Data Processing Terms
These terms apply where we process personal data on your behalf, and satisfy Article 28 GDPR. They form part of the Terms of Service — you do not need to sign a separate agreement, though we will sign one if your procurement process requires it.
Effective 21 August 2026 · Applies to vendorsly.com
1. Roles
The relationship differs depending on which data is in question, and getting this distinction right matters:
| Data | You are | We are |
|---|---|---|
| Your account and billing details | Data subject | Controller |
| Business records in our corpus, before you pull them | — | Controller |
| Records in your workspace, and how you use them | Controller | Processor |
| Data you upload for enrichment or suppression | Controller | Processor |
In short: we are the controller for building the corpus, and your processor for what happens in your workspace. Once you export a file, we have no further role in it at all.
2. Scope of processing
- Subject matter — provision of business data, enrichment and export functionality.
- Duration — for as long as your account is open, plus the 30-day deletion window.
- Nature and purpose — collection, structuring, storage, enrichment and retrieval of business contact information.
- Types of personal data — business names, business email addresses, business phone numbers, business postal addresses, publicly listed owner or proprietor names, and public social profile links.
- Categories of data subject — proprietors, officers and publicly listed contacts of businesses.
- Special category data — none. Do not upload any.
3. Our obligations as processor
We will:
- process personal data only on your documented instructions, which for normal use means your use of the Service itself;
- ensure everyone with access is bound by an appropriate duty of confidence;
- apply the security measures in section 5;
- engage sub-processors only under section 4, and remain liable for them;
- help you respond to data subject requests, and with your DPIAs and regulator consultations, so far as is reasonable;
- notify you without undue delay, and in any case within 48 hours, of a personal data breach affecting your data;
- delete or return your data on termination, at your choice, other than copies we must keep by law;
- make available the information needed to demonstrate compliance and allow audits on reasonable notice, no more than once a year unless a regulator requires otherwise.
4. Sub-processors
You give general authorisation for the sub-processors below. We will give at least 30 days’ notice by email before adding or replacing one, and you may object on reasonable data protection grounds — if we cannot resolve your objection, you may terminate and receive a refund of the unused period.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing and invoicing | US / EU |
| Anthropic, PBC | AI enrichment — Intelligence plans only | US |
| Our infrastructure provider | Application and database hosting | India |
On Data plans there is no AI sub-processor involved — no content leaves our infrastructure for any model provider. That is a consequence of how the product is built, not a setting we toggle.
Content sent for AI enrichment is not used to train models and is not retained by the provider beyond what is needed to return the result.
5. Security measures
- TLS in transit; encryption at rest for database volumes.
- Credentials stored as hashes only — API keys are displayed once and are unrecoverable afterwards.
- Tenant isolation enforced in the data model, so a query cannot cross a workspace boundary.
- Least-privilege access to production, limited to named administrators.
- Signed, replay-resistant webhooks over HTTPS only.
- Logging and retention limits as set out in the Privacy Policy.
6. International transfers
Where personal data moves outside the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum where applicable, or an adequacy decision. Copies are available on request from privacy@vendorsly.com.
7. Data subject requests
If a data subject contacts us directly about data in your workspace, we will refer them to you unless legally required to act, and tell you promptly. Where we are the controller — a business asking to be removed from the corpus — we handle it ourselves under the removal process.
8. Precedence
Where these terms conflict with the Terms of Service on the subject of personal data processing, these terms prevail.
9. Signed copies
Need a countersigned DPA for your records? Email legal@vendorsly.com and we will return one within 5 business days.
This document was drafted for this service specifically rather than copied from a template, but it is not legal advice. Have a qualified lawyer in your jurisdiction review it before you rely on it.