This notice covers the public website, PROVE accounts, vendor profile claiming and vendor information submissions, and the bounded self-service core trial. It explains the current production handling of personal data. Any paid or customer-data pilot requires separate, scope-specific privacy and data-processing terms before customer data is accepted.
Who to contact
PROVE TDI determines how the website, account and vendor-environment data described here is used. Questions and rights requests can be sent to privacy@provetdi.com. PROVE TDI is the service name. The legal operator and registered address are not yet published on this website. They must be identified in scope-specific contracting and data-processing terms before PROVE TDI accepts customer data for a paid engagement.
Accounts, enquiries and trial records
The enquiry form submits and stores the details you provide so the team can assess and respond, then attempts an internal notification and confirmation through the transactional-email service. If you create an account, the authentication service stores the details needed to sign you in and recover access. The application stores the organisation, decision and evidence records you choose to create so it can provide the bounded self-service trial. Do not include credentials or confidential evidence in a public form.
Accounts and authentication
We process your email address, authentication status, account profile, approved roles and security activity to create and protect your account, enforce access, and operate the service. Authentication links and mailbox-confirmation timestamps are used to establish control of an email address.
Vendor contributions
When you add a company or product, propose a correction, submit evidence or report outdated information, we store your name, work email, job title, organisation, relationship to the vendor, the submitted information, source links, form version, submission reference and limited anti-abuse metadata. We use this data to review provenance and scope, contact you about the submission, prevent abuse and preserve an audit trail.
Your contact details are not published on the vendor profile. Submitted sources and attributable claims may be published after moderation. Do not submit credentials, confidential customer material, special-category personal data or information you are not authorised to share.
Vendor profile claiming
For a profile claim, we store the verified email, corporate domain, mailbox-confirmation time, stated corporate relationship, claim status, granted role, review notes, disputes, suspensions, revocations and append-only access events. We use these details to establish and administer vendor-scoped authority, detect conflicting claims and investigate misuse. They are visible only to the claimant, authorised members of that vendor profile and authorised PROVE reviewers.
Enquiries and email delivery
Public enquiry and vendor forms are stored before PROVE attempts transactional email. We keep the submitted details, a durable reference and delivery status so that a delivery outage does not lose the request. Email providers process the recipient, sender, content and delivery metadata to send or suppress the message.
Analytics and technical data
The vendor environment records a limited first-party funnel event, anonymous session identifier, page path, vendor identifier where relevant, campaign parameters and coarse action metadata. It does not store buyer identity or customer decision context in the vendor funnel. Hosting and security providers may process IP address, browser information, requested URL and timestamp to deliver and protect the service. We do not use this data for behavioural advertising.
Legal bases and sharing
Depending on the interaction and applicable law, processing is necessary to provide requested account or claim steps, to review a submission you ask us to consider, to comply with legal duties, or for legitimate interests in operating a secure, attributable vendor information service. Data is shared only with service providers needed for hosting, database, authentication, security and transactional email, or where disclosure is legally required.
Retention
Open contributions and claims are retained while they are being reviewed or while access remains active. Closed submission contact data is scheduled for review and deletion or anonymisation within 24 months unless a dispute, security event, legal obligation or continuing published provenance requires longer retention. Claim and membership audit events may be retained after revocation where needed to prevent conflicting authority and establish the access history. Security and rate-limit records are kept for shorter operational periods.
Your choices and rights
You can ask for access, correction, deletion, restriction or portability, and may object to processing based on legitimate interests, subject to applicable law and necessary audit or legal records. You may also complain to the relevant data-protection authority. Email privacy@provetdi.com and include any submission reference that helps us locate the record.
International processing and changes
Service providers may process data outside your country under applicable transfer safeguards. Material changes to this notice will be dated here. This public notice does not replace a scope-specific data-processing agreement. Controller and processor roles, subprocessors, transfer mechanisms, retention and jurisdiction-specific terms must be agreed before customer data is accepted for a paid engagement.
