Privacy Policy
Effective Date: March 31, 2026
Last Updated:
1. Introduction
VendorLens ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our trust center platform and related services.
This policy is compliant with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679), the Cyprus Processing of Personal Data (Protection of Individuals) Law of 2018 (Law 125(I)/2018), and the EU ePrivacy Directive as applicable in the Republic of Cyprus.
By using VendorLens, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
2. Data Controller Information
For the purposes of applicable data protection laws, the Data Controller is:
VendorLens Technologies Ltd
Registered Office: Nicosia, Cyprus
Data Protection Officer: dpo@vendorlens.io
We are responsible for deciding how and why your personal data is processed. If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer using the details above.
3. Role of VendorLens
VendorLens may act as either a Data Controller or Data Processor depending on the nature of the processing activities.
VendorLens as Data Controller
VendorLens acts as a Data Controller when processing personal data relating to:
- Account registration
- Billing and payments
- Customer support
- Platform analytics
- Security and fraud prevention
- Marketing communications
VendorLens as Data Processor
VendorLens acts as a Data Processor when processing personal data submitted by customers through the VendorLens platform ("Customer Data"). In such cases, the customer acts as the Data Controller, and VendorLens processes personal data solely on documented instructions from the customer.
For the avoidance of doubt, this Privacy Policy applies solely to personal data. Non-personal data, including business, operational, or compliance documentation uploaded by customers, is governed by the applicable Terms of Service.
Where VendorLens acts as a Data Processor, such processing may be governed by a Data Processing Agreement ("DPA") where applicable.
4. Personal Data We Collect
We collect and process the following categories of personal data:
4.1 Information You Provide
- Account Information: Name, email address, company name, job title, and password when you register for an account.
- Profile Information: Company details, contact information, and professional information you add to your vendor profile.
- Communication Data: Information you provide when contacting us for support, including chat transcripts and email correspondence.
- NDA Request Information: Name, email, company, and any additional information required for NDA processing.
- Payment Information: Billing address and payment method details (processed securely through Stripe).
4.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, time spent on the platform.
- Device Information: IP address, browser type, operating system, device identifiers.
- Log Data: Access times, referring URLs, and system activity logs.
- Cookie Data: Information collected through cookies and similar technologies (see Section 16).
4.3 Information from Third Parties
- Authentication Providers: If you sign in via third-party providers (e.g., Google), we receive your name and email.
- E-Signature Providers: Signature status and completion data from DocuSign or SignNow.
- Payment Processors: Transaction confirmations and subscription status from Stripe.
5. How We Collect Your Data
We collect personal data through:
- Direct Interactions: When you create an account, submit forms, request NDA access, or contact support.
- Automated Technologies: Through cookies, analytics tools, and server logs when you use our platform.
- Third-Party Sources: From authentication providers, e-signature services, and payment processors you authorize.
- Publicly Available Sources: Company information from public business registries where relevant.
6. Legal Basis for Processing
Under GDPR and Cyprus data protection law, we process your personal data based on the following legal grounds:
- Contract Performance (Article 6(1)(b) GDPR): Processing necessary to provide our services, manage your account, and fulfill our contractual obligations to you.
- Legitimate Interests (Article 6(1)(f) GDPR): For improving our services, preventing fraud, ensuring security, and marketing (where you have not opted out). We balance our interests against your rights and freedoms.
- Consent (Article 6(1)(a) GDPR): Where you have given explicit consent, such as for marketing communications or optional cookies. You can withdraw consent at any time.
- Legal Obligation (Article 6(1)(c) GDPR): Where processing is necessary to comply with legal requirements, such as tax regulations or court orders.
7. How We Use Your Data
We use your personal data for the following purposes:
- Service Provision: To operate, maintain, and improve VendorLens features and functionality.
- Account Management: To manage your account, subscriptions, and user preferences.
- NDA Processing: To facilitate NDA requests, approvals, and document access workflows.
- Communication: To respond to inquiries, provide support, and send service-related notifications.
- Security: To detect, prevent, and address fraud, abuse, and security issues.
- Analytics: To understand usage patterns and improve our services.
- Compliance: To comply with legal obligations and enforce our terms of service.
- Marketing: With your consent, to send promotional communications about our services.
8. Customer Content Responsibility
VendorLens processes information submitted by customers through the platform. Customers are responsible for ensuring that any personal data submitted to VendorLens:
- Is lawfully collected
- Is accurate
- Is appropriate for disclosure
- Complies with applicable data protection laws
VendorLens does not independently verify customer-provided data.
9. Third-Party Information
VendorLens provides tools enabling customers to share information with third parties. VendorLens does not verify or validate the accuracy of information published by customers.
VendorLens shall not be responsible for any reliance placed on such information by third parties.
10. Data Sharing and Disclosure
We may share your personal data with:
10.1 Service Providers
Third-party companies that help us operate our business, including:
- Cloud Infrastructure: Supabase (database and authentication services)
- Payment Processing: Stripe (payment processing)
- E-Signature: DocuSign, SignNow (electronic signature services)
- Customer Support: Tawk.to (live chat)
- Analytics: Privacy-focused analytics tools
10.2 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
10.3 Legal Requirements
We may disclose your data when required by law, court order, or governmental authority, or to protect our rights, safety, or property.
10.4 With Your Consent
We may share your information for other purposes with your explicit consent.
10.5 Subprocessors
VendorLens may engage third-party service providers ("Subprocessors") to assist in providing the Service. These subprocessors may include:
- Cloud infrastructure providers
- Authentication providers
- Payment processors
- E-signature providers
- Analytics providers
- Customer support providers
VendorLens ensures that subprocessors:
- Are subject to appropriate contractual obligations
- Implement appropriate security measures
- Process personal data only as instructed
VendorLens may update subprocessors from time to time. Customers may request an up-to-date list of subprocessors by contacting privacy@vendorlens.io.
11. International Data Transfers
Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
- Transfers to countries with an EU adequacy decision (e.g., UK, Switzerland, Canada)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- Additional technical and organizational measures to protect your data
You may request information about the safeguards in place for specific transfers by contacting our Data Protection Officer.
12. Data Retention
VendorLens retains personal data only for as long as necessary to fulfill the purposes described in this Policy and in accordance with contractual obligations, legal requirements, and legitimate business needs.
Following account termination, certain data may be retained for a limited period to:
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
- Maintain security logs
Specific retention periods include:
- Account Data: Retained while your account is active and for a limited period after termination in accordance with our Terms of Service.
- Transaction Records: Retained for 7 years to comply with Cyprus tax and accounting regulations.
- Audit Logs: Retained for 3 years for security and compliance purposes.
- NDA Records: Retained for the duration of the NDA plus 7 years after expiry.
- Marketing Preferences: Retained until you withdraw consent or for 3 years of inactivity.
- Support Communications: Retained for 2 years after resolution.
13. Your Rights Under GDPR
Under GDPR and Cyprus data protection law, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data and information about how we process it.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten") in certain circumstances.
- Right to Restriction (Article 18): Request that we limit the processing of your data in certain situations.
- Right to Data Portability (Article 20): Receive your data in a structured, commonly used format and transfer it to another controller.
- Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
- Rights Related to Automated Decisions (Article 22): Not be subject to solely automated decisions with legal or significant effects, and request human intervention.
To exercise any of these rights, please contact us at privacy@vendorlens.io. We will respond within one month, as required by GDPR.
14. Security Measures
VendorLens implements appropriate technical and organizational measures designed to protect personal data, including:
- Encryption in transit using TLS
- Access control and authentication mechanisms
- Role-based access controls
- Logging and monitoring
- Infrastructure security controls
- Regular backups
- Least privilege access policies
Additional information regarding our security practices is available on our Security page.
Despite these measures, no system can be guaranteed to be completely secure.
15. Data Breach Notification
VendorLens shall notify affected customers without undue delay upon becoming aware of a personal data breach affecting personal data processed by VendorLens.
Where VendorLens acts as a Data Processor, VendorLens shall notify the relevant customer to enable compliance with applicable legal obligations, including GDPR breach notification requirements.
17. Children's Privacy
VendorLens is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@vendorlens.io, and we will take steps to delete such information.
18. Automated Decision-Making
VendorLens does not use solely automated decision-making processes that produce legal or similarly significant effects on individuals. Any automated processing we perform (such as spam filtering or usage analytics) is supplementary and does not determine access to services or produce significant effects on data subjects.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification to registered users for significant changes
- Displaying a prominent notice on our platform
We encourage you to review this policy periodically. Continued use of VendorLens after changes constitutes acceptance of the updated policy.
20. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
VendorLens Technologies Ltd
General Inquiries: hello@vendorlens.io
Privacy Inquiries: privacy@vendorlens.io
Data Protection Officer: dpo@vendorlens.io
Security Contact: security@vendorlens.io