Privacy Policy
This policy explains what personal data VendorHub handles, why, and what rights you have. It covers two different groups: the customers who use VendorHub, and the suppliers who complete onboarding through it.
Last updated 31 August 2026This page is a working draft prepared for review. It describes how VendorHub is intended to handle information and should be reviewed and adapted by your own legal counsel before publication, particularly the sections on governing law, retention periods and data transfers.
Who this policy covers
VendorHub is a vendor onboarding workspace operated by eProcureAI. This policy covers two distinct relationships, and the difference matters because the legal basis and the rights differ between them.
| Group | What it means |
|---|---|
| Customers | Organisations that use VendorHub to onboard their suppliers, and the individual users within them |
| Suppliers | Businesses and individuals who complete an onboarding questionnaire because a customer invited them |
| Website visitors | Anyone browsing this site without being a customer or an invited supplier |
Where a customer invites a supplier to complete onboarding, the customer determines what is asked and why. In data protection terms the customer is generally the controller of that information and VendorHub acts as a processor on their instructions.
What we collect
From customers
- Account details such as name, work email, job title and the organisation you belong to
- Authentication and access information, including the role assigned to you
- Records of actions taken in the workspace, such as who approved a supplier and when
- Support correspondence and anything you send us directly
From suppliers
Suppliers provide whatever the inviting customer asks for in their onboarding questionnaire. Typically this includes:
- Business identity details such as legal name, registration number and addresses
- Contact details for the people handling the relationship
- Tax identification information and associated forms
- Insurance certificates, licences, certifications and similar documents
- Banking and remittance details where the customer collects them
- Answers given in writing or by voice, in whichever language the supplier used
We also obtain information about suppliers from public sources, including government registration records, exclusion and sanctions lists and public award records, for the purpose of screening and qualification scoring.
From website visitors
- Basic technical information such as IP address, browser type and pages visited
- Anything you submit through a form on this site, such as a demo request
Why we handle it
| Purpose | Notes |
|---|---|
| Providing the service | Running onboarding, reading documents, screening against public lists and producing qualification scores on behalf of the customer |
| Security and access control | Authenticating users, applying role-based access and maintaining an attributable record of actions |
| Support | Responding to questions and resolving problems |
| Service improvement | Understanding how the product is used so it can be improved |
| Legal obligations | Meeting obligations that apply to us, and helping customers meet theirs |
We do not sell personal data. We do not use supplier information collected during onboarding for any purpose other than delivering the service to the customer who collected it.
Who we share it with
- The inviting customer. Information a supplier provides during onboarding is made available to the customer who invited them. That is the point of the service.
- Service providers. Infrastructure, hosting and similar providers who process data on our behalf under contract.
- Public data sources. We query public records to perform screening. We do not publish or contribute your information to those sources.
- Where legally required. If we are obliged to disclose information by law or valid legal process.
How long we keep it
Customer account data is retained for as long as the account is active and for a period afterwards as agreed in the customer contract. Supplier information is retained according to the instructions of the customer who collected it, because they determine the retention period appropriate to their own obligations. Where a customer ends their relationship with us, data is handled as set out in their agreement, including export and deletion.
Your rights
Depending on where you are located, you may have rights to access, correct, delete or restrict the use of your personal data, to object to certain processing, and to receive a copy in a portable format.
If you are a supplier who completed onboarding at a customer's invitation, the customer determines what happens to that information. We will direct your request to them and support them in responding. If you are a customer or a website visitor, contact us directly and we will respond.
Security
Access to supplier information is scoped by role rather than granted individually, actions are attributed to named users, and records are written as work happens rather than being editable afterwards. Further detail on access and record handling is set out on our security page.
International transfers
Where information is transferred across borders, we put appropriate safeguards in place. Specific arrangements depend on where you and your data are located and are set out in customer agreements.
Changes to this policy
We will update this page when our practices change, and the date at the top reflects the most recent revision. Material changes affecting customers will be communicated directly rather than only posted here.
Contact
For any question about this policy, or to make a request about your data, contact us through the details on our website and we will respond.
