ResourcesTrust & security

    Trust & security

    biosuite handles procurement and spend data and related documents. This page summarises how that data is stored, processed and protected.

    Last updated: 26 August 2026

    Controls in place

    • EU data residency
    • Encrypted in transit and at rest
    • Multi-factor authentication
    • Penetration tested
    • No AI model training
    The Terms of Service, Privacy Policy, Data Processing Agreement and AI Data Processing Policy are the governing documents, and where those documents and this page differ, the governing documents apply.

    Your data is not used to train AI models

    biosuite takes an EU-first approach to data architecture, including private Cloudflare R2 object storage configured with EU jurisdictional restrictions, together with provider-specific AI privacy controls. For biosuite's Mistral AI organization, model-training data sharing is disabled and Zero Data Retention is enabled for supported stateless API processing. biosuite's agreement with Lovable is governed by Lovable's Data Processing Agreement, which prohibits the use of Customer Personal Data for AI/ML model training.

    Our data principles

    You remain in control of the data you upload to biosuite
    We process customer data only to provide and operate the service
    We do not use customer data for advertising
    Access to data is limited and protected using industry-standard security measures
    We rely on reputable infrastructure providers and GDPR-aligned agreements
    When you leave the service, data is deleted or anonymized in line with our policies and legal obligations

    For more information about how we handle personal data, please see our Privacy Policy, Data Processing Agreement, and AI Data Processing Policy, or contact us at privacy@biosuite.io.


    Mistral AI is a trademark of Mistral AI SAS. biosuite ApS is not affiliated with, endorsed, or sponsored by Mistral AI SAS or its affiliates.

    Where your data is stored

    Your workspace data – companies, users, contracts, purchase orders, invoice records and spend data – is held in an application database hosted in the EU.

    Uploaded invoice files are stored separately from the application. They are held in a private object storage service configured with European Union jurisdiction, and the files themselves are not routed through or stored in biosuite's core application environment.

    Access to uploaded invoice files is restricted through server-side access controls and appropriate technical and organisational security measures. Data is encrypted in transit and at rest.

    Some of our providers, and their own sub-processors, may process data outside the EU/EEA. Our providers, their locations and the transfer safeguards that apply are set out in the Data Processing Agreement.

    Application security and authentication

    Sign-in and sensitive operations are protected by additional verification steps beyond a password.

    Application security is periodically assessed, including through penetration testing. Information about the testing methodology is available here. A summary of the assessment of biosuite is available to customers and prospective customers on request.

    AI-assisted invoice reading

    biosuite can read an uploaded invoice and pre-fill the invoice form. Three things govern how that works.

    1A fixed field schema

    Extraction is limited to the fields below. No other data is retained, and the extraction schema expressly excludes bank and payment identifiers.

    Extracted

    • Supplier name
    • Invoice number
    • Invoice date
    • Due date
    • Currency
    • Subtotal
    • VAT amount
    • Total amount
    • Invoice description
    • Invoice line items

    Never extracted

    • IBAN and other bank account numbers
    • SWIFT/BIC codes
    • Payment card data
    • Payment references

    The AI provider returns the document's recognised text alongside the structured fields. biosuite retains only the fields listed above: the recognised text is never logged, never written to the database, and is discarded as soon as processing completes.

    2Bank details are not retained

    Free-text values such as the description and line item text are length-limited and automatically filtered for bank and payment identifiers before storage. The Service does not process, initiate or otherwise contribute to payments, and approvals, statuses and workflow actions do not constitute payment instructions or payment authorisations of any kind.

    3You approve the result

    Every extracted value is presented as a draft in an editable form. Nothing enters your records until you have reviewed and confirmed it. No automated decisions with legal or financial effect are made without user action.

    Our AI providers are named in the sub-processor list in the Data Processing Agreement.

    Contracts

    Contract files are handled differently from invoices. A contract you upload for AI-assisted reading is used for extraction only: the file is deleted after extraction and is never stored in your workspace. Only the contract details you review, confirm and save are kept.

    Extraction is limited to commercial contract terms – vendor, contract value, dates, terms and renewal clauses. Nothing else is extracted or stored.

    What not to upload

    biosuite is built for ordinary business procurement and spend data. Some categories must not be uploaded to the Service at all:

    • Personal data relating to patients or clinical trial subjects, or other special categories of personal data under Article 9 GDPR
    • Government-issued personal identifiers such as national ID, CPR or passport numbers
    • Payment card data
    • Biometric data

    If a document contains any of these, enter the financial details manually instead of uploading it.

    Ordinary commercial contract terms – including protocol references, milestones and pricing in CRO or study agreements – and standard invoice details are not restricted. The full restriction is set out in section 2.7 of the Terms of Service.

    Deleting data

    When you delete an invoice, it and its document are immediately removed from all views, reports and totals, and the original document is no longer accessible through the Service unless the invoice is restored.

    The document remains in the object storage service for 30 days so that a company administrator can restore the invoice, after which the document and the associated invoice fields are automatically and permanently deleted. A record of the deletion is retained.

    When someone leaves: If a user is removed from your workspace or deactivates their account, their access ends immediately, and their name is retained so that the invoices and orders they handled still show who handled them.

    Erasure requests: If a person asks to be erased, contact us and we will anonymise their record. Their name and email are replaced everywhere they appear, including in historical references, while the approvals and confirmations themselves remain intact and attributed to "Deleted user". This is irreversible.

    When a subscription is cancelled, the workspace is kept in a suspended state for 30 days so it can be reactivated. After that, the workspace and all associated data are permanently deleted, covering both the structured data in the application database and the original documents in the object storage service.

    You can export your structured records and download your original documents at any time. There is no lock-in. biosuite is not a backup or archiving service, and we recommend keeping your own copies of documents and reports that matter to you.

    Platform documentation

    biosuite maintains a platform guide covering the platform’s functionality, setup, and day-to-day use, helping customers understand how the platform works and is configured.

    Changes and availability

    Platform changes are released in stages and documented in our changelog. Current platform status is available at status.biosuite.io.

    Questions

    No system is without risk, and we take security seriously in how biosuite is designed and maintained. For security or compliance questions, to report a concern, or to request documentation for a vendor assessment, contact us.

    Last updated: 26 August 2026