Privacy Policy

Last updated 2026-09-13

What we store

If you have an Agreedum account: your name and email address, which sign-in method you use (Google, Microsoft, or an emailed one-time code), the IP address and browser identifier recorded for each of your sign-in sessions, the organizations you belong to, and the content your organization creates in the product — requirement catalog entries, functional requirement documents (FRDs) and their attachments, baselines and change requests, approval records, and the hash-chained audit log of who did what and when.

If you never create an account but are invited to review or approve something: your email address and name, the decision and any comment you add, plus the IP address and browser identifier from which the decision was made — kept as evidence with the approval record.

Where your data lives

Customer data is stored in the EU region — our managed database and object storage both run in an EU data center (eu-west-1). We do not replicate customer content outside the EU.

Subprocessors

We use a small number of subprocessors to run the service: a managed Postgres database provider and an object storage provider, both hosted in the EU; a hosting/compute provider that runs the application itself and renders every page and export, with its functions pinned to the EU (Dublin); an email provider, used to send one-time sign-in codes and notifications; and Stripe, used only to process payment for self-serve plans. Stripe handles your card details directly — we never see or store your card number.

Retention and deletion

You can export any document as a PDF or Word file, and — on plans with the entitlement — generate a full evidence pack, at any time from within the product.

Deleting an organization is a two-step process. A staff member first marks the organization for deletion, starting a grace period (30 days by default) during which the deletion can still be reversed — unless a verified erasure obligation (for example under your data-processing agreement) is recorded on the request, in which case the hard delete can proceed sooner. After the grace period (or that verification), a hard delete requires sign-off from two separate staff members ("four-eyes") and anonymises the organization's row in our systems, producing a tamper-evident certificate that records the deletion took place.

Anonymising the organization does not erase everything. Decided document versions, approvals, baselines and attachments are retained — our database rules refuse to delete them. The audit log and reviewer records are also retained, though for a different reason: the deletion process does not remove them. Once every access path into the organization (memberships, invitations, review links) is removed, all of this becomes unreachable through the product. There is no fixed retention period for this residual data today. Personal data embedded inside your own content — for example, a name mentioned in a requirement's text or in a file you uploaded — is part of that content and is not separately scrubbed out of it. If content containing personal data needs to be removed, that has to happen before the organization is deleted.

Your rights and how to reach us

To ask what data we hold about you, request a correction, or request deletion of your organization, write to us through the contact form on this site. We usually reply within a few business days.