Privacy Policy
Contents
1. Who we are
v3ndor.io is provided by [YOUR LEGAL ENTITY NAME], registered at [YOUR REGISTERED ADDRESS] (company number [REGISTRATION NUMBER]). We are the data controller for personal data processed on our marketing website, and a data processor for personal data customers submit to the v3ndor.io platform.
2. Scope of this policy
This policy covers personal data we process:
- When you visit v3ndor.io (our marketing website)
- When you sign up for, use, or evaluate the v3ndor.io platform
- When you contact our sales, support, or security teams
It does not cover personal data customers process about their vendors via the platform — that is governed by the customer's own privacy practices and the Data Processing Agreement we sign with each customer.
3. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, organization, role | directly from you (signup) |
| Authentication data | OIDC subject id, session tokens | your identity provider (Entra ID etc.) |
| Usage data | pages visited, features used, request timestamps, IP, user agent | your browser + our servers |
| Audit log entries | who did what, when, before/after state | generated by the platform |
| Support communications | ticket subject, body, attachments | directly from you |
| Customer-provided content | vendor records, contracts, evidence files, risk descriptions | uploaded by you (we are processor, not controller) |
| Cookies + similar tech | see Cookie Policy | your browser |
4. How and why we use personal data
- Provide the service — authenticate users, render the UI, store + retrieve your data.
- Communicate — service notifications, security alerts, support replies, billing.
- Improve and secure — usage analytics in aggregate, security monitoring, fraud and abuse detection.
- Comply with law — respond to legal requests, enforce our agreements, detect violations.
5. Legal bases (GDPR / UK GDPR)
- Contract (Art. 6(1)(b)) — to deliver the service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, service improvement.
- Consent (Art. 6(1)(a)) — where required, e.g. for non-essential cookies or marketing emails.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law.
6. Who we share personal data with
We do not sell personal data. We share it only with:
- Sub-processors we engage to help us operate — see the current list at /legal/subprocessors.
- Professional advisers — auditors, lawyers, accountants — under confidentiality.
- Law enforcement and regulators when legally compelled, subject to challenges where we believe a disclosure is overbroad.
- Successors in the event of a merger, acquisition, or asset sale (you will receive notice).
7. International data transfers
Our primary processing region is [YOUR PRIMARY REGION]. When we transfer personal data outside the EU/EEA or UK we rely on:
- EU Commission adequacy decisions where they exist;
- EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum where they don't;
- Binding Corporate Rules where applicable.
A copy of the safeguards is available on request — email privacy@v3ndor.io.
8. Data retention
| Data | Retention |
|---|---|
| Active account data | while your account is active |
| Account data after termination | up to [X] days, then deleted, unless legal retention applies |
| Audit logs | 1 year minimum (SOC 2 / NIST 800-53 AU-11), 7 years in regulated tenants |
| Backups | up to [Y] days post-deletion (rolling) |
| Marketing-website analytics | up to 14 months |
| Support tickets | 3 years from last interaction |
9. Security
Encryption at rest (CMK), TLS 1.2+ in transit, private endpoints on every data resource, Row-Level Security on tenant-scoped tables, least-privilege IAM, MFA on admin accounts, third-party SOC 2 audit. See Security & Trust for the full controls list.
10. Your rights
Subject to applicable law, you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure / "right to be forgotten" — request deletion
- Restriction — limit how we process it
- Portability — receive a copy in a machine-readable format
- Object — to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
- Lodge a complaint — with your supervisory authority
To exercise any right, email privacy@v3ndor.io. We respond within 30 days (extendable by 60 in complex cases).
11. EU/UK-specific notices
If you are in the EU/EEA or UK:
- Our EU representative under GDPR Art. 27 is [NAME OF YOUR EU REPRESENTATIVE], contact [EU REP ADDRESS / EMAIL].
- Our UK representative under UK GDPR Art. 27 is [NAME OF YOUR UK REPRESENTATIVE], contact [UK REP ADDRESS / EMAIL].
- You may lodge a complaint with the supervisory authority in your member state, or with the UK ICO at ico.org.uk.
12. California-specific notices (CCPA / CPRA)
If you are a California resident:
- You have the right to know, delete, correct, opt out of sale/sharing, and limit use of sensitive personal information.
- We do not sell personal information; we do not knowingly share for cross-context behavioral advertising.
- Email privacy@v3ndor.io with the subject line California Privacy Rights to submit a request.
- You may designate an authorized agent to submit requests on your behalf — we will verify the agent's authority before responding.
13. Children's privacy
v3ndor.io is a workplace product. We do not direct the service to children under 16 and we do not knowingly collect personal data from them.
14. Changes to this policy
We will post material changes here and notify account admins by email at least [X] days before they take effect. The "Last updated" date at the top reflects the most recent revision.
15. Contact
- Privacy team — privacy@v3ndor.io
- Data Protection Officer (DPO) — [NAME, EMAIL — required if >250 EU employees or large-scale processing]
- Postal — [YOUR REGISTERED ADDRESS]