VendorBrief
VendorBrief Privacy Policy
Last Updated: [DATE]
This Privacy Policy explains how Elevora Holding LLC ("Elevora," "we," "us") collects, uses, discloses, and protects information in connection with VendorBrief (the "Service") at getvendorbrief.com. We have written this to meet the expectations of enterprise customers and to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
1. Who We Are
Elevora Holding LLC is the controller of personal data processed about your account. For documents you upload, you act as the controller and Elevora acts as your processor; a Data Processing Addendum (DPA) is available for business customers.
2. Information We Collect
Account information: name, business email, password (stored hashed), and optional company, role, and industry.
Uploaded documents and generated briefs: the buyer documents you upload and the Vendor Briefs we generate for you.
Payment information: processed by Stripe. We receive limited billing metadata (such as plan, status, and the last four digits or token references). We never receive or store your full payment card number.
Usage and device data: log data, IP address, browser type, pages viewed, and product events used to operate, secure, and improve the Service.
3. How We Use Information
We use information to: provide and operate the Service; generate your Vendor Briefs; authenticate and secure your account; process payments; provide support; communicate service and transactional messages; monitor, debug, and improve reliability; comply with law; and detect and prevent fraud or abuse.
Legal bases (GDPR): performance of our contract with you; our legitimate interests in operating and securing the Service; your consent where required; and compliance with legal obligations.
4. AI Processing of Your Documents
To generate your Vendor Brief, the relevant content of your uploaded document is transmitted to our AI sub-processor (OpenAI) solely to produce your result. Based on OpenAI's API terms as we understand them, content submitted through the API is not used to train OpenAI's models. We process your document only to deliver the Service to you and do not use your document content to train any independent VendorBrief model. We state this to reflect our sub-processor's terms and our own practice; you should review the linked sub-processor terms for their current commitments.
5. Sub-Processors
We use the following sub-processors to operate the Service. Each processes only the data necessary for its function:
A current list is maintained on our Sub-Processors page. We will provide notice of material changes.
6. How We Share Information
We share information only with: the sub-processors above; professional advisors and authorities where required by law; and a successor in a merger or acquisition (with notice). We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
7. Data Retention and Deletion
We retain account information for as long as your account is active and as needed to provide the Service and meet legal obligations. You may delete individual documents and briefs at any time from your dashboard, and you may delete your entire account and associated data from your account settings or by contacting us. Deletion requests are completed within thirty (30) days, and copies in routine backups are purged on our standard backup cycle (no later than [BACKUP_CYCLE_DAYS] days). We may retain limited records as required by law (for example, tax and transaction records).
8. Your Rights
Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. California residents have rights to know, delete, correct, and opt out of sale/sharing (we do not sell or share), and not to be discriminated against for exercising rights. To exercise any right, contact [CONTACT_EMAIL]. We will verify your request and respond within the time required by applicable law. EU/UK users may also lodge a complaint with a supervisory authority.
9. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including encryption of data in transit and at rest, row-level data isolation so that one account cannot access another account's data, access controls, and audit logging of sensitive actions. We do not currently claim SOC 2, ISO 27001, or other formal certifications, and we do not represent that we hold any certification we have not obtained. No method of transmission or storage is completely secure.
10. Incident Notification
If we become aware of a personal-data breach affecting your information, we will notify affected users and, where required, regulators without undue delay and, where applicable, within 72 hours of confirming the breach, consistent with applicable law.
11. International Transfers
We and our sub-processors may process data in the United States and other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
12. Children
The Service is for business use and is not directed to individuals under 18. We do not knowingly collect data from children.
13. Changes
We may update this Policy; material changes will be communicated through the Service or by email, with the updated date shown above.
14. Contact
Elevora Holding LLC — [REGISTERED_ADDRESS] Privacy contact: [CONTACT_EMAIL]