Privacy Policy

Last updated: 17/06/2026

This Privacy Policy explains how Vendor Check Pro handles personal data in connection with our website, platform, customer onboarding, support, and business operations. It is intended to help customers, prospective customers, vendors, and website users understand what data we handle, why we handle it, and how privacy-related responsibilities are allocated.

Vendor Check Pro is designed to support organisations in managing vendor compliance information with a strong focus on access control, data segregation, auditability, and responsible data handling.

1. Who We Are

Vendor Check Pro is a business-to-business software service designed to help schools and organisations manage vendor compliance workflows, supporting records, and related operational processes.

If you have questions about this Privacy Policy or about how personal data is handled in connection with Vendor Check Pro, you can contact us at:

Email: info@vendorcheckpro.com

2. Scope of This Policy

This Privacy Policy applies to:

  • visitors to our website

  • people who contact us with enquiries

  • prospective customers

  • customer organisation users of Vendor Check Pro

  • vendor users and vendor contacts where their information is processed through the platform

  • support, billing, and operational contacts

This policy does not override the contractual arrangements between Vendor Check Pro and its customers, including any Data Processing Agreement.

3. When Vendor Check Pro Acts as Processor

In most cases, where a customer organisation uses Vendor Check Pro to manage vendor compliance records, that customer organisation determines:

  • what data is collected

  • which vendors or individuals are included

  • which documents are required

  • how long records are retained

  • how the platform is used for its own governance and compliance purposes

In those cases, the customer organisation generally acts as the controller of that personal data, and Vendor Check Pro acts as a processor or service provider in relation to the platform and related support services.

This means we process customer data only:

  • to provide the platform and its features

  • to host, store, secure, maintain, and support the service

  • to troubleshoot issues

  • to provide customer support

  • to maintain auditability and service integrity

  • to meet applicable legal, security, and contractual obligations

If you are an individual whose information appears in a customer’s Vendor Check Pro environment, you should usually direct privacy rights requests to the relevant customer organisation first.

4. When Vendor Check Pro Acts as Controller

Vendor Check Pro also acts as controller for certain personal data processed for its own business purposes, including:

  • website enquiries and contact requests

  • sales and business development communications

  • support emails and operational correspondence

  • account administration

  • billing and finance records

  • supplier and service-provider administration

  • security, fraud-prevention, and operational governance activities

Where we act as controller, this Privacy Policy explains how we use that information.

5. Categories of Personal Data We May Handle

Depending on the context, Vendor Check Pro may handle the following categories of personal data.

5.1 Website and enquiry data

  • name

  • email address

  • organisation name

  • job title or role

  • phone number where provided

  • enquiry content and related correspondence

5.2 Account and user data

  • names

  • work email addresses

  • user roles

  • login and account status information

  • authentication-related records

  • session and activity records

5.3 Organisation and vendor data

  • organisation names

  • vendor company records

  • vendor contact details

  • linked organisation/vendor relationships

  • compliance status information

  • review and approval records

5.4 Vendor personnel and compliance data

Depending on customer use of the platform, this may include:

  • names and role information

  • work contact details

  • compliance status records

  • uploaded compliance documents

  • licences, certificates, permits, and supporting records

  • safeguarding-related records

  • identity and eligibility-related records where required by the customer

Customers are responsible for determining what information they require through the platform and for ensuring their use of the service aligns with their own legal, policy, and governance obligations.

5.5 Audit, usage, and technical data

  • login records

  • audit logs

  • IP address or network-level access records where applicable

  • browser and device information

  • support diagnostics

  • service performance and security monitoring records

5.6 Business administration data

  • billing records

  • payment-related administrative records

  • contract and customer administration information

  • support and service history

6. How We Use Personal Data

We use personal data only where there is a legitimate operational, contractual, security, legal, or customer-service reason to do so.

Depending on the context, we may use personal data to:

  • provide, host, and support Vendor Check Pro

  • manage customer accounts and authorised access

  • process and store customer-submitted records

  • support document review, status tracking, and workflow history

  • respond to website enquiries and support requests

  • manage onboarding, billing, and service communications

  • maintain security, logging, and auditability

  • investigate incidents or misuse

  • comply with legal and regulatory obligations

  • improve service reliability and administration

We do not sell personal data. We do not use customer data for unrelated advertising purposes.

7. Lawful Basis and Processing Rationale

Where Vendor Check Pro acts as controller, we typically process personal data because:

  • it is necessary to respond to enquiries or take steps before entering into a contract

  • it is necessary to perform a contract

  • it is necessary for legitimate business, operational, security, or governance interests

  • it is necessary to comply with legal obligations

Where Vendor Check Pro acts as processor, the relevant customer organisation is generally responsible for determining the lawful basis for the personal data it controls in the platform.

8. Access Control and Data Segregation

Vendor Check Pro is designed to support controlled access to personal data.

Current privacy-supporting controls include:

  • named user accounts

  • role-based permissions

  • organisation-level data segregation

  • restricted access to uploaded documents

  • administrative access limited to named authorised users

  • periodic review and removal of access where required

  • auditability of key platform actions

These controls are intended to reduce the risk of unauthorised access and to support customer governance.

9. Security of Personal Data

Vendor Check Pro maintains security measures intended to protect personal data against unauthorised access, accidental loss, misuse, alteration, or disclosure.

These measures may include:

  • encryption in transit using HTTPS/TLS

  • restricted access controls

  • authentication and two-factor authentication for defined roles

  • account lockout and session controls

  • endpoint and administrative security controls

  • audit logging and monitoring

  • incident handling procedures

  • documented review of access and privileged activity

No system can be guaranteed to be completely risk-free, but we aim to apply appropriate technical and organisational measures in line with the nature of the service and the information being handled.

10. Sharing of Personal Data

We may share personal data only where necessary to provide, support, secure, or administer the service.

This may include sharing with:

  • hosting and infrastructure providers

  • website and email service providers

  • storage and collaboration providers

  • CRM and support systems

  • accounting, payments, and banking providers

  • approved internal tooling providers

  • professional advisers where necessary

  • regulators, authorities, or law-enforcement bodies where legally required

We do not share personal data for unrelated advertising purposes.

A current provider list may be made available as part of due diligence or contractual review.

11. International Transfers

Vendor Check Pro may use service providers located in, or operating from, different jurisdictions. As a result, personal data may be processed or accessed outside the country in which it was originally collected.

Where cross-border processing or transfers occur, Vendor Check Pro aims to use appropriate contractual, organisational, and operational safeguards relevant to the type of data, the service being provided, and applicable legal requirements.

Customers should take account of hosting locations, service-provider locations, and their own transfer obligations when assessing their use of the service.

12. UAE PDPL Considerations

Where customer operations are subject to the UAE Personal Data Protection Law, Vendor Check Pro is intended to support customer compliance through:

  • documented processing arrangements

  • role-based access control

  • organisation-level data segregation

  • auditability of key actions

  • retention and deletion controls

  • support for secure handling of vendor compliance information

  • cooperation on privacy and security matters where contractually appropriate

Customers remain responsible for determining the purposes and legal basis of processing within their own use of the platform.

Where Vendor Check Pro acts as controller in relation to website enquiries, support requests, and its own business administration records, we aim to handle personal data in a manner consistent with applicable transparency, security, and governance expectations, including relevant UAE data protection requirements where they apply.

13. Data Retention

Personal data is retained only for as long as needed for the relevant purpose, including:

  • provision of the service

  • account administration

  • support and operational follow-up

  • audit and security requirements

  • legal, contractual, and financial record-keeping obligations

  • dispute resolution and enforcement of rights

For customer-controlled platform data, retention may depend on the customer’s use of the service, contractual terms, and applicable deletion/export arrangements.

When a customer relationship ends:

  • access may be withdrawn in accordance with the applicable agreement

  • data export may be supported where agreed

  • deletion may be carried out in line with the applicable retention and deletion process

14. Privacy Rights

Where Vendor Check Pro acts as controller, individuals may contact us regarding requests such as:

  • access to personal data

  • correction of inaccurate data

  • deletion where appropriate

  • restriction or objection where applicable

  • questions about how data is handled

Where Vendor Check Pro acts as processor on behalf of a customer organisation, requests relating to platform data should usually be directed to the relevant customer organisation first, as that organisation determines the purposes and means of processing.

If we receive a request that more appropriately belongs with a customer organisation, we may direct the requester to that organisation or assist as appropriate under our contractual arrangements.

15. Incident Handling

If Vendor Check Pro becomes aware of a security incident affecting personal data, we aim to investigate, contain, and respond appropriately.

This may include:

  • technical investigation

  • containment and remediation steps

  • review of affected accounts or systems

  • corrective actions

  • notification to affected customers where required by law, contract, or risk level

16. No Cookies

Vendor Check Pro does not use cookies on its website or within the application.

We do not place cookies for analytics, advertising, tracking, or session management on user devices through the website or platform.

If this changes in the future, this Privacy Policy will be updated accordingly.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the service, legal requirements, operational practices, or documentation.

The latest version will always be made available on our website. Customers and users should review this page periodically for the most current version.

18. Contact

If you have questions about this Privacy Policy or about privacy-related matters concerning Vendor Check Pro, please contact:

Vendor Check Pro
Email: info@vendorcheckpro.com
Website: www.vendorcheckpro.com