Security and data/Data handling and retention

What is collected, where it goes, how long it stays, who can delete it.

The customer owns the record at every stage. Vendidit operates the application. This page states what is collected and why, who can see it, and how deletion works.

Request the data flow summaryTrust center
Six stages · one owner · deletion in the customer's control
Data lifecycle

Six stages, one owner.

The customer owns the record at every stage. Vendidit operates the application.

01
CapturePhotograph taken on the phone. Item data derived from it. Location metadata only if configured.
02
TransitEncrypted connection from the phone to the AIMIS cloud.
03
ProcessingIdentification and description by the identification service. Valuation from comps and condition.
04
StorageRecords and photographs stored on Vendidit operated infrastructure on AWS.
05
ExportThe customer takes the record as CSV or Excel whenever they choose.
06
DeletionRetained until the customer deletes them. Deletion is the customer's control, not Vendidit's.
What is collected

Only what the record needs.

Each data type is listed with the reason it is collected, who can see it, and how long it stays.

DataWhy it is collectedWho can see itRetention
Photographs of itemsThe evidence on the record and the input to identificationThe customer's users, the identification service during processingUntil the customer deletes
Item data (title, description, condition, value, basis)The record itselfThe customer's usersUntil the customer deletes
Location metadataOptional. Ties a capture to a place. Retention is configurable and location data can be stripped on request.The customer's usersConfigurable
Account data (name, email, role)To provision and administer usersCustomer administrators, Vendidit support ConfirmLife of the account Confirm
Usage and diagnostic dataTo operate and support the application Confirm scopeVendidit operationsConfirm
Use of AI servicesPhotographs go to an identification service.

Item identification and description use commercial AI services, currently OpenAI. The architecture is provider agnostic and the underlying service can be changed without changing the product.

Whether customer photographs are used to train provider models: Confirm contract terms Data residency for processing: Confirm

Ownership and portabilityThe record is the customer's.

The customer owns the records and photographs. The export is a spreadsheet and photograph files, readable without AIMIS.

Deletion removes the records and photographs from Vendidit operated storage within Confirm days, including backups within Confirm days.

Access and administration

Who can do what.

Role based access, administered by the customer. Vendidit support access is stated, not assumed.

RoleCanCannot
CustodianCapture items, view their own records, export ConfirmEdit a locked line, delete records Confirm
ReviewerView and export records for their organizationCapture or delete Confirm
AdministratorProvision users, set retention and location settings, delete records Confirm
Vendidit supportConfirm access model and loggingAccess without the customer's request Confirm

Request the data flow summary.

One page, plain language, for the reviewer who has to sign.

Request the security overview