Privacy Policy
Last updated: 2 August 2026
This policy explains what templit collects when you use our SAP Business One add-on and our website, why we collect it, who else ever sees it, and how long we keep it. We've tried to write it in plain language rather than boilerplate — if anything here is unclear, email us at contact@templit.one.
templit is at pilot stage. It has not been released commercially, there is no company behind it yet, and it is being trialled free with a small number of SAP Business One partners. We say so here because it changes what we can honestly promise — please read During the pilot below before you send us anything that belongs to a client of yours.
The short version
- Setting up a template needs one sample invoice. That single PDF goes to our servers, and to Anthropic — the AI provider that works out where each field sits on the page.
- Every invoice you import afterwards is read entirely on your own computer, next to your SAP Business One install. It is never uploaded anywhere.
- We store that one sample PDF encrypted, tied to the template it created.
- We don't sell your data, and we don't train anything on it.
Where your data goes
Exactly two parties besides us ever touch anything of yours, and both only ever see the one sample invoice — never the invoices you import day to day.
Reads the one sample PDF to work out the invoice's layout, on their infrastructure in the United States. Their commercial terms do not permit training on data submitted through their API — if you need that on file for your own compliance review, ask us and we'll point you at the current terms.
Our hosting provider. Runs the templit API and the database that holds your encrypted sample and your account record. Their servers are in Germany, so your sample stays inside the EU — it is only the Anthropic step above that reaches the US.
Nobody else. We don't sell, rent, or otherwise share your data, and we don't use it for advertising.
What we collect, and why
The sample invoice used to build a template
When you create or update a template in the add-on, you choose one PDF invoice from that supplier and pick the fields you want templit to capture. That single PDF is uploaded to our servers, where it is processed and also sent to Anthropic to work out the invoice's layout. We store that sample PDF, encrypted at rest, for as long as the template exists — it is the reference copy behind the template, and is kept even if a template build fails, so we can see why. Deleting or deactivating a template does not retroactively un-send this file to Anthropic; it only affects what we ourselves keep going forward.
Every invoice you import after that
Once a template exists, importing invoices does not involve us at all. The add-on reads the PDF and extracts the fields locally, on the same computer that runs SAP Business One. That document, and the data on it, is never transmitted to our servers, to Anthropic, or to anyone else.
Account information
We keep your company name and a contact email so we can reach you. The add-on authenticates with a single API key; we store only a one-way hash of that key, plus its first few characters so we can identify it in support — never the key itself in readable form.
Usage monitoring
Each time the add-on runs a template against a dropped invoice, it sends us a small ping: which template was used, when, whether it succeeded, and the add-on version. It does not include the invoice, the extracted data, or any supplier information.
Diagnostic logs
Building a template is logged so we can work out why one failed. Those logs hold the sample's filename and size, and the extraction spec produced at each attempt. A spec contains labels lifted from the invoice — the exact wording a supplier uses for "Invoice no.", a column heading, and similar — so logs can contain fragments of your document's text. They are kept for 3 days and then deleted.
Our website
templit.one runs no analytics and no advertising trackers, and loads no fonts, scripts, or assets from anyone else's servers. It sets no cookies beyond what your browser needs to load the page.
Who is responsible for what
If you are an SAP Business One partner trialling templit for a client, the chain runs like this: your client decides what happens to their invoice data (the controller), you act on their instructions (a processor), and templit acts on yours (a sub-processor). In plain terms — we only ever do what you ask with the sample you send us, we make no decisions about it ourselves, and we never use it for our own purposes.
We cannot offer a signed Data Processing Agreement yet. There is not yet a company to sign one, and the hosting tier we run on during the pilot does not come with one either. That is a genuine limitation rather than an oversight, and it is the main reason for the request below.
During the pilot
While templit is being evaluated, we ask that you build templates from your own invoices, or from ones you have anonymised — rather than from a client's live documents. templit needs exactly one sample per supplier, so this is usually easy to arrange, and it means nothing sensitive belonging to a third party sits on evaluation infrastructure while the legal groundwork is still being done.
If you need to trial it against real client documents, talk to us first and we'll agree in writing how that is handled.
How we protect it
Sample invoices are encrypted at rest with AES-GCM. API keys are never stored in plaintext, only as a one-way hash. Access is limited to the people building templit.
Being straight with you: during the pilot templit runs on a free hosting tier. That is appropriate for an evaluation and not for production volumes of real client data — which is the other reason we ask you to trial it with your own or anonymised invoices.
Your rights, and deleting your data
You can ask us what we hold about you, ask us to correct it, or ask us to delete it, by emailing contact@templit.one. We action deletion requests within 30 days, and we delete everything from a pilot when that pilot ends or on request — whichever comes first.
One thing we cannot undo: deleting a stored sample removes our copy, but it does not reach back into the processing Anthropic already performed on the copy sent when the template was built.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and change the "Last updated" date above. For material changes we'll tell pilot partners directly rather than relying on you to notice.
Contact
Questions about this policy or your data: contact@templit.one.