Back to VendorBrief

VendorBrief

Data Processing Addendum

VendorBrief / Elevora Holding LLC

Version 1.0. Last Updated: September 9, 2026

This Data Processing Addendum (the "DPA") forms part of and is incorporated into the VendorBrief Terms of Service or other written agreement (the "Agreement") between Elevora Holding LLC, a Wyoming limited liability company with its registered address at 1021 East Lincolnway #9241, Cheyenne, WY 82001 ("Elevora," "Processor"), and the customer identified in the Agreement ("Customer," "Controller").

This DPA applies where Elevora processes Personal Data on behalf of Customer in the course of providing VendorBrief (the "Service").

1. Definitions

1.1 "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including as applicable the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

1.2 "Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings given in the GDPR, and equivalent terms under other Data Protection Laws are to be read accordingly.

1.3 "Customer Personal Data" means Personal Data contained in or derived from (a) documents Customer uploads to the Service, (b) the Vendor Briefs generated from them, and (c) Customer account and user records, in each case processed by Elevora on Customer's behalf.

1.4 "Sub-processor" means any third party engaged by Elevora to process Customer Personal Data.

1.5 "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, as amended or replaced.

1.6 "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

Capitalized terms not defined here have the meaning given in the Agreement.

2. Roles of the Parties

2.1 Uploaded documents and briefs. With respect to Customer Personal Data contained in documents Customer uploads and in the Vendor Briefs generated from them, Customer is the Controller and Elevora is the Processor.

2.2 Account and billing data. With respect to Personal Data that Elevora processes about Customer's account, its authorized users, and its billing relationship, Elevora acts as an independent Controller for the purposes described in the VendorBrief Privacy Policy. This DPA does not apply to that processing, which is governed by the Privacy Policy.

2.3 Offering scope. This DPA relates to the VendorBrief Offering only. Elevora operates more than one product, service, brand, and application, each separately operated and separately contracted. No obligation in this DPA extends to any other Offering, no other Offering is a party to or guarantor of this DPA, and any claim under this DPA is subject to the non-recourse provisions of Section 2 of the Terms of Service. Customer Personal Data processed under this DPA is not disclosed to, pooled with, or processed for the purposes of any other Offering.

2.4 Customer responsibilities. Customer is responsible for the lawfulness of the Personal Data it uploads and of Elevora's processing of it on Customer's instructions, for having a lawful basis for that processing, for providing any required notice to Data Subjects, and for the accuracy and quality of the data it provides.

2.5 Documents not intended to contain Personal Data. The Service is designed for the analysis of buyer requirement documents, which are not ordinarily expected to contain significant volumes of Personal Data. Customer determines what it uploads. Customer shall not upload special categories of Personal Data as defined in Article 9 GDPR, data relating to criminal convictions and offences, government identification numbers, payment card numbers, or the Personal Data of children, and Elevora's obligations under this DPA are undertaken on the basis that Customer does not do so.

3. Processing Instructions

3.1 In accordance with Article 28(3)(a) of the GDPR, Elevora shall process Customer Personal Data only on documented instructions from Customer, including with regard to transfers to a third country, unless required to do otherwise by applicable law. Where Elevora is so required, it shall inform Customer of that legal requirement before processing, unless the law prohibits that information on important grounds of public interest.

3.2 The Agreement, this DPA, Annex I, and Customer's use of the features of the Service constitute Customer's complete and final documented instructions to Elevora.

3.3 Elevora shall inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

3.4 Elevora shall not sell or share Customer Personal Data as those terms are defined under the CCPA, shall not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, shall not retain, use, or disclose it outside the direct business relationship between the parties, and shall not combine it with Personal Data received from another source except as permitted by the CCPA. Elevora certifies that it understands and will comply with these restrictions. Elevora is a "service provider" to Customer within the meaning of California Civil Code section 1798.140(ag).

3.5 Elevora shall not use Customer Personal Data, or the content of uploaded documents, to train, fine-tune, or otherwise develop any machine learning model of its own.

4. Subject Matter, Duration, Nature, and Purpose

The subject matter, duration, nature and purpose of the processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I. Processing continues for the term of the Agreement and for the retention periods described in Section 9.

5. Confidentiality and Personnel

5.1 Elevora shall treat Customer Personal Data as confidential and shall not disclose it except as permitted by this DPA or required by law.

5.2 Elevora is a single-member limited liability company and has no employees as at the Last Updated date of this DPA. Access to Customer Personal Data in the ordinary course is limited to the sole member and operator of Elevora, who is bound by the confidentiality obligations in this DPA and in the Agreement.

5.3 Where Elevora engages any employee, contractor, or other individual with access to Customer Personal Data, Elevora shall ensure before access is granted that the individual is bound by a written confidentiality obligation of no less protection than this Section, or by an appropriate statutory obligation of confidentiality, and that access is limited to what that individual needs in order to perform their function.

5.4 Elevora shall maintain a current record of the individuals with access to Customer Personal Data and shall make that record available to Customer on request under Section 11.

6. Security

6.1 Elevora shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to Data Subjects.

6.2 The measures in place as at the Last Updated date are described in Annex II. Elevora may update those measures provided that the level of protection is not materially reduced.

6.3 Customer has reviewed Annex II and, in the context of its own use of the Service and the data it chooses to upload, considers the measures appropriate to the risk. Customer acknowledges that Elevora does not hold, and does not claim, SOC 2, ISO 27001, FedRAMP, CMMC, or any other security certification or authorization.

6.4 Customer is responsible for its own use of the security features made available in the Service, including account credential hygiene, the management of authorized users, and the use and revocation of share links.

7. Sub-processors

7.1 Customer grants Elevora general written authorization to engage Sub-processors, subject to this Section.

7.2 The Sub-processors engaged as at the Last Updated date are listed in Annex III and are maintained on the VendorBrief Sub-Processors page.

7.3 Before engaging a new Sub-processor with access to Customer Personal Data, Elevora shall give Customer at least thirty (30) days' notice by updating the Sub-Processors page and, where Customer has provided a notification address, by email.

7.4 Customer may object to a new Sub-processor on reasonable data-protection grounds by written notice within the notice period. The parties shall discuss the objection in good faith. If Elevora cannot make the Service available without the Sub-processor, Customer's sole remedy is to terminate the affected part of the Service on written notice, with a pro-rata refund of prepaid fees for the unused portion of the then-current term.

7.5 Elevora shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Sub-processor's obligations.

8. Data Subject Rights and Assistance

8.1 Taking into account the nature of the processing, Elevora shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights.

8.2 The Service provides Customer with the ability to access, export, correct, and delete uploaded documents, generated briefs, and account records directly. Customer shall use those features to respond to Data Subject requests where they are sufficient.

8.3 Where those features are not sufficient, Elevora shall provide reasonable assistance on written request. Elevora shall respond to such a request within ten (10) business days.

8.4 If Elevora receives a request from a Data Subject relating to Customer Personal Data, it shall not respond to the request itself except to confirm that the request should be directed to Customer, and shall forward the request to Customer without undue delay.

8.5 Elevora shall provide Customer with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to Elevora.

9. Personal Data Breach

9.1 Notification. In accordance with Article 33(2) of the GDPR, Elevora shall notify Customer without undue delay after Elevora confirms a Personal Data Breach affecting Customer Personal Data. Elevora shall use reasonable efforts to give that notification within seventy-two (72) hours of confirmation.

9.2 What confirmation means. Elevora is a single-operator business and does not maintain a continuous staffed monitoring rotation. Elevora confirms a Personal Data Breach when it has established, on the information available to it, that a security incident has actually affected Customer Personal Data. The period in Section 9.1 runs from that point and not from the occurrence of the underlying incident. Elevora shall investigate any credible indication of a security incident without undue delay after becoming aware of it.

9.3 Content of notification. The notification shall describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact.

9.4 Cooperation. Elevora shall cooperate with Customer and take reasonable steps as directed by Customer to assist in the investigation, mitigation, and remediation of the breach, and shall assist Customer with its own notification obligations to supervisory authorities and Data Subjects.

9.5 No admission. Notification under this Section is not and shall not be construed as an acknowledgment of fault or liability by Elevora.

10. Deletion and Return of Data

10.1 During the term. Documents uploaded to the Service are retained for one hundred and eighty (180) days from upload and are then deleted automatically, including the stored file. Extracted requirements and generated briefs are deleted together with the document they were derived from. Customer may delete individual documents and briefs at any time from its dashboard.

10.2 On termination. On expiry or termination of the Agreement, Elevora shall delete Customer Personal Data, or return it to Customer if Customer so requests in writing within thirty (30) days of termination, and shall then delete the remaining copies.

10.3 Defined period. Deletion under Section 10.2 shall be completed within thirty (30) days of the later of the date of termination and the date of a return request under Section 10.2.

10.4 Backups. Copies of Customer Personal Data held in routine infrastructure backups maintained by Elevora's hosting and database providers are overwritten or expire on those providers' standard backup cycle following deletion from the live system. Elevora does not restore backups to serve a deletion request. Elevora does not currently publish a maximum figure for that cycle and will not state one until it can evidence it.

10.5 Retained records. Elevora may retain Customer Personal Data to the extent required by applicable law, and may retain security and access audit logs and processing-cost records, which are anonymized rather than erased so that they no longer identify the Data Subject. Any retained data remains subject to this DPA for as long as it is held.

10.6 Confirmation. Elevora shall confirm deletion in writing on Customer's request.

11. Audit and Information Rights

11.1 In accordance with Article 28(3)(h) of the GDPR, Elevora shall make available to Customer the information necessary to demonstrate compliance with the obligations in Article 28 and this DPA.

11.2 Customer's audit rights shall ordinarily be satisfied by Elevora's response to a written security and privacy questionnaire, by the information in Annex II and on the VendorBrief Security page, and by any current third-party reports or certifications Elevora holds. Elevora shall respond to a questionnaire within twenty (20) business days.

11.3 If that information is not sufficient to demonstrate compliance, Customer may request a further audit, on at least thirty (30) days' written notice, no more than once in any twelve (12) month period unless required by a supervisory authority or following a Personal Data Breach. The audit shall be conducted during normal business hours, shall not unreasonably disrupt Elevora's operations, shall be subject to confidentiality obligations, and shall be limited to information and systems relevant to the processing of Customer Personal Data. Customer shall bear its own costs and Elevora's reasonable costs.

11.4 Customer shall not have a right of access to any data belonging to another customer of Elevora, or to Elevora's confidential commercial information.

12. International Transfers

12.1 Elevora and its Sub-processors process Customer Personal Data primarily in the United States. Annex III identifies each Sub-processor and the location of the relevant processing entity as understood by Elevora.

12.2 Where Customer Personal Data protected by the GDPR is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

(a) Module Two (Controller to Processor) applies, with Customer as data exporter and Elevora as data importer.

(b) Clause 7, the docking clause, applies.

(c) In Clause 9, Option 2, general written authorization, applies, with the notice period specified in Section 7.3 of this DPA.

(d) In Clause 11, the optional independent dispute resolution language does not apply.

(e) In Clause 17, the SCCs are governed by the law of Ireland.

(f) In Clause 18(b), disputes shall be resolved before the courts of Ireland.

(g) Annex I, Annex II, and Annex III to this DPA populate Annexes I and II to the SCCs.

12.3 For transfers subject to the UK GDPR, the UK Addendum applies to the SCCs. In Table 4 of the UK Addendum, neither party may end the Addendum as set out in Section 19 of it, except as permitted by that Section. For transfers subject to Swiss law, references in the SCCs to the GDPR shall be read as references to the Swiss Federal Act on Data Protection, and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

12.4 If a transfer mechanism relied on in this Section is invalidated or superseded, the parties shall work in good faith to implement a valid alternative mechanism without undue delay.

13. Liability

13.1 Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability set out in the Agreement, including the offering-segregation and non-recourse provisions of Section 2 and the cap in Section 15 of the Terms of Service, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.

13.2 Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws, including the rights of Data Subjects to compensation under Article 82 of the GDPR or under Clause 12 of the SCCs.

14. Term, Precedence, and General

14.1 This DPA takes effect on the date the Agreement takes effect, or on the date it is signed by both parties if later, and continues for as long as Elevora processes Customer Personal Data.

14.2 In the event of a conflict, the order of precedence is: (a) the SCCs, where they apply; (b) this DPA; (c) the Agreement.

14.3 This DPA is governed by the law stated in the Agreement, except where Data Protection Laws or the SCCs require otherwise.

14.4 If any provision of this DPA is held unenforceable, it shall be limited or severed to the minimum extent necessary and the remainder shall remain in effect.

14.5 This DPA may be executed in counterparts and by electronic signature.

Signatures

Elevora Holding LLC

Signature: ______________________________

Name: __________________________________

Title: ___________________________________

Date: ___________________________________

Customer

Legal entity name: _______________________

Signature: ______________________________

Name: __________________________________

Title: ___________________________________

Date: ___________________________________

Notification email for Sub-processor changes and breach notices: _______________________

Annex I. Description of Processing

A. Parties

Data exporter: the Customer identified in the Agreement, acting as Controller. Contact details and data protection contact as stated in Customer's account or in the signature block above.

Data importer: Elevora Holding LLC, 1021 East Lincolnway #9241, Cheyenne, WY 82001, United States, acting as Processor. Contact: evens.p@elevoraholding.com.

B. Categories of Data Subjects

Customer's authorized users of the Service. Any individuals whose Personal Data happens to appear in a buyer requirement document that Customer uploads, which may include named contacts, signatories, quality representatives, approvers, and authors identified in that document or in its metadata.

C. Categories of Personal Data

Account and user data: name, business email address, and optional company, role, and industry.

Document content: whatever Personal Data is contained in the documents Customer chooses to upload, and in the Vendor Briefs generated from them, including any Personal Data present in document metadata.

Technical data: IP address, log data, browser type, pages viewed, and product events.

Billing metadata received from the payment processor, such as plan, status, and payment method token references. Elevora does not receive or store full payment card numbers.

D. Special Categories of Personal Data

None. Customer is prohibited from uploading special category data under Section 2.5 of this DPA.

E. Nature and Purpose of the Processing

Receipt, storage, text extraction, and automated and AI-assisted analysis of uploaded documents in order to generate a structured Vendor Brief for Customer; generation of an executive PDF and a share link; provision of the associated account, authentication, support, billing, security, and abuse-prevention functions of the Service.

F. Frequency of Transfer

Continuous, for the duration of the Agreement, on each use of the Service.

G. Duration of Processing

Uploaded documents and derived briefs: 180 days from upload, or until deleted by Customer if earlier.

Account and related records: for the term of the Agreement and as described in Section 10 of this DPA and in the Privacy Policy.

H. Sub-processor Processing

As set out in Annex III. The duration of Sub-processor processing does not exceed the durations stated above, save for routine infrastructure backups as described in Section 10.4.

I. Competent Supervisory Authority

Where the SCCs apply, the competent supervisory authority is that of the EEA Member State in which the data exporter is established, or, where the data exporter is not established in the EEA, that of the Member State in which its Article 27 representative is established, or that of the Member State in which the Data Subjects whose Personal Data is transferred are located.

Annex II. Technical and Organizational Measures

The measures below are those in place as at September 9, 2026. They are described as implemented, not as aspiration. Where a measure is provided by an underlying platform provider rather than built by Elevora, that is stated.

1. Access control and data isolation

Uploaded files are held in private storage, not public storage. Row-level security scoped to the owning account is enforced at the database layer, so that one account cannot read another account's records. Access to the production environment is limited to the sole operator of Elevora and is protected by the authentication controls of the underlying platform providers.

2. Encryption

Data in transit between the user, the Service, and its Sub-processors is protected by TLS. Data at rest in the database and file storage is encrypted using the encryption applied by the relevant platform provider to the storage layer. Elevora does not operate its own key management system and does not offer customer-managed encryption keys.

3. Input validation

File type and file size are validated on the server, not only in the browser, before a document is accepted.

4. Identity and account controls

Company email confirmation is required before access to the workspace, dashboard, or checkout. Authentication is provided by the platform authentication service listed in Annex III.

5. Acceptance and record keeping

The Service records, at the database level, the Customer's acceptance of a specific version of the Terms of Service before an uploaded document can be processed. This record is retained.

6. Logging and monitoring

Audit logging is applied to account, upload, delete, checkout, and subscription events. Application errors are captured by the error monitoring Sub-processor, configured to strip document content, query content, and secrets from diagnostic events.

7. Abuse prevention

Rate limiting and bot protection are applied at the edge and at the application layer using the Sub-processors listed in Annex III. These process client IP addresses.

8. Payment security

Billing is handled by a hosted payment page operated by the payment Sub-processor, with signed webhook verification and idempotent processing. Elevora does not receive or store full payment card numbers.

9. Retention and deletion

Each uploaded document carries an automatically assigned deletion deadline of 180 days from upload, enforced by a scheduled process rather than by manual review. Account deletion removes profile, documents, extracted requirements, briefs, subscription linkage, and stored files, with security audit and cost records anonymized rather than erased. A daily reconciliation check identifies any account whose data was removed while the authentication record survived.

10. Handling of marked controlled material

Documents bearing export-control, ITAR, EAR or ECCN, controlled unclassified, or limited-distribution markings are processed in a restricted mode in which text is extracted on Elevora's own infrastructure and only the extracted text, not the original file, is transmitted to the AI Sub-processor. Documents bearing classified markings are refused before any transmission. This is a risk-reduction measure and is not an authorization to process controlled data.

11. Model training

Elevora does not use Customer Personal Data or uploaded document content to train any model of its own.

12. Organizational measures

Elevora is a single-member limited liability company with no employees. Confidentiality obligations bind the sole operator. Any future personnel or contractor with access will be bound in writing before access is granted, as required by Section 5.3.

13. Limits

Elevora does not hold SOC 2, ISO 27001, FedRAMP, or CMMC certification, does not hold ITAR or EAR authorization, does not operate a continuous staffed security monitoring rotation, and does not offer a contractual uptime or disaster-recovery commitment. Elevora does not represent that it holds any certification it has not obtained.

Annex III. Authorized Sub-processors

As at September 9, 2026. The current list is maintained at getvendorbrief.com/sub-processors.

Sub-processorFunctionPersonal Data processedProcessing location as understood by Elevora
OpenAIDocument analysis and brief generationUploaded document content, or extracted text only in restricted modeUnited States
SupabaseDatabase, authentication, and file storageAccount data, uploaded documents, generated briefsUnited States
VercelApplication hosting and deliveryLog and usage data, including IP addressUnited States
StripePayment processingBilling metadata and payment method token referencesUnited States
ResendTransactional and account emailEmail address, message contentUnited States
Trigger.devBackground processing of analysesUploaded document, extracted text, processing metadataUnited States
SentryError monitoringDiagnostic data with document and query content removedUnited States
UpstashRate limiting and abuse preventionClient IP addressUnited States
CloudflareBot protectionClient IP addressUnited States
Hunter.ioCompany email domain verification at signupCompany email domainFrance

Elevora will give notice of material changes to this list in accordance with Section 7.3.