Privacy Policy
This policy explains what personal information VendorDefense collects, why we use it, how we protect it, and what choices customers and users have when using our website and platform.
Quick overview
What matters most on this page
Operational data only
We collect the information needed to run accounts, provide the service, secure the platform, and communicate with customers.
No surprise data sales
VendorDefense does not sell personal information. Data sharing is limited to service delivery, legal compliance, and platform protection.
Customer control and rights
Users and organizations can request access, correction, deletion, or export of eligible personal information, subject to legal and contractual limits.
01
Scope of This Policy
This policy covers personal information collected through the VendorDefense website, platform, communications, and support interactions.
This Privacy Policy explains how VendorDefense collects, uses, discloses, and protects personal information in connection with our website, hosted applications, dashboards, support channels, and related business operations.
This policy applies to information that identifies, relates to, describes, or could reasonably be linked with an individual. It does not expand any contractual rights or restrict processing that is required to deliver the service under a separate commercial agreement.
02
Information We Collect
We collect information directly from you, from your organization, and automatically through normal use of the service.
The information we collect depends on how you interact with VendorDefense. It may include account details, professional contact information, organization details, billing contacts, support requests, uploaded documents, system logs, device information, and usage events.
We may also collect information from forms, demos, communications, authentication events, cookies, analytics technologies, and integrations you choose to connect to the platform.
Account and profile information such as name, email address, role, company, and login credentials.
Business records and platform content such as vendor contracts, renewal dates, pricing details, notes, reminders, and related metadata.
Technical and diagnostic data such as IP address, browser type, device identifiers, pages viewed, timestamps, and security logs.
03
How We Use Information
Collected information is used to operate the platform, improve reliability, support customers, and satisfy legal obligations.
VendorDefense uses personal information to provide and maintain the service, authenticate users, process uploaded material, generate contract insights, respond to support requests, manage subscriptions, send transactional notices, and protect the platform against misuse or security threats.
We may also use information to improve product performance, troubleshoot issues, understand feature adoption, develop new capabilities, comply with legal obligations, and enforce our agreements.
05
Data Retention
Information is retained for as long as reasonably necessary to provide the service and meet legal, security, and operational needs.
VendorDefense retains personal information for the period needed to fulfill the purposes described in this policy, including maintaining active accounts, supporting customer workflows, resolving disputes, enforcing agreements, and satisfying tax, accounting, security, and legal obligations.
Retention periods may vary depending on the type of information, the sensitivity of the data, applicable legal requirements, and whether the information is needed to prevent fraud or investigate incidents.
06
Security Measures
We use reasonable administrative, technical, and organizational safeguards, while recognizing that no system is perfectly secure.
VendorDefense maintains safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. These measures may include access controls, encryption, logging, environment segmentation, backup procedures, and vendor management practices.
Even with these controls, no method of transmission or storage is guaranteed to be completely secure. Customers are also responsible for protecting their own credentials, devices, endpoints, and internal access practices.
08
Your Privacy Rights and Choices
Depending on your location and relationship to the data, you may have rights to access, correct, export, restrict, or delete certain personal information.
Subject to applicable law, you or your organization may request access to personal information, correction of inaccurate information, deletion of eligible information, or a copy of information in a portable format. You may also object to or request restriction of certain processing in some jurisdictions.
If VendorDefense processes information on behalf of your employer or organization, we may direct your request to the relevant account administrator because that organization may control the data and determine how it is processed.
09
Children's Privacy and International Data Transfers
The service is intended for business users, and data may be processed in locations where we or our providers operate.
VendorDefense is not directed to children and is not intended for use by individuals under the age required by applicable law to consent to data processing in their jurisdiction. If we learn that we have collected personal information from a child inappropriately, we will take steps to delete it.
VendorDefense and its service providers may process information in countries other than the one where the information was originally collected. Where required, we use appropriate safeguards to support lawful international data transfers.
10
Policy Updates and Contact Information
We may revise this policy as the product and legal environment evolve, and the latest version will be posted here.
VendorDefense may update this Privacy Policy from time to time to reflect product changes, legal requirements, security practices, or operational updates. When we do, we will update the effective date shown on this page.
If you have questions, requests, or complaints about this policy or our privacy practices, contact us using the address listed below and include enough detail for us to verify and respond to your request.