Legal

Privacy Policy

This Policy explains how PASMA handles personal information when people visit our website, use a company account, communicate with us, or interact with our procurement services.

Effective date: July 27, 2026

1. Scope and responsibility

This Policy applies to personal information processed by PASMA("PASMA," "we," "us," or "our") through our website, company portal, procurement services, communications, and related operations.

The organization that invites a user may also control information processed through its company account. Users should contact their company administrator about the company, `'`, own privacy practices.

2. Information we collect

  • Account data: name, work email, phone number, job title, department, role, authentication identifiers, and account status.
  • Company data: organization details, billing and delivery information, tax or registration details, and company settings.
  • Procurement data: catalog access, products, quantities, purchase requests, approvals, prices, invoices, notes, and fulfillment records.
  • Communications: support messages, invitations, feedback, and correspondence.
  • Technical data: IP address, browser, device, login activity, timestamps, pages viewed, errors, and security logs.
  • Uploaded content: product images, company logos, documents, and other authorized materials.

Please do not submit unnecessary sensitive personal information in product notes, purchase requests, or support messages.

3. How we use information

  • Create, authenticate, secure, and administer accounts.
  • Verify company membership, roles, permissions, and staff assignments.
  • Provide company-specific catalogs, pricing, and procurement features.
  • Review and process requests, orders, invoices, fulfillment, and delivery matters.
  • Communicate about accounts, invitations, products, service updates, and support.
  • Maintain records, diagnose errors, improve operations, and protect security.
  • Comply with legal, contractual, tax, accounting, and dispute-resolution duties.

Where applicable law requires a legal basis, processing may be based on contract, legal obligation, legitimate interests, or consent.

4. How we share information

We may disclose information to:

  • The user `'`, company, company administrators, and authorized company users.
  • PASMA staff and contractors who need the information to perform their duties.
  • Suppliers, fulfillment providers, delivery partners, and professional advisers involved in the service.
  • Hosting, authentication, storage, email, payment, analytics, security, and other technology providers.
  • Authorities where disclosure is required or permitted by law.
  • A buyer, investor, successor, or adviser in a business transaction.

PASMA does not sell personal information for monetary consideration. We may disclose information to service providers and business partners for the operational purposes described in this Policy.

5. Company-account visibility

Company administrators and authorized users may be able to view account details, procurement activity, requests, approvals, and records associated with their organization. A company may retain its own records after an individual leaves the organization.

6. Cookies, browser storage, and logs

PASMA may use cookies, browser storage, and similar technologies for authentication, session continuity, preferences, security, and service operation. We may collect technical logs needed to maintain, protect, and improve the service.

Where optional analytics or marketing technologies are introduced, PASMA will provide notices or choices required by applicable law.

7. Data retention

We retain personal information for as long as reasonably necessary to provide services, maintain company and transaction records, resolve disputes, protect security, enforce agreements, and satisfy legal, accounting, tax, and regulatory requirements.

8. Information security

PASMA uses administrative, technical, and organizational safeguards intended to protect information, including role-based access, authentication, database and storage controls, logging, and secure service providers. No system or transmission method can be guaranteed to be completely secure.

9. International data transfers

PASMA and its providers may process information in countries other than the country where the individual is located. Where required, we use contractual, organizational, or other lawful safeguards.

10. Privacy rights and choices

Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about how their data is used. Rights may be subject to exceptions and identity verification.

Requests may be sent to privacy@pasma.example. A company user may also need to contact the company `'`, administrator when the company controls the relevant information.

11. Children

PASMA is a business-to-business service and is not directed to children. Individuals who cannot legally enter a business agreement in their location must not create or use an account without valid authorization and any legally required consent.

12. Changes and contact

We may update this Policy to reflect changes in services, information practices, security, or legal obligations. The effective date at the top will be updated.

Privacy questions and requests may be sent to privacy@pasma.example. Written correspondence may be sent to PASMA, Add PASMA's registered business address.