VendorBrief
VendorBrief Privacy Policy
Elevora Holding LLC
Last Updated: September 9, 2026
This Privacy Policy explains how Elevora Holding LLC ("Elevora," "we," "us") collects, uses, discloses, and protects information in connection with VendorBrief (the "Service") at getvendorbrief.com. We have written it to meet the expectations of business customers and to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA).
1. Who We Are and Our Role
Elevora Holding LLC, a Wyoming limited liability company at 1021 East Lincolnway #9241, Cheyenne, WY 82001, United States, operates the Service.
This Policy covers VendorBrief only. Elevora operates more than one product, service, brand, and application (each an "Offering"). Each Offering is separately operated and separately governed by its own terms and privacy policy. Personal data collected through VendorBrief is held in systems dedicated to VendorBrief, is not pooled with the data of any other Offering, and is not used for the purposes of any other Offering. Your relationship under this Policy is in respect of VendorBrief alone.
For personal data about your account, your users, and your billing relationship, Elevora is the controller.
For the documents you upload and the briefs generated from them, you are the controller and Elevora is your processor. A full Data Processing Addendum is available to business customers and is executed on request. Contact evens.p@elevoraholding.com.
2. Information We Collect
Account information: name, business email, and optional company, role, and industry.
Uploaded documents and generated briefs: the buyer requirement documents you upload and the Vendor Briefs we generate from them, including any personal data those documents happen to contain.
Payment information: processed by Stripe. We receive limited billing metadata such as plan, status, and token references. We never receive or store your full payment card number.
Usage and device data: log data, IP address, browser type, pages viewed, and product events, used to operate, secure, and improve the Service.
Trial and unverified sessions. The Service may permit an upload before you have completed company email verification. Where it does, the document you upload and the associated session data are processed as described in this Policy. If you do not complete verification, contact us at the address in Section 15 to request deletion, and in any event the 180-day retention limit in Section 8 applies.
3. How We Use Information
We use information to: provide and operate the Service; generate your Vendor Briefs; authenticate and secure your account; process payments; provide support; send service and transactional messages; monitor, debug, and improve reliability; comply with law; and detect and prevent fraud or abuse.
Legal bases (GDPR): performance of a contract to which you are party, Article 6(1)(b); our legitimate interests in operating, securing, and improving the Service, Article 6(1)(f); your consent where required, Article 6(1)(a); and compliance with legal obligations to which we are subject, Article 6(1)(c).
4. AI Processing of Your Documents
To generate your Vendor Brief, the relevant content of your uploaded document is transmitted to our AI sub-processor, OpenAI, solely to produce your result.
We do not use your document content, or any personal data in it, to train, fine-tune, or develop any model of our own.
Our understanding, based on the API terms published by our AI sub-processor, is that content submitted through the API is not used to train that provider's models. That is a description of our sub-processor's published terms as we understand them, not an independent verification by us. We state it so that you can check it. You should review your own requirements against that provider's current terms, and where the point is material to you, raise it with us before you upload.
Restricted mode for marked material. Where an uploaded document carries export-control, ITAR, EAR or ECCN, controlled unclassified, or limited-distribution markings, the Service extracts the text on our own infrastructure and transmits only that extracted text to the AI sub-processor. The original file is not uploaded to that provider. Documents carrying classified markings are refused before anything is transmitted. This reduces what leaves our infrastructure. It is not an authorization to process controlled data, and it does not analyze page images, so findings that depend on layout may be missed.
5. Accuracy of Briefs
A Vendor Brief is generated by automated analysis and does not identify every obligation in a source document. The limits of the analysis, including what we have measured and the size of that measurement, are described in Section 3 of the Terms of Service. Read that Section before relying on a brief.
6. Sub-Processors
We use the sub-processors below to operate the Service. Each processes only the data necessary for its function.
A current list is maintained on our Sub-Processors page. We give at least thirty days' notice of material changes.
7. How We Share Information
We share information only with: the sub-processors above; professional advisors and authorities where required by law; and a successor in a merger or acquisition, with notice. We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are defined in California Civil Code sections 1798.140(ad) and 1798.140(ah). We do not disclose personal data collected through VendorBrief to any other Offering.
Briefs you choose to share. The Service lets you create a share link to a Vendor Brief and export it as a PDF. When you do that, you are the one making the disclosure. Anyone with the link can view the brief until you revoke it. Revoking a link stops further access through the link; it does not retrieve or delete a copy someone has already downloaded, printed, or forwarded. Confirm you are permitted to disclose the underlying document before you share.
8. Data Retention and Deletion
We retain account information for as long as your account is active and as needed to provide the Service and meet legal obligations.
Uploaded documents are retained for 180 days from upload and are then deleted automatically, including the stored file, whether or not your account remains active. This limit is enforced by a scheduled process, not by manual review. Extracted requirements and generated briefs are deleted together with the document they came from, so download or export anything you need to keep before the 180-day point.
You may delete individual documents and briefs at any time from your dashboard, and you may delete your entire account and associated data from your account settings or by contacting us. Deletion requests are completed within thirty (30) days. Copies held in routine infrastructure backups are purged on our providers' standard backup cycle; we do not currently publish a maximum figure for that cycle, and we will not state one until we can evidence it.
When you delete your account we erase your profile, documents, extracted requirements, briefs, subscription and billing linkage, and stored files. Records we must keep for security or legal reasons, meaning security and access audit logs and processing-cost records, are anonymized rather than erased: the link to you is removed and the remaining entry no longer identifies you. We do this because deleting a security audit log on request would remove the record of access to your own data, and because applicable law permits retaining processing necessary for legal obligations and for establishing or defending legal claims. We may also retain limited records as required by law, for example tax and transaction records.
Account deletion has two parts, and we tell you if only one of them completed. Removing your data and removing your sign-in credential are separate operations. Your data is removed first. If the sign-in credential, meaning your email address as an authentication record, cannot be removed automatically in the same request, we do not report the deletion as finished: the response says so explicitly and gives you a support address. We also run a daily reconciliation check that looks for any account whose data was removed while the sign-in credential survived, so completing it does not depend on you noticing or reporting it. Either way the deletion is completed within the thirty (30) day period stated above. We do not claim that deletion is instantaneous, and we do not claim it is irreversible before the backup cycle described above has passed.
9. Your Rights
Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. California residents have rights to know, delete, correct, and opt out of sale or sharing, which we do not do, and not to be discriminated against for exercising rights.
These rights arise under Articles 15 to 22 of the GDPR and, for California residents, under California Civil Code sections 1798.100 to 1798.125. To exercise any right, contact evens.p@elevoraholding.com. We will verify your request and respond within the time required by applicable law. If your personal data is in a document uploaded by one of our business customers, that customer is the controller and we will refer your request to them. EU and UK users may also lodge a complaint with a supervisory authority.
10. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including encryption of data in transit, encryption at rest as applied by our storage and database providers, row-level data isolation so that one account cannot access another account's data, server-side file validation, access controls, and audit logging of sensitive actions.
We do not currently claim SOC 2, ISO 27001, FedRAMP, CMMC, or any other formal certification, and we do not represent that we hold any certification we have not obtained. We do not operate a continuous staffed monitoring rotation. No method of transmission or storage is completely secure.
A fuller description of our measures is provided in the Data Processing Addendum and on our Security page.
11. Incident Notification
If we confirm a personal data breach affecting your information, we will notify affected users and, where required, regulators without undue delay, and we will use reasonable efforts to do so within 72 hours of confirming the breach, consistent with applicable law. Where we act as a processor for a business customer, we notify that customer rather than their data subjects, as set out in the Data Processing Addendum.
12. International Transfers
We and our sub-processors process personal data principally in the United States, and in France for the domain verification sub-processor identified in Section 6. Where personal data protected by the GDPR or UK GDPR is transferred to a country without an adequacy decision, we rely on the Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, as incorporated into our Data Processing Addendum.
13. Cookies and Similar Technologies
We use cookies and similar technologies that are necessary to operate the Service, including for authentication, session management, security, and bot protection, and we use limited analytics to understand product usage. We do not use advertising cookies and we do not permit third-party advertising trackers on the Service. Further detail is provided on our Cookies page.
14. Children
The Service is for business use and is not directed to individuals under 18. We do not knowingly collect data from children.
15. Changes and Contact
We may update this Policy. Material changes will be communicated through the Service or by email, with the updated date shown above.
Elevora Holding LLC, 1021 East Lincolnway #9241, Cheyenne, WY 82001
Privacy contact: evens.p@elevoraholding.com