This policy is in the review stage for pre-launch. The effective date will be published on the go-live date. It is not legal advice; questions should be directed to [email protected].

Legal

Privacy Policy

Effective date: pending publication

Introduction

TrustVendor Inc. ("TrustVendor", "we", "us", "our") operates trustvendor.co and the TrustVendor platform, including the public Vendor Graph, the Trust Workspace, and the Vendor Pulse API (collectively, the "Services"). This Privacy Policy explains what personal information we collect, how we use it, and the rights available to you. It applies to visitors to our website, users of our Services, and individuals whose information we process on behalf of our customers.

Who is responsible for your data

For personal information collected directly from you as a visitor to trustvendor.co or as an account holder, TrustVendor is the data controller. For personal information processed inside the Trust Workspace or the Vendor Pulse API on behalf of a customer (typically a compliance or security team), that customer is the data controller and TrustVendor is the data processor. Our processing on behalf of customers is governed by the Data Processing Agreement at trustvendor.co/legal/dpa.

Information we collect

We collect information you provide directly (name, business email, company, message content when you submit a contact form, book a demo, or register for an account); information about your business relationship with us (billing details, subscription tier, support tickets); and information generated automatically when you use the Services (IP address, browser and device metadata, timestamps, session identifiers, page views, and event logs). When customers connect third-party integrations such as Vanta, Drata, or Slack, we receive account identifiers and configuration data required to route information between systems.

Information collected about vendors

The public Vendor Graph is assembled from publicly accessible sources — trust centres, subprocessor pages, Certificate Transparency logs, corporate registries (EDGAR, GLEIF, OpenCorporates), and vendor security pages. This information relates to companies, not identified individuals, and is not personal information under most privacy laws. Where individual names appear (for example, an auditor named on a SOC 2 report), we process that information as necessary for the legitimate interest of assessing vendor trust.

How we use your information

We use personal information to provide, secure, and improve the Services; to communicate with you about your account, security events, and product updates; to send marketing communications you have not opted out of; to comply with legal obligations and enforce our contracts; and to detect and prevent fraud, abuse, and security incidents. We do not use customer content processed in the Trust Workspace to train AI models available to other customers or to third parties.

Legal bases (EEA/UK)

For individuals in the European Economic Area and the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR: performance of a contract (to provide the Services to account holders); legitimate interests (to operate, secure, and improve the Services, and to build the public Vendor Graph from publicly accessible sources); consent (for marketing communications and non-essential cookies); and compliance with a legal obligation (tax, accounting, and lawful requests from authorities).

How we share your information

We do not sell personal information. We share personal information with: (a) subprocessors that operate the Services on our behalf, listed in our DPA (trustvendor.co/legal/dpa); (b) professional advisors under confidentiality; (c) government authorities where legally required; and (d) parties involved in a merger, acquisition, or asset transfer, subject to standard confidentiality. All subprocessors are bound by written contracts imposing data protection obligations at least as strict as those we owe you.

International transfers

TrustVendor operates primarily from the United States. When personal information is transferred outside the country where it was collected, we rely on appropriate safeguards including the European Commission Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and equivalent mechanisms. A copy of the safeguards applicable to a specific transfer is available on request to [email protected].

How long we keep information

We retain personal information for as long as required to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Account data is deleted or de-identified within 30 days of account termination, subject to legal hold obligations. Vendor Graph artifacts (immutable, content-addressed document snapshots) are retained indefinitely because they form the audit trail that customers rely on; they contain only company information collected from publicly accessible sources.

Security

We implement administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, and unauthorized access. These include encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, mandatory MFA on production systems, continuous vulnerability scanning, and independent security reviews. Details of our security posture are published at trustvendor.co/security. No security measure is perfect; we notify affected parties and regulators as required by law in the event of a personal data breach.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information; to object to processing based on legitimate interests; to withdraw consent; and to lodge a complaint with a supervisory authority. California residents have specific rights under the CCPA/CPRA, including the right to know, delete, correct, and to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising). To exercise these rights, contact [email protected]. We respond to verifiable requests within the timeframes required by applicable law.

Cookies and similar technologies

We use strictly necessary cookies to operate authenticated sessions, and analytics cookies (where permitted) to measure aggregate usage of trustvendor.co. Analytics are configured to minimize personal information (IP truncation, no cross-site tracking). You can control non-essential cookies through our consent banner and your browser settings. Marketing pages on trustvendor.co do not embed third-party advertising cookies.

Children

The Services are not directed at children under 16 and we do not knowingly collect personal information from them. If you believe a child has provided information to us, contact [email protected] and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to account holders by email at least 30 days before they take effect, and the updated policy will be posted here with a revised "Last updated" date. Continued use of the Services after an update means you accept the revised policy.

Contact us

For privacy questions or to exercise your rights, contact [email protected]. Postal mail may be sent to the address published on the Contact page. EEA/UK data subjects also have the right to contact their local supervisory authority. The TrustVendor Data Protection Officer can be reached at [email protected].