Privacy Policy

Your data is yours. Full stop.

Last updated: April 2026

We believe privacy is a right, not a compliance checkbox. This policy explains what data we collect, how we use it, and the commitments we make to every organisation we work with.

Who We Are

Theoremic Inc. ("Theoremic", "we", "us", or "our") operates the Theoremic platform — an autonomous intelligence layer for enterprise procurement that integrates with ERP systems including SAP, Oracle, Workday, Coupa, and others.

This Privacy Policy applies to our website at theoremic.com, our platform, and any interactions you have with us as a prospective or active partner.

What We Collect

Information You Provide

When you request a pilot, contact us, or engage with our team, we collect the information you share directly — including your name, company, job title, email address, and the details of your ERP environment relevant to a potential deployment.

Usage Data

When you visit our website, we may collect standard server log data such as IP address, browser type, pages visited, and time of access. We use this for site performance and security purposes only.

Platform Data

For active pilot partners, our platform processes data from your connected ERP systems as part of the agreed workflow scope. This is described in detail under ERP & Enterprise Data below.

How We Use It

We use the information we collect strictly for the purposes it was provided for:

  • To evaluate and respond to pilot requests
  • To communicate with you about your deployment or engagement
  • To operate and improve the Theoremic platform for your benefit
  • To fulfil our contractual obligations to pilot partners
  • To comply with applicable laws and regulations

We do not use your data for advertising, profiling, or any purpose unrelated to your engagement with Theoremic.

Data Sharing

We do not sell, rent, or trade personal data. Period.

When We May Share

We may share data only in the following limited circumstances:

  • With trusted infrastructure providers (e.g. cloud hosting) who process data on our behalf under strict confidentiality obligations
  • When legally required — for example, in response to a valid court order or regulatory request
  • With your explicit consent

Sub-processors

We maintain a limited set of sub-processors necessary to operate our platform. Enterprise partners may request a list of sub-processors as part of their due diligence process.

ERP & Enterprise Data

Our core commitment. Data from your ERP environment is processed solely to execute the workflows you have authorised. It is never used to train shared AI models, surfaced to other tenants, or retained beyond the duration necessary for the agreed deployment.

Scope of Access

Theoremic connects to your ERP systems via standard enterprise APIs and Model Context Protocol (MCP). We request only the minimum access necessary to perform the specific procurement workflows in scope for your deployment.

No Cross-Tenant Data

Customer data is logically isolated. Your organisation's data is never accessible to, or visible from, another Theoremic customer's environment.

No Model Training on Customer Data

We do not use data from your ERP environment to train, fine-tune, or improve our AI models for any purpose beyond your own deployment. Your proprietary procurement data stays proprietary.

Retention

Processed data is retained only as long as required to fulfil the active workflow or as agreed in your deployment contract. Upon termination of an engagement, data is deleted or returned in accordance with your instructions.

Your Rights

Depending on your location, you may have rights with respect to your personal data, including the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data where we have no lawful basis to retain it
  • Object to or restrict certain processing activities
  • Data portability, where applicable

To exercise any of these rights, contact us at privacy@theoremic.com. We will respond within 30 days.

Security

We implement technical and organisational measures designed to protect your data against unauthorised access, loss, or misuse. These include encryption in transit and at rest, access controls, and audit logging.

For a detailed overview of our security architecture, see our Security & Compliance page.

Changes to This Policy

We may update this policy as our platform and legal obligations evolve. When we make material changes, we will update the date at the top of this page and, where appropriate, notify active partners directly.

We encourage you to review this policy periodically. Continued use of our platform after any updates constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy, how we handle your data, or want to exercise your rights, please reach out to our team.

privacy@theoremic.com

For security-specific inquiries, please contact security@theoremic.com.