Legal
Privacy policy
Last updated: September 2026. This is a template policy provided for the product foundation and must be reviewed by counsel before publication.
1. Who we are
APIXX Supplier Connect is operated by APIXX. For questions about this policy contact support@apixx.com.
2. Data we process
Account data for buyer users (name, email, role), supplier contact data provided by our customers, supplier-submitted business information (addresses, tax classification, masked banking details, documents such as W-9s and insurance certificates), invoice and payment records synchronized from the customer's ERP, and technical logs including IP address and user agent for security.
3. Roles
For supplier data processed on behalf of a customer organization, the customer is the controller and APIXX is the processor. For buyer account and billing data, APIXX is the controller.
4. How we use data
To provide the service, synchronize with the customer's ERP, send transactional notifications, secure the platform, and meet legal obligations. We do not sell personal data or use it for advertising.
5. Retention
Data is retained for the life of the customer's subscription and deleted or returned within 90 days of termination, except where retention is required by law. Audit logs are retained for a minimum of seven years where required for financial record-keeping.
6. Security
Encryption in transit and at rest, row-level access controls, masked storage of banking and tax identifiers, and an append-only audit log. See the Security page for details.
7. Your rights
Depending on your jurisdiction you may have rights to access, correct, delete, or export your personal data. Supplier users should direct requests to the customer organization that invited them; we will assist that organization in responding.
8. Changes
We will notify customers of material changes to this policy by email and by updating the date above.

