Privacy Policy
Last updated: 20 March 2026
1. Who we are
TerraSecure operates VendorQ, a third-party risk management platform. This policy explains what personal data we process, why, and the rights available to you. For customer workspace content, TerraSecure acts as a processor; the customer organization is the controller.
2. Data we collect
Account data: name, work email, avatar, organization membership and role, authentication factors (including TOTP enrolment status).
Workspace data: vendor records, questionnaire responses, findings, uploaded evidence artifacts, approvals and audit logs created by your organization.
Vendor contact data: the names and email addresses your team supplies so we can deliver assessment questionnaires.
Billing data: organization billing status, plan, cycle and provider identifiers. Card details are collected and stored by our payment provider, never by TerraSecure.
Technical data: IP address, browser metadata and application logs used for security, abuse prevention and troubleshooting.
3. How we use data
To provide and secure the platform, authenticate users, isolate tenants, generate risk and security scores, deliver questionnaires, send transactional and billing notifications, provide support, and meet legal and accounting obligations.
We do not sell personal data and do not use customer workspace content to train third-party models.
4. Public-source research
VendorQ analyses publicly available information about vendor domains — DNS records, TLS configuration, email authentication, published certifications, technology fingerprints and public security reporting — to produce assumed security scores and intelligence. This research targets organizations, not individuals.
5. Sub-processors
We use a small set of vetted providers: cloud database, storage and authentication hosting; transactional email delivery; payment processing and merchant-of-record services; and public web research APIs. A current sub-processor list is available on request.
6. Retention
Workspace data is retained for the life of the subscription and for 30 days after termination, after which it is deleted. Audit and billing records are retained as required by law. Suppressed email addresses are retained to honour opt-outs.
7. Security
Data is encrypted in transit and at rest. Every tenant table is protected by row-level security scoped to organization membership. Role-based access control, optional multi-factor authentication, signed evidence-file access and immutable audit logging are enforced platform-wide.
8. Your rights
Depending on your jurisdiction you may request access, correction, deletion, restriction, portability or objection. Users should contact their organization admin first; requests can also be sent to privacy@terrasecure.co and are answered within 30 days.
9. International transfers
Data may be processed in regions where our infrastructure providers operate. Transfers rely on Standard Contractual Clauses or equivalent safeguards.
10. Contact
privacy@terrasecure.co