Privacy Policy
Last updated: July 29, 2026.
AI7Lab ("Vendoreye", "we", "us") provides a supplier intelligence and governance platform for procurement teams. This policy explains what data we collect, why, and how it's handled — including the cookies and similar technologies we use — across the Vendoreye website, platform, and any supplier or customer-branded portal that links to this policy. See also our Terms of Use.
1. Data we collect
- Account data: name, email, role, and organization for users of the platform.
- Vendor data: information vendors submit during onboarding, including company details, contact information, and uploaded documents.
- Usage data: log and activity data generated as the platform is used.
2. How we use data
To operate the platform, perform vendor screening and verification on your organization's behalf, provide support, and improve the service. We do not sell personal data.
3. Data residency and storage
Data is hosted and processed within the UAE / GCC region.
4. Data sharing
We share data with sub-processors only as needed to operate the platform, under appropriate data-processing terms — specifically, AI and document-processing providers (to extract and verify vendor documents), business-verification data providers (to check registration and licensing status), and email-delivery providers (to send platform notifications). We do not share data with sub-processors for advertising or resale.
5. Cookies and similar technologies
Vendoreye uses cookies and similar technologies, such as browser local storage, to run the platform securely and keep you signed in.
- Strictly necessary: session and authentication cookies, and cross-site request forgery (CSRF) protection. These are required for the platform to function and can't be turned off — blocking them through your browser will prevent you from signing in.
- Analytics and marketing: Vendoreye does not currently set analytics, tracking, advertising, or marketing cookies. If that changes, any non-essential cookie will be switched off by default until you consent, and this policy will be updated first.
- Third-party services: where a platform feature depends on a third-party provider (for example, email delivery), that provider may process data or set its own cookies under its own privacy notice.
Most browsers let you view, block, or delete cookies through their settings; see your browser's help pages for instructions. Blocking strictly necessary cookies will prevent you from signing in.
6. Customer-managed portals
If your organization was invited to use Vendoreye by a customer — for example, as a supplier completing onboarding or an assessment — that organization decides why and how certain data about you is processed, and Vendoreye processes it on their behalf to provide the service. That organization's own privacy notice may also apply. Questions about data submitted through a specific organization's portal should usually go to that organization first; Vendoreye will support them in responding where required.
7. International data transfers
Vendoreye hosts and processes data within the UAE / GCC region (see "Data residency and storage" above). Where any processing does involve a transfer outside that region, such as to a sub-processor described above, we rely on an appropriate safeguard, such as approved standard contractual clauses or another lawful transfer mechanism.
8. Your rights
Subject to applicable law (including the DIFC Data Protection Law, UAE Federal PDPL, and GDPR where relevant), you may have the right to access, correct, or request deletion of your personal data, restrict or object to certain processing, withdraw consent, request a portable copy of your data, and object to direct marketing. To exercise any of these rights, contact hi@vendoreye.ae; we may need to verify your identity first. If your data is controlled by a Vendoreye customer rather than by Vendoreye directly, we may refer your request to that organization.
9. Retention
We retain data for as long as your organization's account is active, or as required to meet legal and contractual obligations, then delete or anonymize it. Cookie-derived data is retained only for the period needed for its purpose, as described above.
10. Security
We use reasonable technical and organizational measures — including encryption, access controls, and monitoring — designed to protect your data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security.
11. Children
Vendoreye is built for business and professional use. It is not directed to children, and we do not knowingly collect personal data from children.
12. Applicable privacy frameworks
Depending on your location and how Vendoreye is used, processing may be subject to the DIFC Data Protection Law No. 5 of 2020, the UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data, the EU General Data Protection Regulation, and/or the UK GDPR. Not every framework applies to every user or interaction.
13. Changes to this policy
We may update this policy as our practices, providers, or legal obligations change. We'll post the revised policy here with a new "Last updated" date, and where a change materially affects how we use cookies or personal data, we'll take reasonable steps to bring it to your attention.
14. Contact
Questions about this policy, or requests relating to your data: hi@vendoreye.ae. If the DIFC Data Protection Law applies to you, you may also have the right to lodge a complaint with the DIFC Commissioner of Data Protection, or with another supervisory authority with jurisdiction over your location.