This Vendor & Supplier Privacy Policy establishes the requirements for third-party vendors, suppliers, and service providers ("Vendors") that access, process, or store personal data on behalf of Spencer's Website.
1. Overview
Spencer's Website is committed to protecting the privacy and security of user data. This policy ensures that all Vendors handling user data maintain the same high standards of data protection that we require of ourselves.
2. Applicability
This policy applies to all Vendors that:
- Process personal data on behalf of Spencer's Website
- Have access to user data through API integrations
- Provide services that involve handling user information
- Store or transmit user data in any capacity
3. Vendor Requirements
All Vendors must:
- Sign a Data Processing Agreement (DPA) prior to accessing any personal data
- Implement appropriate technical and organizational measures to protect personal data
- Process personal data only for the specific purposes authorized by Spencer's Website
- Restrict access to personal data to authorized personnel who need it to perform their duties
- Ensure that all personnel with access to personal data are trained on data protection
- Maintain documentation of their data processing activities
- Comply with all applicable data protection laws (GDPR, CCPA, etc.)
4. Data Handling Standards
4.1 Purpose Limitation
Vendors must process personal data only for the specific purposes outlined in their agreement with Spencer's Website. Any additional processing requires prior written authorization.
4.2 Data Minimization
Vendors must only access and process the minimum amount of personal data necessary to perform their services.
4.3 Data Retention
Vendors must delete or return all personal data upon termination of their agreement with Spencer's Website, unless required by law to retain the data.
4.4 Data Transfer
Vendors must not transfer personal data to third parties or countries without prior written authorization from Spencer's Website.
5. Security Requirements
Vendors must implement appropriate security measures, including:
- Encryption: Encrypt personal data in transit (TLS 1.3+) and at rest (AES-256 or equivalent)
- Access Controls: Implement role-based access controls and authentication mechanisms
- Monitoring: Monitor systems for unauthorized access or data breaches
- Patching: Keep systems updated with security patches
- Testing: Conduct regular security testing and vulnerability assessments
- Training: Provide regular security awareness training to personnel
6. Compliance Obligations
Vendors must comply with:
- GDPR: General Data Protection Regulation (EU)
- CCPA: California Consumer Privacy Act
- Other Applicable Laws: All relevant data protection laws in jurisdictions where they operate
Vendors must assist Spencer's Website in fulfilling its obligations under these laws, including responding to data subject rights requests.
7. Audit Rights
Spencer's Website reserves the right to audit Vendor compliance with this policy, including:
- Reviewing Vendor data processing documentation
- Requesting evidence of security measures
- Conducting on-site security assessments (with reasonable notice)
- Requiring independent third-party audits
8. Breach Notification
Vendors must notify Spencer's Website immediately (within 24 hours) upon discovery of any actual or suspected data breach involving personal data processed on our behalf. Notification must include:
- Description of the breach
- Categories of personal data affected
- Approximate number of data subjects affected
- Steps taken to address the breach
- Contact information for follow-up
9. Termination
Spencer's Website may terminate its agreement with a Vendor for:
- Violation of this policy
- Failure to comply with applicable data protection laws
- Unauthorized access to or disclosure of personal data
- Refusal to cooperate with audits or breach investigations
Upon termination, Vendors must immediately delete or return all personal data and provide written confirmation of deletion.
10. Contact
For questions about this Vendor & Supplier Privacy Policy, contact us:
Email: support@thespencerwebsite.com
Subject line: "Vendor Privacy Policy Inquiry"