We use cookies and similar technologies to improve your experience and analyse usage. By continuing you agree to our Privacy Policy.

    VendorLens

    Privacy Policy

    Effective Date: March 31, 2026
    Last Updated:

    1. Introduction

    VendorLens ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our trust center platform and related services.

    This policy is compliant with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679), the Cyprus Processing of Personal Data (Protection of Individuals) Law of 2018 (Law 125(I)/2018), and the EU ePrivacy Directive as applicable in the Republic of Cyprus.

    By using VendorLens, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

    2. Data Controller Information

    For the purposes of applicable data protection laws, the Data Controller is:

    VendorLens Technologies Ltd

    Registered Office: Nicosia, Cyprus
    Data Protection Officer: dpo@vendorlens.io

    We are responsible for deciding how and why your personal data is processed. If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer using the details above.

    3. Role of VendorLens

    VendorLens may act as either a Data Controller or Data Processor depending on the nature of the processing activities.

    VendorLens as Data Controller

    VendorLens acts as a Data Controller when processing personal data relating to:

    • Account registration
    • Billing and payments
    • Customer support
    • Platform analytics
    • Security and fraud prevention
    • Marketing communications

    VendorLens as Data Processor

    VendorLens acts as a Data Processor when processing personal data submitted by customers through the VendorLens platform ("Customer Data"). In such cases, the customer acts as the Data Controller, and VendorLens processes personal data solely on documented instructions from the customer.

    For the avoidance of doubt, this Privacy Policy applies solely to personal data. Non-personal data, including business, operational, or compliance documentation uploaded by customers, is governed by the applicable Terms of Service.

    Where VendorLens acts as a Data Processor, such processing may be governed by a Data Processing Agreement ("DPA") where applicable.

    4. Personal Data We Collect

    We collect and process the following categories of personal data:

    4.1 Information You Provide

    • Account Information: Name, email address, company name, job title, and password when you register for an account.
    • Profile Information: Company details, contact information, and professional information you add to your vendor profile.
    • Communication Data: Information you provide when contacting us for support, including chat transcripts and email correspondence.
    • NDA Request Information: Name, email, company, and any additional information required for NDA processing.
    • Payment Information: Billing address and payment method details (processed securely through Stripe).

    4.2 Information Collected Automatically

    • Usage Data: Pages visited, features used, actions taken, time spent on the platform.
    • Device Information: IP address, browser type, operating system, device identifiers.
    • Log Data: Access times, referring URLs, and system activity logs.
    • Cookie Data: Information collected through cookies and similar technologies (see Section 16).

    4.3 Information from Third Parties

    • Authentication Providers: If you sign in via third-party providers (e.g., Google), we receive your name and email.
    • E-Signature Providers: Signature status and completion data from DocuSign or SignNow.
    • Payment Processors: Transaction confirmations and subscription status from Stripe.

    5. How We Collect Your Data

    We collect personal data through:

    • Direct Interactions: When you create an account, submit forms, request NDA access, or contact support.
    • Automated Technologies: Through cookies, analytics tools, and server logs when you use our platform.
    • Third-Party Sources: From authentication providers, e-signature services, and payment processors you authorize.
    • Publicly Available Sources: Company information from public business registries where relevant.

    7. How We Use Your Data

    We use your personal data for the following purposes:

    • Service Provision: To operate, maintain, and improve VendorLens features and functionality.
    • Account Management: To manage your account, subscriptions, and user preferences.
    • NDA Processing: To facilitate NDA requests, approvals, and document access workflows.
    • Communication: To respond to inquiries, provide support, and send service-related notifications.
    • Security: To detect, prevent, and address fraud, abuse, and security issues.
    • Analytics: To understand usage patterns and improve our services.
    • Compliance: To comply with legal obligations and enforce our terms of service.
    • Marketing: With your consent, to send promotional communications about our services.

    8. Customer Content Responsibility

    VendorLens processes information submitted by customers through the platform. Customers are responsible for ensuring that any personal data submitted to VendorLens:

    • Is lawfully collected
    • Is accurate
    • Is appropriate for disclosure
    • Complies with applicable data protection laws

    VendorLens does not independently verify customer-provided data.

    9. Third-Party Information

    VendorLens provides tools enabling customers to share information with third parties. VendorLens does not verify or validate the accuracy of information published by customers.

    VendorLens shall not be responsible for any reliance placed on such information by third parties.

    10. Data Sharing and Disclosure

    We may share your personal data with:

    10.1 Service Providers

    Third-party companies that help us operate our business, including:

    • Cloud Infrastructure: Supabase (database and authentication services)
    • Payment Processing: Stripe (payment processing)
    • E-Signature: DocuSign, SignNow (electronic signature services)
    • Customer Support: Tawk.to (live chat)
    • Analytics: Privacy-focused analytics tools

    10.2 Business Transfers

    In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

    10.3 Legal Requirements

    We may disclose your data when required by law, court order, or governmental authority, or to protect our rights, safety, or property.

    10.4 With Your Consent

    We may share your information for other purposes with your explicit consent.

    10.5 Subprocessors

    VendorLens may engage third-party service providers ("Subprocessors") to assist in providing the Service. These subprocessors may include:

    • Cloud infrastructure providers
    • Authentication providers
    • Payment processors
    • E-signature providers
    • Analytics providers
    • Customer support providers

    VendorLens ensures that subprocessors:

    • Are subject to appropriate contractual obligations
    • Implement appropriate security measures
    • Process personal data only as instructed

    VendorLens may update subprocessors from time to time. Customers may request an up-to-date list of subprocessors by contacting privacy@vendorlens.io.

    11. International Data Transfers

    Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:

    • Transfers to countries with an EU adequacy decision (e.g., UK, Switzerland, Canada)
    • Standard Contractual Clauses (SCCs) approved by the European Commission
    • Binding Corporate Rules where applicable
    • Additional technical and organizational measures to protect your data

    You may request information about the safeguards in place for specific transfers by contacting our Data Protection Officer.

    12. Data Retention

    VendorLens retains personal data only for as long as necessary to fulfill the purposes described in this Policy and in accordance with contractual obligations, legal requirements, and legitimate business needs.

    Following account termination, certain data may be retained for a limited period to:

    • Comply with legal obligations
    • Resolve disputes
    • Enforce agreements
    • Maintain security logs

    Specific retention periods include:

    • Account Data: Retained while your account is active and for a limited period after termination in accordance with our Terms of Service.
    • Transaction Records: Retained for 7 years to comply with Cyprus tax and accounting regulations.
    • Audit Logs: Retained for 3 years for security and compliance purposes.
    • NDA Records: Retained for the duration of the NDA plus 7 years after expiry.
    • Marketing Preferences: Retained until you withdraw consent or for 3 years of inactivity.
    • Support Communications: Retained for 2 years after resolution.

    13. Your Rights Under GDPR

    Under GDPR and Cyprus data protection law, you have the following rights:

    • Right of Access (Article 15): Request a copy of your personal data and information about how we process it.
    • Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
    • Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten") in certain circumstances.
    • Right to Restriction (Article 18): Request that we limit the processing of your data in certain situations.
    • Right to Data Portability (Article 20): Receive your data in a structured, commonly used format and transfer it to another controller.
    • Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing.
    • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
    • Rights Related to Automated Decisions (Article 22): Not be subject to solely automated decisions with legal or significant effects, and request human intervention.

    To exercise any of these rights, please contact us at privacy@vendorlens.io. We will respond within one month, as required by GDPR.

    14. Security Measures

    VendorLens implements appropriate technical and organizational measures designed to protect personal data, including:

    • Encryption in transit using TLS
    • Access control and authentication mechanisms
    • Role-based access controls
    • Logging and monitoring
    • Infrastructure security controls
    • Regular backups
    • Least privilege access policies

    Additional information regarding our security practices is available on our Security page.

    Despite these measures, no system can be guaranteed to be completely secure.

    15. Data Breach Notification

    VendorLens shall notify affected customers without undue delay upon becoming aware of a personal data breach affecting personal data processed by VendorLens.

    Where VendorLens acts as a Data Processor, VendorLens shall notify the relevant customer to enable compliance with applicable legal obligations, including GDPR breach notification requirements.

    16. Cookies and Tracking Technologies

    We use cookies and similar technologies to enhance your experience:

    16.1 Essential Cookies

    Required for the platform to function, including authentication and security cookies. These cannot be disabled.

    16.2 Analytics Cookies

    Help us understand how visitors use our platform. We use privacy-focused analytics that do not track individuals across websites.

    16.3 Functional Cookies

    Remember your preferences and settings to enhance your experience.

    16.4 Managing Cookies

    You can control cookies through your browser settings. Note that disabling certain cookies may affect platform functionality. In accordance with the EU ePrivacy Directive, we will obtain your consent before placing non-essential cookies.

    17. Children's Privacy

    VendorLens is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@vendorlens.io, and we will take steps to delete such information.

    18. Automated Decision-Making

    VendorLens does not use solely automated decision-making processes that produce legal or similarly significant effects on individuals. Any automated processing we perform (such as spam filtering or usage analytics) is supplementary and does not determine access to services or produce significant effects on data subjects.

    19. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

    • Posting the updated policy on our website with a new "Last Updated" date
    • Sending an email notification to registered users for significant changes
    • Displaying a prominent notice on our platform

    We encourage you to review this policy periodically. Continued use of VendorLens after changes constitutes acceptance of the updated policy.

    20. Contact Us

    If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    VendorLens Technologies Ltd

    General Inquiries: hello@vendorlens.io
    Privacy Inquiries: privacy@vendorlens.io
    Data Protection Officer: dpo@vendorlens.io
    Security Contact: security@vendorlens.io

    21. Supervisory Authority

    If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with the supervisory authority in Cyprus:

    Office of the Commissioner for Personal Data Protection

    Address: 1 Iasonos Street, 1082 Nicosia, Cyprus
    Telephone: +357 22 818 456
    Fax: +357 22 304 565
    Email: commissioner@dataprotection.gov.cy
    Website: www.dataprotection.gov.cy

    You may also lodge a complaint with the supervisory authority in your country of residence if you are located in another EU member state.