Privacy Policy
Last updated: 17/06/2026
This Privacy Policy explains how Vendor Check Pro handles personal data in connection with our website, platform, customer onboarding, support, and business operations. It is intended to help customers, prospective customers, vendors, and website users understand what data we handle, why we handle it, and how privacy-related responsibilities are allocated.
Vendor Check Pro is designed to support organisations in managing vendor compliance information with a strong focus on access control, data segregation, auditability, and responsible data handling.
1. Who We Are
Vendor Check Pro is a business-to-business software service designed to help schools and organisations manage vendor compliance workflows, supporting records, and related operational processes.
If you have questions about this Privacy Policy or about how personal data is handled in connection with Vendor Check Pro, you can contact us at:
Email: info@vendorcheckpro.com
2. Scope of This Policy
This Privacy Policy applies to:
visitors to our website
people who contact us with enquiries
prospective customers
customer organisation users of Vendor Check Pro
vendor users and vendor contacts where their information is processed through the platform
support, billing, and operational contacts
This policy does not override the contractual arrangements between Vendor Check Pro and its customers, including any Data Processing Agreement.
3. When Vendor Check Pro Acts as Processor
In most cases, where a customer organisation uses Vendor Check Pro to manage vendor compliance records, that customer organisation determines:
what data is collected
which vendors or individuals are included
which documents are required
how long records are retained
how the platform is used for its own governance and compliance purposes
In those cases, the customer organisation generally acts as the controller of that personal data, and Vendor Check Pro acts as a processor or service provider in relation to the platform and related support services.
This means we process customer data only:
to provide the platform and its features
to host, store, secure, maintain, and support the service
to troubleshoot issues
to provide customer support
to maintain auditability and service integrity
to meet applicable legal, security, and contractual obligations
If you are an individual whose information appears in a customer’s Vendor Check Pro environment, you should usually direct privacy rights requests to the relevant customer organisation first.
4. When Vendor Check Pro Acts as Controller
Vendor Check Pro also acts as controller for certain personal data processed for its own business purposes, including:
website enquiries and contact requests
sales and business development communications
support emails and operational correspondence
account administration
billing and finance records
supplier and service-provider administration
security, fraud-prevention, and operational governance activities
Where we act as controller, this Privacy Policy explains how we use that information.
5. Categories of Personal Data We May Handle
Depending on the context, Vendor Check Pro may handle the following categories of personal data.
5.1 Website and enquiry data
name
email address
organisation name
job title or role
phone number where provided
enquiry content and related correspondence
5.2 Account and user data
names
work email addresses
user roles
login and account status information
authentication-related records
session and activity records
5.3 Organisation and vendor data
organisation names
vendor company records
vendor contact details
linked organisation/vendor relationships
compliance status information
review and approval records
5.4 Vendor personnel and compliance data
Depending on customer use of the platform, this may include:
names and role information
work contact details
compliance status records
uploaded compliance documents
licences, certificates, permits, and supporting records
safeguarding-related records
identity and eligibility-related records where required by the customer
Customers are responsible for determining what information they require through the platform and for ensuring their use of the service aligns with their own legal, policy, and governance obligations.
5.5 Audit, usage, and technical data
login records
audit logs
IP address or network-level access records where applicable
browser and device information
support diagnostics
service performance and security monitoring records
5.6 Business administration data
billing records
payment-related administrative records
contract and customer administration information
support and service history
6. How We Use Personal Data
We use personal data only where there is a legitimate operational, contractual, security, legal, or customer-service reason to do so.
Depending on the context, we may use personal data to:
provide, host, and support Vendor Check Pro
manage customer accounts and authorised access
process and store customer-submitted records
support document review, status tracking, and workflow history
respond to website enquiries and support requests
manage onboarding, billing, and service communications
maintain security, logging, and auditability
investigate incidents or misuse
comply with legal and regulatory obligations
improve service reliability and administration
We do not sell personal data. We do not use customer data for unrelated advertising purposes.
7. Lawful Basis and Processing Rationale
Where Vendor Check Pro acts as controller, we typically process personal data because:
it is necessary to respond to enquiries or take steps before entering into a contract
it is necessary to perform a contract
it is necessary for legitimate business, operational, security, or governance interests
it is necessary to comply with legal obligations
Where Vendor Check Pro acts as processor, the relevant customer organisation is generally responsible for determining the lawful basis for the personal data it controls in the platform.
8. Access Control and Data Segregation
Vendor Check Pro is designed to support controlled access to personal data.
Current privacy-supporting controls include:
named user accounts
role-based permissions
organisation-level data segregation
restricted access to uploaded documents
administrative access limited to named authorised users
periodic review and removal of access where required
auditability of key platform actions
These controls are intended to reduce the risk of unauthorised access and to support customer governance.
9. Security of Personal Data
Vendor Check Pro maintains security measures intended to protect personal data against unauthorised access, accidental loss, misuse, alteration, or disclosure.
These measures may include:
encryption in transit using HTTPS/TLS
restricted access controls
authentication and two-factor authentication for defined roles
account lockout and session controls
endpoint and administrative security controls
audit logging and monitoring
incident handling procedures
documented review of access and privileged activity
No system can be guaranteed to be completely risk-free, but we aim to apply appropriate technical and organisational measures in line with the nature of the service and the information being handled.
10. Sharing of Personal Data
We may share personal data only where necessary to provide, support, secure, or administer the service.
This may include sharing with:
hosting and infrastructure providers
website and email service providers
storage and collaboration providers
CRM and support systems
accounting, payments, and banking providers
approved internal tooling providers
professional advisers where necessary
regulators, authorities, or law-enforcement bodies where legally required
We do not share personal data for unrelated advertising purposes.
A current provider list may be made available as part of due diligence or contractual review.
11. International Transfers
Vendor Check Pro may use service providers located in, or operating from, different jurisdictions. As a result, personal data may be processed or accessed outside the country in which it was originally collected.
Where cross-border processing or transfers occur, Vendor Check Pro aims to use appropriate contractual, organisational, and operational safeguards relevant to the type of data, the service being provided, and applicable legal requirements.
Customers should take account of hosting locations, service-provider locations, and their own transfer obligations when assessing their use of the service.
12. UAE PDPL Considerations
Where customer operations are subject to the UAE Personal Data Protection Law, Vendor Check Pro is intended to support customer compliance through:
documented processing arrangements
role-based access control
organisation-level data segregation
auditability of key actions
retention and deletion controls
support for secure handling of vendor compliance information
cooperation on privacy and security matters where contractually appropriate
Customers remain responsible for determining the purposes and legal basis of processing within their own use of the platform.
Where Vendor Check Pro acts as controller in relation to website enquiries, support requests, and its own business administration records, we aim to handle personal data in a manner consistent with applicable transparency, security, and governance expectations, including relevant UAE data protection requirements where they apply.
13. Data Retention
Personal data is retained only for as long as needed for the relevant purpose, including:
provision of the service
account administration
support and operational follow-up
audit and security requirements
legal, contractual, and financial record-keeping obligations
dispute resolution and enforcement of rights
For customer-controlled platform data, retention may depend on the customer’s use of the service, contractual terms, and applicable deletion/export arrangements.
When a customer relationship ends:
access may be withdrawn in accordance with the applicable agreement
data export may be supported where agreed
deletion may be carried out in line with the applicable retention and deletion process
14. Privacy Rights
Where Vendor Check Pro acts as controller, individuals may contact us regarding requests such as:
access to personal data
correction of inaccurate data
deletion where appropriate
restriction or objection where applicable
questions about how data is handled
Where Vendor Check Pro acts as processor on behalf of a customer organisation, requests relating to platform data should usually be directed to the relevant customer organisation first, as that organisation determines the purposes and means of processing.
If we receive a request that more appropriately belongs with a customer organisation, we may direct the requester to that organisation or assist as appropriate under our contractual arrangements.
15. Incident Handling
If Vendor Check Pro becomes aware of a security incident affecting personal data, we aim to investigate, contain, and respond appropriately.
This may include:
technical investigation
containment and remediation steps
review of affected accounts or systems
corrective actions
notification to affected customers where required by law, contract, or risk level
16. No Cookies
Vendor Check Pro does not use cookies on its website or within the application.
We do not place cookies for analytics, advertising, tracking, or session management on user devices through the website or platform.
If this changes in the future, this Privacy Policy will be updated accordingly.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the service, legal requirements, operational practices, or documentation.
The latest version will always be made available on our website. Customers and users should review this page periodically for the most current version.
18. Contact
If you have questions about this Privacy Policy or about privacy-related matters concerning Vendor Check Pro, please contact:
Vendor Check Pro
Email: info@vendorcheckpro.com
Website: www.vendorcheckpro.com
