This Privacy Policy explains how Daros Systems, Inc., a Delaware corporation (“Daros,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal data in connection with the Provendor lead-list and market-report service and the website provendor.io (collectively, the “Service”). Provendor lets you search public business listings for free — with no account — and buy, in a single one-off payment, an enriched list of matching businesses together with a market intelligence report. By accessing or using the Service, you acknowledge the practices described here.
This Policy applies to personal data processed by Daros when you visit the website, run a free search, buy a list, or contact us. Daros determines the purposes and means of this processing and acts as the data controller. The Service does not require an account, and we do not host uploads of your own data.
Section 6 separately describes the business contact data about third-party businesses that we compile from publicly available sources and include in the lists we sell. In limited cases where we process personal data on a customer's documented instructions (for example, a bespoke request), our Data Processing Addendum applies and Daros acts as a processor.
Purchase email. When you buy a list, you enter an email address at checkout. We use it, and our payment processor uses it, to take payment, send your receipt, and deliver the link to your purchase. Checkout is a one-off payment; we do not create an account for you and do not store your full card number.
Search queries and funnel events. The business category and location you search, whether a search succeeded or returned no results, and events such as a search being run or a checkout being started. We use these for product analytics — to operate, measure, and improve the Service.
Contact and communications. Information you submit through our contact form, and emails or support messages you send us (including your name and email where you provide them).
Usage, log, and device data. IP address, browser and device identifiers, operating system, pages viewed, referring URLs, session timestamps, error reports, and approximate location derived from IP.
Cookies and similar technologies. Strictly necessary cookies to operate the site and remember your consent choice; with your consent, analytics and marketing cookies. See our Cookie Policy.
Delivery of your purchase. We deliver each order as an emailed link to a private, tokenized order page (for example, provendor.io/list/<token>) that hosts your downloadable list and market report. Anyone with the link can view that order, so keep it confidential.
Where the GDPR or UK GDPR applies, we rely on the following lawful bases to process personal data:
AI and model training. Parts of the market report are generated by large language models that research public business information and synthesize the report. We do not use your purchase email or the content of your searches to train third-party foundation models, and our AI providers do not use that data to train their models. We may use aggregated or de-identified data to improve the Service.
No sale of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
We use strictly necessary cookies to operate the Service (theme preference and consent state). We also use analytics and marketing/advertising cookies to understand how the site is used and to measure our campaigns. Details, durations, and opt-out instructions are in our Cookie Policy. You can change your preferences at any time via the cookie banner.
The lists we sell describe businesses, not the people who buy from us. For each matching business, a list may include its name, a business email address and phone number, its website, address, rating and review count, a description, its services, an approximate size, and a match score.
Where it comes from. We assemble this data at the moment you search, from publicly available sources — public business listings and directories, and the businesses' own public websites — supplemented by AI web research. We do not keep a standing database of business contacts; each list is compiled on demand for a specific search.
Some of this information may relate to an identifiable individual (for example, where a small business publishes an owner's name or a personal-style email). Where that is the case, Daros is the controller of that data and processes it for the legitimate interest of compiling and offering business-to-business contact information drawn from public sources.
If you are a listed business. If you are, or represent, a business that appears in our data and you wish to access, correct, object to, or have your information removed, email Legal@daros.ai with the business name and details, and we will action your request.
Third-party service providers. We share personal data with vetted third-party providers that power the Service. Each is engaged under written data-processing terms, confidentiality obligations, and appropriate safeguards. We engage providers in the following categories:
We do not publish individual provider names here; a current, named list is available on request to Legal@daros.ai. This list may evolve as we add or replace providers, and we will update this Privacy Policy consistent with our notice obligations.
Business partners. Referral and co-marketing partners where you have engaged with them, subject to appropriate safeguards.
Legal and safety. When we believe in good faith that disclosure is required by law, legal process, or is necessary to protect the rights, property, or safety of Daros, our users, or others.
Corporate transactions. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, in which case this Policy will continue to apply unless the acquirer adopts a different policy you are notified about.
Daros is based in the United States, and personal data is stored and processed primarily in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States. Where we transfer personal data internationally, we apply appropriate safeguards. Questions can be sent to Legal@daros.ai.
We retain your purchase email and order records for as long as needed to deliver and support your purchase and to keep the order page available, and thereafter as required for our records. Search queries and funnel events are retained in log and analytics form for up to 13 months. Billing and tax records are retained for up to 7 years as required by law. Marketing data is retained until you unsubscribe or request deletion. Business-listing data is compiled per search and is not maintained as a standing database.
We implement appropriate technical and organizational measures designed to protect personal data, including: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, principle of least privilege for staff, logging and alerting, vulnerability scanning, scoped tokens for order pages, secure software development practices, employee confidentiality and training, and incident-response procedures. No method of transmission or storage is perfectly secure. Report suspected issues to Legal@daros.ai.
Depending on where you live, you may have rights to:
To exercise rights, email Legal@daros.ai. We will verify your identity before responding. If you are a listed business seeking removal or objection, see Section 6.
If you are a California resident, the CCPA/CPRA grants you the rights to know, delete, correct, and request a copy of your personal information, to opt out of sale/sharing (we do not sell or share for cross-context behavioral advertising), and to limit the use of sensitive personal information (we do not use sensitive personal information for purposes requiring a limit). We do not discriminate against you for exercising these rights. To submit a request, email Legal@daros.ai. You may use an authorized agent; we will require written authorization and identity verification.
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will delete it.
The Service may link to third-party websites or integrate with third-party services. Their privacy practices are governed by their own policies. We recommend reviewing those policies before interacting with them.
We may update this Policy from time to time. Material changes will be communicated by posting a prominent notice on the website. The “Last updated” date at the top reflects the most recent version.
Daros Systems, Inc.
Legal, privacy, security & data processing: Legal@daros.ai
General & support: Support@daros.ai