Privacy built into supplier information exchange.

SDS is designed to help buyers and suppliers exchange business information with greater structure, transparency, and control. Our privacy approach follows the information from collection through authorized use, retention, and deletion
Supplier maintained
Information stays closer to its source
Permission based
Sharing follows authorized relationships
Module aware
Controls reflect information sensitivity
Lifecycle focused
Privacy continues beyond collection
Our Privacy Principles

Responsible information use starts with clear design choices.

SDS applies privacy considerations across the platform experience, product decisions, operating processes, and relationships with customers, suppliers, and service providers.
Purpose limitation
Information should be collected and used for defined business, platform, compliance, or service purposes—not simply because it may be available.
Data minimization
Programs and modules should request information that is relevant to the intended outcome, with higher-sensitivity information treated more carefully.
Permission-based sharing
Reusable supplier information is shared within authorized buyer-supplier relationships and according to applicable platform permissions.
Access control
Access should reflect a user’s organization, role, permissions, and legitimate need to view or manage particular information.
Lifecycle management
Privacy considerations extend to information quality, updates, retention, deletion, backups, and the end of an account or customer relationship.
Accountability
Privacy requires documented responsibilities, appropriate safeguards, vendor oversight, incident processes, and continuous improvement.

Privacy at every stage.

The SDS model is designed around information that remains current and useful over time. That means privacy cannot stop when information enters the platform.

1

Define
Identify the purpose, participant, module, and information requirement.

2

Collect
Request information through structured and proportionate workflows.

3

Use & Share
Apply permissions and make information available for authorized purposes.

4

Maintain
Support updates, quality review, access changes, and information currency.

5

Retain or Delete
Manage information in line with agreements, legal needs, and retention practices.

Privacy aligned to the product and the information.

Not every SDS workflow involves the same type or sensitivity of information. Our approach is intended to scale with the product, module, use case, and participant relationship.

SupplierSync™

Supports structured collection and maintenance of supplier information through buyer-selected programs, modules, invitations, roles, and submission workflows.

SDS Supplier Information Xchange™

Enables reusable profiles and permission-based information sharing while preserving the requirements and governance of each participating organization.

PriceDrift® by SDS

Privacy considerations will be incorporated as the forthcoming product’s pricing workflows, access model, data uses, and retention practices are finalized.

Higher-sensitivity modules

Payment Information, Cybersecurity, Compliance, and similar modules require particular attention to necessity, permissions, visibility, and appropriate handling.

Privacy aligned to the product and the information.

SDS provides the platform and supporting controls, but responsible information handling also depends on how customers configure programs and how users manage the information entrusted to them.

Platform stewardship

Design and operate the service with privacy-aware processes, access controls, service-provider oversight, incident preparation, and contractual commitments.

Program governance

Define legitimate requirements, select appropriate modules, limit access, communicate intended uses, and manage information according to applicable obligations.

Information accuracy

Provide authorized information, keep profiles and users current, review sharing decisions, and avoid submitting unnecessary personal or sensitive information.
The legal privacy roles of SDS and participating organizations may vary by product, jurisdiction, use case, and contract. Applicable agreements govern each relationship.

Designed for an international network.

SDS serves a business environment in which buyers, suppliers, users, and service providers may operate across jurisdictions.

Questions should reach the right organization.

Requests involving personal information may need to be handled by SDS, a buyer, a supplier, or another organization depending on who collected the information and why.

Approach vs. policy

This page explains the principles and design approach SDS uses when considering privacy. It is not a substitute for the SDS Privacy Policy, customer agreements, data processing terms, product documentation, or other legally binding notices.

For details about personal information collected through SDS websites and services, review the SDS Privacy Policy. For information about platform protection, review the Security Overview and Trust Center.

Have a privacy question?

Contact SDS for questions about our privacy approach, services, or request-routing process.