Vendorful and GDPR
CertReports found no public GDPR evidence for Vendorful as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Scope
- We collect and store user email addresses as each user's login ID. In addition we use their email address to send them application notifications (they may opt out of receiving those notifications in their user profile) and password reset links upon request. Users may optionally enter their name and business title, but that information is not required. If given, that information is used solely to properly display their names in communications and within the application. We also store information about organizations, including identifying information such as organization name and (optionally) address, and allow users to view other members of their own organization. Users and organizations may opt in to sharing their organization name and user contact information with customers using the application to find new suppliers. In addition, organizations that pay for our Vendor Management module may request that their vendor organizations supply information such as certificates of insurance, corporate tax IDs, payment terms - i.e. standard supplier/customer information as would typically be tracked in a Vendor Management system. Vendor Management is NOT shared with any other third parties other than the organization that requests it from the specific vendor, and the vendor may of course choose not to supply that information. No information is disclosed to third parties outside of the application.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Vendorful, Inc.: Inactive | Live pagesha256 54bf2869d2 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Vendorful GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.