Privacy Policy

1. Who we are

v3ndor.io is provided by [YOUR LEGAL ENTITY NAME], registered at [YOUR REGISTERED ADDRESS] (company number [REGISTRATION NUMBER]). We are the data controller for personal data processed on our marketing website, and a data processor for personal data customers submit to the v3ndor.io platform.

2. Scope of this policy

This policy covers personal data we process:

It does not cover personal data customers process about their vendors via the platform — that is governed by the customer's own privacy practices and the Data Processing Agreement we sign with each customer.

3. Personal data we collect

CategoryExamplesSource
Account dataname, email, organization, roledirectly from you (signup)
Authentication dataOIDC subject id, session tokensyour identity provider (Entra ID etc.)
Usage datapages visited, features used, request timestamps, IP, user agentyour browser + our servers
Audit log entrieswho did what, when, before/after stategenerated by the platform
Support communicationsticket subject, body, attachmentsdirectly from you
Customer-provided contentvendor records, contracts, evidence files, risk descriptionsuploaded by you (we are processor, not controller)
Cookies + similar techsee Cookie Policyyour browser

4. How and why we use personal data

6. Who we share personal data with

We do not sell personal data. We share it only with:

7. International data transfers

Our primary processing region is [YOUR PRIMARY REGION]. When we transfer personal data outside the EU/EEA or UK we rely on:

A copy of the safeguards is available on request — email privacy@v3ndor.io.

8. Data retention

DataRetention
Active account datawhile your account is active
Account data after terminationup to [X] days, then deleted, unless legal retention applies
Audit logs1 year minimum (SOC 2 / NIST 800-53 AU-11), 7 years in regulated tenants
Backupsup to [Y] days post-deletion (rolling)
Marketing-website analyticsup to 14 months
Support tickets3 years from last interaction

9. Security

Encryption at rest (CMK), TLS 1.2+ in transit, private endpoints on every data resource, Row-Level Security on tenant-scoped tables, least-privilege IAM, MFA on admin accounts, third-party SOC 2 audit. See Security & Trust for the full controls list.

10. Your rights

Subject to applicable law, you have the right to:

To exercise any right, email privacy@v3ndor.io. We respond within 30 days (extendable by 60 in complex cases).

11. EU/UK-specific notices

If you are in the EU/EEA or UK:

12. California-specific notices (CCPA / CPRA)

If you are a California resident:

13. Children's privacy

v3ndor.io is a workplace product. We do not direct the service to children under 16 and we do not knowingly collect personal data from them.

14. Changes to this policy

We will post material changes here and notify account admins by email at least [X] days before they take effect. The "Last updated" date at the top reflects the most recent revision.

15. Contact

← Back to Legal hub