Skip to main content

Privacy Policy

Last updated: 8 September 2026.

Vendoreye is a business discovery, procurement and vendor-governance platform. This notice covers our website, public business directory, accounts, onboarding, verification, sourcing, tenders, reverse auctions and monitoring features. It also explains business recommendations and introductions. Read it with our Terms of Use.

1. Who is responsible for your information?

Vendoreye is a UAE-led business operated by AI7lab Tech Innovation Limited, a Dubai entity. Its parent is AI7lab (ai7lab.net), whose legal name is AI7lab Tech Evolution Pte. (Singapore). For further company information, contact hi@vendoreye.ae. In this notice, “we” means AI7lab Tech Innovation Limited. Parent-company access is limited to the purposes and safeguards described below; group membership alone does not authorize unrestricted access.

For accounts, website operations, our public directory and our own business recommendations, we determine the relevant processing purposes. For private buyer-managed onboarding, assessments, documents and procurement records, we generally process information on that buyer’s instructions. The buyer’s notice and applicable data-processing agreement also apply. A company can have different roles for different activities.

2. Information and sources

A public business listing can exist without that business holding an account. Business information may contain personal data, particularly for sole traders, directors or named contacts. Availability from a public source does not remove applicable privacy obligations. Please submit only information you are authorized to provide, and avoid unnecessary personal documents.

3. Purposes and legal grounds

We use relevant information to operate accounts and workflows; enable business discovery and enquiries; process documents; assist verification, screening and monitoring; deliver tender and sourcing features; provide support; secure the platform; prevent abuse; maintain audit records; and improve reliability and relevance.

Depending on the activity and applicable law, processing relies on valid consent, contractual necessity, legal obligations or another available lawful ground or exception. These are not interchangeable blanket permissions. Where we act for a buyer, processing follows its documented instructions and the applicable agreement. We obtain additional consent where required for a new purpose.

4. Public profiles, tenders and search engines

Designated public business fields and public tender summaries may appear in Vendoreye search, category pages, public profiles and sitemaps, and may be indexed by external search engines. Listing does not mean a business has registered, endorsed Vendoreye or passed verification. Tender summaries can originate from third-party sources and are distinct from private bids or buyer-created auction opportunities.

Private onboarding documents, identity evidence, bank details, private bids and buyer-only screening reports are not made public simply because a business has a directory listing. Contact us to request correction or review of a listing. Changes on Vendoreye may take time to appear in independent search-engine caches.

5. Screening, AI and ongoing monitoring

Enabled features may use automated extraction, matching, classification or AI-generated assistance. Enrolled vendors and relevant connected parties may be re-screened on an ongoing schedule; the current published monitoring description is weekly, not uninterrupted real-time surveillance. Coverage depends on enrollment, configuration and available sources. Reports and alerts are available to authorized users in the relevant buyer workspace.

A possible match is not a finding of wrongdoing. PEP status is not itself misconduct or a sanctions designation; a well-known person is not necessarily a PEP. Results can be incomplete, outdated or incorrect and require appropriate human review. Contact us or the relevant buyer to raise an identity mismatch or disputed finding. We do not treat this policy as permission to use private documents or risk reports for unrelated marketing or unrestricted AI training.

6. Relevant offers, AI7lab and partner introductions

We may use appropriate business profile information, stated needs, product interests, interactions and preferences to identify relevant services, opportunities or potential value propositions from Vendoreye, its parent AI7lab, or selected third-party business providers. Recommendations are relevance estimates, not guarantees of the best price, suitability or outcome. Paid or sponsored placement will be identified where applicable.

Vendoreye may present or send relevant recommendations itself, subject to applicable marketing rules and your choices. Before sharing personal contact details with a partner for that partner’s independent sales or marketing, we will identify the recipient, information and purpose and obtain a separate opt-in where required. A requested introduction may involve sharing the contact and requirements you authorize. The recipient’s own privacy notice applies to its subsequent independent processing.

We do not sell personal data. We do not use private buyer documents, confidential bids, identity or bank evidence, PEP or sanctions findings, or screening reports to build unrelated marketing audiences. Private customer-controlled information is not repurposed for parent-company or partner marketing merely by updating this policy. Optional marketing is not a condition of core platform access. You can object or withdraw marketing consent through the communication’s opt-out mechanism or by contacting us. Necessary service and security notices may continue.

7. Recipients and disclosure limits

Information may be accessible to authorized users of the relevant buyer or vendor organization and shared with service providers for hosting, storage, security, document/AI processing, business verification, screening, communications and enabled integrations. Access is limited by purpose, permissions and applicable contractual protections. AI7lab may support platform operation and authorized business-recommendation activities under the same purpose restrictions. Independent partner marketing is governed separately by section 6.

We may disclose information when required by law, to respond to lawful authorities, protect legal rights or address fraud and security incidents. A corporate transaction may require limited disclosure under appropriate safeguards and applicable notice obligations. We do not describe independent marketing partners as mere subprocessors.

8. Hosting and international transfers

The standard platform is not represented as UAE/GCC-only hosting. Current production hosting includes the United States; parent-company involvement may involve Singapore, and service providers may process information in other countries. Any specific residency commitment must be stated in your agreement. Applicable transfer requirements must be met through the appropriate safeguards and arrangements before restricted data is transferred. Contact us for information about relevant recipients, locations and safeguards for your service.

9. Cookies and measurement

We use necessary authentication, session, security and preference technologies. The current consent implementation supports Google Analytics: cookie-based analytics is controlled through cookie preferences, while the Google tag can load with storage denied and send cookieless measurement requests before analytics consent. Cookieless does not mean that no information is transmitted to Google. Advertising consent signals are currently denied.

Use “Cookie settings” to review available choices or withdraw optional cookie consent, and your browser settings to remove stored cookies. Blocking necessary cookies can prevent sign-in. Cookie preferences are separate from consent for partner introductions or marketing contact. Any measurement that requires prior consent must be blocked until that consent is obtained; publication of this notice does not cure a consent-control defect.

10. Retention and security

Retention depends on the purpose, account and contractual requirements, dispute or legal obligations, and the type of record. Public directory records may be retained independently of an account while a lawful directory purpose remains. Private procurement and monitoring records follow the applicable customer agreement and retention obligations. We delete or anonymize information when no longer required, subject to lawful holds and backup lifecycles. Minimal suppression information may be retained to respect opt-outs.

We use reasonable technical and organizational safeguards, including access restrictions and security monitoring. No service is absolutely secure. Incidents will be assessed and notified to affected customers, individuals or authorities where required by applicable law.

11. Your choices, requests and complaints

Depending on applicable law, you may request access, correction, deletion, restriction, portability or review of certain automated processing, object to processing or direct marketing, or withdraw consent. These rights have conditions and exceptions. We may verify identity proportionately. For buyer-controlled records, contact that buyer; we will assist or direct your request as appropriate. You may also complain to the competent data-protection authority.

Contact hi@vendoreye.ae for privacy requests, listing corrections, marketing choices or complaints. Vendoreye is intended for business and professional use, not children.

12. Applicable laws and changes

Relevant requirements may include Singapore’s PDPA, the UAE Federal PDPL, DIFC or other local data-protection laws, and EU/UK requirements where applicable. Not every regime applies to every interaction. We will publish a dated version and communicate material changes as required. New purposes will be assessed before use; where required, fresh consent will be obtained. Continued use alone is not blanket consent to materially new personal-data sharing.