Privacy Policy
Last updated: 18 August 2026
1. Who we are
approve-it.online ("we", "us", "our") is a purchase-approval platform operated by Go Live AI. For the personal data your organisation puts into the platform, your organisation (the "Tenant") is the data controller and we act as a processor on its instructions. For account records, billing and the security of the service itself, we act as controller. You can reach us at info@go-liveai.com.
2. Data we collect
- Account data — name, email address, tenant membership and assigned role (tenant admin, approver, finance or member).
- Request data — request title, date, reason, description, supplier, expense category, location, cost and currency, chosen approver, and decision comments.
- Attachments — quotes, purchase documents and invoices uploaded by users.
- Audit data — who did what and when: submissions, pre-approvals, invoice uploads, finance verifications, variance overrides, role changes and admin configuration changes.
- Technical data — IP address, browser user agent, timestamps and email delivery events (sent, bounced, unsubscribed).
We do not collect special category data, and the platform is not intended for it.
3. Why we process it, and on what basis
- Performance of a contract — creating accounts, routing approvals, storing attachments, sending workflow notifications and providing exports.
- Legitimate interests — keeping the service secure, preventing abuse, maintaining an audit trail that our customers rely on for internal financial control, and improving reliability.
- Legal obligation — retaining records where law requires it and responding to lawful requests.
- Consent — where you opt in to non-essential communications. You can withdraw consent at any time.
We do not sell personal data, we do not use it for advertising, and we do not use it to train machine learning models.
4. Who we share it with
We share data only with the providers needed to run the service, and only to the extent required:
- Cloud platform provider — application hosting, database, authentication and encrypted file storage.
- Email delivery provider — sending transactional notifications from our sending domain.
- Your nominated accounting inbox — where a tenant admin configures auto-forwarding (for example a Xero draft inbox), approved request details and attachments are sent to that address on the tenant's instruction. The tenant chooses and controls that destination.
- Professional advisers or authorities — only where legally required.
5. International transfers
Our providers may process data outside the UK/EEA. Where that happens, transfers are covered by an adequacy decision or by Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus technical safeguards such as encryption in transit and at rest.
6. How long we keep it
- Account data — for as long as the account is active.
- Requests and attachments — for as long as the tenant's subscription is active, so that the financial record stays complete.
- Audit events — retained for the tenant's compliance purposes. If a user is deleted, the audit entry stays but the personal identifiers in it are redacted.
- After termination — tenant data is deleted within 30 days of the subscription ending, unless earlier deletion is requested or the law requires longer retention.
- Email delivery and suppression records — kept as long as needed to honour unsubscribes and protect deliverability.
7. How we protect it
- Encryption in transit (TLS) and at rest.
- Strict per-tenant isolation enforced at the database level with row-level security, so one tenant cannot read another's data.
- Role-based permissions, with roles stored separately from user profiles and checked server-side.
- Attachments held in private storage and served only through short-lived signed links to authorised users.
- Server-side validation of every approval action, including prevention of self-approval.
- An append-only audit trail of security-relevant actions.
No system is perfectly secure, so we do not promise absolute security — but we do commit to the measures above.
8. Your rights
Under the UK and EU GDPR you can ask to access, correct, delete, restrict or port your data, and object to certain processing. In the app:
- Privacy Centre — download a machine-readable copy of your profile and your requests, or request deletion of your account.
- Deletion — your profile is removed and identifiers in the audit log are redacted; the underlying financial record remains available to your tenant admin for internal control purposes.
- Emails — every notification includes an unsubscribe link for non-essential mail.
If your organisation controls the data, we may direct your request to your tenant admin. Email info@go-liveai.com and we will respond within one month.
9. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in and to remember your cookie choice. We do not run advertising, profiling or cross-site tracking cookies.
10. Children
The service is for business use and is not directed at anyone under 16. We do not knowingly collect their data.
11. Changes
If we make a material change we will update the date at the top of this page and notify tenant admins by email before it takes effect.
12. Complaints
Contact us first at info@go-liveai.com. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
Questions about this document? Email info@go-liveai.com.