Trust & technology · how we keep your data yours

Your data never leaves your systems.
Our numbers never arrive without sources.

eprocurz is built for global enterprises entering emerging markets — which means enterprise-grade data discipline from day one, verifiable rather than claimed.

Pledge 01

Client-tenant architecture. Your spend files, contracts and bids live in your own Drive/SharePoint. We work inside your environment on access you can revoke any minute.

Pledge 02

Sourced or flagged. Every number we publish is sourced and dated, or clearly marked illustrative. Nobody pays to appear in our data — not landlords, builders or vendors.

Pledge 03

Human-reviewed AI. Our digital employees draft; a 26-year procurement professional reviews and signs. AI tools we use never train on your inputs.

01 · The technology layer

Four layers, engineered so data barely travels

Layer 1 — Your tenant (system of record)your control

Engagement folders are created in your cloud workspace. Raw documents — spend extracts, contracts, vendor bids — are never copied to eprocurz systems. Access is named-user, least-privilege, and revocable by you instantly. Offboarding ends with a written deletion certificate.

Layer 2 — Digital employees (AI workforce)human-in-loop

Named AI agents handle drafting, market scans, bid normalization and contract clause extraction — always on commercial AI tiers with no-training-on-inputs guarantees, always with client identities replaced by codenames before any prompt, and always with human review before anything reaches you. Award decisions and negotiations are never delegated to AI.

Layer 3 — The intelligence spineanonymized by design

What we retain is deliberately minimal: derived, anonymized market facts — a rate, a lease term, a clause position — under an explicit licence in our agreement. No client names, no documents. Benchmarks are published only when aggregated from three or more independent sources.

Layer 4 — Client memory & continuityevery thread kept

Every client relationship has its own separated knowledge base: interaction logs, decision registers and commitment trackers per service line — so context is never lost between conversations, and no other client's context can ever bleed into yours.

02 · Data protection

Three labels. Clear rules. Written into the contract.

ClassificationExamplesWhere it livesRetention
Client-ConfidentialSpend data, contracts, bids, strategiesYour tenant onlyEngagement + 30 days, then deletion certificate
Derived-AnonymizedMarket rates, clause positions, cycle benchmarks (codenamed)eprocurz spineRetained under contractual licence; ≥3-source rule before any publication
PublicState policies, published market reportsOpen sources, citedRefreshed with last-verified dates
03 · GDPR & DPDP alignment

Built for EU and global parents, registered under India's DPDP era

Our clients are global enterprises — EU, UK, US and beyond — establishing centres in emerging markets. Our practices are aligned to GDPR principles and India's Digital Personal Data Protection (DPDP) Act, and are designed around a simple advantage: we process very little personal data at all. Our work concerns organisational spend, suppliers and contracts.

PrincipleHow eprocurz applies it
Data minimisationWe collect only what a sourcing event needs; personal data is limited to professional contact details of deal participants.
Purpose limitationData is used solely for the contracted engagement; anonymized derivatives only under explicit licence.
Processor role & DPAWhere we touch personal data, we act as a processor on your documented instructions. A Data Processing Addendum is available on request, including Standard Contractual Clauses where transfers require them.
Storage limitationClient-Confidential material: engagement + 30 days, then certified deletion. You can request earlier deletion at any time.
Data-subject rightsAccess, correction and erasure requests are honoured within statutory timelines; contact privacy@eprocurz.com.
Residency by architectureBecause raw data stays in your tenant, it inherits your residency, region and retention configuration — the cleanest possible answer to data-localisation questions.
Honest status: eprocurz maintains GDPR- and DPDP-aligned practices and contracts; we do not claim certifications we haven't earned. Our roadmap: professional-indemnity & cyber cover at first engagement, independent security review (VAPT) in year one, ISO-27001-aligned controls as we scale. This page is updated as each lands.
04 · The responsible-AI charter

Verifiable, not just claimed

CommitmentThe proof mechanism
No training on your dataCommercial AI tiers with contractual no-training guarantees only
Identity protectionClient codenames replace names before any AI prompt
Human accountabilityEvery AI output passes a human threshold — the founder’s 26 years of Real Estate, Facilities & Procurement category leadership — before it reaches a client; awards and negotiations are human-only
Provenance on every numberSource type, date and confidence level cited in every paid report; illustrative figures labelled as such
Conflict-free, auditedAnnual independent CA attestation that our books contain zero supplier-side income — published
Savings you can trustCertificates signed by your finance team; CA-countersigned above ₹25L, per our public Verification Protocol

Ask us the hard questions.

Security questionnaires, DPA requests, architecture walkthroughs — welcomed, not tolerated.

Request our DPA / security pack → Back to the GCC engine