Privacy Policy
Last updated: July 2026
This privacy policy explains how we process personal data when you use the Vendor Risk Platform website and application. Replace this template with a version reviewed for your legal setup (GDPR, hosting providers, Stripe, Supabase).
1. Controller
[Company name]
[Address]
Email: [privacy@your-company.com]
2. What data we process
Account data (name, email, organization), usage data within the platform, billing data processed via Stripe, and documents uploaded by vendors as part of the service.
3. Purposes and legal bases
We process data to provide the platform, manage contracts, ensure security, and comply with legal obligations (Art. 6(1)(b) and (f) GDPR).
4. Processors and hosting
We use Supabase (database, auth, storage) and Vercel (hosting) in the EU where possible. Payment processing is handled by Stripe.
5. Retention
We retain data as long as your account is active and as required for audit, billing, and legal obligations.
6. Your rights
You may request access, rectification, deletion, restriction, portability, and object to processing. Contact [privacy@your-company.com]. You may lodge a complaint with your supervisory authority.
7. Cookies and authentication
The application uses session cookies required for login and security. No marketing cookies are used in the MVP.