Questions? We reply fast — support@vendradial.com
Vendra CRMVendra DialWhy VendraPricingHelp centreLog inStart free trial
Legal

Privacy Policy

How Vendra Company handles personal data — as a controller for our own website, accounts and billing, and as a processor for the data you put into your Workspace. This policy is written to be complete rather than short.

Version 3.0 · Effective 1 January 2026 · Supersedes all previous versions · Vendra Company, Copenhagen, Denmark

1. Who we are and the scope of this policy

Vendra Company, Copenhagen, Denmark operates the Vendra CRM and Vendra Dial services and this website. This policy explains how we handle personal data in two distinct capacities, which it is important not to confuse.

As controller, we determine the purposes and means of processing for: data about you as a visitor to this website; data about you as an account holder, administrator or billing contact; and data generated by your interactions with our support and marketing communications.

As processor, we process the personal data that you upload to or generate inside your Workspace — your contacts, leads, companies, deal notes, call logs, recordings and similar. For that data you are the controller. We act only on your documented instructions, and our obligations are set out in the Data Processing Agreement. Requests from your own customers and contacts must be directed to you, not to us; where such a person contacts us directly we will normally refer them to you.

2. Categories of personal data we process

Account and identity data: name, work email address, password hash, workspace name, role, language and interface preferences, and the identifiers we assign to your account.

Billing data: company name, billing address, VAT identification number, subscription plan, seat count, invoice history and payment status. Full payment card details are collected and stored by our payment processor and are never received or stored by us.

Usage and technical data: IP address, approximate location derived from IP, browser and device type, operating system, pages and features accessed, timestamps, referring URL, error and diagnostic events, and security and audit events such as sign-in attempts.

Communications data: the content of messages you send to support, sales or via forms on this website, together with metadata such as time of sending and the address used.

Customer Data (processor role): whatever you choose to place in your Workspace. You decide what is collected and you are responsible for ensuring you have a lawful basis for it. We ask that you do not upload special category data, criminal offence data, payment card numbers or national identification numbers, and you do so at your own risk.

3. Purposes and legal bases

Performance of a contract (Art. 6(1)(b) GDPR): creating and administering your account, providing the Services, processing subscriptions and payments, and providing support.

Legitimate interests (Art. 6(1)(f)): securing and monitoring our systems, preventing fraud and abuse, diagnosing faults, understanding aggregate product usage in order to improve the Services, enforcing our terms, establishing, exercising or defending legal claims, and sending business communications to existing customers about the products they already use. We have assessed in each case that these interests are not overridden by your rights.

Legal obligation (Art. 6(1)(c)): retaining accounting and tax records and responding to lawful requests from competent authorities.

Consent (Art. 6(1)(a)): optional marketing emails to non-customers and any non-essential cookies. Consent may be withdrawn at any time, without affecting processing carried out before withdrawal.

4. Cookies and similar technologies

We use a deliberately small number of technologies. Strictly necessary storage keeps you signed in, remembers your workspace, and holds your language and currency preference; it cannot be disabled without breaking the service and does not require consent. Preference storage remembers interface choices. We do not use advertising cookies, we do not sell data to advertisers, and we do not permit third-party advertising trackers on this site.

Where any non-essential technology is used, it is set only after consent, and you may withdraw consent at any time by clearing site data in your browser.

5. Sharing and recipients

We share personal data only with: (a) sub-processors engaged to run the Services, listed and kept current on our legal page, each bound by written terms imposing obligations no less protective than ours; (b) our payment processor, for subscription billing; (c) professional advisers such as auditors and lawyers, under duties of confidentiality; (d) competent authorities where required by law, and only to the extent required; and (e) an acquirer or successor in the event of a merger, acquisition, reorganisation or sale of assets, subject to this policy continuing to apply.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We do not use Customer Data to train machine learning models.

6. International transfers

Our infrastructure is located in the European Union and we design the service so that Customer Data is stored and processed in the EU. Where a limited transfer outside the EEA is unavoidable — for example a support tool or a payment processor with global operations — we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses together with a transfer impact assessment and any supplementary technical measures we consider necessary.

7. Retention

Account data is retained for the life of the account and then for up to twelve (12) months, to allow recovery of an account closed in error and to defend potential claims. Billing and accounting records are retained for five (5) years as required by Danish bookkeeping legislation. Security, audit and diagnostic logs are retained for up to twelve (12) months. Support correspondence is retained for up to twenty-four (24) months. Marketing consent records are retained for as long as consent stands and for two (2) years afterwards as proof of consent.

Customer Data is retained for as long as your Workspace is active. Following termination we delete it in the ordinary course of operations, with residual copies in encrypted backups removed on the ordinary backup rotation. You should export anything you need before your access ends.

8. Your rights

Subject to the conditions and exemptions in applicable law, you have the right to request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; portability of data you provided to us in a structured, commonly used, machine-readable format; and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time.

To exercise a right, contact us at support@vendradial.com from the address associated with your account. We may ask for information reasonably necessary to verify your identity, and we will not disclose personal data to a person whose identity we cannot verify. We respond within one (1) month, extendable by two (2) further months for complex or numerous requests, and we will tell you if an extension applies. Manifestly unfounded or excessive requests, in particular repetitive ones, may attract a reasonable fee or be refused, with reasons.

If you are dissatisfied you may complain to your local supervisory authority. In Denmark this is Datatilsynet (the Danish Data Protection Agency). We would appreciate the chance to resolve the matter first.

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control within workspaces, least-privilege internal access, segregation of environments, logging and monitoring of security-relevant events, regular patching, and backup with restoration testing. Access to production systems is limited to personnel who require it and is logged.

No system is perfectly secure. You are responsible for your own account hygiene, including keeping credentials confidential, granting the least access necessary, and removing Users who leave. Where a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority and, where required, affected controllers and individuals, in accordance with Articles 33 and 34 GDPR.

10. Children

The Services are business tools intended for organisations. They are not directed at children and we do not knowingly collect personal data from anyone under 18 in a controller capacity. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. The current version is always published here with an effective date. Where a change materially affects how we process your personal data as controller, we will take reasonable steps to notify you in advance by email or in-product notice. Continued use after the effective date constitutes acknowledgement of the updated policy.

12. Contact

Vendra Company, Copenhagen, Denmark. Data protection enquiries: support@vendradial.com. We have assessed that we are not required to appoint a Data Protection Officer; enquiries are handled directly by the team responsible for the Services.