Privacy Policy
Effective Date: August 11, 2026
Last Updated:
1. Introduction
VendorLens ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our trust center platform and related services.
This policy is compliant with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679), the Cyprus Processing of Personal Data (Protection of Individuals) Law of 2018 (Law 125(I)/2018), and the EU ePrivacy Directive as applicable in the Republic of Cyprus.
By using VendorLens, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
2. Data Controller Information
For the purposes of applicable data protection laws, the Data Controller is:
VendorLens Technologies Ltd
Company Registration Number: HE488809 (Registrar of Companies, Republic of Cyprus)
Registered Office: Limassol, Cyprus
Data Protection Officer: dpo@vendorlens.io
We are responsible for deciding how and why your personal data is processed. If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer using the details above.
3. Role of VendorLens
VendorLens may act as either a Data Controller or Data Processor depending on the nature of the processing activities.
VendorLens as Data Controller
VendorLens acts as a Data Controller when processing personal data relating to:
- Account registration
- Billing and payments
- Customer support
- Platform analytics
- Security and fraud prevention
- Marketing communications
VendorLens as Data Processor
VendorLens acts as a Data Processor when processing personal data submitted by customers through the VendorLens platform ("Customer Data"). In such cases, the customer acts as the Data Controller, and VendorLens processes personal data solely on documented instructions from the customer.
For the avoidance of doubt, this Privacy Policy applies solely to personal data. Non-personal data, including business, operational, or compliance documentation uploaded by customers, is governed by the applicable Terms of Service.
Where VendorLens acts as a Data Processor, such processing may be governed by a Data Processing Agreement ("DPA") where applicable.
4. Personal Data We Collect
We collect and process the following categories of personal data:
4.1 Information You Provide
- Account Information: Name, email address, company name, job title, and password when you register for an account.
- Profile Information: Company details, contact information, and professional information you add to your vendor profile.
- Communication Data: Information you provide when contacting us for support, including chat transcripts and email correspondence.
- NDA Request Information: Name, email, company, and any additional information required for NDA processing.
- Payment Information: Billing address and payment method details (processed securely through Stripe).
4.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, time spent on the platform.
- Device Information: IP address, browser type, operating system, device identifiers.
- Log Data: Access times, referring URLs, and system activity logs.
- Cookie Data: Information collected through cookies and similar technologies (see Section 16).
4.3 Information from Third Parties
- Authentication Providers: If you sign in via third-party providers (e.g., Google), we receive your name and email.
- E-Signature Providers: Signature status and completion data from DocuSign or SignNow.
- Payment Processors: Transaction confirmations and subscription status from Stripe.
5. How We Collect Your Data
We collect personal data through:
- Direct Interactions: When you create an account, submit forms, request NDA access, or contact support.
- Automated Technologies: Through cookies, analytics tools, and server logs when you use our platform.
- Third-Party Sources: From authentication providers, e-signature services, and payment processors you authorize.
- Publicly Available Sources: Company information from public business registries where relevant.
6. Legal Basis for Processing
Under GDPR and Cyprus data protection law, we process your personal data based on the following legal grounds:
- Contract Performance (Article 6(1)(b) GDPR): Processing necessary to provide our services, manage your account, and fulfill our contractual obligations to you.
- Legitimate Interests (Article 6(1)(f) GDPR): For improving our services, preventing fraud, ensuring security, and marketing (where you have not opted out). We balance our interests against your rights and freedoms.
- Consent (Article 6(1)(a) GDPR): Where you have given explicit consent, such as for marketing communications or optional cookies. You can withdraw consent at any time.
- Legal Obligation (Article 6(1)(c) GDPR): Where processing is necessary to comply with legal requirements, such as tax regulations or court orders.
7. How We Use Your Data
We use your personal data for the following purposes:
- Service Provision: To operate, maintain, and improve VendorLens features and functionality.
- Account Management: To manage your account, subscriptions, and user preferences.
- NDA Processing: To facilitate NDA requests, approvals, and document access workflows.
- Communication: To respond to inquiries, provide support, and send service-related notifications.
- Security: To detect, prevent, and address fraud, abuse, and security issues.
- Analytics: To understand usage patterns and improve our services.
- Compliance: To comply with legal obligations and enforce our terms of service.
- Marketing: With your consent, to send promotional communications about our services.
8. Customer Content Responsibility
VendorLens processes information submitted by customers through the platform. Customers are responsible for ensuring that any personal data submitted to VendorLens:
- Is lawfully collected
- Is accurate
- Is appropriate for disclosure
- Complies with applicable data protection laws
VendorLens does not independently verify customer-provided data.
9. Third-Party Information
VendorLens provides tools enabling customers to share information with third parties. VendorLens does not verify or validate the accuracy of information published by customers.
VendorLens shall not be responsible for any reliance placed on such information by third parties.
9A. Supplier Assessment Data
The Vendor Assessments feature lets a customer (the "assessing organisation") review its own suppliers. Where personal data is processed through this feature, the assessing organisation is the Controller and VendorLens acts as Processor on its documented instructions under our Data Processing Agreement.
Data processed in this feature includes: supplier company records (name, category, industry, criticality, contract term, internal owner); supplier contact details (name, business email) entered by the assessing organisation; assessment invitations and reminders sent to those contacts, together with the delivery status and the access-link identifiers used to authenticate the responder; questionnaire responses submitted by the supplier, including free-text answers and autosaved drafts; evidence files uploaded by the supplier in support of an answer; and decisions recorded by the assessing organisation, including outcome, rationale, residual-risk note, conditions and next review date.
Supplier contacts receive an invitation because the assessing organisation identified them as the appropriate respondent. VendorLens does not use supplier contact details, questionnaire responses or evidence files for its own purposes, does not sell them, and does not use them to train models. Access links are time-limited, stored only in hashed form, excluded from analytics and search-engine indexing, and can be revoked or rotated by the assessing organisation.
Evidence files are validated on upload for file type and structure and are stored in access-controlled storage; they are retrievable only through short-lived signed links issued to authorised users. Access, answer submissions, clarifications and decisions are written to an assessment audit log with the acting user recorded server-side.
Assessment records, responses, evidence and decisions are retained for as long as the assessing organisation's account remains active, and are deleted in line with Section 12 (Data Retention) after account closure. A supplier contact who wishes to exercise data-subject rights in relation to an assessment should contact the assessing organisation as Controller; if a request reaches us first, we will refer it to them and assist as Processor.
10. Data Sharing and Disclosure
We may share your personal data with:
10.1 Service Providers
Third-party companies that help us operate our business, including:
- Cloud Infrastructure: Supabase (database and authentication services)
- Payment Processing: Stripe (payment processing)
- E-Signature: DocuSign, SignNow (electronic signature services)
- Customer Support: Tawk.to (live chat)
- Analytics: Privacy-focused analytics tools
10.2 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
10.3 Legal Requirements
We may disclose your data when required by law, court order, or governmental authority, or to protect our rights, safety, or property.
10.4 With Your Consent
We may share your information for other purposes with your explicit consent.
10.5 Subprocessors
VendorLens may engage third-party service providers ("Subprocessors") to assist in providing the Service. These subprocessors may include:
- Cloud infrastructure providers
- Authentication providers
- Payment processors
- E-signature providers
- Analytics providers
- AI Processing Service — Lovable AI gateway and its underlying model providers: purpose: generating draft suggestions for AI-assisted features, including AI-assisted analysis of security documents you select (see sections 18A and 18B). Content processed: text extracted from the documents selected for a run and the trust centre content under review.
- Customer support providers
VendorLens ensures that subprocessors:
- Are subject to appropriate contractual obligations
- Implement appropriate security measures
- Process personal data only as instructed
VendorLens may update subprocessors from time to time. Customers may request an up-to-date list of subprocessors by contacting privacy@vendorlens.io.
11. International Data Transfers
Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
- Transfers to countries with an EU adequacy decision (e.g., UK, Switzerland, Canada)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- Additional technical and organizational measures to protect your data
You may request information about the safeguards in place for specific transfers by contacting our Data Protection Officer.
12. Data Retention
VendorLens retains personal data only for as long as necessary to fulfill the purposes described in this Policy and in accordance with contractual obligations, legal requirements, and legitimate business needs.
Following account termination, certain data may be retained for a limited period to:
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
- Maintain security logs
Specific retention periods include:
- Account Data: Retained while your account is active and for a limited period after termination in accordance with our Terms of Service.
- Transaction Records: Retained for 7 years to comply with Cyprus tax and accounting regulations.
- Audit Logs: Retained for 3 years for security and compliance purposes.
- NDA Records: Retained for the duration of the NDA plus 7 years after expiry.
- Marketing Preferences: Retained until you withdraw consent or for 3 years of inactivity.
- Support Communications: Retained for 2 years after resolution.
- AI Processing: Within VendorLens, we retain the extracted document passages cited by an AI suggestion, plus the suggestions and their review status, for as long as the underlying document and workspace exist. Retention by the AI gateway and its underlying model providers is governed by their terms and is described in section 18A.
13. Your Rights Under GDPR
Under GDPR and Cyprus data protection law, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data and information about how we process it.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten") in certain circumstances.
- Right to Restriction (Article 18): Request that we limit the processing of your data in certain situations.
- Right to Data Portability (Article 20): Receive your data in a structured, commonly used format and transfer it to another controller.
- Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
- Rights Related to Automated Decisions (Article 22): Not be subject to solely automated decisions with legal or significant effects, and request human intervention.
To exercise any of these rights, please contact us at privacy@vendorlens.io. We will respond within one month, as required by GDPR.
14. Security Measures
VendorLens implements appropriate technical and organizational measures designed to protect personal data, including:
- Encryption in transit using TLS
- Access control and authentication mechanisms
- Role-based access controls
- Logging and monitoring
- Infrastructure security controls
- Regular backups
- Least privilege access policies
Additional information regarding our security practices is available on our Security page.
Despite these measures, no system can be guaranteed to be completely secure.
15. Data Breach Notification
VendorLens shall notify affected customers without undue delay upon becoming aware of a personal data breach affecting personal data processed by VendorLens.
Where VendorLens acts as a Data Processor, VendorLens shall notify the relevant customer to enable compliance with applicable legal obligations, including GDPR breach notification requirements.
17. Children's Privacy
VendorLens is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@vendorlens.io, and we will take steps to delete such information.
18. Automated Decision-Making
VendorLens does not use solely automated decision-making processes that produce legal or similarly significant effects on individuals. Any automated processing we perform (such as spam filtering or usage analytics) is supplementary and does not determine access to services or produce significant effects on data subjects.
18A. AI Processing and Model Usage
Where VendorLens offers AI-assisted features, requests are sent through the Lovable AI gateway, which forwards them to the underlying model provider that serves the selected model. We do not train our own models on your content.
- Instructed Processing Only: We instruct our AI subprocessors to process the content we send solely to return a result to the requesting workspace, and not for their own purposes.
- Per-Request Isolation: Each request carries only the content selected for that request by the requesting workspace. We do not send one customer's content in another customer's request.
- Human in the Loop: AI output is presented to authorised users as draft suggestions for review. VendorLens does not use AI output to make solely automated decisions with legal or similarly significant effects.
- Retention and Training at Provider Level: Retention and training behaviour at the gateway and its underlying model providers is governed by those providers' terms, which we do not control and cannot unilaterally guarantee. We therefore do not claim that content sent for AI processing is never retained or never used for training. The current status of our data-processing terms, retention configuration and training settings for these subprocessors is available on request from privacy@vendorlens.io.
- Workspace Control: AI-assisted features are off by default and are enabled per workspace. If a workspace is not enabled, no workspace content is sent for AI processing.
18B. AI-Assisted Document Analysis
The AI Trust Pack Builder is an optional, workspace-level feature that reads security documents you have already uploaded to your Document Vault and proposes draft improvements to your trust centre — for example suggested document titles, document types and dates, visibility recommendations, an overview narrative, FAQ entries, certifications, custom trust sections, and notices about missing or outdated evidence.
18B.1 When Processing Happens
Analysis never runs on its own. It runs only when an authorised owner or editor of your workspace explicitly starts it and selects the documents to include. There is no background, scheduled or automatic analysis of your documents.
18B.2 What Is Sent, and Where
When an analysis is started, text extracted from the selected documents — together with the current trust centre content being reviewed — is sent through the Lovable AI gateway to the underlying model infrastructure that serves the selected model. Only the documents chosen for that analysis are included. Documents you do not select are not sent. Because uploaded security documents can contain personal data (such as names of personnel, auditors or contacts), you should select documents with that in mind.
18B.3 Results Are Drafts Only
Everything the analysis produces is a draft suggestion held in a private review area. Nothing is published, changed on your trust centre, or made visible to third parties automatically. Each suggestion must be reviewed and individually accepted, edited or rejected, and then explicitly applied, by an authorised owner or editor. Suggestions that would make a document publicly downloadable require a separate, additional confirmation before they can be applied.
18B.4 No Solely Automated Decisions
This feature does not make decisions about individuals. It does not evaluate, score or profile people, and it is not used to make solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR. A human decides what, if anything, is adopted.
18B.5 Workspace Controls
- The feature is disabled by default and must be enabled for your workspace before it can be used.
- Only workspace owners and editors can start an analysis or apply a suggestion. Viewers cannot.
- Usage is capped by a monthly allowance per workspace.
- Starting an analysis, and accepting, editing, rejecting or applying a suggestion, are recorded in your audit log. Those audit records describe the action and the affected item; they do not store the document text that was analysed.
18B.6 Retention of Analysis Data
To let you check a suggestion against its source, VendorLens stores the extracted document passages a suggestion cites, together with the run's suggestions and their review status. This material is held inside your workspace, is accessible only to your authorised workspace members, and is deleted when the underlying document or the workspace is deleted. Retention by the AI gateway and its underlying model providers is governed by their terms as described in section 18A.
If you would prefer that no document content is processed by AI, ask us to keep the feature disabled for your workspace, or simply do not start an analysis.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification to registered users for significant changes
- Displaying a prominent notice on our platform
We encourage you to review this policy periodically. Continued use of VendorLens after changes constitutes acceptance of the updated policy.
20. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
VendorLens Technologies Ltd
Company Registration Number: HE488809 · Limassol, Cyprus
General Inquiries: hello@vendorlens.io
Privacy Inquiries: privacy@vendorlens.io
Data Protection Officer: dpo@vendorlens.io
Security Contact: security@vendorlens.io