Privacy Policy
Last updated: August 12, 2026
Introduction
Paitify (“we,” “our,” or “us”) is operated by Bera Software & Consultancy Ltd (company number 12073744, registered in England and Wales), and provides the Paitify spend policy engine platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, and is written to comply with UK GDPR and the Data Protection Act 2018. By using Paitify, you agree to the practices described herein.
If you do not agree with the terms of this Privacy Policy, please do not access the Service.
Information We Collect
We collect several types of information in connection with the Service:
- Account data: Name, email address, and company name you provide during registration.
- Agent transaction data: Authorization requests submitted by your AI agents, including amounts, currencies, merchant identifiers, MCC codes, and timestamps.
- Audit logs: A complete record of every authorization decision including rule evaluations, approval/denial reasons, and agent identifiers.
- Policy configuration: Spend limits, allowed/blocked MCC codes, merchant lists, velocity windows, and business hours settings you configure.
- Usage data: Log data such as IP addresses, browser type, pages visited, and API request metadata collected automatically.
- API key metadata: We store API key prefixes and usage timestamps, but never the full plaintext key after initial issuance.
- Billing data: Plan tier, subscription status, and payment details, processed for us by Stripe (see Third-Party Services below) — we do not store your full card details ourselves.
Lawful Basis for Processing
Under UK GDPR, we rely on the following lawful bases to process your data:
- Contract:Processing account data, agent transaction data, policy configuration, and billing data is necessary to provide the Service you've signed up for.
- Legitimate interests: Processing usage data and audit logs to secure the Service, detect and prevent fraud or abuse, and improve our product.
- Legal obligation: Processing necessary to comply with applicable law, such as tax and accounting record-keeping.
How We Use Your Information
We use the collected information to:
- Provide, operate, and maintain the Paitify Service
- Evaluate authorization requests against your configured policies in real time
- Generate audit logs and analytics dashboards for your account
- Send transactional notifications (e.g., approval requests, spend alerts)
- Detect and prevent fraudulent or unauthorized use of the Service
- Improve our Service through aggregate, anonymized usage analysis
- Respond to customer support requests
- Comply with legal obligations
We do not sell, rent, or trade your personal data or your agents' transaction data to third parties for marketing purposes.
Data Retention
Authorization decisions are written to an append-only audit log that we do not delete, so that it remains a reliable, tamper-evident record. Your plan determines how much of that history is visible and exportable through the dashboard and API — data outside that window still exists but is not shown to you:
- Free plan: Audit log visible for the last 7 days.
- Starter plan: Audit log visible for the last 90 days.
- Growth plan: Audit log visible for the last 365 days.
- Account data: Retained for the duration of your account plus 30 days after termination, then deleted.
You may request deletion of your account data (not the audit log, which is retained by design — see above) by contacting info@paitify.io.
Third-Party Services
We use the following third-party services (sub-processors) to operate Paitify:
- Clerk: Authentication and user management. Clerk processes your email and identity data under their own privacy policy. See clerk.com/privacy.
- Railway:Application hosting, and our PostgreSQL database and Redis cache, all running on Railway's managed infrastructure.
- Resend:Transactional email delivery for notifications and alerts. Email content is transmitted through Resend's infrastructure. See resend.com/privacy.
- Stripe: Billing and payment processing for paid plans. Stripe processes your payment details directly — we do not store full card numbers. See stripe.com/privacy.
International Data Transfers
Our infrastructure (application, database, and cache) is hosted in the European Union. Some of our sub-processors (such as Clerk, Resend, and Stripe) may process data outside the UK and EU, including in the United States. Where that happens, we rely on the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or an equivalent adequacy mechanism, to safeguard your data.
Data Security
We implement industry-standard security measures including TLS encryption in transit, RSA-2048 signed JWT tokens, and role-based access controls. API keys are hashed before storage — only the prefix is retained after initial issuance.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Portability: Request your data in a machine-readable format.
- Objection: Object to processing of your data for certain purposes.
- CCPA: California residents have the right to know what personal information is collected, the right to delete, and the right to opt out of sale (we do not sell personal data).
To exercise your rights, contact info@paitify.io. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO), our supervisory authority, at ico.org.uk.
Cookies
We use essential session cookies required for authentication (provided by Clerk). We do not use third-party advertising cookies or cross-site tracking.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated “last updated” date. Continued use of the Service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Bera Software & Consultancy Ltd
Privacy inquiries: info@paitify.io