Draft — pending legal review. This page describes what the product actually does today. It is not yet reviewed by a lawyer and must not be treated as a binding policy until it is (CUTOVER-RUNBOOK.md §2.4).

Privacy Policy

Last updated: draft, not yet published.

What we collect

Account details you provide (name, email), the organization data you or your team create (service catalog, request content, comments, approval decisions), and operational logs needed to run the service (email delivery status, error tracking once enabled).

Where it's processed

Sub-processors used to run Fulfilra:

  • Supabase — database, authentication
  • Vercel — application hosting
  • Resend — transactional email delivery
  • Atlassian — Jira/JSM integration, when connected
  • PostHog — product analytics, once enabled for your organization

Retention

Email delivery logs (the notifications table) are kept for 90 days and then automatically deleted. Request, catalog, and approval data is kept for as long as your organization exists on Fulfilra.

Deletion

An organization admin can permanently delete the organization and everything in it — catalog, requests, members, and history — from Organization Settings at any time. This is the mechanism for exercising the right to erasure. Contact support@itsm-ltd.com for anything the self-service control doesn't cover.

Contact

Questions about this policy: support@itsm-ltd.com