VendorLens

    Welcome offer: 50% off your first 3 months

    New customers only. Applied automatically at checkout.

    20d:07h:40m:02s
    See pricing

    Privacy Policy

    Effective Date: August 11, 2026
    Last Updated:

    1. Introduction

    VendorLens ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our trust center platform and related services.

    This policy is compliant with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679), the Cyprus Processing of Personal Data (Protection of Individuals) Law of 2018 (Law 125(I)/2018), and the EU ePrivacy Directive as applicable in the Republic of Cyprus.

    By using VendorLens, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

    2. Data Controller Information

    For the purposes of applicable data protection laws, the Data Controller is:

    VendorLens Technologies Ltd

    Company Registration Number: HE488809 (Registrar of Companies, Republic of Cyprus)
    Registered Office: Limassol, Cyprus
    Data Protection Officer: dpo@vendorlens.io

    We are responsible for deciding how and why your personal data is processed. If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer using the details above.

    3. Role of VendorLens

    VendorLens may act as either a Data Controller or Data Processor depending on the nature of the processing activities.

    VendorLens as Data Controller

    VendorLens acts as a Data Controller when processing personal data relating to:

    • Account registration
    • Billing and payments
    • Customer support
    • Platform analytics
    • Security and fraud prevention
    • Marketing communications

    VendorLens as Data Processor

    VendorLens acts as a Data Processor when processing personal data submitted by customers through the VendorLens platform ("Customer Data"). In such cases, the customer acts as the Data Controller, and VendorLens processes personal data solely on documented instructions from the customer.

    For the avoidance of doubt, this Privacy Policy applies solely to personal data. Non-personal data, including business, operational, or compliance documentation uploaded by customers, is governed by the applicable Terms of Service.

    Where VendorLens acts as a Data Processor, such processing may be governed by a Data Processing Agreement ("DPA") where applicable.

    4. Personal Data We Collect

    We collect and process the following categories of personal data:

    4.1 Information You Provide

    • Account Information: Name, email address, company name, job title, and password when you register for an account.
    • Profile Information: Company details, contact information, and professional information you add to your vendor profile.
    • Communication Data: Information you provide when contacting us for support, including chat transcripts and email correspondence.
    • NDA Request Information: Name, email, company, and any additional information required for NDA processing.
    • Payment Information: Billing address and payment method details (processed securely through Stripe).

    4.2 Information Collected Automatically

    • Usage Data: Pages visited, features used, actions taken, time spent on the platform.
    • Device Information: IP address, browser type, operating system, device identifiers.
    • Log Data: Access times, referring URLs, and system activity logs.
    • Cookie Data: Information collected through cookies and similar technologies (see Section 16).

    4.3 Information from Third Parties

    • Authentication Providers: If you sign in via third-party providers (e.g., Google), we receive your name and email.
    • E-Signature Providers: Signature status and completion data from DocuSign or SignNow.
    • Payment Processors: Transaction confirmations and subscription status from Stripe.

    5. How We Collect Your Data

    We collect personal data through:

    • Direct Interactions: When you create an account, submit forms, request NDA access, or contact support.
    • Automated Technologies: Through cookies, analytics tools, and server logs when you use our platform.
    • Third-Party Sources: From authentication providers, e-signature services, and payment processors you authorize.
    • Publicly Available Sources: Company information from public business registries where relevant.

    7. How We Use Your Data

    We use your personal data for the following purposes:

    • Service Provision: To operate, maintain, and improve VendorLens features and functionality.
    • Account Management: To manage your account, subscriptions, and user preferences.
    • NDA Processing: To facilitate NDA requests, approvals, and document access workflows.
    • Communication: To respond to inquiries, provide support, and send service-related notifications.
    • Security: To detect, prevent, and address fraud, abuse, and security issues.
    • Analytics: To understand usage patterns and improve our services.
    • Compliance: To comply with legal obligations and enforce our terms of service.
    • Marketing: With your consent, to send promotional communications about our services.

    8. Customer Content Responsibility

    VendorLens processes information submitted by customers through the platform. Customers are responsible for ensuring that any personal data submitted to VendorLens:

    • Is lawfully collected
    • Is accurate
    • Is appropriate for disclosure
    • Complies with applicable data protection laws

    VendorLens does not independently verify customer-provided data.

    9. Third-Party Information

    VendorLens provides tools enabling customers to share information with third parties. VendorLens does not verify or validate the accuracy of information published by customers.

    VendorLens shall not be responsible for any reliance placed on such information by third parties.

    9A. Supplier Assessment Data

    The Vendor Assessments feature lets a customer (the "assessing organisation") review its own suppliers. Where personal data is processed through this feature, the assessing organisation is the Controller and VendorLens acts as Processor on its documented instructions under our Data Processing Agreement.

    Data processed in this feature includes: supplier company records (name, category, industry, criticality, contract term, internal owner); supplier contact details (name, business email) entered by the assessing organisation; assessment invitations and reminders sent to those contacts, together with the delivery status and the access-link identifiers used to authenticate the responder; questionnaire responses submitted by the supplier, including free-text answers and autosaved drafts; evidence files uploaded by the supplier in support of an answer; and decisions recorded by the assessing organisation, including outcome, rationale, residual-risk note, conditions and next review date.

    Supplier contacts receive an invitation because the assessing organisation identified them as the appropriate respondent. VendorLens does not use supplier contact details, questionnaire responses or evidence files for its own purposes, does not sell them, and does not use them to train models. Access links are time-limited, stored only in hashed form, excluded from analytics and search-engine indexing, and can be revoked or rotated by the assessing organisation.

    Evidence files are validated on upload for file type and structure and are stored in access-controlled storage; they are retrievable only through short-lived signed links issued to authorised users. Access, answer submissions, clarifications and decisions are written to an assessment audit log with the acting user recorded server-side.

    Assessment records, responses, evidence and decisions are retained for as long as the assessing organisation's account remains active, and are deleted in line with Section 12 (Data Retention) after account closure. A supplier contact who wishes to exercise data-subject rights in relation to an assessment should contact the assessing organisation as Controller; if a request reaches us first, we will refer it to them and assist as Processor.

    10. Data Sharing and Disclosure

    We may share your personal data with:

    10.1 Service Providers

    Third-party companies that help us operate our business, including:

    • Cloud Infrastructure: Supabase (database and authentication services)
    • Payment Processing: Stripe (payment processing)
    • E-Signature: DocuSign, SignNow (electronic signature services)
    • Customer Support: Tawk.to (live chat)
    • Analytics: Privacy-focused analytics tools

    10.2 Business Transfers

    In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

    10.3 Legal Requirements

    We may disclose your data when required by law, court order, or governmental authority, or to protect our rights, safety, or property.

    10.4 With Your Consent

    We may share your information for other purposes with your explicit consent.

    10.5 Subprocessors

    VendorLens may engage third-party service providers ("Subprocessors") to assist in providing the Service. These subprocessors may include:

    • Cloud infrastructure providers
    • Authentication providers
    • Payment processors
    • E-signature providers
    • Analytics providers
    • AI Processing Service — Lovable AI gateway and its underlying model providers: purpose: generating draft suggestions for AI-assisted features, including AI-assisted analysis of security documents you select (see sections 18A and 18B). Content processed: text extracted from the documents selected for a run and the trust centre content under review.
    • Customer support providers

    VendorLens ensures that subprocessors:

    • Are subject to appropriate contractual obligations
    • Implement appropriate security measures
    • Process personal data only as instructed

    VendorLens may update subprocessors from time to time. Customers may request an up-to-date list of subprocessors by contacting privacy@vendorlens.io.

    11. International Data Transfers

    Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:

    • Transfers to countries with an EU adequacy decision (e.g., UK, Switzerland, Canada)
    • Standard Contractual Clauses (SCCs) approved by the European Commission
    • Binding Corporate Rules where applicable
    • Additional technical and organizational measures to protect your data

    You may request information about the safeguards in place for specific transfers by contacting our Data Protection Officer.

    12. Data Retention

    VendorLens retains personal data only for as long as necessary to fulfill the purposes described in this Policy and in accordance with contractual obligations, legal requirements, and legitimate business needs.

    Following account termination, certain data may be retained for a limited period to:

    • Comply with legal obligations
    • Resolve disputes
    • Enforce agreements
    • Maintain security logs

    Specific retention periods include:

    • Account Data: Retained while your account is active and for a limited period after termination in accordance with our Terms of Service.
    • Transaction Records: Retained for 7 years to comply with Cyprus tax and accounting regulations.
    • Audit Logs: Retained for 3 years for security and compliance purposes.
    • NDA Records: Retained for the duration of the NDA plus 7 years after expiry.
    • Marketing Preferences: Retained until you withdraw consent or for 3 years of inactivity.
    • Support Communications: Retained for 2 years after resolution.
    • AI Processing: Within VendorLens, we retain the extracted document passages cited by an AI suggestion, plus the suggestions and their review status, for as long as the underlying document and workspace exist. Retention by the AI gateway and its underlying model providers is governed by their terms and is described in section 18A.

    13. Your Rights Under GDPR

    Under GDPR and Cyprus data protection law, you have the following rights:

    • Right of Access (Article 15): Request a copy of your personal data and information about how we process it.
    • Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
    • Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten") in certain circumstances.
    • Right to Restriction (Article 18): Request that we limit the processing of your data in certain situations.
    • Right to Data Portability (Article 20): Receive your data in a structured, commonly used format and transfer it to another controller.
    • Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing.
    • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
    • Rights Related to Automated Decisions (Article 22): Not be subject to solely automated decisions with legal or significant effects, and request human intervention.

    To exercise any of these rights, please contact us at privacy@vendorlens.io. We will respond within one month, as required by GDPR.

    14. Security Measures

    VendorLens implements appropriate technical and organizational measures designed to protect personal data, including:

    • Encryption in transit using TLS
    • Access control and authentication mechanisms
    • Role-based access controls
    • Logging and monitoring
    • Infrastructure security controls
    • Regular backups
    • Least privilege access policies

    Additional information regarding our security practices is available on our Security page.

    Despite these measures, no system can be guaranteed to be completely secure.

    15. Data Breach Notification

    VendorLens shall notify affected customers without undue delay upon becoming aware of a personal data breach affecting personal data processed by VendorLens.

    Where VendorLens acts as a Data Processor, VendorLens shall notify the relevant customer to enable compliance with applicable legal obligations, including GDPR breach notification requirements.

    16. Cookies and Tracking Technologies

    We use cookies and similar technologies to operate the platform and, where permitted, to measure usage. Our approach depends on the region you are visiting from.

    16.1 Essential Cookies

    Required for the platform to function, including authentication and security cookies. These cannot be disabled.

    16.2 Regional Approach

    For visitors in the United Kingdom, the EU/EEA and Switzerland, analytics and advertising technologies are not loaded until you give an explicit choice. Reject and Accept are presented with equal prominence, and continued browsing is never treated as consent.

    For visitors in the United States and other regions outside that list, analytics is enabled by default and you can opt out at any time. Where the region cannot be determined reliably, we apply the stricter opt-in approach.

    16.3 Region Detection

    Region is determined server-side by our content delivery provider, Cloudflare, which supplies a two-letter country code. We do not store your IP address for this purpose and do not infer location from your browser language, timezone or locale.

    16.4 Analytics and Advertising

    Where permitted, we use Google Analytics 4 to measure site and product usage, and Google Ads attribution to understand which campaigns lead to account registrations. Analytics and advertising can be enabled or disabled independently.

    16.5 Global Privacy Control

    If your browser sends a Global Privacy Control signal, we treat it as an advertising opt-out: advertising storage and personalization stay disabled, advertising identifiers such as the Google click identifier are not stored, and no attributed advertising conversion is reported.

    16.6 Changing Your Choices

    Use the "Privacy choices" link in the site footer at any time to view your detected policy, enable or disable analytics and advertising attribution, see whether a Global Privacy Control signal was detected, or withdraw an earlier decision. Browser settings can also be used to control cookies, though disabling certain cookies may affect platform functionality.

    17. Children's Privacy

    VendorLens is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@vendorlens.io, and we will take steps to delete such information.

    18. Automated Decision-Making

    VendorLens does not use solely automated decision-making processes that produce legal or similarly significant effects on individuals. Any automated processing we perform (such as spam filtering or usage analytics) is supplementary and does not determine access to services or produce significant effects on data subjects.

    18A. AI Processing and Model Usage

    Where VendorLens offers AI-assisted features, requests are sent through the Lovable AI gateway, which forwards them to the underlying model provider that serves the selected model. We do not train our own models on your content.

    • Instructed Processing Only: We instruct our AI subprocessors to process the content we send solely to return a result to the requesting workspace, and not for their own purposes.
    • Per-Request Isolation: Each request carries only the content selected for that request by the requesting workspace. We do not send one customer's content in another customer's request.
    • Human in the Loop: AI output is presented to authorised users as draft suggestions for review. VendorLens does not use AI output to make solely automated decisions with legal or similarly significant effects.
    • Retention and Training at Provider Level: Retention and training behaviour at the gateway and its underlying model providers is governed by those providers' terms, which we do not control and cannot unilaterally guarantee. We therefore do not claim that content sent for AI processing is never retained or never used for training. The current status of our data-processing terms, retention configuration and training settings for these subprocessors is available on request from privacy@vendorlens.io.
    • Workspace Control: AI-assisted features are off by default and are enabled per workspace. If a workspace is not enabled, no workspace content is sent for AI processing.

    18B. AI-Assisted Document Analysis

    The AI Trust Pack Builder is an optional, workspace-level feature that reads security documents you have already uploaded to your Document Vault and proposes draft improvements to your trust centre — for example suggested document titles, document types and dates, visibility recommendations, an overview narrative, FAQ entries, certifications, custom trust sections, and notices about missing or outdated evidence.

    18B.1 When Processing Happens

    Analysis never runs on its own. It runs only when an authorised owner or editor of your workspace explicitly starts it and selects the documents to include. There is no background, scheduled or automatic analysis of your documents.

    18B.2 What Is Sent, and Where

    When an analysis is started, text extracted from the selected documents — together with the current trust centre content being reviewed — is sent through the Lovable AI gateway to the underlying model infrastructure that serves the selected model. Only the documents chosen for that analysis are included. Documents you do not select are not sent. Because uploaded security documents can contain personal data (such as names of personnel, auditors or contacts), you should select documents with that in mind.

    18B.3 Results Are Drafts Only

    Everything the analysis produces is a draft suggestion held in a private review area. Nothing is published, changed on your trust centre, or made visible to third parties automatically. Each suggestion must be reviewed and individually accepted, edited or rejected, and then explicitly applied, by an authorised owner or editor. Suggestions that would make a document publicly downloadable require a separate, additional confirmation before they can be applied.

    18B.4 No Solely Automated Decisions

    This feature does not make decisions about individuals. It does not evaluate, score or profile people, and it is not used to make solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR. A human decides what, if anything, is adopted.

    18B.5 Workspace Controls

    • The feature is disabled by default and must be enabled for your workspace before it can be used.
    • Only workspace owners and editors can start an analysis or apply a suggestion. Viewers cannot.
    • Usage is capped by a monthly allowance per workspace.
    • Starting an analysis, and accepting, editing, rejecting or applying a suggestion, are recorded in your audit log. Those audit records describe the action and the affected item; they do not store the document text that was analysed.

    18B.6 Retention of Analysis Data

    To let you check a suggestion against its source, VendorLens stores the extracted document passages a suggestion cites, together with the run's suggestions and their review status. This material is held inside your workspace, is accessible only to your authorised workspace members, and is deleted when the underlying document or the workspace is deleted. Retention by the AI gateway and its underlying model providers is governed by their terms as described in section 18A.

    If you would prefer that no document content is processed by AI, ask us to keep the feature disabled for your workspace, or simply do not start an analysis.

    19. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

    • Posting the updated policy on our website with a new "Last Updated" date
    • Sending an email notification to registered users for significant changes
    • Displaying a prominent notice on our platform

    We encourage you to review this policy periodically. Continued use of VendorLens after changes constitutes acceptance of the updated policy.

    20. Contact Us

    If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    VendorLens Technologies Ltd

    Company Registration Number: HE488809 · Limassol, Cyprus
    General Inquiries: hello@vendorlens.io
    Privacy Inquiries: privacy@vendorlens.io
    Data Protection Officer: dpo@vendorlens.io
    Security Contact: security@vendorlens.io

    21. Supervisory Authority

    If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with the supervisory authority in Cyprus:

    Office of the Commissioner for Personal Data Protection

    Address: 1 Iasonos Street, 1082 Nicosia, Cyprus
    Telephone: +357 22 818 456
    Fax: +357 22 304 565
    Email: commissioner@dataprotection.gov.cy
    Website: www.dataprotection.gov.cy

    You may also lodge a complaint with the supervisory authority in your country of residence if you are located in another EU member state.