Privacy Policy
Approveit Privacy Policy
Approveit Privacy Policy
Approveit Privacy Policy
Last updated: September 21, 2026
Introduction
Introduction
Introduction
Approveit, Inc. is committed to protecting your privacy and ensuring you have a positive experience when using the services we provide, which we generally refer to as Approveit or the Approveit Service.
Approveit, Inc. is committed to protecting your privacy and ensuring you have a positive experience when using the services we provide, which we generally refer to as
Approveit or Approveit services.
Scope of this Privacy Policy
Scope of this Privacy Policy
This Privacy Policy explains how we handle data: what we collect, how we obtain it, how we use it, when and if we disclose it, and your options for managing it. It covers:
This Privacy Policy explains how we handle data: what we collect, how we obtain it, how we use it, when and if we disclose it, and your options for managing it. It covers:
• The Approveit Service, including the Approveit AI Assistant and the Approveit MCP server
• Our website approveit.today
• Our sales, support and marketing activities
• The Approveit Service, including the Approveit AI Assistant and the Approveit MCP server
• Our website approveit.today
• Our sales, support and marketing activities
• The Approveit Service, including the Approveit AI Assistant and the Approveit MCP server
• Our website approveit.today
• Our sales, support and marketing activities
Who are we and how to contact us?
Who are we and how to contact us?
Who are we and how to contact us?
Personal data described in this policy is processed by Approveit, Inc., a company incorporated in the State of Delaware with its principal place of business at 455 Valencia Street, San Francisco, CA 94103, USA. The words “we”, “our” and “us” refer to Approveit, Inc.
Contact: support@approveit.today, or Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA.
Data protection contact: Serge Gusev, Chief Executive Officer, serge@approveit.today.
Personal data described in this policy is processed by Approveit, Inc., a company incorporated in the State of Delaware with its principal place of business at 455 Valencia Street, San Francisco, CA 94103, USA. The words “we”, “our” and “us” refer to Approveit, Inc.
Contact: support@approveit.today, or Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA.
Data protection contact: Serge Gusev, Chief Executive Officer, serge@approveit.today.
Personal data described in this policy is processed by Approveit, Inc., a company incorporated in the State of Delaware with its principal place of business at 455 Valencia Street, San Francisco, CA 94103, USA. The words “we”, “our” and “us” refer to Approveit, Inc.
Contact: support@approveit.today, or Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA.
Data protection contact: Serge Gusev, Chief Executive Officer, serge@approveit.today.
Our two roles: processor and controller
Our two roles: processor and controller
Our two roles: processor and controller
Most of the data inside the Approveit Service belongs to our customers. For that data we are a processor: our customers are the controllers, they decide what is processed and why, and we act on their instructions. If you are an employee or contractor of one of our customers and you want to exercise a right over your approval data, contact your employer first. We will refer such requests to them and assist them in responding.
For a smaller set of data we are the controller: our website visitors, prospects, billing contacts, marketing contacts and the people we speak to on sales and support calls.
Our processing as a processor is governed by our Data Processing Addendum, which takes effect automatically when a customer accepts our Terms of Service. No signature is required. If your organization needs a countersigned copy for its records, email support@approveit.today.
Most of the data inside the Approveit Service belongs to our customers. For that data we are a processor: our customers are the controllers, they decide what is processed and why, and we act on their instructions. If you are an employee or contractor of one of our customers and you want to exercise a right over your approval data, contact your employer first. We will refer such requests to them and assist them in responding.
For a smaller set of data we are the controller: our website visitors, prospects, billing contacts, marketing contacts and the people we speak to on sales and support calls.
Our processing as a processor is governed by our Data Processing Addendum, which takes effect automatically when a customer accepts our Terms of Service. No signature is required. If your organization needs a countersigned copy for its records, email support@approveit.today.
Most of the data inside the Approveit Service belongs to our customers. For that data we are a processor: our customers are the controllers, they decide what is processed and why, and we act on their instructions. If you are an employee or contractor of one of our customers and you want to exercise a right over your approval data, contact your employer first. We will refer such requests to them and assist them in responding.
For a smaller set of data we are the controller: our website visitors, prospects, billing contacts, marketing contacts and the people we speak to on sales and support calls.
Our processing as a processor is governed by our Data Processing Addendum, which takes effect automatically when a customer accepts our Terms of Service. No signature is required. If your organization needs a countersigned copy for its records, email support@approveit.today.
What we process as a processor, on our customers’ behalf
What we process as a processor, on our customers’ behalf
Personal data processed in the Approveit Service on our customers’ instructions may include: name, display name and username; email address and company; workplace information such as team or department; identifiers from integrated platforms such as a Slack or Microsoft Teams user ID; the content of approval requests, attachments, comments and workflow messages; the content of instructions submitted to AI features; timestamps such as creation and approval time; and usage logs, audit trails, session recordings and technical metadata needed for the Service to function and stay secure.
Our Data Processing Addendum sets out the full description of this processing.
Personal data processed in the Approveit Service on our customers’ instructions may include: name, display name and username; email address and company; workplace information such as team or department; identifiers from integrated platforms such as a Slack or Microsoft Teams user ID; the content of approval requests, attachments, comments and workflow messages; the content of instructions submitted to AI features; timestamps such as creation and approval time; and usage logs, audit trails, session recordings and technical metadata needed for the Service to function and stay secure.
Our Data Processing Addendum sets out the full description of this processing.
Where we rely on legitimate interests, you may object at any time by contacting support@approveit.today.
Providing the personal data needed to create and administer an account is a requirement of our contract with the customer. Without it we cannot provide the Approveit Service. Providing marketing contact details is optional.
Processing
Processing
Processing
Purpose
Purpose
Purpose
Legal basis (GDPR)
Legal basis (GDPR)
Legal basis (GDPR)
Account creation and administration
Account creation and administration
Account creation and administration
Providing the Service under our Terms
Providing the Service under our Terms
Art. 6(1)(b) contract, or Art. 6(1)(f) legitimate interests where the individual is not the contracting party
Art. 6(1)(b) contract, or Art. 6(1)(f) legitimate interests where the individual is not the contracting party
Billing, invoicing and tax records
Billing, invoicing and tax records
Billing, invoicing and tax records
Taking payment and meeting accounting obligations
Taking payment and meeting accounting obligations
Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation
Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation
Error monitoring and security logging for our own systems
Error monitoring and security logging for our own systems
Error monitoring and security logging for our own systems
Debugging and securing the Service
Debugging and securing the Service
Art. 6(1)(f) legitimate interests; balancing assessment available on request
Art. 6(1)(f) legitimate interests; balancing assessment available on request
Sales and support calls, including recording and transcription where notified
Sales and support calls, including recording and transcription where notified
Sales and support calls, including recording and transcription where notified
Selling and supporting the Service
Selling and supporting the Service
Art. 6(1)(f) legitimate interests; consent where required by local law
Art. 6(1)(f) legitimate interests; consent where required by local law
Marketing emails to business contacts
Marketing emails to business contacts
Marketing emails to business contacts
Promoting the Service
Promoting the Service
Art. 6(1)(f) legitimate interests, or Art. 6(1)(a) consent where required
Art. 6(1)(f) legitimate interests, or Art. 6(1)(a) consent where required
Non-essential cookies and similar technologies
Non-essential cookies and similar technologies
Non-essential cookies and similar technologies
Website analytics and advertising measurement
Website analytics and advertising measurement
Art. 6(1)(a) consent
Art. 6(1)(a) consent
Security monitoring, fraud prevention and audit logging
Security monitoring, fraud prevention and audit logging
Security monitoring, fraud prevention and audit logging
Protecting the Service and its users
Protecting the Service and its users
Art. 6(1)(f); Art. 6(1)(c)
Art. 6(1)(f); Art. 6(1)(c)
Responding to legal and regulatory requests
Responding to legal and regulatory requests
Responding to legal and regulatory requests
Legal compliance
Legal compliance
Art. 6(1)(c)
Art. 6(1)(c)
Where we rely on legitimate interests, you may object at any time by contacting support@approveit.today.
Providing the personal data needed to create and administer an account is a requirement of our contract with the customer. Without it we cannot provide the Approveit Service. Providing marketing contact details is optional.
Where we rely on legitimate interests, you may object at any time by contacting support@approveit.today.
Providing the personal data needed to create and administer an account is a requirement of our contract with the customer. Without it we cannot provide the Approveit Service. Providing marketing contact details is optional.
We do not use inferences to build profiles for advertising or to make decisions about individuals. Apart from account log-in credentials, which we use only to authenticate users and secure accounts, we do not intentionally collect sensitive personal information, and we do not use sensitive personal information to infer characteristics about anyone.
For the preceding twelve months:
Categories of personal information (California)
Categories of personal information (California)
Category
Category
Category
Examples
Examples
Examples
Sources
Sources
Sources
Business purpose
Business purpose
Business purpose
Disclosed to
Disclosed to
Disclosed
to
Sold
Sold
Sold
Shared
Shared
Shared
Identifiers
Identifiers
Name, email, workspace ID, Slack or Teams user ID, IP address, cookie identifiers
Name, email, workspace ID, Slack or Teams user ID, IP address, cookie identifiers
You; your employer; platforms you connect on your instruction; automatically from your device
You; your employer; platforms you connect on your instruction; automatically from your device
Providing and securing the Service; advertising measurement on our marketing website
Providing and securing the Service; advertising measurement on our marketing website
Hosting, support, analytics and AI sub-processors; advertising partners (marketing website only)
Hosting, support, analytics and AI sub-processors; advertising partners (marketing website only)
No
No
Yes, online identifiers through marketing website cookies only
Yes, online identifiers through marketing website cookies only
Yes, online identifiers through marketing website cookies only
Commercial information
Commercial information
Subscription, billing and purchase history
Subscription, billing and purchase history
You; our payment processor
You; our payment processor
Billing, tax and accounting
Billing, tax and accounting
Payment processor, accounting
Payment processor, accounting
No
No
No
No
No
Internet or network activity
Internet or network activity
Usage events, session recordings, error logs, cookie data
Usage events, session recordings, error logs, cookie data
Automatically from your device
Automatically from your device
Analytics, debugging, advertising measurement on our marketing website
Analytics, debugging, advertising measurement on our marketing website
Analytics and error monitoring vendors; advertising partners (marketing website only)
Analytics and error monitoring vendors; advertising partners (marketing website only)
No
No
Yes, marketing website cookies only
Yes, marketing website cookies only
Yes, marketing website cookies only
Professional or employment information
Professional or employment information
Employer, team, role, approval authority
Employer, team, role, approval authority
Your employer
Your employer
Operating approval workflows
Operating approval workflows
Hosting and AI sub-processors
Hosting and AI sub-processors
No
No
No
No
No
Audio and visual information
Audio and visual information
Sales and support call recordings and transcripts
Sales and support call recordings and transcripts
You, with notice at the start of the call
You, with notice at the start of the call
Sales and support
Sales and support
Transcription and conferencing vendors
Transcription and conferencing vendors
No
No
No
No
No
Inferences
Inferences
None
None
-
-
-
-
-
-
No
No
No
No
No
Sensitive personal information
Sensitive personal information
Account log-in credentials
Account log-in credentials
You
You
Authenticating you and securing your account
Authenticating you and securing your account
Hosting sub-processor
Hosting sub-processor
No
No
No
No
No
We do not use inferences to build profiles for advertising or to make decisions about individuals. Apart from account log-in credentials, which we use only to authenticate users and secure accounts, we do not intentionally collect sensitive personal information, and we do not use sensitive personal information to infer characteristics about anyone.
We do not use inferences to build profiles for advertising or to make decisions about individuals. Apart from account log-in credentials, which we use only to authenticate users and secure accounts, we do not intentionally collect sensitive personal information, and we do not use sensitive personal information to infer characteristics about anyone.
Restricted data
Restricted data
The Approveit Service is not designed for special categories of personal data under Article 9 of the GDPR, protected health information, full payment card numbers, or government identification numbers. Unless we have agreed otherwise in writing, our customers are contractually responsible for not submitting them, under our Terms of Service and our Data Processing Addendum. Where such data is submitted contrary to that prohibition, we do not use or disclose it for any purpose that would give rise to a right to limit its use under the CPRA.
The Approveit Service is not designed for special categories of personal data under Article 9 of the GDPR, protected health information, full payment card numbers, or government identification numbers. Unless we have agreed otherwise in writing, our customers are contractually responsible for not submitting them, under our Terms of Service and our Data Processing Addendum. Where such data is submitted contrary to that prohibition, we do not use or disclose it for any purpose that would give rise to a right to limit its use under the CPRA.
Where we get data from
Where we get data from
We collect most personal data directly from you, from your employer where you use Approveit as part of your work, and from platforms you connect on your instruction. We also obtain business contact details for prospective customers from public sources, referral partners and business data providers.
We collect most personal data directly from you, from your employer where you use Approveit as part of your work, and from platforms you connect on your instruction. We also obtain business contact details for prospective customers from public sources, referral partners and business data providers.
Who we share data with
Who we share data with
We use third-party service providers to operate parts of the Approveit Service and to run our business. We share with each provider the data reasonably needed for the service it provides.
Where a provider processes data on our customers’ behalf, it is engaged under a written contract that restricts its use of that data to performing the services for us, and prohibits it from retaining, using or disclosing it for any other purpose or combining it with personal information from other sources. Some providers we engage for our own business operations, such as our payment processor, act as independent controllers for limited purposes such as fraud prevention and regulatory compliance; their own privacy notices govern that processing.
We maintain the current list of sub-processors that process customer data on our customers’ behalf, with each one’s purpose and processing location, in Exhibit 2A of our Data Processing Addendum. That list is the authoritative record. We give customers advance notice of new sub-processors, and customers may object on reasonable data protection grounds, as set out in that Addendum. Hosting, session replay, in-product analytics and error monitoring are performed by sub-processors listed in Exhibit 2A. We also use service providers for our own business operations, including payment processing, CRM and marketing, call recording and transcription, and website analytics; those are listed in Exhibit 2B of the same document.
We use third-party service providers to operate parts of the Approveit Service and to run our business. We share with each provider the data reasonably needed for the service it provides.
Where a provider processes data on our customers’ behalf, it is engaged under a written contract that restricts its use of that data to performing the services for us, and prohibits it from retaining, using or disclosing it for any other purpose or combining it with personal information from other sources. Some providers we engage for our own business operations, such as our payment processor, act as independent controllers for limited purposes such as fraud prevention and regulatory compliance; their own privacy notices govern that processing.
We maintain the current list of sub-processors that process customer data on our customers’ behalf, with each one’s purpose and processing location, in Exhibit 2A of our Data Processing Addendum. That list is the authoritative record. We give customers advance notice of new sub-processors, and customers may object on reasonable data protection grounds, as set out in that Addendum. Hosting, session replay, in-product analytics and error monitoring are performed by sub-processors listed in Exhibit 2A. We also use service providers for our own business operations, including payment processing, CRM and marketing, call recording and transcription, and website analytics; those are listed in Exhibit 2B of the same document.
AI features
AI features
AI features
Approveit offers AI features, including the Approveit AI Assistant in Slack, Microsoft Teams and the web app, and an MCP server that lets you connect Approveit to an AI client of your choice. The AI Assistant works by sending data to a third-party AI model provider. The MCP server sends data only to the AI client you connect.
Who processes the data. The Approveit AI Assistant is powered by Anthropic, PBC (United States), using Anthropic’s commercial API. We do not use consumer AI products for it. Our MCP server does not use Anthropic or any AI model of ours; it passes data to the AI client you choose to connect. Other vendors we use apply their own automated or machine-learning analysis to the data they receive in order to provide their services to us, including PostHog and ELU Labs (product analytics and session replay) and Sentry (error monitoring). Separately, Fathom Video applies automated analysis to our own sales and support call recordings, as described under Sales and support calls. Each is listed in Exhibit 2A or 2B of our Data Processing Addendum with its purpose. If we change or add an AI model provider, we will update Exhibit 2A of our Data Processing Addendum and notify customers at least 30 days before the new provider begins processing customer data.
What is sent. When a user invokes the AI Assistant, we send the text of the user’s instruction and the approval requests, workflow configurations, comments and metadata relevant to that request that the user is already entitled to see in Approveit. Approveit’s access controls apply to the AI Assistant in the same way they apply to the rest of the product.
What is not sent. We do not send data that the requesting user is not already entitled to see in Approveit, and we do not send data from workspaces where the AI Assistant is switched off.
No model training. Approveit does not use customer content to train or fine-tune generative AI models. Where we need to investigate a fault you have reported, we access only the data necessary to do so, under the access controls described in our Data Processing Addendum. Our AI model provider is contractually prohibited from training its models on customer content transmitted through the Approveit Service.
Retention. Our AI model provider retains inputs and outputs for a limited period under its own published policy, and details are available on request. Separately, Approveit stores AI conversations in your workspace so that you can review them, for the period stated in Data retention below.
Human oversight. The Approveit AI Assistant drafts, summarises and answers questions; it does not approve or reject a request on its own. Where your administrator connects an AI client or a service account and gives it permission to act, actions it takes are executed under the Approveit account that authorized it and recorded in your audit trail. You decide whether to grant that permission.
You are dealing with an AI system. Where you interact with the Approveit AI Assistant, you are interacting with an artificial intelligence system and not with a member of our staff. AI output can be incomplete or wrong and should be checked before you rely on it.
Turning it off. A workspace administrator can have the AI Assistant switched off for the whole workspace at any time by contacting us at support@approveit.today. We will action the request promptly and confirm in writing, after which we stop transmitting that workspace’s data to our AI model provider. MCP connections are revoked separately, as described below.
Approveit offers AI features, including the Approveit AI Assistant in Slack, Microsoft Teams and the web app, and an MCP server that lets you connect Approveit to an AI client of your choice. The AI Assistant works by sending data to a third-party AI model provider. The MCP server sends data only to the AI client you connect.
Who processes the data. The Approveit AI Assistant is powered by Anthropic, PBC (United States), using Anthropic’s commercial API. We do not use consumer AI products for it. Our MCP server does not use Anthropic or any AI model of ours; it passes data to the AI client you choose to connect. Other vendors we use apply their own automated or machine-learning analysis to the data they receive in order to provide their services to us, including PostHog and ELU Labs (product analytics and session replay) and Sentry (error monitoring). Separately, Fathom Video applies automated analysis to our own sales and support call recordings, as described under Sales and support calls. Each is listed in Exhibit 2A or 2B of our Data Processing Addendum with its purpose. If we change or add an AI model provider, we will update Exhibit 2A of our Data Processing Addendum and notify customers at least 30 days before the new provider begins processing customer data.
What is sent. When a user invokes the AI Assistant, we send the text of the user’s instruction and the approval requests, workflow configurations, comments and metadata relevant to that request that the user is already entitled to see in Approveit. Approveit’s access controls apply to the AI Assistant in the same way they apply to the rest of the product.
What is not sent. We do not send data that the requesting user is not already entitled to see in Approveit, and we do not send data from workspaces where the AI Assistant is switched off.
No model training. Approveit does not use customer content to train or fine-tune generative AI models. Where we need to investigate a fault you have reported, we access only the data necessary to do so, under the access controls described in our Data Processing Addendum. Our AI model provider is contractually prohibited from training its models on customer content transmitted through the Approveit Service.
Retention. Our AI model provider retains inputs and outputs for a limited period under its own published policy, and details are available on request. Separately, Approveit stores AI conversations in your workspace so that you can review them, for the period stated in Data retention below.
Human oversight. The Approveit AI Assistant drafts, summarises and answers questions; it does not approve or reject a request on its own. Where your administrator connects an AI client or a service account and gives it permission to act, actions it takes are executed under the Approveit account that authorized it and recorded in your audit trail. You decide whether to grant that permission.
You are dealing with an AI system. Where you interact with the Approveit AI Assistant, you are interacting with an artificial intelligence system and not with a member of our staff. AI output can be incomplete or wrong and should be checked before you rely on it.
Turning it off. A workspace administrator can have the AI Assistant switched off for the whole workspace at any time by contacting us at support@approveit.today. We will action the request promptly and confirm in writing, after which we stop transmitting that workspace’s data to our AI model provider. MCP connections are revoked separately, as described below.
Connecting Approveit to your own AI client (MCP)
Connecting Approveit to your own AI client (MCP)
Approveit publishes an MCP server. A workspace administrator may use it to connect Approveit to an AI client operated by you or by a third party, such as Claude. Once you authorise such a connection, that client can read the Approveit data covered by the permissions you granted, and can take the actions you permitted.
When you connect an AI client, you instruct us to disclose that data to it. This is a disclosure for a business purpose at your direction, not a sale. The operator of that client processes the data under its own terms and privacy policy, not ours, and we are not responsible for what it does with the data once it is transmitted. You are responsible for deciding which clients to connect, which permissions to grant, and for revoking access when it is no longer needed. You may revoke an authorized connection at any time, including by contacting us at support@approveit.today.
Approveit publishes an MCP server. A workspace administrator may use it to connect Approveit to an AI client operated by you or by a third party, such as Claude. Once you authorise such a connection, that client can read the Approveit data covered by the permissions you granted, and can take the actions you permitted.
When you connect an AI client, you instruct us to disclose that data to it. This is a disclosure for a business purpose at your direction, not a sale. The operator of that client processes the data under its own terms and privacy policy, not ours, and we are not responsible for what it does with the data once it is transmitted. You are responsible for deciding which clients to connect, which permissions to grant, and for revoking access when it is no longer needed. You may revoke an authorized connection at any time, including by contacting us at support@approveit.today.
Product analytics, session replay and error monitoring
Product analytics, session replay and error monitoring
We use product analytics, session replay and error monitoring tools to understand how the Approveit Service is used and to find and fix faults. These tools record interactions with the interface and capture technical details of errors, which can include content displayed on screen at the time and identifiers of the user concerned. We configure them to mask password and payment fields and attachment contents where the tool supports it. We do not use them for advertising or to build marketing profiles.
A customer can ask us to exclude its workspace from session replay, as set out in our Data Processing Addendum. Contact support@approveit.today.
We use product analytics, session replay and error monitoring tools to understand how the Approveit Service is used and to find and fix faults. These tools record interactions with the interface and capture technical details of errors, which can include content displayed on screen at the time and identifiers of the user concerned. We configure them to mask password and payment fields and attachment contents where the tool supports it. We do not use them for advertising or to build marketing profiles.
A customer can ask us to exclude its workspace from session replay, as set out in our Data Processing Addendum. Contact support@approveit.today.
We use product analytics, session replay and error monitoring tools to understand how the Approveit Service is used and to find and fix faults. These tools record interactions with the interface and capture technical details of errors, which can include content displayed on screen at the time and identifiers of the user concerned. We configure them to mask password and payment fields and attachment contents where the tool supports it. We do not use them for advertising or to build marketing profiles.
A customer can ask us to exclude its workspace from session replay, as set out in our Data Processing Addendum. Contact support@approveit.today.
Sales and support calls
Sales and support calls
We record and transcribe some sales and support calls so that we can follow up accurately and improve our service. Where we do, we tell you before recording begins and, where the law requires it, ask for your consent. You may ask us not to record, and we will not. Recordings are processed by Fathom Video, Inc. and Zoom Video Communications, Inc., and Fathom produces automated transcripts and summaries of them.
We record and transcribe some sales and support calls so that we can follow up accurately and improve our service. Where we do, we tell you before recording begins and, where the law requires it, ask for your consent. You may ask us not to record, and we will not. Recordings are processed by Fathom Video, Inc. and Zoom Video Communications, Inc., and Fathom produces automated transcripts and summaries of them.
Google API Services usage disclosure
Google API Services usage disclosure
Google API Services usage disclosure
The Approveit app uses Google APIs when users sync events created in the app with their Google Calendar. We read calendar data only to the extent needed to create and update the events the app itself creates. We do not modify, copy or store events that Approveit did not create.
Approveit’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer data received from Google APIs to our AI model provider, and we do not use it to develop, train or improve any AI or machine learning model.
The Approveit app uses Google APIs when users sync events created in the app with their Google Calendar. We read calendar data only to the extent needed to create and update the events the app itself creates. We do not modify, copy or store events that Approveit did not create.
Approveit’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer data received from Google APIs to our AI model provider, and we do not use it to develop, train or improve any AI or machine learning model.
Automated decisions
Automated decisions
Automated decisions
Approveit does not, on its own initiative, make automated decisions about you that produce legal effects or similarly significant effects. Our AI Assistant generates suggestions, drafts and summaries.
Every approval action is recorded against the Approveit user account that took it, with the time and, where the action came through an integration or a connected AI client, the client used. Our customers configure their own workflows and integrations, and a customer may choose to create a service account or connect an AI client that submits approval decisions without a person reviewing them. Where a customer does that, the customer decides the purposes and means of that processing and is responsible for meeting any obligations that apply to automated decision-making, including providing human intervention on request. Our role remains that of a processor acting on the customer’s instructions, and the audit trail is available to support the customer in meeting that obligation.
Approveit does not, on its own initiative, make automated decisions about you that produce legal effects or similarly significant effects. Our AI Assistant generates suggestions, drafts and summaries.
Every approval action is recorded against the Approveit user account that took it, with the time and, where the action came through an integration or a connected AI client, the client used. Our customers configure their own workflows and integrations, and a customer may choose to create a service account or connect an AI client that submits approval decisions without a person reviewing them. Where a customer does that, the customer decides the purposes and means of that processing and is responsible for meeting any obligations that apply to automated decision-making, including providing human intervention on request. Our role remains that of a processor acting on the customer’s instructions, and the audit trail is available to support the customer in meeting that obligation.
Security
Security
We maintain an information security program aligned with the AICPA Trust Services Criteria, including encryption of personal data in transit and at rest in our production environment, least-privilege access control, logical separation of each customer’s data, vulnerability scanning, logging and monitoring, and security training for our personnel. The full technical and organizational measures are set out in our Data Processing Addendum. We maintain a SOC 2 Type II attestation, and our then-current report is available to customers under confidentiality on request, for the scope and period stated in it. No method of transmission or storage is completely secure. While we work to protect personal data using the measures described above, we cannot guarantee its absolute security.
We maintain an information security program aligned with the AICPA Trust Services Criteria, including encryption of personal data in transit and at rest in our production environment, least-privilege access control, logical separation of each customer’s data, vulnerability scanning, logging and monitoring, and security training for our personnel. The full technical and organizational measures are set out in our Data Processing Addendum. We maintain a SOC 2 Type II attestation, and our then-current report is available to customers under confidentiality on request, for the scope and period stated in it. No method of transmission or storage is completely secure. While we work to protect personal data using the measures described above, we cannot guarantee its absolute security.
Data breach notification
Data breach notification
If we become aware of a personal data breach affecting data we process on a customer’s behalf, we notify that customer as required by our Data Processing Addendum. Where we are the controller, we notify affected individuals and the relevant supervisory authorities as required by law.
If we become aware of a personal data breach affecting data we process on a customer’s behalf, we notify that customer as required by our Data Processing Addendum. Where we are the controller, we notify affected individuals and the relevant supervisory authorities as required by law.
Legal and law enforcement disclosures
Legal and law enforcement disclosures
We may disclose personal data where required by law, court order or a binding request from a public authority, or, for data for which we are the controller, to establish, exercise or defend legal claims. Where the request concerns data we process on a customer’s behalf, we notify that customer promptly unless we are legally prohibited from doing so, and, where notice is prohibited, we use commercially reasonable efforts to obtain a waiver or to limit the scope of the disclosure.
We may disclose personal data where required by law, court order or a binding request from a public authority, or, for data for which we are the controller, to establish, exercise or defend legal claims. Where the request concerns data we process on a customer’s behalf, we notify that customer promptly unless we are legally prohibited from doing so, and, where notice is prohibited, we use commercially reasonable efforts to obtain a waiver or to limit the scope of the disclosure.
Business transfers
Business transfers
If we are involved in a merger, acquisition, financing, reorganization or sale of assets, personal data may be transferred as part of that transaction. We will post notice of any resulting change to this policy on this page.
If we are involved in a merger, acquisition, financing, reorganization or sale of assets, personal data may be transferred as part of that transaction. We will post notice of any resulting change to this policy on this page.
Aggregated and de-identified data
Aggregated and de-identified data
We may create aggregated and de-identified data from our operation of the Service, such as feature usage counts, latency and error rates, and use it to operate, secure, improve and develop our products. We keep de-identified data in de-identified form, do not attempt to re-identify it, and require anyone we share it with to do the same.
We may create aggregated and de-identified data from our operation of the Service, such as feature usage counts, latency and error rates, and use it to operate, secure, improve and develop our products. We keep de-identified data in de-identified form, do not attempt to re-identify it, and require anyone we share it with to do the same.
Third-party services and links
Third-party services and links
Third-party services and links
Our website and the Approveit Service may link to, or be connected by you to, services operated by third parties, including Slack, Microsoft Teams, Google and accounting systems. Those services are controlled by the third parties that operate them, and their own privacy policies and security practices apply. We are not responsible for their content, practices or availability.
Our website and the Approveit Service may link to, or be connected by you to, services operated by third parties, including Slack, Microsoft Teams, Google and accounting systems. Those services are controlled by the third parties that operate them, and their own privacy policies and security practices apply. We are not responsible for their content, practices or availability.
Data residency
Data residency
Data residency
We host the Approveit Service on Amazon Web Services in the United States by default. EU hosting of primary data storage is available to customers on request. Support, monitoring and AI features may still involve access from or transfer to the United States, as set out in our Data Processing Addendum. Our support platform operates in the United States or the European Union.
We host the Approveit Service on Amazon Web Services in the United States by default. EU hosting of primary data storage is available to customers on request. Support, monitoring and AI features may still involve access from or transfer to the United States, as set out in our Data Processing Addendum. Our support platform operates in the United States or the European Union.
Cookies
Cookies
Cookies
A cookie is a file containing an identifier that is sent by a web server to a web browser and stored by the browser. The identifier is then sent back to the server each time the browser requests a page.
Necessary cookies make the website usable by enabling basic functions such as page navigation and access to secure areas. Statistic cookies help us understand how visitors interact with the website. Marketing cookies may be used on our marketing website to show relevant advertising, including on other websites.
Where the law requires your prior consent, we set non-essential cookies only after you accept them. Everywhere else, you can reject them at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, and we will stop. We do not use advertising or marketing cookies inside the authenticated Approveit Service.
We do not respond to Do Not Track browser signals, which have no agreed technical standard. Where required by applicable law, we treat a Global Privacy Control signal as a request to opt out of sale and sharing for that browser.
A cookie is a file containing an identifier that is sent by a web server to a web browser and stored by the browser. The identifier is then sent back to the server each time the browser requests a page.
Necessary cookies make the website usable by enabling basic functions such as page navigation and access to secure areas. Statistic cookies help us understand how visitors interact with the website. Marketing cookies may be used on our marketing website to show relevant advertising, including on other websites.
Where the law requires your prior consent, we set non-essential cookies only after you accept them. Everywhere else, you can reject them at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, and we will stop. We do not use advertising or marketing cookies inside the authenticated Approveit Service.
We do not respond to Do Not Track browser signals, which have no agreed technical standard. Where required by applicable law, we treat a Global Privacy Control signal as a request to opt out of sale and sharing for that browser.
Sale and sharing of personal information
Sale and sharing of personal information
Sale and sharing of personal information
We do not sell personal information for monetary or other valuable consideration, and we have not done so in the preceding twelve months.
We do share personal information for cross-context behavioral advertising on our marketing website, approveit.today, through advertising cookies. Under the California Privacy Rights Act this is “sharing”. You can opt out at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, or by sending a Global Privacy Control signal from your browser, as described under Cookies.
We do not sell or share any personal data that our customers process through the Approveit Service. We do not knowingly sell or share the personal information of consumers under 16 years of age.
We do not sell personal information for monetary or other valuable consideration, and we have not done so in the preceding twelve months.
We do share personal information for cross-context behavioral advertising on our marketing website, approveit.today, through advertising cookies. Under the California Privacy Rights Act this is “sharing”. You can opt out at any time through the cookie preference centre, reachable from the “Cookie settings” link in our website footer, or by sending a Global Privacy Control signal from your browser, as described under Cookies.
We do not sell or share any personal data that our customers process through the Approveit Service. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Your rights
Your rights
Your rights
Depending on where you live, you may have the right to: be informed about our processing; access your personal data; have it corrected; have it deleted; restrict processing; object to processing, including for direct marketing; withdraw consent where we rely on it; receive your data in a portable format; and not be subject to solely automated decisions with legal or similarly significant effects.
California residents also have the right to know what personal information we collect and why, to opt out of sale or sharing, to limit the use of sensitive personal information (which does not apply to our use of log-in credentials described above), and not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right.
How to exercise them. Email support@approveit.today. You may use an authorized agent; we will ask the agent for proof of authorisation and may ask you to verify your identity directly. Before we act on a request we take steps to verify your identity, which may include matching your information against our records.
How long we take. For GDPR and UK GDPR requests we respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. For CCPA requests we acknowledge receipt within 10 business days and respond within 45 days, extendable once by a further 45 days.
If we decline. You may appeal by emailing support@approveit.today with “Appeal” in the subject line. We will respond within 45 days with our decision and our reasons, and will tell you how to complain to your state Attorney General. You also have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or where you believe an infringement has taken place.
Where Approveit acts as a processor on behalf of a customer, we will refer your request to that customer and assist them in responding.
Depending on where you live, you may have the right to: be informed about our processing; access your personal data; have it corrected; have it deleted; restrict processing; object to processing, including for direct marketing; withdraw consent where we rely on it; receive your data in a portable format; and not be subject to solely automated decisions with legal or similarly significant effects.
California residents also have the right to know what personal information we collect and why, to opt out of sale or sharing, to limit the use of sensitive personal information (which does not apply to our use of log-in credentials described above), and not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right.
How to exercise them. Email support@approveit.today. You may use an authorized agent; we will ask the agent for proof of authorisation and may ask you to verify your identity directly. Before we act on a request we take steps to verify your identity, which may include matching your information against our records.
How long we take. For GDPR and UK GDPR requests we respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. For CCPA requests we acknowledge receipt within 10 business days and respond within 45 days, extendable once by a further 45 days.
If we decline. You may appeal by emailing support@approveit.today with “Appeal” in the subject line. We will respond within 45 days with our decision and our reasons, and will tell you how to complain to your state Attorney General. You also have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or where you believe an infringement has taken place.
Where Approveit acts as a processor on behalf of a customer, we will refer your request to that customer and assist them in responding.
Depending on where you live, you may have the right to: be informed about our processing; access your personal data; have it corrected; have it deleted; restrict processing; object to processing, including for direct marketing; withdraw consent where we rely on it; receive your data in a portable format; and not be subject to solely automated decisions with legal or similarly significant effects.
California residents also have the right to know what personal information we collect and why, to opt out of sale or sharing, to limit the use of sensitive personal information (which does not apply to our use of log-in credentials described above), and not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right.
How to exercise them. Email support@approveit.today. You may use an authorized agent; we will ask the agent for proof of authorisation and may ask you to verify your identity directly. Before we act on a request we take steps to verify your identity, which may include matching your information against our records.
How long we take. For GDPR and UK GDPR requests we respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. For CCPA requests we acknowledge receipt within 10 business days and respond within 45 days, extendable once by a further 45 days.
If we decline. You may appeal by emailing support@approveit.today with “Appeal” in the subject line. We will respond within 45 days with our decision and our reasons, and will tell you how to complain to your state Attorney General. You also have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or where you believe an infringement has taken place.
Where Approveit acts as a processor on behalf of a customer, we will refer your request to that customer and assist them in responding.
International data transfers
International data transfers
International data transfers
Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supported by a transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we may also rely on that certification. The relevant clauses are incorporated into our Data Processing Addendum and copies are available on request.
Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supported by a transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we may also rely on that certification. The relevant clauses are incorporated into our Data Processing Addendum and copies are available on request.
Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where applicable, supported by a transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we may also rely on that certification. The relevant clauses are incorporated into our Data Processing Addendum and copies are available on request.
We retain personal data for no longer than necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
Data retention
Data retention
Data retention
We retain personal data for no longer than necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
We retain personal data for no longer than necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
Data
Data
Data
Retention
Retention
Retention
Content customers submit to the Service, including approval requests and AI conversations
Content customers submit to the Service, including approval requests and AI conversations
Content customers submit to the Service, including approval requests and AI conversations
Life of the account, and after termination until the customer asks us to delete it. We may delete it at our discretion from 90 days after termination
Life of the account, and after termination until the customer asks us to delete it. We may delete it at our discretion from 90 days after termination
MCP connection records and access logs
MCP connection records and access logs
MCP connection records and access logs
Connection records for as long as the connection is authorized; access logs for the life of the account
Connection records for as long as the connection is authorized; access logs for the life of the account
Account details
Account details
Account details
Life of the account, and after termination on the same basis as customer content
Life of the account, and after termination on the same basis as customer content
Purchase and billing history
Purchase and billing history
Purchase and billing history
7 years from the transaction date, for accounting and tax
7 years from the transaction date, for accounting and tax
Marketing contact data
Marketing contact data
Marketing contact data
3 years from collection or until you opt out
3 years from collection or until you opt out
Session recordings
Session recordings
Session recordings
Up to 30 days
Up to 30 days
Error logs
Error logs
Error logs
Up to 90 days
Up to 90 days
Support conversations
Support conversations
Support conversations
Up to 3 years from last contact, or earlier if the customer asks us to delete them
Up to 3 years from last contact, or earlier if the customer asks us to delete them
Sales and support call recordings and transcripts
Sales and support call recordings and transcripts
Sales and support call recordings and transcripts
Up to 12 months
Up to 12 months
Website analytics and cookie data
Website analytics and cookie data
Up to 13 months
Up to 13 months
Website analytics and cookie data
Approval records and other content customers submit are retained for as long as the customer’s account is active, and after termination until the customer asks us to delete it, because customers rely on that record as their approval history. We do not delete that content on a schedule of our own, although we may delete it at our discretion from 90 days after termination. A customer can ask us to delete specific records at any time by contacting support@approveit.today. Where a period above is stated as “up to”, it is a maximum for our active systems. Where we are the controller, we may retain data for longer where required by law, to resolve disputes or to enforce our agreements. Data in encrypted backups is isolated from active processing and is removed in the ordinary course of backup rotation.
Approval records and other content customers submit are retained for as long as the customer’s account is active, and after termination until the customer asks us to delete it, because customers rely on that record as their approval history. We do not delete that content on a schedule of our own, although we may delete it at our discretion from 90 days after termination. A customer can ask us to delete specific records at any time by contacting support@approveit.today. Where a period above is stated as “up to”, it is a maximum for our active systems. Where we are the controller, we may retain data for longer where required by law, to resolve disputes or to enforce our agreements. Data in encrypted backups is isolated from active processing and is removed in the ordinary course of backup rotation.
Communications about your account, and marketing
Communications about your account, and marketing
We use your contact details to send you transactional messages about your account, security and the operation of the Service. These are not marketing and you cannot opt out of them while you hold an account.
Where required by applicable law we will obtain your consent before sending marketing communications. Where consent is not required, we may send marketing communications to your business contact details, and marketing consent is never a condition of using Approveit. You can opt out at any time using the unsubscribe link in any marketing email or by emailing support@approveit.today.
We do not sell your contact information to third-party marketers or provide it to them for their own marketing.
We use your contact details to send you transactional messages about your account, security and the operation of the Service. These are not marketing and you cannot opt out of them while you hold an account.
Where required by applicable law we will obtain your consent before sending marketing communications. Where consent is not required, we may send marketing communications to your business contact details, and marketing consent is never a condition of using Approveit. You can opt out at any time using the unsubscribe link in any marketing email or by emailing support@approveit.today.
We do not sell your contact information to third-party marketers or provide it to them for their own marketing.
Approval records and other content customers submit are retained for as long as the customer’s account is active, and after termination until the customer asks us to delete it, because customers rely on that record as their approval history. We do not delete that content on a schedule of our own, although we may delete it at our discretion from 90 days after termination. A customer can ask us to delete specific records at any time by contacting support@approveit.today. Where a period above is stated as “up to”, it is a maximum for our active systems. Where we are the controller, we may retain data for longer where required by law, to resolve disputes or to enforce our agreements. Data in encrypted backups is isolated from active processing and is removed in the ordinary course of backup rotation.
Changes to this Policy
Changes to this Policy
Communications about your account, and marketing
We use your contact details to send you transactional messages about your account, security and the operation of the Service. These are not marketing and you cannot opt out of them while you hold an account.
Where required by applicable law we will obtain your consent before sending marketing communications. Where consent is not required, we may send marketing communications to your business contact details, and marketing consent is never a condition of using Approveit. You can opt out at any time using the unsubscribe link in any marketing email or by emailing support@approveit.today.
We do not sell your contact information to third-party marketers or provide it to them for their own marketing.
We update this policy when our practices change, and we post the updated version here with a new last-updated date. Where a change is material, we will also tell customers by email or through the Service before it takes effect. New sub-processors are notified to customers as set out in our Data Processing Addendum, and any change of AI model provider at least 30 days in advance. Previous versions are available on request.
We update this policy when our practices change, and we post the updated version here with a new last-updated date. Where a change is material, we will also tell customers by email or through the Service before it takes effect. New sub-processors are notified to customers as set out in our Data Processing Addendum, and any change of AI model provider at least 30 days in advance. Previous versions are available on request.
We update this policy when our practices change, and we post the updated version here with a new last-updated date. Where a change is material, we will also tell customers by email or through the Service before it takes effect. New sub-processors are notified to customers as set out in our Data Processing Addendum, and any change of AI model provider at least 30 days in advance. Previous versions are available on request.
Children
Children
Changes to this Policy
The Approveit Service is offered to businesses and is not intended for individuals under 18 years of age, consistent with our Terms of Service. If we learn that we have collected personal data from someone under 18, we will take steps to delete it.
The Approveit Service is offered to businesses and is not intended for individuals under 18 years of age, consistent with our Terms of Service. If we learn that we have collected personal data from someone under 18, we will take steps to delete it.
Accessibility
Accessibility
Children
This policy is published in accessible HTML. If you need it in another format, contact support@approveit.today.
This policy is published in accessible HTML. If you need it in another format, contact support@approveit.today.
Compliance
Compliance
Accessibility
The Approveit Service is offered to businesses and is not intended for individuals under 18 years of age, consistent with our Terms of Service. If we learn that we have collected personal data from someone under 18, we will take steps to delete it.
We design our practices to comply with the privacy laws applicable to our business, including the GDPR, the UK GDPR, the CCPA and CPRA, and other US state privacy laws. Residents of other US states with comprehensive privacy laws have rights equivalent to those described above, including the right to appeal a declined request, and may exercise them through support@approveit.today.
For any question about this policy or our privacy practices, email support@approveit.today.
We design our practices to comply with the privacy laws applicable to our business, including the GDPR, the UK GDPR, the CCPA and CPRA, and other US state privacy laws. Residents of other US states with comprehensive privacy laws have rights equivalent to those described above, including the right to appeal a declined request, and may exercise them through support@approveit.today.
For any question about this policy or our privacy practices, email support@approveit.today.
Compliance
This policy is published in accessible HTML. If you need it in another format, contact support@approveit.today.
We design our practices to comply with the privacy laws applicable to our business, including the GDPR, the UK GDPR, the CCPA and CPRA, and other US state privacy laws. Residents of other US states with comprehensive privacy laws have rights equivalent to those described above, including the right to appeal a declined request, and may exercise them through support@approveit.today.
For any question about this policy or our privacy practices, email support@approveit.today.
©2026 All rights reserved. Approveit, Inc.





