Privacy Policy

Last updated: August 2026

Introduction

This Privacy Policy explains what information UTUMATE collects, why the information is collected, and how the information is protected when the UTUMATE invoice approval platform and related services (the Service) are used. Use of the Service indicates acceptance of the practices described in this policy.

Information collected

Account data: Full name, work email, company name, job role, and workspace settings associated with an account.

Invoice content: Uploaded files and extracted invoice fields such as amount, currency, invoice number, dates, payment terms, line‑item descriptions, classifications, approval records, and comments.

Billing data: Subscription details, seat counts, billing history. Payment card details are processed directly by a third‑party payment processor and are not stored by UTUMATE.

Usage and log data: Authentication events, actions recorded in audit logs, device and browser metadata, IP addresses, and other diagnostic information necessary to operate and secure the Service.

How information is used

Information is used to operate and improve the Service, including:

  • Authenticating accounts and enforcing access controls.
  • Routing invoices through configured approval workflows.
  • Generating dashboards, reports, and audit trails.
  • Processing subscription billing through third‑party payment processors.
  • Providing technical support and responding to security incidents.
  • Detecting and preventing fraud and abuse.

UTUMATE does not sell personal information or use invoice content for advertising.

Automated processing of uploads

Uploaded invoices may be processed using automated extraction technologies (for example OCR and machine learning) to suggest field values and prefill forms. Extracted data and suggested values are stored within the originating workspace and are used only to provide and improve the Service. Extracted content is not used to train third‑party models without explicit agreement.

Workspace isolation and access controls

  • Each organization operates within an isolated workspace enforced at the data and database level.
  • Access within a workspace is governed by role‑based permissions: team members see personal submissions and assigned queues; supervisors see invoices routed to them; administrators have workspace‑wide visibility and configuration rights.
  • Administrators are responsible for managing user invitations, role assignments, and internal access policies.

Service providers and subprocessors

UTUMATE uses a limited set of third‑party service providers to host, process, and deliver the Service (for example cloud hosting, database services, payment processing, email delivery, and automated document extraction). Subprocessors act only on UTUMATE’s instructions and are contractually required to implement appropriate security measures. A current list of subprocessors is available on request.

Data retention and export

  • Workspace data is retained for the duration of an active subscription and for a limited period after subscription termination to allow for export.
  • Audit logs and records may be retained longer where required for security, accounting, or legal obligations.
  • Procedures for data export and deletion are documented in the account settings and data retention policy.

Security measures

  • Data is encrypted in transit and at rest.
  • Access controls include authentication, role‑based permissions, and row‑level security where applicable.
  • Routine security monitoring, vulnerability management, and incident response processes are maintained.

While reasonable technical and organizational measures are implemented to reduce risk, no system can be guaranteed completely secure.

Rights and requests

Subject to applicable law, individuals may request access to, correction of, export of, or deletion of personal data. Workspace members should contact the workspace Administrator for internal requests. Administrators may submit verified requests to UTUMATE for assistance with data access, correction, export, or deletion. UTUMATE responds to verified requests within a reasonable timeframe and in accordance with applicable law.

Cookies and local storage

  • Strictly necessary cookies and local storage are used to maintain authenticated sessions and remember workspace preferences.
  • Third‑party advertising cookies are not used.
  • Details on cookie usage and options for managing cookies are provided in the Cookie Notice.

Changes to this policy and contact information

Material changes to this Privacy Policy will be communicated to workspace Administrators by email or in‑product notice. For questions, reach us through the contact page.

Effective date: This Privacy Policy is effective as of the date above and supersedes prior privacy notices related to the Service.