Privacy Policy
Last updated 18 July 2026
This policy explains what personal data Vandorisk processes, why, and the rights you have over it. Vandorisk provides software that guides manufacturers through EU Cyber Resilience Act (CRA) self-assessment and generates the accompanying documentation. It is written for the European Union’s General Data Protection Regulation (GDPR).
For the data described in sections 1–4 we act as the controller. For the content our customers put into the platform we act as a processoron their behalf — see section 5.
1. Who we are
Vandorisk is operated by the Vandorisk team. We are the controller for the personal data set out below. You can reach us at hello@vandorisk.com for any privacy question or to exercise your rights.
2. Data we collect as controller, and why
We only collect what the service needs. We do not sell personal data, and we run no third-party advertising, analytics, or tracking on the application.
| Data | Why | Lawful basis (GDPR Art. 6(1)) |
|---|---|---|
| Account data — name, email, password (stored only as a bcrypt hash), organization, and role | Creating and operating your account, authentication, access control | (b) performance of a contract |
| Waitlist email address | Telling you about Vandorisk’s launch and availability | (a) consent — withdraw any time by emailing us |
| Audit log and security/access logs — user IDs, actions, and timestamps | Keeping the service and your data secure, and investigating abuse | (f) legitimate interests (service security) |
| Session cookies and authentication tokens | Keeping you signed in | (b) performance of a contract |
| Support and sales correspondence | Answering you | (b) contract / (f) legitimate interests |
The audit trail is dual-purpose: entries that record activity inside a customer’s assessment are handled as processor (section 5); our own security logging is handled as controller.
3. Cookies
The application uses only strictly necessary cookies for your session and authentication. We set no analytics or advertising cookies, so no cookie-consent banner is required. If that ever changes, this policy and the site will change with it.
4. Your rights
Where we are the controller, you have the rights of access, rectification, erasure, restriction, portability, and objection (GDPR Arts. 15–21), and the right to withdraw consent where consent is the basis. To exercise any of these, write to hello@vandorisk.com; we aim to respond within one month.
You also have the right to lodge a complaint with your data-protection supervisory authority.
5. Data our customers put into the platform (we are processor)
Organizations use Vandorisk to assess their products. The content they enter or upload — product details, applicability and classification answers, risk assessments, Annex I requirement statuses, evidence text and attachments, SBOM files, and the generated technical documentation and Declaration of Conformity drafts — belongs to the customer. The customer is the controller of any personal data within it.
We process that content only on the customer’s documented instructions under our Data Processing Agreement. Assessment content is about products, but it may incidentally contain personal data (for example, names of contributors or signatories). If your name appears in a customer’s assessment because you work for them, that customer is your controller — direct your request to them, and we will assist them as their processor.
6. Third-party flow: vulnerability screening via OSV.dev
When a customer uploads a software bill of materials (SBOM) and uses vulnerability screening, our servers extract the package names and versionslisted in the SBOM and query the public OSV.dev vulnerability database, operated by Google LLC (USA), to retrieve known-vulnerability information.
- The SBOM file itself is not transmitted.
- Customer identity is not included in the query.
- Package coordinates are ordinarily not personal data.
Because OSV.dev is operated from the United States, we treat this conservatively as an international transfer and disclose it here. Customers who do not want this to happen can simply not use the SBOM screening feature.
7. Retention
- Account data: kept for the life of the account and a short period after closure, then deleted or anonymized (except where invoicing or tax law requires longer).
- Waitlist emails: kept until you unsubscribe or after a period of inactivity.
- Security logs: kept for a limited period.
- Customer compliance content, including evidence and audit trails: retained for as long as the customer instructs. The CRA (Art. 13(13)) obliges manufacturers to keep technical documentation for 10 years, or the support period if longer, so the product is built to retain compliance evidence for 10+ years at the customer’s instruction. This retention period is anchored to the customer’s own legal obligation, not our preference. On termination, customers can export everything, and we delete or return content per the Data Processing Agreement.
8. Security
Passwords are stored only as bcrypt hashes. Access is role-restricted and scoped to each organization. Changes to assessments are recorded in an append-only audit trail. We use transport encryption and apply further technical and organizational measures appropriate to the data we hold.
9. International transfers
We host in the EU. Apart from the OSV.dev flow described in section 6, we do not transfer personal data outside the EU/EEA. If that changes, we will put an appropriate Art. 46 GDPR safeguard in place (such as Standard Contractual Clauses) and update this policy.
10. Children
The service is business-to-business and is not directed at children.
11. Changes
We will post changes on this page and, for material changes, notify account holders by email.
Contact
This is our current privacy policy; it is not legal advice. If anything here is unclear, or you want to exercise a right or ask how your data is handled, email us at hello@vandorisk.com and we will help.
See also our Terms of Service.