Brunnfeld

Privacy Policy

Last updated: July 2026

This privacy policy explains how we process personal data when you use the Vendor Risk Platform website and application. Replace this template with a version reviewed for your legal setup (GDPR, hosting providers, Stripe, Supabase).

1. Controller

[Company name]

[Address]

Email: [privacy@your-company.com]

2. What data we process

Account data (name, email, organization), usage data within the platform, billing data processed via Stripe, and documents uploaded by vendors as part of the service.

3. Purposes and legal bases

We process data to provide the platform, manage contracts, ensure security, and comply with legal obligations (Art. 6(1)(b) and (f) GDPR).

4. Processors and hosting

We use Supabase (database, auth, storage) and Vercel (hosting) in the EU where possible. Payment processing is handled by Stripe.

5. Retention

We retain data as long as your account is active and as required for audit, billing, and legal obligations.

6. Your rights

You may request access, rectification, deletion, restriction, portability, and object to processing. Contact [privacy@your-company.com]. You may lodge a complaint with your supervisory authority.

7. Cookies and authentication

The application uses session cookies required for login and security. No marketing cookies are used in the MVP.