Legal
Privacy Policy
1. Who we are
Packseen Limited provides independent packaging procurement intelligence to businesses and is the data controller for the personal data described below. For privacy questions, contact support@packseen.com.
Packseen Limited is a company registered in England and Wales under company number 17416830. Registered office: 5 Brayford Square, London, England, E1 0SG.
2. Data we process
- Account data: name, business email address, company name, workspace role and authentication records.
- Purchasing data you upload: invoices, quotations, specifications, supplier names, prices, volumes and related commercial documents.
- Analysis and commercial records: opportunities, verification evidence, success fees, invoices and payment records.
- Support correspondence and in-product notifications.
- Technical logs needed to operate and secure the service.
We ask you not to upload special category personal data. Uploaded documents are expected to be business records, not personnel records.
3. Why we process it
- To provide the analysis, benchmarking and reporting you request.
- To administer your account, workspace access and support requests.
- To assess technical and commercial suitability for customer requirements, using information provided by suppliers.
- To calculate, evidence and invoice success fees where a qualifying saving is verified.
- To keep the service secure and to prevent misuse.
- To meet legal, accounting and tax obligations.
We rely on performance of our contract with you for providing and administering the service, our legitimate interests in keeping the service secure and preventing misuse, and compliance with legal obligations for accounting, tax and dispute records.
4. Service providers we use
We use a small number of processors to run the service. Each processes data only to deliver the function described:
- Hosting, database and storage: hosts the application, stores account data, uploaded documents and commercial records.
- Email delivery: sends transactional email such as account confirmations, invitations, billing notices and support replies.
- Payments and invoicing: issues success-fee invoices and records payment status. Card details are handled by the payment provider and are not stored by Packseen.
- Product measurement (PostHog): first-party measurement of how the website and platform are used, hosted in the European Union. See “Product and conversion measurement” below.
Product and conversion measurement
We use PostHog, configured on its EU hosting, to measure a small, fixed set of product and conversion events so we can see which parts of the site and platform work. It runs in a memory-only mode: we do not intentionally set analytics cookies or store analytics identifiers on your device, and we configure measurement to avoid tracking individual visitors across sessions. Session recording and automatic click capture are switched off, and IP address storage is disabled.
The events counted are: clicks on the “Request a cost review” and “Talk to us” buttons, starting and completing account sign-up, a successful document upload, and the start and completion of a benchmark run, plus basic page views. Alongside each event we process only technical data: the page path (with query strings and any record references removed), referrer, campaign parameters where present, approximate country derived from your IP address, your browser user-agent string, and browser, operating system, device type and screen size.
We do not send names, email addresses, company names, spend or savings figures, document contents or database identifiers to PostHog, and we do not identify signed-in users to it.
Separately, our own servers keep a count of anonymous Quick Check steps — the page being opened, figures first being entered, a result being produced, the further figures section being opened, and a check being saved — so we can measure how much the tool is used. This is a count only: no figures you enter, and no data that identifies you or your company, is recorded with it.
Automated document processing (document reading and Packseen Procurement Intelligence) We use automated processing, accessed through the Lovable gateway, for two purposes: reading the documents you upload so their figures can be benchmarked, and answering questions in Packseen Procurement Intelligence. All processing requests are made by our servers; no provider key or request is ever handled by your browser.
For Packseen Procurement Intelligence, we send only your typed question and a small, already-formatted summary of your own workspace, for example a saving’s title and status, a fee state or an invoice state. We do not send names, email addresses, passwords, payment details, database identifiers or any other customer’s data, and it has no access to any workspace other than yours. Prompts and outputs are processed only to provide the service and are never shown to other customers; we keep counts and outcomes so we can apply usage limits and monitor abuse. Replies are explanatory only: it cannot change anything on your account, and it is not used to make decisions about you. Output is not used to train external models on your data.
A current list of the processors we rely on, their locations and the safeguards applied to any international transfer is available on request from support@packseen.com.
5. Sharing
We do not sell your data. We do not disclose your purchasing data or supplier pricing to other customers. Aggregated, non-identifying reference information may be used to improve benchmarking. We may disclose data where required by law or to enforce our terms.
Supplier-provided confidential information is not published publicly and is not disclosed to other suppliers.
6. Retention
Account, analysis and commercial records are retained while your account is active and afterwards for the period needed to meet legal, accounting and dispute-resolution obligations. Usage records used for fair-use enforcement are retained for a limited rolling period.
You can ask us for the retention period that applies to a specific category of your data, or ask us to delete data you have uploaded, by contacting support@packseen.com.
On written request we will export the workspace data you have provided, or delete it, subject to records we must keep for legal, accounting and dispute-resolution purposes.
7. Security
Access to your workspace data is restricted to your own account and the colleagues you invite. Commercial records are protected by database-level access controls, and privileged actions by Packseen staff are recorded in an audit log.
For a fuller explanation of workspace isolation, roles, document storage and automated processing, see Security & Data Protection.
8. Your rights
Subject to applicable law you may request access to, correction of, or deletion of your personal data, object to certain processing, or request a copy of the data you provided. Contact support@packseen.com. You may also complain to the relevant supervisory authority.
9. Changes
We will update this policy when our processing changes and will note the effective date here. Where a change materially affects how we handle your data we will notify account administrators by email.
