Record of processing activities
# Data Handling and Retention Summary — SupplierClear
This public summary describes the main categories of data used to provide SupplierClear. It is not a substitute for the Privacy Policy or an executed data processing agreement.
| Activity | Typical data | Purpose | Retention approach |
|----------|--------------|---------|--------------------|
| Account access | Name, email, account and session data | Authentication and account administration | For the account life, subject to applicable deletion requests and legal obligations |
| Assessments | Supplier details, quote inputs, assessment answers | Pre-PO decision support | Until deleted by the customer or under the applicable organisation policy |
| Reports and supporting material | Assessment snapshot and customer-provided material | Deliver reports and requested product features | According to the relevant assessment or organisation retention setting, subject to legal obligations |
| Security and audit events | Account and activity metadata | Security, fraud prevention, and service integrity | Retained for a limited period consistent with security and legal needs |
| Optional clarity features | Assessment context needed for the requested explanation | Provide an advisory plain-language explanation | Consistent with the related assessment |
| Optional analytics | Limited usage information where enabled and permitted | Improve the product | According to the applicable analytics and consent settings |
## International transfers and sub-processors
Where applicable, SupplierClear uses appropriate transfer mechanisms and makes its current sub-processor list available in the Trust Center. Customers that require a data processing agreement or additional transfer information may request an Enterprise security review.
## Contact
For privacy or data-protection questions, contact privacy@bacenik.com.