ResourcesTrust & security
biosuite handles procurement and spend data and related documents. This page summarises how that data is stored, processed and protected.
Last updated: 26 August 2026
Controls in place
biosuite takes an EU-first approach to data architecture, including private Cloudflare R2 object storage configured with EU jurisdictional restrictions, together with provider-specific AI privacy controls. For biosuite's Mistral AI organization, model-training data sharing is disabled and Zero Data Retention is enabled for supported stateless API processing. biosuite's agreement with Lovable is governed by Lovable's Data Processing Agreement, which prohibits the use of Customer Personal Data for AI/ML model training.
For more information about how we handle personal data, please see our Privacy Policy, Data Processing Agreement, and AI Data Processing Policy, or contact us at privacy@biosuite.io.
Mistral AI is a trademark of Mistral AI SAS. biosuite ApS is not affiliated with, endorsed, or sponsored by Mistral AI SAS or its affiliates.
Your workspace data – companies, users, contracts, purchase orders, invoice records and spend data – is held in an application database hosted in the EU.
Uploaded invoice files are stored separately from the application. They are held in a private object storage service configured with European Union jurisdiction, and the files themselves are not routed through or stored in biosuite's core application environment.
Access to uploaded invoice files is restricted through server-side access controls and appropriate technical and organisational security measures. Data is encrypted in transit and at rest.
Some of our providers, and their own sub-processors, may process data outside the EU/EEA. Our providers, their locations and the transfer safeguards that apply are set out in the Data Processing Agreement.
Sign-in and sensitive operations are protected by additional verification steps beyond a password.
Application security is periodically assessed, including through penetration testing. Information about the testing methodology is available here. A summary of the assessment of biosuite is available to customers and prospective customers on request.
biosuite can read an uploaded invoice and pre-fill the invoice form. Three things govern how that works.
Extraction is limited to the fields below. No other data is retained, and the extraction schema expressly excludes bank and payment identifiers.
Extracted
Never extracted
The AI provider returns the document's recognised text alongside the structured fields. biosuite retains only the fields listed above: the recognised text is never logged, never written to the database, and is discarded as soon as processing completes.
Free-text values such as the description and line item text are length-limited and automatically filtered for bank and payment identifiers before storage. The Service does not process, initiate or otherwise contribute to payments, and approvals, statuses and workflow actions do not constitute payment instructions or payment authorisations of any kind.
Every extracted value is presented as a draft in an editable form. Nothing enters your records until you have reviewed and confirmed it. No automated decisions with legal or financial effect are made without user action.
Our AI providers are named in the sub-processor list in the Data Processing Agreement.
Contract files are handled differently from invoices. A contract you upload for AI-assisted reading is used for extraction only: the file is deleted after extraction and is never stored in your workspace. Only the contract details you review, confirm and save are kept.
Extraction is limited to commercial contract terms – vendor, contract value, dates, terms and renewal clauses. Nothing else is extracted or stored.
biosuite is built for ordinary business procurement and spend data. Some categories must not be uploaded to the Service at all:
If a document contains any of these, enter the financial details manually instead of uploading it.
Ordinary commercial contract terms – including protocol references, milestones and pricing in CRO or study agreements – and standard invoice details are not restricted. The full restriction is set out in section 2.7 of the Terms of Service.
When you delete an invoice, it and its document are immediately removed from all views, reports and totals, and the original document is no longer accessible through the Service unless the invoice is restored.
The document remains in the object storage service for 30 days so that a company administrator can restore the invoice, after which the document and the associated invoice fields are automatically and permanently deleted. A record of the deletion is retained.
When someone leaves: If a user is removed from your workspace or deactivates their account, their access ends immediately, and their name is retained so that the invoices and orders they handled still show who handled them.
Erasure requests: If a person asks to be erased, contact us and we will anonymise their record. Their name and email are replaced everywhere they appear, including in historical references, while the approvals and confirmations themselves remain intact and attributed to "Deleted user". This is irreversible.
When a subscription is cancelled, the workspace is kept in a suspended state for 30 days so it can be reactivated. After that, the workspace and all associated data are permanently deleted, covering both the structured data in the application database and the original documents in the object storage service.
You can export your structured records and download your original documents at any time. There is no lock-in. biosuite is not a backup or archiving service, and we recommend keeping your own copies of documents and reports that matter to you.
biosuite maintains a platform guide covering the platform’s functionality, setup, and day-to-day use, helping customers understand how the platform works and is configured.
Platform changes are released in stages and documented in our changelog. Current platform status is available at status.biosuite.io.
No system is without risk, and we take security seriously in how biosuite is designed and maintained. For security or compliance questions, to report a concern, or to request documentation for a vendor assessment, contact us.
Last updated: 26 August 2026