Privacy Policy

Last updated July 2026

1. Who we are & our roles

VenGuard is operated by 1001398049 Ontario Inc. ("VenGuard", "we"), based in Ontario, Canada. This policy applies to venguard.io, workspace subdomains, and related services.

Two roles: for account, billing, and website data, we act as the data controller. For the content your workspace stores (vendor records, documents, questionnaire responses), your organization is the controller and we act as a processor on your instructions — we host and process it solely to provide the service.

2. What we collect

Account data: email address, password (one-way hash), optional two-factor authentication enrollment.

Workspace content: vendor records, license and cost data, renewal dates, vendor payment-method metadata (card brand and last four digits only — never full numbers), uploaded compliance documents, questionnaire responses, and teammate emails you invite.

Billing data: handled by Stripe; we store subscription status and plan, never full card details.

Technical data: IP addresses (rate limiting, security logs), browser type, request logs retained for a limited period.

Questionnaire respondents: name, work email, and answers, collected on behalf of the workspace that sent the questionnaire.

3. What we don't do

We don't sell personal information, show advertising, or use third-party ad trackers. We don't use workspace content to train machine-learning models. Our breach-monitoring feature sends vendor names and public news headlines to an AI classification service — never your documents, questionnaire answers, or account data.

4. Purposes & legal bases

Where GDPR or similar laws apply, we process personal data on these bases:

Performance of contract: providing the service — accounts, workspaces, alerts, reminders, questionnaires, billing. Legitimate interests: securing the platform (rate limiting, abuse prevention, security logging), improving the service, and defending legal claims — balanced against your rights. Consent: optional marketing communications (withdraw any time). Legal obligation: tax, accounting, and lawful requests.

5. Cookies

Functional cookies only: your sign-in session, shared across venguard.io subdomains so one login works everywhere. No advertising or cross-site tracking cookies.

6. Sharing & subprocessors

We share data only with the subprocessors needed to run the service — listed with purposes and locations on our Security page — each bound by data-protection terms and processing data only for its function. We notify workspace owners by email before adding a subprocessor that handles customer data, with an opportunity to object. We may also disclose information when required by law, or in a merger or acquisition (this policy continues to apply to previously collected data).

7. International transfers

Our infrastructure providers store and process data in the United States. Where GDPR/UK GDPR applies, transfers rely on appropriate safeguards — our subprocessors' Standard Contractual Clauses and, where applicable, EU–US Data Privacy Framework certifications. Canadian customers: your data is processed outside Canada and may be accessible to foreign authorities under local law.

8. Retention & disposal

Workspace content is retained while your workspace is active; you control it and can delete vendors (and their documents) at any time. On workspace closure we delete organization data within 30 days, except minimal records retained for legal, billing, or security purposes. Security logs are retained up to 12 months. Backups age out on a rolling schedule (see the SLA in our Terms). Disposal uses our providers' secure-deletion processes.

9. Security & breach notification

Safeguards are described on our Security page: database-enforced tenant isolation, encryption in transit and at rest, MFA, signed-URL document access, and least-privilege internal access. If we become aware of a personal data breach affecting your workspace, we will notify affected workspace owners without undue delay and within 72 hours of confirming it, with what we know, the likely impact, and the measures taken — and we'll cooperate with your own notification obligations as controller.

10. Your rights

Depending on your jurisdiction (PIPEDA in Canada; GDPR/UK GDPR in Europe), you have the right to access your personal data, rectify inaccuracies, erase it, restrict or object to processing, data portability (a machine-readable export), and to withdraw consent where processing is based on consent — without affecting prior processing. Exercise any of these via privacy@venguard.io; we respond within 30 days. You may also complain to your supervisory authority (in Canada, the Office of the Privacy Commissioner; in the EU, your local DPA). If your data is in a customer's workspace, we may redirect your request to that customer as controller.

11. Data processing agreement

Customers who need a signed DPA (including Standard Contractual Clauses) for their GDPR compliance can request one at legal@venguard.io.

12. Children

VenGuard is a business tool, not directed at children; we don't knowingly collect information from anyone under 16.

13. Changes

Changes are posted here with an updated date; material changes are emailed to workspace owners before taking effect.

Questions about this document: legal@venguard.io