Esolbay - Plataforma AI-Native para Procurement
Back to home
Esolbay

Privacy Policy and Data Protection

Last updated: June 2026

At Esolbay we understand that trust is an essential component of any enterprise technology relationship. Our clients, users, suppliers and partners entrust us with information tied to critical procurement, sourcing, evaluation, negotiation, purchase order activation, document management and operational traceability processes. For that reason, data protection, confidentiality, information security and the responsible use of artificial intelligence are central to how we operate.

This Privacy Policy describes how Esolbay collects, uses, stores, protects, shares and processes personal data and information related to the use of our website, our digital channels, our commercial communications and our technology platform.

Esolbay develops an artificial intelligence platform applied to procurement and sourcing, designed to automate, assist and optimize end-to-end business processes, including internal requests, RFx processes, receipt and analysis of offers, technical and economic evaluation, awards, activations, receipts, document traceability, audit and operational governance.

Our commitment is to process information in a lawful, transparent, secure, proportionate manner, limited to legitimate purposes, in compliance with applicable regulations and international best practices regarding privacy, security, data protection and responsible artificial intelligence governance.

Identity and contact

For the purposes of this Policy, the responsible entity is:

Esolbay SAS

Website: www.esolbay.com

Contact email: hola@esolbay.com

Any query, request or communication related to privacy, personal data protection, information security or the exercise of rights may be directed to:

privacidad@esolbay.com

Scope of this Policy

This Policy applies to the information Esolbay processes in connection with:

  • Access to and navigation of the Esolbay website.
  • Contact forms, demo requests, commercial inquiries or institutional communications.
  • Interactions via email, WhatsApp, meetings, events, campaigns, presentations or enabled digital channels.
  • Evaluation, contracting, implementation, support, operation and service delivery processes.
  • Use of the Esolbay platform by clients, authorized users, invited suppliers and other process participants.
  • Integrations, document uploads, communications, files, transactional data or operational information related to procurement and sourcing processes.
  • Security, audit, traceability, technical support, service improvement, analytics, fraud prevention and regulatory compliance activities.

This Policy applies both to the processing of personal data and, where applicable, to the processing of business, documentary, operational or confidential information related to the use of Esolbay services.

Where a specific agreement exists between Esolbay and a client, that agreement may establish additional or complementary conditions regarding confidentiality, data processing, security, subprocessors, service levels, integrations, retention, audit or deletion of information.

Esolbay's roles in data processing

Depending on the context, Esolbay may act as:

Data controller

Esolbay acts as data controller when it determines the purposes and means of processing personal data. This may occur, for example, in relation to data collected through the website, contact forms, commercial communications, prospect management, management of business relationships, site security and improvement of our services.

Data processor or service provider

When Esolbay processes information on behalf of a client in the context of the use of the platform, it may act as data processor or technology provider, following the client's documented instructions and in accordance with the applicable contractual agreement.

In those cases, the client is responsible for determining what data is incorporated into the platform, for what purpose, which users have access, which suppliers participate and which legal bases or authorizations apply.

Mixed or complementary processing

In certain scenarios, Esolbay may process information both to provide the service to the client and for its own legitimate purposes, such as security, abuse prevention, technical audit, quality control, aggregate analysis, product improvement or legal compliance, always within the limits permitted by applicable regulations and current contractual agreements.

Privacy and data governance principles

Esolbay adopts a privacy-by-design, security-by-design and responsible information governance approach. In practice, this means we seek to apply the following principles:

  • Lawfulness and transparency: we process data on legitimate bases and in a clear manner for data subjects.
  • Purpose limitation: we use information for specified, explicit and legitimate purposes.
  • Data minimization: we seek to process only the information necessary for each purpose.
  • Accuracy: we aim to keep data reasonably up to date, complete and correct.
  • Security: we apply technical and organizational measures to protect information.
  • Confidentiality: we restrict access to sensitive, commercial or strategic information.
  • Traceability: we record relevant events for audit, security and operational control.
  • Accountability: we design our processes to be able to demonstrate reasonable compliance practices.
  • Responsible use of AI: we use artificial intelligence as an assistive capability, not as an automatic, unconsidered substitute for critical business decisions.

Categories of data we may process

Esolbay may collect and process different categories of data depending on the type of interaction, the contracted service, the person's role and the operational context.

Identification and contact data

We may process data such as first name, last name, corporate email, phone, company, job title, area, country, city, language, professional information and other information the person voluntarily provides.

Business relationship data

We may process information related to inquiries, meetings, demos, proposals, client needs, communications, interaction history, functional requirements, implementation processes, support, renewals, billing, contracting and management of the business relationship.

Website navigation and usage data

We may collect technical and navigation information, including IP address, device identifiers, browser type, operating system, pages visited, time spent, traffic source, form interactions, cookie preferences, conversion events and aggregate behavior metrics.

Platform user data

When the Esolbay platform is used, we may process information relating to authorized users, including name, corporate email, organization, legal name, role, permissions, area, activity within the system, configurations, access logs, approvals, comments, executed actions, dates, audit events and operational traceability.

Supplier data

In procurement and sourcing processes, Esolbay may process information from invited or registered suppliers, including contact details, legal name, commercial information, submitted documentation, responses to RFx processes, technical offers, economic offers, attachments, commercial conditions, deadlines, communications and participation in quotation, evaluation or award processes.

Documentary and transactional data

The platform may process documents and data associated with requests, RFx, quotations, proposals, spreadsheets, PDFs, emails, receipts, invoices, debit notes, credit notes, purchase orders, contracts, technical annexes, specifications, evaluation criteria, comparisons, attachments, reports and other documentation related to procurement and sourcing.

Data generated or derived by the platform

Esolbay may generate information derived from the use of the platform, including summaries, normalizations, classifications, scores, comparison tables, rankings, alerts, recommendations, indicators, criteria traceability, inconsistency records, operational metrics, interaction histories and results derived from automated or AI-assisted processing.

Support and security data

We may process information related to support inquiries, tickets, incident reports, technical logs, security events, access logs, errors, diagnostics, suspicious activity, device information, technical metadata and communications necessary to resolve problems or protect the platform.

Business, confidential and strategic information

In addition to personal data, Esolbay may process sensitive, confidential or strategic business information of its clients and suppliers. This information may include prices, commercial conditions, supplier databases, sourcing needs, technical specifications, budgets, comparisons, evaluations, awards, purchase orders, receipts, communications, internal documents and operational data.

Esolbay recognizes that this information may have significant strategic value for its clients. For that reason, it processes it under criteria of confidentiality, restricted access, logical separation, traceability, security and use limited to authorized purposes.

Esolbay does not sell client, user or supplier information. Nor does it use confidential client information for purposes unrelated to the provision of the service, unless there is express authorization, a legal obligation, a contractual necessity, or aggregate processing with restricted identification that does not reasonably allow identification of the client, its suppliers, its operations or its sensitive business data.

How we collect information

We may obtain information through:

  • Data provided directly by visitors, users, clients, suppliers or prospects.
  • Web forms, demo requests, downloads, registrations or communications.
  • Emails, WhatsApp, meetings, presentations, events or commercial interactions.
  • Use of the Esolbay platform.
  • Uploading documents, files, messages, quotations, receipts or other operational information.
  • Authorized integrations with enterprise systems, ERPs, document tools, communication channels or third-party platforms.
  • Technology providers used for infrastructure, security, authentication, analytics, communications, support or automation.
  • Legitimate public or professional sources, where applicable and permitted by applicable regulations.

Purposes of processing

Esolbay may process information for the following purposes:

Operation and provision of the service

We use data to operate, maintain, configure, administer and provide the Esolbay platform, including procurement, sourcing, RFx, evaluation, award, activation, receipts, traceability, audit, documentation, notifications, integrations and reporting functionalities.

Automation and intelligence applied to procurement processes

We process information to automate and assist processes such as document extraction, offer interpretation, data normalization, technical and economic comparison, document classification, generation of comparison tables, detection of inconsistencies, award recommendation, purchase order tracking and generation of operational alerts.

User, role and permission management

We use data to create accounts, authenticate users, manage permissions, assign roles, control access, log activity, maintain traceability and protect the security of each organization within the platform.

Operational communications

We may use information to send notifications, alerts, reminders, supplier invitations, process updates, support communications, technical notices, transactional messages and communications related to the use of the platform.

Commercial and institutional management

We may process data to respond to inquiries, coordinate meetings, send information about services, prepare proposals, manage commercial opportunities, follow up on prospects, communicate news and maintain institutional or B2B commercial relationships.

Security, audit and prevention of misuse

We process information to protect the platform, prevent unauthorized access, detect anomalous activity, investigate incidents, maintain audit logs, apply internal controls, protect rights and preserve the integrity of processes.

Product improvement and service quality

We may use usage data, aggregate metrics, technical information, feedback and operational logs to improve functionality, fix errors, optimize performance, develop new capabilities, strengthen the user experience and raise service quality.

Legal, contractual and regulatory compliance

We may process information to comply with legal, tax, accounting, regulatory, contractual, judicial, administrative, audit, fraud prevention obligations, defense of rights or attention to requirements of a competent authority.

Legal bases for processing

Depending on the context and applicable regulations, Esolbay may process personal data on one or more of the following bases:

  • Consent of the data subject.
  • Performance of a contractual or pre-contractual relationship.
  • Compliance with legal obligations.
  • Legitimate interest of Esolbay or its clients.
  • Provision of technology services requested by a client organization.
  • Documented instructions of the client when Esolbay acts as data processor.
  • Security, fraud prevention, audit, traceability and operational continuity.
  • Management of B2B commercial communications, where permitted by applicable regulations.

Where a purpose requires specific consent, Esolbay will seek to obtain it in a clear, prior and informed manner.

Use of artificial intelligence

Esolbay incorporates artificial intelligence technologies to assist, automate and optimize procurement and sourcing processes. These capabilities may include language models, document processing, OCR, classifiers, recommendation engines, semantic analysis, data extraction, information normalization, summary generation and inconsistency detection.

Artificial intelligence may be used to:

  • Interpret documents submitted by users or suppliers.
  • Extract information from PDFs, spreadsheets, emails, quotations or other files.
  • Normalize offers with heterogeneous structures.
  • Identify relevant fields, omissions, differences or inconsistencies.
  • Assist in technical and economic evaluations.
  • Generate comparison tables.
  • Suggest rankings or award recommendations.
  • Classify requests, categories, suppliers, documents or receipts.
  • Generate alerts, summaries, indicators and reports.
  • Improve the traceability and consistency of processes.

Esolbay uses artificial intelligence as a tool for assistance and capability augmentation, not as an absolute substitute for human judgment, business responsibility or each client's internal controls.

The recommendations, rankings, alerts, analyses or results generated by the platform must be reviewed and validated by authorized users, internal officers or competent areas of each organization.

Unless expressly agreed otherwise, Esolbay will not use confidential client information, offers, prices, documents, suppliers, commercial processes or identifiable data to train public models or third-party models in a way that could compromise the confidentiality, identity, commercial strategy or sensitive information of the client.

Automated decisions and human oversight

Esolbay may generate automated or AI-assisted results, but business, commercial, contractual, financial or award decision-making belongs to the client and its authorized users.

The platform may assist in evaluation and recommendation, but it does not replace the approval, review, validation, compliance, budget control, internal audit or corporate governance processes defined by each organization.

Where applicable, clients must ensure that their users review the results generated by the platform before adopting final decisions that may have legal, economic, contractual or commercial impact.

Confidentiality and no sale of data

Esolbay does not sell personal data.

Esolbay does not commercialize databases of clients, users, suppliers or prospects.

Esolbay does not disclose confidential client information except where necessary to provide the service, comply with the client's instructions, operate integrations, use authorized technology providers, comply with legal obligations, protect rights or respond to valid requirements of competent authorities.

Internal access to client information is limited to personnel, collaborators or providers who reasonably need access to such information to operate, provide support for, maintain, protect or improve the service, under confidentiality and security obligations.

Technology providers and subprocessors

Esolbay may use technology providers to operate and deliver its services. These providers may include infrastructure, hosting, storage, authentication, security, analytics, communications, email, messaging, document processing, artificial intelligence, support, monitoring, integration, automation or operational management services.

When these providers process personal data or confidential information on behalf of Esolbay, we will seek to ensure they are subject to reasonable obligations of confidentiality, security, limited processing, data protection and use in accordance with authorized purposes.

Esolbay may update its technology providers in line with the evolution of the service, operational needs, security, scalability and applicable contractual conditions.

In enterprise agreements, clients may request additional information about subprocessors, security measures, international transfers, applicable controls and specific data processing conditions, according to the current contract.

Integrations with third-party systems

Esolbay may integrate with enterprise systems, ERPs, document solutions, communication channels, management tools, signature platforms, ticketing systems, calendars, repositories, APIs or other applications used by clients.

When a client enables an integration, Esolbay may receive, send, synchronize, process or query information in accordance with the agreed functional and technical scope.

The client is responsible for verifying that it has the necessary authorizations, permissions, legal bases, configurations and internal controls to connect its systems with Esolbay and to share information through such integrations.

Esolbay will process information from integrations in accordance with this Policy, the applicable contract and the client's documented instructions.

Cookies and similar technologies

The Esolbay website may use cookies, pixels, tags, local storage, identifiers and similar technologies for technical, functional, analytical, security and, where applicable, commercial purposes.

These technologies may be used to:

  • Enable the operation of the website.
  • Remember user preferences.
  • Measure performance and stability.
  • Analyze navigation and aggregate behavior.
  • Improve content, experience and forms.
  • Measure the effectiveness of campaigns.
  • Prevent fraud, abuse or unauthorized activity.
  • Manage consent and preferences.

Users may configure their browser to block, delete or restrict cookies. However, certain site functionalities may be affected if technical or necessary cookies are disabled.

Where applicable, Esolbay may implement cookie consent or preference configuration mechanisms in accordance with applicable regulations.

Institutional and commercial communications

Esolbay may send institutional, informational or commercial communications related to its services, content, news, events, use cases, invitations, proposals, updates or information relevant to organizations, clients, prospects or professional contacts.

The recipient may request to stop receiving non-essential communications by writing to:

hola@esolbay.com

Strictly operational, transactional, contractual, legal or security communications may continue to be sent when necessary to provide the service, comply with obligations or manage the client relationship.

International transfers

Esolbay may use infrastructure, technology providers or services located in different jurisdictions. As a result, personal data or service-related information may be processed, stored or accessed from countries other than the country of residence of the data subject or the client.

When international transfers take place, Esolbay will seek to apply reasonable measures and adequate mechanisms to protect the information, including contractual commitments, security controls, access limitations, confidentiality obligations and safeguards compatible with applicable regulations.

In enterprise contexts, the specific international transfer mechanisms may be regulated in the corresponding contract, data processing agreement, security annex or complementary documentation.

Information security

Esolbay adopts reasonable technical, organizational and administrative measures to protect personal data and business information against loss, unauthorized access, misuse, alteration, disclosure, destruction or unauthorized processing.

These measures may include, as applicable:

  • Access control based on users, roles and permissions.
  • Secure authentication.
  • Session management.
  • Logical separation of information by client or organization.
  • Audit logs and event traceability.
  • Encryption in transit and/or at rest where applicable.
  • Technical monitoring and security controls.
  • Internal confidentiality policies.
  • Access restriction based on operational need.
  • Backups, continuity and recovery.
  • Incident management.
  • Evaluation of relevant technology providers.
  • Secure development practices.
  • Controls over environments, integrations and access.

Esolbay works to maintain a level of security proportionate to the nature of the information processed, the service context, the associated risks and reasonable market best practices.

Nevertheless, no technology system can guarantee absolute security. If an incident is identified that may compromise personal data or relevant information, Esolbay will adopt reasonable measures to contain, investigate, mitigate and communicate it where appropriate in accordance with applicable regulations and agreements.

Data retention and deletion

Esolbay will retain personal data and related information for as long as necessary to fulfill the purposes for which it was collected, provide the service, comply with contracts, maintain operational records, provide support, preserve traceability, comply with legal obligations, resolve disputes, protect rights or perform audits.

Retention periods may vary depending on:

  • Type of data.
  • Nature of the service.
  • Relationship with the client, user, supplier or prospect.
  • Legal, tax, accounting or contractual requirements.
  • Security, audit or traceability needs.
  • Client instructions when Esolbay acts as data processor.

When data is no longer necessary, Esolbay will seek to delete, anonymize, aggregate or securely retain it in accordance with its internal policies, legal obligations and applicable contractual agreements.

For enterprise clients, the specific terms for return, export, deletion or post-contractual retention of data may be regulated in the corresponding contract.

Rights of data subjects

In accordance with applicable regulations, data subjects may exercise certain rights over their information, including:

  • Access.
  • Rectification.
  • Update.
  • Erasure.
  • Objection.
  • Restriction of processing, where applicable.
  • Withdrawal of consent, where processing is based on consent.
  • Information about purposes, recipients and processing conditions.

To exercise these rights, the data subject may contact Esolbay by writing to:

privacidad@esolbay.com

The request must include sufficient information to identify the requester, verify their identity and allow proper handling of the request.

When Esolbay acts as data processor on behalf of a client, it may refer or coordinate the request with that client, to the extent the client is the one who determines the purposes and means of processing.

Esolbay will respond to requests in accordance with the deadlines, conditions and exceptions provided by applicable regulations.

Client responsibilities

When an organization uses Esolbay to manage procurement, sourcing, supplier, documentation, offer, purchase order, receipt or evaluation processes, the client is responsible for:

  • Determining what data is incorporated into the platform.
  • Defining which users will have access.
  • Assigning roles, permissions and authorization levels.
  • Informing its employees, collaborators, suppliers and third parties where applicable.
  • Having sufficient legal bases to process and share information.
  • Ensuring that the uploaded information is lawful, relevant and necessary.
  • Reviewing and validating the results generated by the platform.
  • Adopting final decisions in accordance with its internal policies, controls, compliance rules and business criteria.
  • Complying with its own legal, contractual, tax, labor, regulatory and data protection obligations.

Esolbay provides a technology solution for assistance, automation, traceability and applied intelligence, but it does not replace the client's own responsibilities regarding business decisions, contracting, award, internal control, regulatory compliance or supplier management.

Sensitive data

Esolbay does not intentionally request sensitive data through its website, commercial forms or general contact channels.

Sensitive data is considered to be data that may reveal racial or ethnic origin, political opinions, religious, philosophical or moral convictions, union membership, health-related data, sexual life, biometric data or other categories specially protected by applicable regulations.

Users and clients must not upload sensitive data to the platform unless it is strictly necessary for a legitimate purpose, is permitted by applicable regulations and there is an adequate legal or contractual basis.

If sensitive data is incorporated into the platform by decision of the client or authorized users, the client will be responsible for ensuring that such processing is lawful, necessary, proportionate and duly informed.

Data of minors

Esolbay's services are aimed at organizations, companies, corporate users, suppliers and professional contacts. They are not directed at minors.

Esolbay does not intentionally seek to collect personal data of minors. If we become aware that data of minors has been processed without a valid basis, we will adopt reasonable measures to delete, restrict or manage it in accordance with applicable regulations.

Third-party links and services

The Esolbay website or platform may contain links, integrations or references to third-party sites, applications, platforms or services.

Esolbay does not control the privacy, security, content or operating practices of such third parties, except to the extent they act as providers contracted by Esolbay for the provision of the service.

We recommend reviewing the privacy policies and terms of use of any external site or service before providing information.

Changes to this Policy

Esolbay may update this Privacy Policy to reflect legal, regulatory, technological, operational, commercial or security changes.

When we make relevant changes, we may communicate them through the website, the platform, email or other reasonable means.

The version in force will be the one published on the Esolbay website, identified by the date of last update.

Continued use of the website, the platform or Esolbay services after an update is published will imply knowledge of the version in force, without prejudice to the specific consents that may apply in accordance with applicable regulations.

Contact

For inquiries, requests, claims or communications related to this Privacy Policy, personal data protection, confidentiality or information security, you may contact Esolbay at:

privacidad@esolbay.com

Contact: hola@esolbay.com · privacidad@esolbay.com