VendorGuard

Privacy Notice

Last updated: 19 July 2026

This Privacy Notice explains how VendorGuard, based in Martina Franca, Italy ("VendorGuard", "we", "us"), collects and processes personal data when you use the VendorGuard web application (the "Service"). VendorGuard is the data controller for personal data described below.

1. Personal data we collect

  • Account data: name, email address, login credentials.
  • Content data: vendor records, Certificates of Insurance (COI) documents, notes, and other data you upload.
  • Usage & telemetry: pages visited, actions taken, device identifiers, IP address, and error logs.
  • Communications: support messages you send us and email interactions.
  • Billing data: processed by our Merchant of Record, Paddle. We receive limited data such as your country, plan, and subscription status; we do not store full payment card details.

2. Purposes and legal bases

  • Provide the Service (creating your account, storing your data, sending reminder emails) — performance of a contract.
  • Security & fraud prevention — legitimate interests.
  • Product improvement and analytics — legitimate interests.
  • Customer support — performance of a contract / legitimate interests.
  • Legal compliance (accounting, tax, responding to lawful requests) — legal obligation.
  • Marketing emails, where sent — consent, which you can withdraw at any time.

3. Who we share data with

  • Service providers / subprocessors such as our hosting, database, email delivery, and error-monitoring providers.
  • Paddle, our Merchant of Record, for the sale of the Service, subscription management, payments, tax compliance, and invoicing.
  • Professional advisers (legal, accounting) where necessary.
  • Authorities where required by law.

We do not sell your personal data.

4. International transfers

Some of our providers process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.

5. Retention

We keep personal data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce our agreements. When no longer needed, data is deleted or anonymised.

6. Your rights (GDPR)

You have the right to:

  • access, rectify, or erase your personal data;
  • restrict or object to processing;
  • request portability of the data you provided;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali) or your local supervisory authority.

We respond to rights requests within one month.

7. Security

We apply appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and least-privilege permissions on our database. No system is completely secure; please contact us immediately if you suspect a security incident affecting your account.

8. Cookies

We use essential cookies and similar technologies required to run the Service (for example, to keep you signed in). We do not use advertising cookies. If we introduce analytics cookies in the future, we will ask for your consent first.

9. Contact

For privacy questions or to exercise your rights, contact us at darioluisi.dl@gmail.com.