Vendor & Supplier Privacy Policy

Requirements for third-party vendors and suppliers handling user data.

Updated May 5, 2026 Version 1.0

This Vendor & Supplier Privacy Policy establishes the requirements for third-party vendors, suppliers, and service providers ("Vendors") that access, process, or store personal data on behalf of Spencer's Website.

Important: By accepting our vendor agreement or accessing user data, you agree to comply with this policy. Non-compliance may result in immediate termination of our business relationship.

1. Overview

Spencer's Website is committed to protecting the privacy and security of user data. This policy ensures that all Vendors handling user data maintain the same high standards of data protection that we require of ourselves.

2. Applicability

This policy applies to all Vendors that:

  • Process personal data on behalf of Spencer's Website
  • Have access to user data through API integrations
  • Provide services that involve handling user information
  • Store or transmit user data in any capacity

3. Vendor Requirements

All Vendors must:

  • Sign a Data Processing Agreement (DPA) prior to accessing any personal data
  • Implement appropriate technical and organizational measures to protect personal data
  • Process personal data only for the specific purposes authorized by Spencer's Website
  • Restrict access to personal data to authorized personnel who need it to perform their duties
  • Ensure that all personnel with access to personal data are trained on data protection
  • Maintain documentation of their data processing activities
  • Comply with all applicable data protection laws (GDPR, CCPA, etc.)

4. Data Handling Standards

4.1 Purpose Limitation

Vendors must process personal data only for the specific purposes outlined in their agreement with Spencer's Website. Any additional processing requires prior written authorization.

4.2 Data Minimization

Vendors must only access and process the minimum amount of personal data necessary to perform their services.

4.3 Data Retention

Vendors must delete or return all personal data upon termination of their agreement with Spencer's Website, unless required by law to retain the data.

4.4 Data Transfer

Vendors must not transfer personal data to third parties or countries without prior written authorization from Spencer's Website.

5. Security Requirements

Vendors must implement appropriate security measures, including:

  • Encryption: Encrypt personal data in transit (TLS 1.3+) and at rest (AES-256 or equivalent)
  • Access Controls: Implement role-based access controls and authentication mechanisms
  • Monitoring: Monitor systems for unauthorized access or data breaches
  • Patching: Keep systems updated with security patches
  • Testing: Conduct regular security testing and vulnerability assessments
  • Training: Provide regular security awareness training to personnel

6. Compliance Obligations

Vendors must comply with:

  • GDPR: General Data Protection Regulation (EU)
  • CCPA: California Consumer Privacy Act
  • Other Applicable Laws: All relevant data protection laws in jurisdictions where they operate

Vendors must assist Spencer's Website in fulfilling its obligations under these laws, including responding to data subject rights requests.

7. Audit Rights

Spencer's Website reserves the right to audit Vendor compliance with this policy, including:

  • Reviewing Vendor data processing documentation
  • Requesting evidence of security measures
  • Conducting on-site security assessments (with reasonable notice)
  • Requiring independent third-party audits

8. Breach Notification

Vendors must notify Spencer's Website immediately (within 24 hours) upon discovery of any actual or suspected data breach involving personal data processed on our behalf. Notification must include:

  • Description of the breach
  • Categories of personal data affected
  • Approximate number of data subjects affected
  • Steps taken to address the breach
  • Contact information for follow-up

9. Termination

Spencer's Website may terminate its agreement with a Vendor for:

  • Violation of this policy
  • Failure to comply with applicable data protection laws
  • Unauthorized access to or disclosure of personal data
  • Refusal to cooperate with audits or breach investigations

Upon termination, Vendors must immediately delete or return all personal data and provide written confirmation of deletion.

10. Contact

For questions about this Vendor & Supplier Privacy Policy, contact us:

Email: support@thespencerwebsite.com

Subject line: "Vendor Privacy Policy Inquiry"