sub-processors listed in Exhibit 2A. We also use service providers for our own business operations, including payment processing, CRM and marketing, call recording and transcription, and website analytics; those are listed in Exhibit 2B of the same document. AI features AI features AI features Approveit offers AI features, including the Approveit AI Assistant in Slack, Microsoft Teams and the web app, and an MCP server that lets you connect Approveit to an AI client of your choice. The AI Assistant works by sending data to a third-party AI model provider. The MCP server sends data only to the AI client you connect. Who processes the data. The Approveit AI Assistant is powered by Anthropic, PBC (United States), using Anthropic’s commercial API. We do not use consumer AI products for it. Our MCP server does not use Anthropic or any AI model of ours; it passes data to the AI client you choose to connect. Other vendors we use apply their own automated or machine-learning analysis to the data they receive in order to provide their services to us, including PostHog and ELU Labs (product analytics and session replay) and Sentry (error monitoring). Separately, Fathom Video applies automated analysis to our own sales and support call recordings, as described under Sales and support calls. Each is listed in Exhibit 2A or 2B of our Data Processing Addendum with its purpose. If we change or add an AI model provider, we will update Exhibit 2A of our Data Processing Addendum and notify customers at least 30 days before the new provider begins processing customer data. What is sent. When a user invokes the AI Assistant, we send the text of the user’s instruction and the approval requests, workflow configurations, comments and metadata relevant to that request that the user is already entitled to see in Approveit. Approveit’s access controls apply to the AI Assistant in the same way they apply to the rest of the product. What is not sent. We do not send data that the requesting user is not already entitled to see in Approveit, and we do not send data from workspaces where the AI Assistant is switched off. No model training. Approveit does not use customer content to train or fine-tune generative AI models. Where we need to investigate a fault you have reported, we access only the data necessary to do so, under the access controls described in our Data Processing Addendum. Our AI model provider is contractually prohibited from training its models on customer content transmitted through the Approveit Service. Retention. Our AI model provider retains inputs and outputs for a limited period under its own published policy, and details are available on request. Separately, Approveit stores AI conversations in your workspace so that you can review them, for the period stated in Data retention below. Human oversight. The Approveit AI Assistant drafts, summarises and answers questions; it does not approve or reject a request on its own. Where your administrator connects an AI client or a service account and gives it permission to act, actions it takes are executed under the Approveit account that authorized it and recorded in your audit trail. You decide whether to grant that permission. You are dealing with an AI system. Where you interact with the Approveit AI Assistant, you are interacting with an artificial intelligence system and not with a member of our staff. AI output can be incomplete or wrong and should be checked before you rely on it. Turning it off. A workspace administrator can have the AI Assistant switched off for the whole workspace at any time by contacting us at support@approveit.today. We will action the request promptly and confirm in writing, after which we stop transmitting that workspace’s data to our AI model provider. MCP connections are revoked separately, as described below. Approveit offers AI features, including the Approveit AI Assistant in Slack, Microsoft Teams and the web app, and an MCP server that lets you connect Approveit to an AI client of your choice. The AI Assistant works by sending data to a third-party AI model provider. The MCP server sends data only to the AI client you connect. Who processes the data. The Approveit AI Assistant is powered by Anthropic, PBC (United States), using Anthropic’s commercial API. We do not use consumer AI products for it. Our MCP server does not use Anthropic or any AI model of ours; it passes data to the AI client you choose to connect. Other vendors we use apply their own automated or machine-learning analysis to the data they receive in order to provide their services to us, including PostHog and ELU Labs (product analytics and session replay) and Sentry (error monitoring). Separately, Fathom Video applies automated analysis to our own sales and support call recordings, as described under Sales and support calls. Each is listed in Exhibit 2A or 2B of our Data Processing Addendum with its purpose. If we change or add an AI model provider, we will update Exhibit 2A of our Data Processing Addendum and notify customers at least 30 days before the new provider begins processing customer data. What is sent. When a user invokes the AI Assistant, we send the text of the user’s instruction and the approval requests, workflow configurations, comments and metadata relevant to that request that the user is already entitled to see in Approveit. Approveit’s access controls apply to the AI Assistant in the same way they apply to the rest of the product. What is not sent. We do not send data that the requesting user is not already entitled to see in Approveit, and we do not send data from workspaces where the AI Assistant is switched off. No model training. Approveit does not use customer content to train or fine-tune generative AI models. Where we need to investigate a fault you have reported, we access only the data necessary to do so, under the access controls described in our Data Processing Addendum. Our AI model provider is contractually prohibited from training its models on customer content transmitted through the Approveit Service. Retention. Our AI model provider retains inputs and outputs for a limited period under its own published policy, and details are available on request. Separately, Approveit stores AI conversations in your workspace so that you can review them, for the period stated in Data retention below. Human oversight. The Approveit AI Assistant drafts, summarises and answers questions; it does not approve or reject a request on its own. Where your administrator connects an AI client or a service account and gives it permission to act, actions it takes are executed under the Approveit account that authorized it and recorded in your audit trail. You decide whether to grant that permission. You are dealing with an AI system. Where you interact with the Approveit AI Assistant, you are interacting with an artificial intelligence system and not with a member of our staff. AI output can be incomplete or wrong and should be checked before you rely on it. Turning it off. A workspace administrator can have the AI Assistant switched off for the whole workspace at any time by contacting us at support@approveit.today. We will action the request promptly and confirm in writing, after which we stop transmitting that workspace’s data to our AI model provider. MCP connections are revoked separately, as described below. Connecting Approveit to your own AI client (MCP) Connecting Approveit to your own AI client (MCP) Approveit publishes an MCP server. A workspace administrator may use it to connect Approveit to an AI client operated by you or by a third party, such as Claude. Once you authorise such a connection, that client can read the Approveit data covered by the permissions you granted, and can take the actions you permitted. When you connect an AI client, you instruct us to disclose that data to it. This is a disclosure for a business purpose at your direction, not a sale. The operator of that client processes the data under its own terms and privacy policy, not ours, and we are not responsible for what it does with the data once it is transmitted. You are responsible for deciding which clients to connect, which permissions to grant, and for revoking access when it is no longer needed. You may revoke an authorized connection at any time, including by contacting us at support@approveit.today. Approveit publishes an MCP server. A workspace administrator may use it to connect Approveit to an AI client operated by you or by a third party, such as Claude. Once you authorise such a connection, that client can read the Approveit data covered by the permissions you granted, and can take the actions you permitted. When you connect an AI client, you instruct us to disclose that data to it. This is a disclosure for a business purpose at your direction, not a sale. The operator of that client processes the data under its own terms and privacy policy, not ours, and we are not responsible for what it does with the data once it is transmitted. You are responsible for deciding which clients to connect, which permissions to grant, and for revoking access when it is no longer needed. You may revoke an authorized connection at any time, including by contacting us at support@approveit.today. Product analytics, session replay and error monitoring Product analytics, session replay and error monitoring We use product analytics, session replay and error monitoring tools to understand how the Approveit Service is used and to find and fix faults. These tools record interactions with the interface and capture technical details of errors, which can include content displayed on screen at the time and identifiers of the user concerned. We configure them to mask password and payment fields and attachment contents where the tool supports it. We do not use them for advertising or to build marketing profiles. A customer can ask us to exclude its workspace from session replay, as set out in our Data Processing Addendum. Contact support@approveit.today. We use product analytics, session replay and error monitoring tools to understand how the Approveit Service is used and to find and fix faults. These tools record interactions with the interface and capture technical details of errors, which can include content displayed on screen at the time and identifiers of the user concerned. We configure them to mask password and payment fields and attachment contents where the tool supports it. We do not use them for advertising or to build marketing profiles. A customer can ask us to exclude its workspace from session replay, as set out in our Data Processing Addendum. Contact support@approveit.today. We use product analytics, session replay and error monitoring tools to understand how the Approveit Service is used and to find and fix faults. These tools record interactions with the interface and capture technical details of errors, which can include content displayed on screen at the time and identifiers of the user concerned. We configure them to mask password and payment fields and attachment contents where the tool supports it. We do not use them for advertising or to build marketing profiles. A customer can ask us to exclude its workspace from session replay, as set out in our Data Processing Addendum. Contact support@approveit.today. Sales and support calls Sales and support calls We record and transcribe some sales and support calls so that we can follow up accurately and improve our service. Where we do, we tell you before recording begins and, where the law requires it, ask for your consent. You may ask us not to record, and we will not. Recordings are processed by Fathom Video, Inc. and Zoom Video Communications, Inc., and Fathom produces automated transcripts and summaries of them. We record and transcribe some sales and support calls so that we can follow up accurately and improve our service. Where we do, we tell you before recording begins and, where the law requires it, ask for your consent. You may ask us not to record, and we will not. Recordings are processed by Fathom Video, Inc. and Zoom Video Communications, Inc., and Fathom produces automated transcripts and summaries of them. Google API Services usage disclosure Google API Services usage disclosure Google API Services usage disclosure The Approveit app uses Google APIs when users sync events created in the app with their Google Calendar. We read calendar data only to the extent needed to create and update the events the app itself creates. We do not modify, copy or store events that Approveit did not create. Approveit’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer data received from Google APIs to our AI model provider, and we do not use it to develop, train or improve any AI or machine learning model. The Approveit app uses Google APIs when users sync events created in the app with their Google Calendar. We read calendar data only to the extent needed to create and update the events the app itself creates. We do not modify, copy or store events that Approveit did not create. Approveit’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer data received from Google APIs to our AI model provider, and we do not use it to develop, train or improve any AI or machine learning model. Automated decisions Automated decisions Automated decisions Approveit does not, on its own initiative, make automated decisions about you that produce legal effects or similarly significant effects. Our AI Assistant generates suggestions, drafts and summaries. Every approval action is recorded against the Approveit user account that took it, with the time and, where the action came through an integration or a connected AI client, the client used. Our customers configure their own workflows and integrations, and a customer may choose to create a service account or connect an AI client that submits approval decisions without a person reviewing them. Where a customer does that, the customer decides the purposes and means of that processing and is responsible for meeting any obligations that apply to automated decision-making, including providing human intervention on request. Our role remains that of a processor acting on the customer’s instructions, and the audit trail is available to support the customer in meeting that obligation. Approveit does not, on its own initiative, make automated decisions about you that produce legal effects or similarly significant effects. Our AI Assistant generates suggestions, drafts and summaries. Every approval action is recorded against the Approveit user account that took it, with the time and, where the action came through an integration or a connected AI client, the client used. Our customers configure their own workflows and integrations, and a customer may choose to create a service account or connect an AI client that submits approval decisions without a person reviewing them. Where a customer does that, the customer decides the purposes and means of that processing and is responsible for meeting any obligations that apply to automated decision-making, including providing human intervention on request. Our role remains that of a processor acting on the customer’s instructions, and the audit trail is available to support the customer in meeting that obligation. Security Security We maintain an information security program aligned with the AICPA Trust Services Criteria, including encryption of personal data in transit and at rest in our production environment, least-privilege access control, logical separation of each customer’s data, vulnerability scanning, logging and monitoring, and security training for our personnel. The full technical and organizational measures are set out in our Data Processing Addendum. We maintain a SOC 2 Type II attestation, and our then-current report is available to customers under confidentiality on request, for the scope and period stated in it. No method of transmission or storage is completely secure. While we work to protect personal data using the measures described above, we cannot guarantee its absolute security. We maintain an information security program aligned with the AICPA Trust Services Criteria, including encryption of personal data in transit and at rest in our production environment, least-privilege access control, logical separation of each customer’s data, vulnerability scanning, logging and monitoring, and security training for our personnel. The full technical and organizational measures are set out in our Data Processing Addendum. We maintain a SOC 2 Type II attestation, and our then-current report is available to customers under confidentiality on request, for the scope and period stated in it. No method of transmission or storage is completely secure. While we work to protect personal data using the measures described above, we cannot guarantee its absolute security. Data breach notification Data breach notification If we become aware of a personal data breach affecting data we process on a customer’s behalf, we notify that customer as required by our Data Processing Addendum. Where we are the controller, we notify affected individuals and the relevant supervisory authorities as required by law. If we become aware of a personal data breach affecting data we process on a customer’s behalf, we notify that customer as required by our Data Processing Addendum. Where we are the controller, we notify affected individuals and the relevant supervisory authorities as required by law. Legal and law enforcement disclosures Legal and law enforcement disclosures We may disclose personal data where required by law, court order or a binding request from a public authority, or, for data for which we are the controller, to establish, exercise or defend legal claims. Where the request concerns data we process on a customer’s behalf, we notify that customer promptly unless we are legally prohibited from doing so, and, where notice is prohibited, we use commercially reasonable efforts to obtain a waiver or to limit the scope of the disclosure. We may disclose personal data where required by law, court order or a binding request from a public authority, or, for data for which we are the controller, to establish, exercise or defend legal claims. Where the request concerns data we process on a customer’s behalf, we notify that customer promptly unless we are legally prohibited from doing so, and, where notice is prohibited, we use commercially reasonable efforts to obtain a waiver or to limit the scope of the disclosure. Business transfers Business transfers If we are involved in a merger, acquisition, financing, reorganization or sale of assets, personal data may be transferred as part of that transaction. We will post notice of any resulting change to this policy on this page. If we are involved in a merger, acquisition, financing, reorganization or sale of assets, personal data may be transferred as part of that transaction. We will post notice of any resulting change to this policy on this page. Aggregated and de-identified data Aggregated and de-identified data We may create aggregated and de-identified data from our operation of the Service, such as feature usage counts, latency and error rates, and use it to operate, secure, improve and develop our products. We keep de-identified data in de-identified form, do not attempt to re-identify it, and require anyone we share it with to do the same. We may create aggregated and de-identified data from our operation of the Service, such as feature usage counts, latency and error rates, and use it to operate, secure, improve and develop our products. We keep de-identified data in de-identified form, do not attempt to re-identify it, and require anyone we share it with to do the same. Third-party services and links Third-party services and links Third-party services and links Our website and the Approveit Service may link to, or be connected by you to, services operated by third parties, including Slack, Microsoft Teams, Google and accounting systems. Those services are controlled by the third parties that operate them, and their own privacy policies and security practices apply. We are not responsible for their content, practices or availability. Our website and the Approveit Service may link to, or be connected by you to, services operated by third parties, including Slack, Microsoft Teams, Google and accounting systems. Those services are controlled by the third parties that operate them, and their own privacy policies and security practices apply. We are not responsible for their content, practices or availability. Data residency Data residency Data residency We host the Approveit Service on Amazon Web Services in the United States by default. EU hosting of primary data storage is available to customers on request. Support, monitoring and AI features may still involve access from or transfer to the United States, as set out in our Data Processing Addendum. Our support platform operates in the United States or the European Union. We host the Approveit Service on Amazon Web Services in the United States by default. EU hosting of primary data storage is available to customers on request. Support, monitoring and AI features may still involve access from or transfer to the United States, as set out in our Data Processing Addendum. Our support platform operates in the United States or the European Union. Cookies Cookies Cookies A cookie is a file containing an identifier that is sent by a web server to a web browser and stored by the browser. The identifier is then sent back to the server each time the browser requests a page. Necessary cookies make the website usable by enabling basic functions such as page navigation and access to secure areas. Statistic cookies help us understand how visitors interact with the website. Marketing cookies may be used on our marketing website to show relevant advertising, including on other websites. Where the law requires your prior consent, we set non-essential cookies only after you accept them. Everywhere else, you can reject them at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, and we will stop. We do not use advertising or marketing cookies inside the authenticated Approveit Service. We do not respond to Do Not Track browser signals, which have no agreed technical standard. Where required by applicable law, we treat a Global Privacy Control signal as a request to opt out of sale and sharing for that browser. A cookie is a file containing an identifier that is sent by a web server to a web browser and stored by the browser. The identifier is then sent back to the server each time the browser requests a page. Necessary cookies make the website usable by enabling basic functions such as page navigation and access to secure areas. Statistic cookies help us understand how visitors interact with the website. Marketing cookies may be used on our marketing website to show relevant advertising, including on other websites. Where the law requires your prior consent, we set non-essential cookies only after you accept them. Everywhere else, you can reject them at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, and we will stop. We do not use advertising or marketing cookies inside the authenticated Approveit Service. We do not respond to Do Not Track browser signals, which have no agreed technical standard. Where required by applicable law, we treat a Global Privacy Control signal as a request to opt out of sale and sharing for that browser. Sale and sharing of personal information Sale and sharing of personal information Sale and sharing of personal information We do not sell personal information for monetary or other valuable consideration, and we have not done so in the preceding twelve months. We do share personal information for cross-context behavioral advertising on our marketing website, approveit.today, through advertising cookies. Under the California Privacy Rights Act this is “sharing”. You can opt out at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, or by sending a Global Privacy Control signal from your browser, as described under Cookies. We do not sell or share any personal data that our customers process through the Approveit Service. We do not knowingly sell or share the personal information of consumers under 16 years of age. We do not sell personal information for monetary or other valuable consideration, and we have not done so in the preceding twelve months. We do share personal information for cross-context behavioral advertising on our marketing website, approveit.today, through advertising cookies. Under the California Privacy Rights Act this is “sharing”. You can opt out at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, or by sending a Global Privacy Control signal from your browser, as described under Cookies. We do not sell or share any personal data that our customers process through the Approveit Service. We do not knowingly sell or share the personal information of consumers under 16 years of age. Your rights Your rights Your rights Depending on where you live, you may have the right to: be informed about our processing; access your personal data; have it corrected; have it deleted; restrict processing; object to processing, including for direct marketing; withdraw consent where we rely on it; receive your data in a portable format; and not be subject to solely automated decisions with legal or similarly significant effects. California residents also have the right to know what personal information we collect and why, to opt out of sale or sharing, to limit the use of sensitive personal information (which does not apply to our use of log-in credentials described above), and not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right. How to exercise them. Email support@approveit.today. You may use an authorized agent; we will ask the agent for proof of authorisation and may ask you to verify your identity directly. Before we act on a request we take steps to verify your identity, which may include matching your information against our records. How long we take. For GDPR and UK GDPR requests we respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. For CCPA requests we acknowledge receipt within 10 business days and respond within 45 days, extendable once by a further 45 days. If we decline. You may appeal by emailing support@approveit.today with “Appeal” in the subject line. We will respond within 45 days with our decision and our reasons, and will tell you how to complain to your state Attorney General. You also have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or where you believe an infringement has taken place. Where Approveit acts as a processor on behalf of a customer, we will refer your request to that customer and assist them in responding. Depending on where you live, you may have the right to: be informed about our processing; access your personal data; have it corrected; have it deleted; restrict processing; object to processing, including for direct marketing; withdraw consent where we rely on it; receive your data in a portable format; and not be subject to solely automated decisions with legal or similarly significant effects. California residents also have the right to know what personal information we collect and why, to opt out of sale or sharing, to limit the use of sensitive personal information (which does not apply to our use of log-in credentials described above), and not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right. How to exercise them. Email support@approveit.today. You may use an authorized agent; we will ask the agent for proof of authorisation and may ask you to verify your identity directly. Before we act on a request we take steps to verify your identity, which may include matching your information against our records. How long we take. For GDPR and UK GDPR requests we respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. For CCPA requests we acknowledge receipt within 10 business days and respond within 45 days, extendable once by a further 45 days. If we decline. You may appeal by emailing support@approveit.today with “Appeal” in the subject line. We will respond within 45 days with our decision and our reasons, and will tell you how to complain to your state Attorney General. You also have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or where you believe an infringement has taken place. Where Approveit acts as a processor on behalf of a customer, we will refer your request to that customer and assist them in responding. Depending on where you live, you may have the right to: be informed about our processing; access your personal data; have it corrected; have it deleted; restrict processing; object to processing, including for direct marketing; withdraw consent where we rely on it; receive your data in a portable format; and not be subject to solely automated decisions with legal or similarly significant effects. California residents also have the right to know what personal information we collect and why, to opt out of sale or sharing, to limit the use of sensitive personal information (which does not apply to our use of log-in credentials described above), and not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right. How to exercise them. Email support@approveit.today. You may use an authorized agent; we will ask the agent for proof of authorisation and may ask you to verify your identity directly. Before we act on a request we take steps to verify your identity, which may include matching your information against our records. How long we take. For GDPR and UK GDPR requests we respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. For CCPA requests we acknowledge receipt within 10 business days and respond within 45 days, extendable once by a further 45 days. If we decline. You may appeal by emailing support@approveit.today with “Appeal” in the subject line. We will respond within 45 days with our decision and our reasons, and will tell you how to complain to your state Attorney General. You also have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or where you believe an infringement has taken place. Where Approveit acts as a processor on behalf of a customer, we will refer your request to that customer and assist them in responding. International data transfers International data transfers International data transfers Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supported by a transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we may also rely on that certification. The relevant clauses are incorporated into our Data Processing Addendum and copies are available on request. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supported by a transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we may also rely on that certification. The relevant clauses are incorporated into our Data Processing Addendum and copies are available on request. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supported by a transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we may also rely on that certification. The relevant clauses are incorporated into our Data Processing Addendum and copies are available on request. We retain personal data for no longer than necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Data retention Data retention Data retention We retain personal data for no longer than necessary for the purposes described in this policy, unless a longer period is required or permitted by law. We retain personal data for no longer than necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Data Data Data Retention Retention Retention Content customers submit to the Service, including approval requests and AI conversations Content customers submit to the Service, including approval requests and AI conversations Content customers submit to the Service, including approval requests and AI conversations Life of the account, and after termination until the customer asks us to delete it. We may delete it at our discretion from 90 days after termination Life of the account, and after termination until the customer asks us to delete it. We may delete it at our discretion from 90 days after termination MCP connection records and access logs MCP connection records and access logs MCP connection records and access logs Connection records for as long as the connection is authorized; access logs for the life of the account Connection records for as long as the connection is authorized; access logs for the life of the account Account details Account details Account details Life of the account, and after termination on the same basis as customer content Life of the account, and after termination on the same basis as customer content Purchase and billing history Purchase and billing history Purchase and billing history 7 years from the transaction date, for accounting and tax 7 years from the transaction date, for accounting and tax Marketing contact data Marketing contact data Marketing contact data 3 years from collection or until you opt out 3 years from collection or until you opt out Session recordings Session recordings Session recordings Up to 30 days Up to 30 days Error logs Error logs Error logs Up to 90 days Up to 90 days Support conversations Support conversations Support conversations Up to 3 years from last contact, or earlier if the customer asks us to delete them Up to 3 years from last contact, or earlier if the customer asks us to delete them Sales and support call recordings and transcripts Sales and support call recordings and transcripts Sales and support call recordings and transcripts Up to 12 months Up to 12 months Website analytics and cookie data Website analytics and cookie data Up to 13 months Up to 13 months Website analytics and cookie data Approval records and other content customers submit are retained for as long as the customer’s account is active, and after termination until the customer asks us to delete it, because customers rely on that record as their approval history. We do not delete that content on a schedule of our own, although we may delete it at our discretion from 90 days after termination. A customer can ask us to delete specific records at any time by contacting support@approveit.today. Where a period above is stated as “up to”, it is a maximum for our active systems. Where we are the controller, we may retain data for longer where required by law, to resolve disputes or to enforce our agreements. Data in encrypted backups is isolated from active processing and is removed in the ordinary course of backup rotation. Approval records and other content customers submit are retained for as long as the customer’s account is active, and after termination until the customer asks us to delete it, because customers rely on that record as their approval history. We do not delete that content on a schedule of our own, although we may delete it at our discretion from 90 days after termination. A customer can ask us to delete specific records at any time by contacting support@approveit.today. Where a period above is stated as “up to”, it is a maximum for our active systems. Where we are the controller, we may retain data for longer where required by law, to resolve disputes or to enforce our agreements. Data in encrypted backups is isolated from active processing and is removed in the ordinary course of backup rotation. Communications about your account, and marketing Communications about your account, and marketing We use your contact details to send you transactional messages about your account, security and the operation of the Service. These are not marketing and you cannot opt out of them while you hold an account. Where required by applicable law we will obtain your consent before sending marketing communications. Where consent is not required, we may send marketing communications to your business contact details, and marketing consent is never a condition of using Approveit. You can opt out at any time using the unsubscribe link in any marketing email or by emailing support@approveit.today. We do not sell your contact information to third-party marketers or provide it to them for their own marketing. We use your contact details to send you transactional messages about your account, security and the operation of the Service. These are not marketing and you cannot opt out of them while you hold an account. Where required by applicable law we will obtain your consent before sending marketing communications. Where consent is not required, we may send marketing communications to your business contact details, and marketing consent is never a condition of using Approveit. You can opt out at any time using the unsubscribe link in any marketing email or by emailing support@approveit.today. We do not sell your contact information to third-party marketers or provide it to them for their own marketing. Approval records and other content customers submit are retained for as long as the customer’s account is active, and after termination until the customer asks us to delete it, because customers rely on that record as their approval history. We do not delete that content on a schedule of our own, although we may delete it at our discretion from 90 days after termination. A customer can ask us to delete specific records at any time by contacting support@approveit.today. Where a period above is stated as “up to”, it is a maximum for our active systems. Where we are the controller, we may retain data for longer where required by law, to resolve disputes or to enforce our agreements. Data in encrypted backups is isolated from active processing and is removed in the ordinary course of backup rotation. Changes to this Policy Changes to this Policy Communications about your account, and marketing We use your contact details to send you transactional messages about your account, security and the operation of the Service. These are not marketing and you cannot opt out of them while you hold an account. Where required by applicable law we will obtain your consent before sending marketing communications. Where consent is not required, we may send marketing communications to your business contact details, and marketing consent is never a condition of using Approveit. You can opt out at any time using the unsubscribe link in any marketing email or by emailing support@approveit.today. We do not sell your contact information to third-party marketers or provide it to them for their own marketing. We update this policy when our practices change, and we post the updated version here with a new last-updated date. Where a change is material, we will also tell customers by email or through the Service before it takes effect. New sub-processors are notified to customers as set out in our Data Processing Addendum, and any change of AI model provider at least 30 days in advance. Previous versions are available on request. We update this policy when our practices change, and we post the updated version here with a new last-updated date. Where a change is material, we will also tell customers by email or through the Service before it takes effect. New sub-processors are notified to customers as set out in our Data Processing Addendum, and any change of AI model provider at least 30 days in advance. Previous versions are available on request. We update this policy when our practices change, and we post the updated version here with a new last-updated date. Where a change is material, we will also tell customers by email or through the Service before it takes effect. New sub-processors are notified to customers as set out in our Data Processing Addendum, and any change of AI model provider at least 30 days in advance. Previous versions are available on request. Children Children Changes to this Policy The Approveit Service is offered to businesses and is not intended for individuals under 18 years of age, consistent with our Terms of Service. If we learn that we have collected personal data from someone under 18, we will take steps to delete it. The Approveit Service is offered to businesses and is not intended for individuals under 18 years of age, consistent with our Terms of Service. If we learn that we have collected personal data from someone under 18, we will take steps to delete it. Accessibility Accessibility Children This policy is published in accessible HTML. If you need it in another format, contact support@approveit.today. This policy is published in accessible HTML. If you need it in another format, contact support@approveit.today. Compliance Compliance Accessibility The Approveit Service is offered to businesses and is not intended for individuals under 18 years of age, consistent with our Terms of Service. If we learn that we have collected personal data from someone under 18, we will take steps to delete it. We design our practices to comply with the privacy laws applicable to our business, including the GDPR, the UK GDPR, the CCPA and CPRA, and other US state privacy laws. Residents of other US states with comprehensive privacy laws have rights equivalent to those described above, including the right to appeal a declined request, and may exercise them through support@approveit.today. For any question about this policy or our privacy practices, email support@approveit.today. We design our practices to comply with the privacy laws applicable to our business, including the GDPR, the UK GDPR, the CCPA and CPRA, and other US state privacy laws. Residents of other US states with comprehensive privacy laws have rights equivalent to those described above, including the right to appeal a declined request, and may exercise them through support@approveit.today. For any question about this policy or our privacy practices, email support@approveit.today. Compliance This policy is published in accessible HTML. If you need it in another format, contact support@approveit.today. We design our practices to comply with the privacy laws applicable to our business, including the GDPR, the UK GDPR, the CCPA and CPRA, and other US state privacy laws. Residents of other US states with comprehensive privacy laws have rights equivalent to those described above, including the right to appeal a declined request, and may exercise them through support@approveit.today. For any question about this policy or our privacy practices, email support@approveit.today. Features Workflow Automation Approval Software BPM Software Process Management Human-in-the-Loop Pricing Use Cases Accounts Payable Accounts Receivable Integrations Teams Finance Human Resources Operations IT & Security Resources Blog Case Studies User Guides How-to Videos Partnership Contact Sales 5.0 STARS Rating by G2 users 5.0 STARS Rating by Capterra users 455 Valencia St., San Francisco, CA 94103 support@approveit.today DPA Privacy Policy Terms of Service ©2026 All rights reserved. Approveit, Inc. Features Workflow Automation Approval Software BPM Software Process Management Human-in-the-Loop Pricing Use Cases Accounts Payable Accounts Receivable Integrations Teams Finance Human Resources Operations IT & Security Resources Blog Case Studies User Guides How-to Videos Partnership Contact Sales 5.0 STARS Rating by G2 users 5.0 STARS Rating by Capterra users 455 Valencia St., San Francisco, CA 94103 support@approveit.today DPA Privacy Policy Terms of Service ©2026 All rights reserved. Approveit, Inc. Features Workflow Automation Approval Software BPM Software Process Management Human-in-the-Loop Pricing Use Cases Accounts Payable Accounts Receivable Integrations Teams Finance Human Resources Operations IT & Security Resources Blog Case Studies User Guides How-to Videos Partnership Contact Sales 5.0 STARS Rating by G2 users 5.0 STARS Rating by Capterra users 455 Valencia St., San Francisco, CA 94103 support@approveit.today DPA Privacy Policy Terms of Service ©2026 All rights reserved. Approveit, Inc. Approveit Log In Request a Demo Request a Demo