VendorGuard
This Privacy Policy explains how VendorGuard handles information when you use the VendorGuard vendor security and risk management platform.
Last updated: 3 October 2026
VendorGuard may process information provided when an account is created or the platform is used. This may include your name, email address, organisation information, account role and information entered into the platform.
The platform may also contain vendor security information, assessment responses, security findings, remediation information, risk decisions and generated reports provided by users of an organisation.
Information is used to provide and operate VendorGuard, authenticate users, manage organisation membership, perform vendor security assessments, track security findings and remediation activities, manage risk decisions, and generate vendor risk reports.
Information may also be used to maintain the security, reliability and performance of the platform and to investigate technical or security issues.
VendorGuard is designed so that organisation data is associated with the relevant organisation and its authorised users. Access to platform features may depend on the role assigned to a user, such as Owner, Admin or Member.
Users should only enter information into VendorGuard that they are authorised to process and manage on behalf of their organisation.
VendorGuard uses technical and organisational measures intended to protect information from unauthorised access, alteration, disclosure or loss. These measures include authentication, role-based access controls and database access controls.
No internet-based service can guarantee absolute security. Users are responsible for protecting their account credentials and notifying the appropriate administrator if they believe their account has been compromised.
VendorGuard may rely on third-party technology and infrastructure providers to operate parts of the service, including application hosting, database infrastructure, authentication and email delivery.
These providers may process information where necessary to provide their services to VendorGuard.
Information may be retained for as long as necessary to provide the VendorGuard service, maintain security and operational records, and meet applicable legal or regulatory requirements.
Retention requirements may vary depending on the type of information and the organisation using the platform.
Depending on applicable data protection law, individuals may have rights relating to their personal information. These may include rights to request access, correction, deletion, restriction or information about how personal information is processed.
Where an account is provided through an organisation, some requests may need to be handled by that organisation as the organisation responsible for the relevant information.
This Privacy Policy may be updated as VendorGuard develops or when legal, regulatory or operational requirements change. The latest version will be made available through the VendorGuard platform.
Questions or requests relating to privacy and the processing of personal information can be submitted through the VendorGuard support contact once available.
VendorGuard v1.0
Return to VendorGuard →