Vendorisk.ai // Legal & policy

Unreviewed draft // pending legal review

This document was drafted from the application's actual data flows and has not been reviewed by counsel. It is not yet legally binding and must be reviewed, completed (see the bracketed placeholders throughout, indexed under Placeholders to complete) and approved before Vendorisk.ai is offered to customers.

Document 01 // Data protection

Privacy Policy

Vendorisk.ai produces source-cited risk assessments of software vendors from public web material. This policy explains the personal data we hold about the people who use Vendorisk.ai, the personal data we necessarily process about executives named in public reporting, and what you can ask us to do about either.

Last drafted: 2026-07-31 · Version: draft 0.1 · Effective date: [Policy effective date]

01. Who is responsible

Vendorisk.ai is operated by [Legal entity name], of [Registered address]("Vendorisk.ai", "we", "us"). For the purposes of the UK GDPR and EU GDPR we are the controller of the personal data described in this policy, except where we act as processor on behalf of a customer organisation - see 02. Scope of this policy.

Our data protection contact is [Privacy contact email]. Our data protection officer and, where required, our Article 27 representative in the EU/UK is [DPO / EU representative].

02. Scope of this policy

This policy covers the Vendorisk.ai web application, its API and the transactional and digest emails we send. It covers three distinct categories of information, which are worth separating because the rules that apply to them differ:

  1. Account data - personal data about you, the person signing in. We are the controller.
  2. Vendor research data - mostly information about companies, which is not personal data, but which can include facts about named individuals acting in a professional capacity (executives, founders, officers). We are the controller.
  3. Customer workspace content - questionnaire answers, approval decisions and notes that your organisation records inside Vendorisk.ai about a vendor. Your organisation decides what goes in there; we host it on their instructions.

03. Data about account holders

We deliberately collect very little about account holders. There is no password, no profile photo upload, no phone number and no analytics identity. Specifically we hold:

  • Your email address. Sign-in is by email magic link; we do not issue or store passwords. Your address is held in the authentication store of our database provider (Supabase), together with sign-in timestamps.
  • Your display name and default workspace, in the profiles table, if you choose to set them.
  • Organisation membership and role - which workspace you belong to and whether you are an owner, admin or member (org_members).
  • Invitations. If you are invited to a workspace, the email address the inviter typed is stored in org_invites with the assigned role and a SHA-256 hash of the invite token. The plaintext token appears only in the invite link and is never stored. Links expire after 14 days and become single-use once accepted - only the account that redeemed a link can reopen it. Until it is accepted, treat the link as a secret and do not forward it.
  • Billing identifiers.Your organisation's Stripe customer and subscription identifiers, plan, seat limit and credit balance, plus a ledger of credit movements (credit_ledger). Card numbers are handled entirely by Stripe and never reach our servers.
  • Workspace branding and settings - organisation name, slug, and optional brand name, logo URL, primary colour and custom domain.
  • Your research history. Every investigation records the search text you submitted and the user who triggered it (research_jobs), and we retain which vendors you saved, watched, approved or rejected. Treat this as commercially sensitive: taken together it is a record of which vendors your organisation has been examining, and when. We do not sell it, mine it for advertising, or use it to profile you, but it is retained - see 09. Retention and deletion.
  • Integration secrets you supply. If you connect Slack, the incoming webhook URL you paste is stored in the org_integrations configuration column. It is a secret; treat it as one, and remove the integration if it leaks.
  • Your IP address, transiently. Requests to our research and API endpoints are rate limited per client IP address, read from the x-forwarded-forheader. This counter is held in the running server process's memory for the length of the rate-limit window and is not written to the database or to a log we retain.

04. Data about people named in research

Vendorisk.ai's output is a dossier about a company, assembled from public web sources. Most of what it contains - funding, headcount bands, product descriptions, outage and breach reporting - is not personal data. Two parts of it can be.

First, the leadership notes stored on each company record (leadership_json) summarise what public reporting says about named executives and founders: role, tenure, previous employment, notable public statements. Second, company enrichment can return a company's public profile links and firmographics that identify individuals indirectly. Facts about a person in their professional capacity are still personal data under the GDPR, and we treat them as such.

To be precise about what we do notdo: Vendorisk.ai performs no person-level lookups. Our enrichment call is made against a company domain and returns company attributes. Our breach checks query the public Have I Been Pwned breach catalogue filtered to a vendor's domain - the catalogue of publicly reported incidents - and we deliberately do not call the paid endpoints that would enumerate affected email addresses or search for an individual's credentials. Vendorisk.ai does not tell you whether a named person's account was in a breach, and it is not built to.

The Article 14 tension, stated honestly

People named in a dossier have never interacted with Vendorisk.ai, and we have no reliable way to contact them individually to give the notice Article 14 contemplates. We rely on the disproportionate-effort exception and on publishing this policy, and we accept that this is a live and contestable position rather than a settled one. Our practical mitigations are: we synthesise only from sources that are already public and we cite them; we restrict the leadership notes to professional matters; we do not infer or record special category data, criminal-offence data, personal contact details or home addresses; and we will correct or remove material about a named individual on request through the contact page. If you are named in a Vendorisk.ai dossier and object to being there, tell us and we will act on it.

05. Legal bases

  • Contract (Art. 6(1)(b)) - creating and running your account, delivering the assessments you request, taking payment.
  • Legitimate interests (Art. 6(1)(f)) - conducting and delivering third-party due-diligence research, which is the substance of the service and a recognised interest of both Vendorisk.ai and its customers; keeping a retained record of investigations so that assessments can be re-checked and audited; abuse prevention and rate limiting; and product security. Where we rely on legitimate interests for research about named individuals, we have balanced that against their rights on the basis that the information is already public, is limited to professional conduct, and is correctable on request. You may object at any time.
  • Legal obligation (Art. 6(1)(c)) - tax, accounting and responding to lawful requests.
  • Consent - only for optional email digests, which you can switch off in your workspace settings or by asking us.

We do not rely on consent for cookies, because the only cookies we set are strictly necessary for sign-in.

06. Sub-processors

The list below is derived from the application's source code rather than from a marketing page. Several entries are optional integrations that only run when the operator has configured an API key for them.

  • Supabase

    Database · Authentication · Session storage

    Our primary processor. Holds everything described in this policy that is stored at rest: your email address in the authentication store, your profile, organisation and membership records, research history, questionnaires, approvals and the vendor research corpus.

  • Groq

    LLM inference · model qwen/qwen3.6-27b

    Receives the vendor search query and excerpts of the third-party web pages we retrieved, in order to synthesise the dossier text and risk rationale. It does not receive your account data, your organisation's workspace content or your billing details.

  • Tavily / Serper

    Web search retrieval

    Receives the vendor search query string in order to return candidate sources. Exactly one provider is used per installation: Tavily is preferred, with Serper as a fallback. No account identifier is sent with the query.

  • People Data Labs

    Company enrichment

    Receives a company domain and returns firmographics - legal name, industry, size band, employee count, founding year, location and the company's public profile links. It is a company lookup, not a person lookup. The returned attributes can nevertheless identify individuals indirectly.

    Optional · Runs only when a PDL API key is configured

  • Have I Been Pwned

    Public breach catalogue

    Receives a vendor domain and returns the publicly documented breaches associated with it. We do not use the paid breached-domain endpoint and we do not submit email addresses.

    Optional · Runs only when an HIBP API key is configured

  • Stripe

    Payments · Subscriptions · Customer portal

    Handles checkout, the customer portal, subscription state and billing webhooks. Stripe holds your payment method and billing contact details under its own privacy notice; we store only the resulting customer and subscription identifiers.

  • Resend

    Transactional and digest email delivery

    Receives the recipient address and message content for digests and notifications. Email delivery degrades quietly rather than failing the request when no Resend key is configured.

    Optional · Runs only when a Resend API key is configured

  • Inngest

    Background job orchestration

    Coordinates long-running research runs. It receives the internal job identifier so that the run can be scheduled, retried and observed.

  • Slack

    Outbound notifications

    Outbound only, and only if your organisation pastes an incoming webhook URL. We post assessment notifications to the channel you chose. We never read from your Slack workspace.

    Optional · Runs only when your organisation configures a webhook

  • Hosting

    Application hosting · Edge network · Logs

    The application is hosted by [Hosting provider] in [Hosting region]. The repository is written and documented for deployment to Vercel, and that is the documented target, but the operator must confirm the provider and region actually in use before this policy is published.

We do not use advertising networks, analytics vendors, session-replay tools or data brokers for marketing purposes, and we do not sell or share personal data for cross-context behavioural advertising.

07. International transfers

Every processor listed above is either US-headquartered or operates US-based infrastructure, so personal data will be transferred to and processed in the United States and potentially in other countries where those providers run infrastructure. Where we transfer personal data out of the UK, EEA or Switzerland we rely on [Transfer mechanism] - the operator must record here which mechanism applies to each processor (Standard Contractual Clauses, the UK Addendum, the EU–US Data Privacy Framework certification, or an adequacy decision) and complete a transfer impact assessment. You may request a copy of the relevant safeguards from [Privacy contact email].

08. Cookies and browser storage

Vendorisk.ai sets no advertising, analytics or tracking cookies. There is no tag manager, no pixel and no cross-site identifier in the application. The only cookies we set are the authentication session cookies issued by our authentication provider, which are strictly necessary to keep you signed in and are refreshed automatically as you navigate. They cannot be disabled without disabling sign-in, which is why we do not show a consent banner.

Separately, the application stores one key in your browser's sessionStorage - vendorisk:lastQuery - so that a failed investigation can be retried without you retyping it. It stays in the browser tab, is cleared when the tab closes, and is only ever sent to us if you actually re-run the search.

09. Retention and deletion

We should be straightforward about this: Vendorisk.ai does not currently run an automated retention or deletion schedule. Records persist until they are deleted, and deletion today is performed manually by us on request rather than by a scheduled job. Building that schedule is outstanding work, and until it exists you should read the periods below as our policy intention rather than as an automated guarantee.

  • Account and organisation records - for the life of the account, then [Data retention period] after closure.
  • Research history (search text and who triggered it) - [Data retention period].
  • Workspace content(questionnaires, approvals, notes) - for the life of the organisation's account, then [Data retention period].
  • Invite tokens - 14 days from issue, enforced in code.
  • Rate-limit counters - the length of the rate-limit window, in memory only.
  • Billing records - as required by tax and accounting law, which is typically longer than the periods above.
  • Vendor research and dossiers - retained as a historical record so that assessments remain auditable and comparable over time, subject to correction and erasure requests about named individuals.

10. Your rights

Depending on where you live you have some or all of the following rights: access to the personal data we hold about you; rectification of data that is wrong; erasure; restriction of processing; data portability; objection to processing carried out on the basis of legitimate interests, including the research described in section 04; and withdrawal of consent for digest emails. You also have the right to complain to your supervisory authority - in the UK, the Information Commissioner's Office.

There is currently no self-service export or account-deletion button in the product. Requests are handled by a person: email [Privacy contact email], or use the routes on the contact page. We will acknowledge and respond within [DSAR response SLA] and in any event within the statutory period. We may ask you to confirm control of the email address on the account before we act, and for requests about a dossier we will ask which company and which claim you mean so that we can find the record.

If your organisation administers your account, we may need to route your request through them where they, and not we, decide what workspace content is kept.

11. California rights

If you are a California resident, you have the right to know what personal information we collect and disclose, to request access and deletion, to correct inaccurate information, and to be free from retaliation for exercising those rights. The categories we collect are identifiers (email address), commercial information (plan and credit history), internet activity limited to your use of the service, and professional information about named executives contained in public reporting.

Vendorisk.ai does not sell personal information, and does not share it for cross-context behavioural advertising, so there is nothing to opt out of - but you can still exercise the right by writing to [Privacy contact email] and we will confirm in writing. We do not use or disclose sensitive personal information for purposes that require an opt-out, and we do not knowingly collect the personal information of minors.

12. Children

Vendorisk.ai is a business tool sold to organisations and is not directed at children. We do not knowingly create accounts for anyone under 16. If you believe a child has registered, write to [Privacy contact email] and we will delete the account and the data associated with it.

13. Security

Access to workspace data is restricted at the database layer by row-level security rather than only in application code; the privileged service key is used exclusively server-side; sign-in uses email magic links so there is no reusable password to steal; card data is handled by Stripe; and the application sets security headers and a content security policy. We hold no security certification of our own - Vendorisk.ai assesses other companies' posture, it has not yet been audited itself. The security disclosure page sets all of this out in more detail, including the current limitations, and explains how to report a vulnerability.

14. Changes to this policy

When we change this policy we will update the drafted date at the head of the document and, for changes that materially affect you, notify account holders by email before the change takes effect. Continued use of the service after a change takes effect means you accept the updated policy. Superseded versions are available on request.

15. How to reach us

Privacy and data subject requests: [Privacy contact email]. Postal: [Legal entity name], [Registered address]. Data protection officer or EU/UK representative: [DPO / EU representative]. For disputes about the accuracy of a vendor assessment, use the dispute route on the contact page - it reaches the people who can actually amend the dossier.

99. Placeholders to complete

Every bracketed placeholder used on this page is listed below. Each one is a fact the application's source code cannot supply and the operator must fill in before this document is published as binding.

  • [Policy effective date]
  • [Legal entity name]
  • [Registered address]
  • [Privacy contact email]
  • [DPO / EU representative]
  • [Hosting provider]
  • [Hosting region]
  • [Transfer mechanism]
  • [Data retention period]
  • [DSAR response SLA]