Pilot review draft — this English translation has not yet received legal approval. If it differs from the Hungarian version, the Hungarian text prevails.
1. Controller and processor roles
The customer is the controller for its own procurement projects, supplier contacts, RFQs, replies, and quotes. Vendvisor acts as a processor for these data under the customer's documented instructions. The Data Processing Agreement contains the detailed terms.
Vendvisor is an independent controller for account, access security, billing, service operations, support, and its own legal-claims data.
- Operator for Vendvisor's independent controller activities: Pásztor Dániel
- Legal form: egyéni vállalkozó
- Registered address: 3535 Miskolc, Szikla utca 17., Magyarország
- Registration number: 62767394
- Tax number: 92345313-1-25
- Service: Vendvisor
- Website: vendvisor.hu
- General contact: [email protected]
- Phone: +36 30 748 7480
- Privacy contact: [email protected]
2. Data processed
- Registration and account data: name, email address, technical password hash, company name, role, and permissions.
- Company workspace data: company name, billing or organizational details, team members, roles, permissions, and invitations.
- Procurement projects: needs, multi-item lists, specifications, own supplier lists, supplier contacts, quotes, orders, delivery data, and invoice-review data.
- Supplier source and contact-readiness data: public business source URL, source type, search provider, collection time, whether the email domain matches the official website domain, whether the address is role-based or personal, assessment method, reason, time, and business-contact approval status.
- Files and documents: uploaded quotes, attachments, purchase-order (PO) documents, invoices, delivery documents, and their technical metadata.
- Email and communications data: RFQ, follow-up, and order emails, recipients, replies, attachments, incoming reply.vendvisor.hu messages, and support inquiries.
- Processing data: procurement content provided by users, email drafts, quote summaries, and processing results.
- Logs and security data: IP address, browser, session identifier, audit logs, administrator events, security events, and system errors.
- Legal and activation evidence: name, internal version and hash of an accepted or acknowledged document; event time, user and role, IP address and browser identifier; and results of administrative checks of B2B status, signing authority, and the order form.
- Export, offboarding, and deletion data: requests and status, deadlines, export manifests and file hashes, download events, deletion operations, legal-hold exceptions, and deletion confirmations from external processors. After substantive customer data is deleted, limited evidence needed to prove deletion may be retained separately.
- Prospect data: contact forms, demo requests, email inquiries, a technical source indicator identifying the solution page that led to the form, and the time at which the person acknowledged the Privacy Notice. Acknowledgement is not consent.
- Founder's B2B pilot outreach: non-personal role-based address published on a business's official website, source URL and verification time, brief relevance reason, delivery and objection status, and business contact details voluntarily provided in a reply.
- Aggregated product-tour events: daily counts by display surface for plays, 25/50/75 percent milestones, completion, and pilot-button clicks. Vendvisor does not store visitor, session, device, IP, email, or browser identifiers for this purpose and does not create raw event records.
A user's acknowledgement of the Privacy Notice is not consent; it is immutable evidence that the notice was made available. Acceptance of the Terms or DPA is a separate contractual act.
3. Purposes, legal bases, and whether data is required
As an independent controller, Vendvisor selects legal bases only for its own purposes identified above. For personal data in customer procurement projects, the customer is the controller and determines purposes and legal bases; Vendvisor as processor does not establish an independent legal basis on the customer's behalf.
| Purpose | Typical data | Legal basis | Whether required |
|---|---|---|---|
| Accounts, permissions, and operation of the service | Name, business email, company role, permissions, basic account metadata | For company users, Vendvisor's and the customer's legitimate interests in securely performing the contract and managing authorized contacts; if the individual is the contracting party, performance of a contract. | Data needed to create and use an account is mandatory; without it the account or affected function cannot be activated. |
| Security, abuse prevention, audit, and legal claims | IP address, session, event and audit data, security events | Legitimate interests in protecting the service, customers and system and in establishing, exercising or defending legal claims; legal obligation where applicable. | Technically necessary logging is a condition of secure use; unnecessary tracking is not part of this purpose. |
| Contracts, billing, and business administration | Contract contact, representation details, order form, and billing data for paid service | For an individual contracting party, contract performance or pre-contractual steps at their request; for company contacts, legitimate interests; for accounting and tax data, legal obligation. | Without data necessary for the contract or statutory accounting, paid service cannot begin or be invoiced. |
| Contact, demo, and support requests | Name, business contact, company, and request contents | Pre-contractual steps for an individual's own contracting request; legitimate interests in responding to company contacts and managing the business relationship. | Contact details and request contents needed to reply are mandatory; omitting optional fields causes no disadvantage. |
| Limited founder-led B2B pilot outreach | Organizational role address on an official website, source and relevance; business contact details if someone replies | A genuine organizational mailbox does not identify an individual. If personal data is processed, Vendvisor relies on its legitimate interest in introducing a limited B2B pilot and handling the reply, constrained by a documented balancing test, one manual outreach, and an unconditional right to object. | Not mandatory. No automated follow-up or tracking; no further outreach after an objection. |
| Optional marketing or non-essential technology | Data clearly stated for the particular subscription or consent | Consent, which can be withdrawn at any time without affecting the lawfulness of prior processing. | Voluntary; refusal or withdrawal does not affect the basic service. |
| Aggregated measurement of product-tour usability | Daily event counts by surface, without visitor identifiers | The aggregation itself does not seek to identify an individual. For endpoint abuse protection, an IP address may be processed temporarily only for rate limiting under the legitimate interest in service security. | Automatic measurement without cookies or profiles; it does not affect basic service use. |
Vendvisor documents a balancing test for processing based on legitimate interests. A meaningful summary is available from [email protected]. A data subject may object at any time on grounds relating to their particular situation; for direct marketing, the right to object is unconditional.
Automated decision-making: as an independent controller, Vendvisor does not use solely automated decision-making or profiling that produces legal or similarly significant effects for individuals. A source-based contact-readiness status does not select a supplier or recipient, send a message, or make a business decision.
4. AI and supplier data
Vendvisor is intended only to support B2B procurement, not consumer marketing lists or mass cold campaigns. Separate assistant functions may use AI to interpret or summarize purchase needs, but reminders sent automatically by Follow-up Autopilot are produced only from approved, versioned templates, without generative AI.
The legal characterization of an RFQ depends on its actual content and purpose. If a message promotes goods, services, or the sender's business, it may be direct marketing or electronic advertising. Such messages may not be sent by Follow-up Autopilot until the customer has established the necessary separate legal basis and electronic-advertising conditions.
Vendvisor does not read the user's Gmail inbox. Supplier replies may arrive at two destinations: a unique reply.vendvisor.hu address created by Vendvisor for the project, and the mailbox of the user who actually sent the RFQ. Vendvisor processes the message and attachments in the copy received directly at the unique reply address to handle the quote and project and enable related communication. For enabled functions, AI may extract data or prepare a summary.
Only as needed for a particular function, the OpenAI API may receive project descriptions and purchase items; supplier and contact names; email drafts; replies received directly at reply.vendvisor.hu and text extracted from them or PDF attachments; quote prices and terms; negotiation data; and project, quote, order, and delivery summaries. Vendvisor's OpenAI API use does not, by default, permit API inputs and outputs to be used for model training. Without Zero Data Retention, OpenAI may by default retain API inputs, outputs, and related metadata in abuse-prevention logs for up to 30 days.
- Supplier contact data may come from public business sources or a user-provided supplier list. The system may record the specific source URL where available, source type, and collection time. For personal data from public sources, the controller generally gives information under Article 14 GDPR no later than the first communication or, absent communication, within one month of obtaining the data, unless a statutory exception applies. If the customer supplied the data, the customer as controller is responsible for this notice; Vendvisor may provide technical support.
- The system may assess whether a public business email address is technically ready for sending under source-based rules. A recent role-based address on the supplier's official website with a matching domain may be marked usable without another click. Personal, public-webmail, different-domain, old, or uncertain-source addresses require user review. For audit, the system may log an email hash rather than the full address, together with source category, reason, and time.
- Source-based contact review only expresses risk-based usability of the address. It is not a business assessment or recommendation of the supplier, does not select a recipient, does not send email automatically, and does not start a Follow-up Autopilot action.
- The first B2B RFQ email contains privacy information and a contact for objections/deletion requests. An email- or domain-based suppression entry may be recorded after an objection.
- Users are responsible for lawful use of their own supplier lists and outgoing communications.
- AI-generated content must be reviewed before sending or deciding.
- Before first use, the AI assistant clearly states that the user is interacting with an AI system; acknowledgement may be logged.
- A human decides on prices, terms, suppliers, winners, orders, and all other legally significant or material business questions. AI may only search, extract, suggest, or draft.
- Follow-up Autopilot manages no more than two reminders tied to a manually sent RFQ. It does not rank suppliers, choose winners, prepare orders, or make business decisions.
- For Autopilot actions, the rule-check result, approving user, reason for blocking, execution status, and project or RFQ identifier may be logged. The full email body and attachments are not part of the control-log export.
- Incoming replies and quotes are processed only to support that customer's particular project. They are not used to serve other customers without separate consent.
5. Google Workspace API data and Limited Use
When connecting a Google account, Vendvisor requests only openid, email, and https://www.googleapis.com/auth/gmail.send permissions. Access is used to identify the connected Google account and send procurement emails initiated by the user. Vendvisor does not read, list, modify, or delete messages in the Gmail inbox.
Data received from Google, its use, and storage
- Account identifier: the Google account email address, used to link the account, identify the sender, and check that the connected address matches the Vendvisor user's address. Vendvisor does not request the
profilepermission or collect the Google display name. - OAuth credentials: access and refresh tokens, expiry time, and authorized scopes, stored encrypted and used only to maintain the connection and authenticate sending initiated by the user.
- Sending technical data: Gmail API message ID, sending status, and related security or troubleshooting logs, used to check delivery, audit, prevent abuse, and diagnose errors.
The data above is stored on Vendvisor's server and PostgreSQL database infrastructure only as needed to operate the service. On disconnection, Vendvisor attempts to revoke the Google token with Google, always deletes stored access and refresh tokens, and marks the connection revoked. Minimal necessary technical and audit data may remain under the security, legal, and troubleshooting retention periods in this notice.
Data sharing and recipient categories
| Recipient or category | Google data disclosed and purpose |
|---|---|
| Google LLC / Google APIs | The complete outgoing MIME message approved by the user—including recipients, sender address, subject, body, technical headers, and attachments—and technical data needed to send it through the Gmail API. |
| Business recipients selected by the user | The email approved and sent to them, sender address, and attachments. They do not receive OAuth tokens or Google account data unnecessary for delivery. |
| Hosting, database, and edge infrastructure | Hetzner Online GmbH may process the account, encrypted OAuth, and sending technical data listed above. Cloudflare's security proxy may process the IP, network, TLS, and HTTP technical data needed to access the service. These providers may not use the data for their own advertising or AI/ML purposes. |
| Authorized personnel and contractors | Only as necessary for user-requested support, investigating a security event, complying with law, or protecting the service, subject to access controls and confidentiality. |
| OpenAI, AWS SES/S3/SQS, Zoho Mail EU, ZeptoMail EU, DataForSEO, other AI/ML providers, advertisers, data brokers, and credit-scoring providers | Do not receive raw, derived, aggregated, or anonymized Google Workspace API data. |
Vendvisor does not create or share aggregated or anonymized Google Workspace API datasets. Apart from the Google, business-recipient, Hetzner/Cloudflare infrastructure, and exceptional human access expressly named above, no other party receives raw, derived, aggregated, or anonymized Google Workspace API data.
Vendvisor does not sell Google Workspace API data, use it for targeted advertising, credit scoring or lending, or pass it to a third party that would use it for those purposes. Human access occurs only in the limited support, security, or legal cases above, or at the user's express request.
AI/ML separation and Limited Use statement
Vendvisor does not provide OpenAI or any other AI/ML provider with raw Google Workspace API data or derived, aggregated, or anonymized data from it. AI functions may process only project data entered directly into Vendvisor by users and separate reply copies received directly at Vendvisor's unique reply.vendvisor.hu project address. The receiving infrastructure handles these separate copies directly; they are not read from the user's Gmail inbox or obtained through the Google Workspace API.
Google Limited Use compliance statement: The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Vendvisor does not use, transfer, or disclose Google Workspace API data—including raw, derived, aggregated, or anonymized data—to create, train, or improve generalized or non-personalized artificial intelligence or machine learning models.
6. Microsoft Graph API data
Connecting a Microsoft account is voluntary and enables sending email only from the Outlook or Microsoft 365 mailbox selected by the user. Vendvisor requests delegated offline_access, User.Read, and Mail.Send permissions. It does not request Mail.Read, Mail.ReadWrite, or application-level mailbox access, so it neither reads nor lists messages in the Microsoft mailbox.
Data received from Microsoft, its use, and storage
- Account and sender identifiers: Microsoft account ID, login or mailbox email, display name, mailbox type, and sender addresses reported by Microsoft Graph, used only to identify the connected account and usable sender identity.
- OAuth credentials: access and refresh tokens, expiry, and granted permissions, stored encrypted and used only to maintain the connection and authenticate user-initiated sending.
- Outgoing message: the complete message approved by the user—including recipients, sender, subject, body, technical headers, and attachments—is sent to Microsoft Graph's
/me/sendMailendpoint. Microsoft may also retain the message in the user's Sent Items according to its service settings. - Sending technical data: connection status, sending and error statuses, and minimal logs needed to prevent abuse and diagnose problems.
User.Read is used only to identify the signed-in user's basic Microsoft profile and sender mailbox reported by Graph; Vendvisor does not modify the profile. offline_access is needed only so the user does not have to sign in again before every send.
When the Microsoft connection is disconnected, Vendvisor deletes stored access and refresh tokens and marks the connection revoked. The user or their organization's administrator may also revoke Vendvisor's Microsoft permission in Microsoft account or Microsoft 365 organizational app management. Minimal technical and audit data may remain under the retention periods in this notice.
Data sharing and AI/ML separation
Microsoft receives the approved outgoing message only to carry out sending, and business recipients selected by the user receive it when delivered. Account, encrypted OAuth, and minimal technical data may be processed on Vendvisor's Hetzner-based infrastructure; network metadata needed to access the service may be processed by Cloudflare's security proxy.
Vendvisor does not provide Microsoft Graph API data—including profile, mailbox, token, or sending data—to OpenAI, DataForSEO, or other AI/ML providers, advertisers, data brokers, or credit-scoring providers. AI processing of supplier replies may use only a separate copy received directly at Vendvisor's unique reply.vendvisor.hu project address; Vendvisor does not read it from the Microsoft mailbox or through the Microsoft Graph API.
7. Retention periods
- Account data: for the life of the account, then as required for deletion or legal retention. Personal data from unaccepted pilot registrations is deleted or converted into non-reidentifiable technical remnants after 30 days; no active account is created from it.
- Pilot contract and electronic evidence: business and representative details, declarations, versions, HTML/PDF, hashes, email-code verification, session, time, IP address, and browser identifier support contract formation and performance and proof of claims. For a sole-trader contracting party, the legal basis is Article 6(1)(b) GDPR; for a company representative, legitimate interests in contract administration and legal enforcement under Article 6(1)(f). Contract evidence is retained during the relationship and applicable limitation period, and during a reviewed, segregated legal hold if a dispute arises. The code is not a qualified signature. The actual code is not stored in readable form; the challenge is deleted after 30 days.
- Pilot waiting list: only with separate, voluntary consent under Article 6(1)(a) GDPR, an email address, declaration, time, and minimal evidence are stored for a single participation notice for no more than six calendar months or until withdrawal. Consent can be withdrawn through the deletion option provided in the interface or via the privacy address, without affecting previous lawful processing. This creates no automatic account, contract, or marketing subscription.
- Founder-led B2B pilot outreach: data on researched but unselected candidates is kept for no more than 30 days after the research round closes; sent outreach without a reply for no more than 90 days. After a substantive reply, data may remain for a period appropriate to the business relationship. After an objection or permanent delivery failure, the message content is deleted and only minimal suppression data needed to prevent further contact is retained.
- Procurement projects: in the customer's account until deletion or archiving, or for the period needed for contractual or statutory claims.
- DataForSEO searches: DataForSEO retains the original API request, including the submitted keyword or search text, and API task data for 365 days; JSON results from the Live Organic SERP, Live Local Finder, and Google Shopping endpoints used are retained for no more than 30 days. Vendvisor therefore sends only data-minimized business product and supplier search terms without personal data.
- Email and incoming-reply data: for the period needed to manage the procurement project, by default no more than 180 days as actively stored message bodies and attachments; afterward, retention-based deletion or metadata-level preservation may occur.
- Email and MFA delivery events: by default no more than 365 days for audit and troubleshooting.
- MFA challenges: used or expired email MFA challenges are kept for no more than 30 days; the one-time code is stored only as a hash.
- MFA blocks: an active address block remains until lifted; a lifted block may be kept for up to a further 30 days to evidence closure of the security event.
- Paid-service data: only under a separate agreement and for the period required by applicable law.
- Temporary security logs: generally no more than 90 days; evidence linked to an incident, legal claim, or mandatory retention may be kept longer in a separate store.
- Aggregated product-video metrics: daily aggregates for no more than 24 months; no visitor- or session-level record is created.
- Tenant exports: available for download for 60 days after creation, then the export file is deleted. Evidence of the export's occurrence, manifest, and hash may be retained for contract accounting and legal claims.
- Evidence of legal acceptance, activation, and deletion: during the contract and afterward for the period needed for limitation of related civil claims, legal duties, or proof to authorities, subject to restricted access.
- Contact inquiry data: no more than one year after the matter is closed, unless another legal basis supports longer retention.
8. Processors and external providers
The following actually used provider categories and integrations may support Platform operations. The exact flow of data depends on the functions and integrations used.
- Hosting and runtime: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; contact [email protected]; website hetzner.com; technical operation based on Coolify.
- Edge network, media hosting, and security proxy: Cloudflare, Inc. or the applicable Cloudflare contracting entity provides DNS, TLS proxy, DDoS, and network security protection for vendvisor.hu, app.vendvisor.hu, and media.vendvisor.hu, and serves the public product-tour video. IP addresses, network and HTTP/TLS metadata, and technical data from proxied traffic may be processed to protect and deliver the service.
- Database: PostgreSQL-based storage.
- Human correspondence: Zoho Mail EU for Vendvisor's own human customer, privacy, and security correspondence.
- Automated system email and email MFA: ZeptoMail EU delivers one-time authentication and contract-signing codes, registration, security, invitation, contact, and other transactional messages, plus personalized pilot agreement PDF attachments. Open and click tracking are disabled. The contract PDF contains business, representation, and contracting data, not procurement project data.
- Incoming project email — AWS: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg; classic Amazon SES Email Receiving, encrypted S3 storage, and SQS queue in
eu-central-1(Frankfurt). A successfully received raw MIME copy is deleted; after a processing error it may remain for up to 30 days. The AWS Data Processing Addendum forms part of the service terms, and AWS SCCs apply to relevant third-country transfers. - User's outgoing email: the Google Gmail, Microsoft Graph, or SMTP account connected by the user or customer. For Gmail, access is used to send mail; Vendvisor does not request permission to read the inbox.
- AI service: OpenAI Ireland Ltd. under the OpenAI API contracting/processor framework used in the EEA, supporting procurement-assistant, drafting, and data-extraction functions, without disclosing Google Workspace API data.
- Supplier and web search: DataForSEO OÜ, company number 14502291 (Estonia), when supplier discovery is used. Only data-minimized, structured business search terms may be sent; transfer of personal data is not intended, and search terms undergo separate minimization and filtering before transmission. According to DataForSEO, the original API payload, including the keyword or search text, and task data are kept for 365 days. JSON results from the Live Organic SERP, Live Local Finder, and Google Shopping endpoints used are kept for no more than 30 days. Payloads and results are stored on Hetzner infrastructure in Germany and not shared with another subprocessor.
Vendvisor currently uses no active online payment or third-party marketing analytics service on its public website. Only anonymous daily aggregate metrics are collected for its own product tour. If person-linked measurement or another non-essential technology is introduced later, this notice will be updated and consent obtained in advance where required.
Vendvisor assesses and documents the specific legal basis, safeguard, and any necessary supplementary measures for each transfer outside the EU/EEA. In the absence of an adequacy decision, the European Commission's standard contractual clauses (SCCs) and, where needed, a documented transfer impact assessment normally apply. The AWS DPA and relevant SCCs, Zoho group's EU data-center and SCC framework, and EEA processing and transfer safeguards under the OpenAI DPA form the contractual privacy basis for the affected services. A copy or meaningful extract of the applicable safeguard may be requested from [email protected], with necessary redactions for third-party trade secrets and security information.
9. Data subject rights
Under the GDPR, you may request access, rectification, deletion, restriction of processing, and data portability, and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time.
Send your request to [email protected]. We may ask you to verify your entitlement before fulfilling it.
10. Security
- Encrypted HTTPS connections and Cloudflare-based network/TLS protection.
- Passwords stored in a non-reversible form.
- Two-factor authentication available through a one-time email code or an authenticator app (TOTP); MFA is mandatory for platform administrator accounts.
- TOTP secrets are encrypted; one-time email and recovery codes are stored only as hashes.
- MFA challenges, delivery events, and address blocks may include tenant and user identifiers, status, and security metadata for access protection, troubleshooting, and abuse prevention.
- Permission- and role-based access.
- CSRF protection, session management, and security logging.
- Data access only when needed for business or operations.
11. Contact and complaints
For privacy questions, email [email protected].
You may also complain to the Hungarian National Authority for Data Protection and Freedom of Information:
- NAIH: 1055 Budapest, Falk Miksa utca 9-11, Hungary.
- Website: www.naih.hu