Legal

Privacy Policy

Last updated: May 5, 2026

This Privacy Policy explains how Venzip Solutions Inc. (“Venzip”, “we”, “our”) collects, uses, stores, and protects information when you use the Venzip platform and related services.

1. Information We Collect

  • Account information — name, email address, company.
  • Usage data — pages visited, features used, telemetry needed to operate the service.
  • Compliance data you upload — assessment responses, evidence files, risk register entries.
  • Trust Scanner responses — the answers you provide to the public scanner along with the company name and email you optionally share.
  • Payment information — processed by Stripe; we do not store card details on our infrastructure.

2. How We Use Your Information

  • To operate, maintain, and improve the Venzip platform.
  • To send compliance-related notifications (with your consent).
  • To generate AI-powered insights using your compliance data, on demand.
  • To communicate product updates and security alerts.

3. Data Storage & Security

  • All data is stored in Supabase (PostgreSQL) with row-level security enforced per tenant.
  • Data is encrypted at rest and in transit (TLS 1.3).
  • Hosting is provided by Vercel (CDN) and Supabase (database) — both SOC 2 certified.
  • We never sell your data to third parties.

4. AI Processing

Your compliance data may be processed by OpenAI’s GPT-4o family of models to generate insights, summaries, and recommendations. We use OpenAI’s API under a data processing agreement, and OpenAI does not retain or train on Venzip customer data. AI responses are generated suggestions only and do not constitute legal, audit, or certification advice.

5. Your Rights (GDPR)

  • Right to access your data.
  • Right to deletion (the “right to be forgotten”).
  • Right to data portability.
  • Right to object to processing.

To exercise any of these rights, contact us at privacy@venzip.com.

6. Cookies

  • Essential cookies — authentication and session management.
  • Analytics cookies — usage patterns, only after you accept.
  • You can manage cookies any time via the cookie banner at the bottom of the page.

7. Contact

Data Controller: Venzip Solutions Inc.
Email: privacy@venzip.com
Address: Canada

See also our Terms of Use.