VAT IT Reclaim logo
VAT IT Reclaim

VAT IT Reclaim

App description

Ramp gives finance teams real-time visibility and control over company spend. Our integration connects directly to your Ramp environment and automatically retrieves transaction data and invoice images via a secure API. This creates an automated flow of expense data into VAT IT's recovery platform, where our specialists identify and recover eligible VAT across both foreign and domestic jurisdictions, All with minimal effort from your team.

Security and compliance

Can anyone at your company access the data flowing to your app?

No. Access to client data is strictly restricted and granted only to authorised personnel based on business need and role requirements.

VAT IT Reclaim enforces role-based access control (RBAC), ensuring employees can only access the data necessary to perform their job functions. All access requests must be approved, and permissions are reviewed regularly by management.

Additional safeguards include:

Least privilege principle: Access is limited to what is strictly required for job responsibilities

Multi-factor authentication (MFA): Required for access to critical systems

Access monitoring: User activity is logged and monitored

Onboarding/offboarding controls: Access is provisioned via HR processes and promptly removed upon termination

All employees are also bound by confidentiality agreements and must comply with strict information security policies and training requirements.

Additional details are available in the attached SOC 2 report and Information Security Policy.

What is your data retention policy?

VAT IT Reclaim retains client data only for as long as necessary to fulfil its contractual, legal, and regulatory obligations. Retention periods are determined based on the applicable laws and audit requirements of the jurisdictions in which VAT/tax claims are submitted.

When services are terminated, client data is either returned, retained for the required legal period, or securely deleted/sanitized upon request. After the retention period has lapsed, data is permanently deleted, anonymized, or destroyed using secure methods to prevent recovery.

All media containing client data is sanitized or destroyed prior to disposal, and deletion processes can be certified upon client request.

Additional details are available in the attached Retention, Destruction, Deletion and Decommissioning Policy.

https://vatitprocessing-my.sharepoint.com/:b:/g/personal/albertv_vatit_com/IQARtuXdcplHTahOz10snJBMAfU6VRPZbfzd1PnzHFrBW6w?email=sam.bacon%40ramp.com&e=kKEspN

SOC 2 TYPE 2.

Information Security Policy

Retention, Destruction, Deletion and Decommissioning Policy

ISO 27001-aligned Information Security Management System (ISMS)

Discover more integrations

Ramp integrates with all your existing software so you can manage your business with ease—from one place.

Time is money. Save both.