Privacy Policy

Version 1.0 · Effective August 2026

How we collect, use, and protect your information — and how we handle the public-record business information the platform is built on.

Our Privacy Commitment

VendorDSS (a product of QuestFeed Pty Ltd, ABN 58 632 013 855) is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also respect the rights of individuals under the GDPR and other applicable international privacy regulations.

No Data Selling

We never sell your personal information to third parties.

Encrypted & Secure

Data encrypted in transit and at rest, on managed cloud infrastructure.

Your Control

Access, correct, or delete your data at any time — one email.

1. About Us

VendorDSS is a product name and brand of QuestFeed Pty Ltd. This privacy policy is issued by, and all data protection obligations are held by:

Company Name

QuestFeed Pty Ltd

ABN

58 632 013 855

Entity Type

Australian Private Company

Location

Queensland 4210, Australia

2. Information We Collect

Information You Provide

Account Information

Email address, name, and password (stored only as a salted hash — we cannot read your password)

Saved Searches & Watchlists

The searches you save, their notification settings, and the match history that powers your digests

Communication

Messages, support requests, correction and removal requests, and feedback you send us

Automatically Collected

Usage Data

How you interact with the platform — pages visited, features used, query patterns — used to operate and improve the service

Email Events

Delivery status of the emails we send you (sign-in codes, digests), so broken addresses stop receiving mail

During the free early-access preview we do not collect any payment information. If paid plans are introduced, payment processing terms will be added to this policy before any payment details are collected.

3. Public-Record Business Information

The platform's content — awards, tenders, grants, and business listings — is compiled from official government publications. Most of it concerns companies and government bodies rather than individuals. Where public records do touch individuals, we apply these rules:

  • Grant recipients without a published business registration are not named. An unregistered recipient may be a private individual, so those records display no recipient name — by design, enforced in how the data is built.
  • Personal applicant names in public records are masked by default and shown only where a deliberate, jurisdiction-specific decision permits it.
  • Sole traders appear as their registered business identity, exactly as the government register publishes them.
  • Anyone may request correction or removal of information about their business or themselves — see the process in our Terms, and Section 8 below for your privacy rights.

Removal from VendorDSS does not remove the underlying record from the government register that published it — that register remains the authoritative source.

4. How We Use Your Information

  • Operate your account and authenticate you securely
  • Run your saved searches and send the watchlist digests you asked for
  • Provide customer support and respond to correction or removal requests
  • Improve the platform's search, resolution, and presentation
  • Send service communications (sign-in codes, security notices, material changes to terms)
  • Comply with legal obligations and enforce our Terms

5. Email Preferences

  • — Watchlist digests are sent only for searches you saved with notifications on, and only when new matching records are published.
  • — Every digest carries a working one-click unsubscribe. Unsubscribing stops all digest email to your address immediately; you can re-enable notifications any time from a saved search's settings in the app.
  • — Transactional email (sign-in codes, password resets, security notices) is sent only when you or your account's security requires it.
  • — We do not send marketing email during the early-access preview.

6. What We Do NOT Do

We will NEVER:

  • Sell your personal information to third parties
  • Share your searches or watchlists with other users or third parties
  • Use your activity for advertising, or run advertising or tracking cookies
  • Disclose who is researching which businesses or contracts

7. Data Security and Retention

Encryption

TLS in transit; encryption at rest on managed cloud infrastructure. Passwords are stored only as salted hashes.

Infrastructure

AWS cloud infrastructure (serverless compute and managed database, US region) with Cloudflare for delivery and DDoS protection.

Access Control

Least-privilege access internally; your account data is never used beyond operating the service.

Incident Response

Eligible data breaches are notified in accordance with the Australian Notifiable Data Breaches scheme.

Information Type Retention
Account information Duration of active account + up to 2 years after deletion
Saved searches & match history Duration of active account (deletable by you at any time)
Email suppression list Kept while suppression is in force, so an unsubscribed address stays unsubscribed
Support & removal correspondence 3 years from resolution
Usage analytics Aggregated; not retained in identifiable form beyond 26 months

You may request deletion of your data at any time. We process deletion requests within 30 days, subject to legal retention requirements.

8. Your Rights

Under the Australian Privacy Principles and applicable international regulations, you have the right to:

Access

Request a copy of personal information we hold about you

Correction

Request correction of inaccurate or outdated information

Deletion

Request deletion of your personal information

Portability

Receive your data in a structured, machine-readable format

Restrict Processing

Request limitation of how we process your data

Withdraw Consent

Withdraw consent for data processing at any time

How to Exercise Your Rights

Contact us at hello@vendordss.com. We respond within 30 days.

You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or your local data protection authority.

9. Cookies and Local Storage

The platform uses only what it needs to function:

  • Essential session storage in your browser keeps you signed in and remembers preferences like your selected market. Clearing it signs you out.
  • No advertising or cross-site tracking cookies. We do not run third-party advertising or tracking technologies.

10. International Transfers and Third-Party Services

VendorDSS operates from Australia with infrastructure in the United States. Your data may be processed in:

  • — United States (AWS infrastructure — primary application data storage)
  • — Australia (company operations)
  • — Cloudflare's global edge network (content delivery)

Where data is transferred internationally, we take reasonable steps required by APP 8 (cross-border disclosure) and, for EU individuals, rely on appropriate safeguards.

AWS

Cloud infrastructure: serverless compute, managed database, transactional email delivery

Cloudflare

Content delivery, DDoS protection, and frontend hosting

These are currently our only material service providers. If paid plans introduce a payment processor, this policy will be updated before any payment data is collected.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be notified by email to registered users or by a prominent notice on the platform. Continued use of VendorDSS after changes constitutes acceptance of the updated policy.

Contact Us About Privacy

For questions about this policy or to exercise your privacy rights:

QuestFeed Pty Ltd

ABN: 58 632 013 855

Email: hello@vendordss.com

Web: vendordss.com

Location: Queensland 4210, Australia

Document Version: 1.0 | Effective: August 2026