Trust & data handling
Security & Data Protection
Packseen handles commercially sensitive purchasing information: invoices, quotations and supplier pricing. This page explains, in plain terms, how that data is separated, who can see it, and how uploaded documents are stored.
- Your data is isolated to your workspace. That isolation is enforced at the database level, not only in the interface.
- Nothing is reachable without authenticated sign-in.
- Documents are encrypted in transit and at rest, and removed from storage when you delete them.
- Automated processing is read-only and never exposes your data to other customers.
Your data stays in your own workspace
- Every record is tied to your organisation. That covers documents, line items, suppliers, opportunities and savings.
- Access is enforced at the database level, and the interface reflects that.
- Another Packseen customer cannot query, view or receive your purchasing data.
Authenticated access and roles
- Access requires a verified sign-in. Nothing in the platform is reachable without an authenticated account.
- Within your workspace, you decide who joins and assign roles (procurement, operations, finance, warehouse).
- Billing and administrative actions are limited to the people you designate.
How uploaded documents are handled
- Uploaded documents are stored in a private store that is not publicly reachable.
- When you open a document, it’s served through a short-lived private link created for your session only.
- Files are encrypted in transit and at rest by our infrastructure provider.
- When you delete a document, the uploaded file is removed from document storage. Related processing records may be retained where needed for account history, audit, billing or legal obligations, as explained in the Privacy Policy.
What we use your procurement data for
- Used to run the Packseen service for you. Aggregated, non-identifying reference information may also be used to improve benchmarking, as explained in our Privacy Policy.
- Not sold, not shared with other customers, not published.
- Benchmark comparisons are never presented in a way that exposes another customer’s pricing.
Automated document processing
- Some steps use automated document processing to read your documents and answer questions about your own data.
- All processing requests are made by Packseen servers, never from your browser. No provider key is ever exposed to the client.
- Processing is read-only: it can describe your data but cannot change anything on your account.
- Processing prompts and outputs are handled only to provide the service and are not shown to other customers.
Audit and administrative access
- Privileged administrative actions taken by Packseen staff are written to an internal audit log with the acting user and timestamp.
- Support access is used only to operate the service, investigate a fault, or act on a request from you.
Hosting and infrastructure
- Packseen runs on the Lovable Cloud platform, built on Supabase and Cloudflare infrastructure.
- Our infrastructure providers maintain their own security, compliance and data-processing programmes. Where relevant, provider documentation can be shared during onboarding.
- These programmes belong to those providers and cover the underlying infrastructure. They are not certifications held by Packseen directly.
Packseen runs on managed cloud infrastructure with GDPR data processing terms available through our providers. Processor details, transfer safeguards and data-processing terms can be shared before upload or onboarding, and the processors we rely on are summarised in the Privacy Policy.
Packseen Limited is the data controller for the customer data it processes and applies the controls described on this page. We are building the platform around clear evidence, controlled data handling and verified savings, not unsupported estimates.
Packseen Limited is a company registered in England and Wales under company number 17416830. Registered office: 5 Brayford Square, London, England, E1 0SG.
Working with your procurement or IT desk
Most reviews stall because a vendor cannot answer basic onboarding questions. These are the answers.
- Data we need: packaging invoices, quotations and specifications you already hold. No system integration, no ERP access, no credentials.
- Where it is processed: within our hosted infrastructure in our providers’ data centres. Documents are stored privately and read server-side only.
- Sub-processors: our hosting, database, storage and AI processing providers, listed in the Privacy Policy. We do not sell or share your data, and it is never used to price for another customer.
- Retention, export and deletion: your documents and results are kept in line with the retention position described in the Privacy Policy, and we will export or delete your workspace data on written request.
- A mutual non-disclosure agreement is available on request from enquiries@packseen.com and can be signed before any document is uploaded.
- Before you upload: nothing is sent until you choose to send it. Ask your data-handling questions first, and we will provide the processors we rely on and their locations on request.
- Independent certification: we rely on our infrastructure providers’ certifications and hold none in our own name. We say so rather than implying otherwise.
- Security contact and questionnaires: send security or supplier-onboarding questionnaires to our support address and we will complete them.
To see the output format before sending any document, read the specimen report.
Reporting a concern
If you believe you have found a security issue, email support@packseen.com with the details. We will acknowledge and investigate.
For how long we keep data, your rights and the processors we rely on, see the Privacy Policy and Terms of Use.
Share this page with your procurement or IT team before upload.
Your procurement data stays private to your organisation. Read how we protect it.
