Candex
How It Works Integrations Pricing About Blog
Contact Sales Sign In
How It Works Integrations Pricing About Blog
Contact Sales Sign In

Privacy Policy

Last updated: January 14, 2026

1. Introduction

Candex, Inc. ("the Company," "we," "us," or "our") operates the website getcandex.com and the Candex enterprise AP automation platform (together, the "Service"). Candex automates cross-border supplier payments for large enterprises: our platform collects supplier tax documentation, performs identity and sanctions verification, applies withholding rules, and executes payment disbursements on behalf of enterprise clients. This Privacy Policy explains what information we collect across that workflow, how we use it, with whom we share it, and the choices available to you.

The Company is located at 1350 Broadway, Suite 1510, New York, NY 10018 and can be reached at [email protected] or +1 (212) 553-6073.

This Policy applies to information collected through the Service, through direct communications with enterprise clients and their AP teams, and through the supplier-facing data-collection flows that are part of our payment processing service.

2. Information We Collect

2.1 Information Enterprise Clients Provide

When a client organization registers for or accesses the Candex platform, we collect:

  • Company name, billing address, and tax identification details for the client entity;
  • Names, work email addresses, and roles of authorized users on the client's AP team;
  • Payment instructions submitted through the platform: supplier name, country, invoice amount, currency, and purpose of payment;
  • ERP or accounting system identifiers where clients elect to export audit-trail records.

2.2 Supplier Payment Data

To execute a compliant cross-border payment, Candex's platform collects the following data from or about the payee supplier, typically through a guided supplier onboarding flow:

  • Legal business name, registered address, and country of tax residence;
  • Tax identification numbers (US Employer Identification Number, foreign tax ID, or equivalent);
  • W-8 or W-9 tax forms and associated certifications;
  • Bank account details or payment routing instructions for payment disbursement;
  • Know-Your-Business (KYB) identity verification documents as required under applicable compliance frameworks;
  • Information needed to apply OFAC and international sanctions screening before payment dispatch.

Supplier payment data is processed solely to complete the payment transaction, fulfill our compliance obligations to the client and applicable regulators, and generate the audit-trail record required by the client's AP workflow. We do not use supplier payment data for marketing purposes.

2.3 Information Collected Automatically from Website Visitors

When you visit getcandex.com, we automatically collect limited technical information:

  • IP address and approximate location (city or region level);
  • Browser type, operating system, and device class;
  • Pages visited, referring URLs, and time on page;
  • Cookie and similar identifiers (see Section 5 and our Cookie Policy).

2.4 Inquiry and Contact Data

When you contact us through the website or by email or phone, we collect the details you provide: name, work email, company, and the content of your inquiry.

2.5 Children's Data

The Service is directed to enterprise professionals and is not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe a child has submitted information to us, contact [email protected] and we will delete it.

3. How We Use Information

We use the information we collect to:

  • Execute payment transactions submitted through the platform, including tax-form collection, KYB verification, sanctions screening, and payment disbursement;
  • Generate structured audit-trail records exportable to the client's ERP or accounting system;
  • Apply correct withholding rules under US tax law (IRS guidance under Chapters 3 and 4, W-8 series, W-9) and applicable tax treaties;
  • Respond to inquiries and provide onboarding, technical, and compliance support to authorized users;
  • Operate, maintain, and improve the Service, including platform reliability and compliance coverage;
  • Send service-related communications to authorized users (account notices, payment confirmations, compliance updates);
  • Send marketing communications with your consent where required, and process unsubscribes promptly;
  • Detect, investigate, and prevent fraud, unauthorized access, and financial crime;
  • Comply with applicable legal obligations, including tax reporting requirements and regulatory record-retention rules.

We do not sell personal information for monetary value. We do not use supplier payment data or tax documentation to train machine-learning models without explicit written consent from the data subject or the responsible enterprise client.

4. Sharing of Information

Candex shares personal and supplier information only as follows:

  • Payment processing sub-processors: we engage banking partners and payment-rail providers to execute cross-border disbursements. These providers receive only the information needed to complete the payment (payee account details, amount, currency). Each sub-processor is bound by contractual data-processing terms and applicable financial-sector data-handling obligations;
  • Compliance and identity verification providers: we use third-party KYB and sanctions-screening services to verify supplier identity and check against OFAC and other sanctions lists before payment dispatch. These providers process only the data required for the specific check;
  • Infrastructure and operational service providers: cloud infrastructure, email delivery, and analytics services acting as data processors under confidentiality and data-processing agreements;
  • Enterprise clients: we return structured payment records and audit-trail data to the client organization that submitted the payment request, in the format they have configured (CSV, JSON, or ERP export);
  • Legal and regulatory authorities: when required by law, court order, or regulatory directive, or to protect the rights, safety, or property of the Company, our clients, or the public;
  • Business transfers: in the event of a merger, acquisition, or asset sale, personal information may be transferred to a successor entity, subject to this Policy.

We do not sell personal information to third parties. We do not share supplier data with client companies beyond the audit-trail records generated for the specific payment transaction the client submitted.

4.1 International Data Transfers

Candex serves enterprise clients paying suppliers across many countries. Some payment transactions require transferring supplier and payment data to banking partners or compliance-verification providers located outside the United States. Where such transfers occur, we rely on contractual protections and applicable international data-transfer frameworks to ensure appropriate protection of the data. Suppliers located in the European Economic Area, United Kingdom, or Switzerland should note that their data may be transferred to the US and to other countries as part of payment processing; those transfers are governed by standard contractual clauses or equivalent approved transfer mechanisms where required by applicable law.

5. Cookies and Tracking

We use cookies and similar technologies to operate the website, remember visitor preferences, and measure usage. The Candex platform itself uses session cookies for authentication and CSRF protection. For full details and choices, see our Cookie Policy.

6. Data Retention

We retain information only as long as needed for the purposes described in this Policy and to meet our legal obligations:

  • Supplier payment data and tax documentation are retained for the period required by the client's configured audit-retention setting and applicable tax-record retention rules. US tax regulations generally require retention of Forms W-8 and W-9 for a minimum period following the year of the relevant payment, and we retain these records accordingly;
  • Platform user account data is retained for the duration of the client's active subscription and for a reasonable period following contract termination to support audit and dispute resolution;
  • Website inquiry data is retained for 24 months from last contact, after which inactive records are purged;
  • Marketing list contacts are purged after 24 months of inactivity;
  • Server access logs are retained for 90 days, then aggregated.

7. Security

We apply administrative, technical, and physical safeguards designed to protect personal and financial data, including encryption of data in transit (TLS) and at rest, restricted-access databases with least-privilege access controls, and access-logging on systems that process supplier financial data. Supplier payment data is handled with the same controls our team applied when running multi-jurisdiction AP compliance programs at global enterprises before building this platform.

No system is perfectly secure. We cannot guarantee absolute security of any information transmitted to or stored on our systems. In the event of a data breach that triggers notification obligations under applicable law, we will notify affected parties as required.

8. Your General Rights

Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.

For enterprise platform users, certain rights related to supplier data in the platform should be coordinated with the enterprise client organization that submitted the relevant payment request, as that organization is responsible for the data it submits to the platform.

9. New York Residents

New York does not currently have a comprehensive consumer privacy statute applicable to the Candex platform. As a matter of policy, the Company extends the following baseline rights to all US residents regardless of state of residence.

9.1 Baseline Rights

  • Right to Know: request the categories of personal information we have collected about you;
  • Right to Delete: request deletion of personal information you have provided;
  • Right to Correct: request correction of inaccurate personal information;
  • Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.

9.2 How to Exercise

Email [email protected] with a description of your request and sufficient detail for us to verify your identity. We respond within 45 days. Note that supplier payment data may be subject to legal retention obligations that limit deletion rights for a defined period.

9.3 Sector-Specific Rights

Because Candex processes financial data and facilitates payments subject to US tax withholding rules, data processed through the platform may also be subject to federal sector frameworks including the Gramm-Leach-Bliley Act (GLBA) where applicable to our banking sub-processors, and IRS recordkeeping requirements. Those laws may govern your rights with respect to the covered data. Enterprises using the platform for payments subject to US federal tax withholding should also be aware of their own obligations as withholding agents.

9.4 California Visitors

If you are a California resident, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. The Company does not sell personal information and does not "share" personal information for cross-context behavioral advertising.

To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

11. Contact

Questions, requests, or complaints about this Policy can be sent to:

Candex, Inc.
1350 Broadway, Suite 1510
New York, NY 10018
Email: [email protected]
Phone: +1 (212) 553-6073
Candex

Enterprise AP automation for one-off international supplier payments.

Product

  • How It Works
  • Pricing
  • Integrations
  • Security
  • Sign In

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
+1 (212) 553-6073
[email protected]
1350 Broadway, Suite 1510, New York, NY 10018

© 2026 Candex, Inc. All rights reserved.

Privacy Terms Cookies Cookie preferences