What personal information this site holds, why, who sees it, how long we keep it and what you can require of us. The last five sections set out the rights that apply where you are.
In force from 27 August 2026. Last revised 27 August 2026.
Contents
Straker Media LLC is the controller of the personal information described in this policy — in Canadian terms the organisation accountable for it, in Hong Kong terms the data user, and in Singapore terms the organisation. Our contact details are in the terms of use.
For anything about your personal information, including exercising any right in this policy, write to privacy@buysidefintech.com. We answer within the time the law where you are allows, and within 30 days if it sets no shorter period.
| Role | Who |
|---|---|
| EEA representative (GDPR Article 27) | to be supplied: EEA representative name and EU postal address |
| UK representative (UK GDPR Article 27) | to be supplied: UK representative name and UK postal address |
| Data protection officer, Singapore (PDPA) | to be supplied: named DPO and business contact information |
| Privacy officer, Canada (PIPEDA) | to be supplied: named privacy officer and contact details |
This policy covers the personal information we handle when you visit buysidefintech.com, register an account, write a review, claim or maintain a vendor listing, run a request for proposal or answer one.
It does not cover other companies' websites we link to, or what a vendor does with information you give it directly.
This is a business-to-business service. Most of what we hold is information about companies, which is not personal information at all. Where we hold information that identifies a person, this policy applies to it.
The table below is the complete list, taken from the database schema rather than written from memory.
| Category | What it is | Where it comes from |
|---|---|---|
| Account | Your work email address and its domain, a one-way hash of your password (never the password itself), your role on the site, and the professional context shown on a review byline: your type of firm, its assets-under-management band and your job role. | You, at registration. |
| Sign-in session | A one-way hash of your session token, the IP address and browser user-agent string recorded when the session was created, and its expiry. | Created automatically when you sign in. |
| Firm | Your firm's name, email domain, type, size band and country. | You, when you set up a request for proposal. |
| Request for proposal | The title, the category you are buying in, your intake answers, your chosen questions and weights, your deadline, which vendors you invited, and whether you chose to reveal your identity. | You. |
| RFP invitation and response | The vendor address an invitation was sent to, a one-way hash of the private access link, when it was opened, acknowledged or submitted, how many reminders were sent, and — for the person who answers — their name, email address and job role, with their answers. | You, and the vendor representative who answers. |
| Reviews | Your rating on each dimension and what you wrote. | You. |
| Vendor directory | Company facts: name, website, headquarters, founding year, ownership, products and categories, plus a business contact address, phone number or contact page, each recorded with the page it was taken from and the date. | Published pages on vendors' own websites and industry publications, and from vendor representatives who claim a listing. |
| Correspondence | Emails you send us and our replies. | You. |
| Server logs | Your IP address, the page requested, the time, the response status and your browser user-agent string. | Recorded automatically by our web server. |
We do not collect special category data — nothing about health, race, religion, political opinions, trade union membership, sex life or sexual orientation, biometrics or genetics. Please do not send it to us.
We do not knowingly collect information from children. The site is for professional use and is not directed at anyone under 18.
About the directory's contact details. These are business contact addresses published by companies for the purpose of being contacted about their products. Of the contact addresses in the directory today, effectively all are role addresses such as info@, sales@ or support@ rather than a named individual's address. Where an address does identify a person, that person may ask us to remove it and we will, using section 11.
The legal basis column applies where the GDPR or UK GDPR governs the processing. Elsewhere, the purpose column states why we do it and the regional sections explain the local basis.
| Purpose | Information used | Legal basis (EEA/UK) |
|---|---|---|
| Create and run your account, sign you in, keep you signed in | Account, sign-in session | Performance of a contract with you (Article 6(1)(b)) |
| Confirm you work where you say you do, so reviews come from practitioners and vendor listings are claimed by the right company | Account, email domain | Legitimate interests (Article 6(1)(f)): keeping the directory honest, which is the point of the service and what every user relies on |
| Publish your review with its professional context | Reviews, account context fields | Performance of a contract, and legitimate interests in publishing an accurate record |
| Run a request for proposal: send it, chase it, collect and compare answers | Firm, RFP, invitation, response | Performance of a contract with the firm; legitimate interests as regards the vendor contacts we invite (Article 6(1)(f)), being the mutual business interest in vendors learning of relevant opportunities |
| Compile and maintain the vendor directory | Vendor directory | Legitimate interests (Article 6(1)(f)): publishing an independent, sourced record of a market, which is journalism in substance and is what buyers use the site for |
| Moderate content, investigate reports, enforce the rules | Any of the above | Legitimate interests, and legal obligation where one applies |
| Keep the site secure, prevent abuse, diagnose faults | Server logs, sign-in session | Legitimate interests (Article 6(1)(f)): protecting the service and its users |
| Reply to you | Correspondence | Legitimate interests, or performance of a contract |
| Comply with the law, and establish or defend legal claims | Any of the above | Legal obligation (Article 6(1)(c)); legitimate interests (Article 6(1)(f)) |
Where we rely on legitimate interests we have weighed those interests against your rights and freedoms. You can object to any of it — see section 11 — and you can ask us for our assessment.
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. The RFP comparison scores vendors, on weights the buying firm sets, and every score is shown with the arithmetic that produced it.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either.
We share information only as follows:
| Who | What they get | Why |
|---|---|---|
| Vendors you invite to an RFP | Your requirements and questions. Your firm's type and size band. Your firm's identity only if you choose to reveal it. | To answer your RFP. |
| The firm that invited you, if you answer an RFP | Your answers, your name, email address and role. | So the firm can evaluate and contact you. |
| Readers of the site | Your review, with your firm type, size band and job role — never your name or email address. | To publish the review. |
| The vendor whose product you reviewed | The same published review. | So they can exercise their right of reply. |
| Our hosting provider, Hetzner Online GmbH, Falkenstein, Germany | Everything stored by the service, as the operator of the servers it runs on. They do not access it for their own purposes. | To run the service. |
| Our email delivery provider | The recipient address and the content of the message. | To deliver confirmation, sign-in, invitation and reminder emails. |
| Professional advisers, and authorities | Only what is necessary. | Legal, accounting and insurance advice; and where we are required by law, or need to establish or defend a legal claim. |
| A buyer of our business | The information as part of the business. | If the business is sold or reorganised. We would tell you, and the buyer would be bound by this policy or one no less protective. |
Everyone acting for us is bound by contract to use the information only on our instructions, to keep it secure and to return or delete it when they stop working for us.
The service runs on servers in Germany, operated by Hetzner Online GmbH in Falkenstein, Germany. Your information is stored in the European Union.
Straker Media LLC is established in the United States, and its personnel administer the service from there. That means personal information may be accessed from the United States, which for readers in the EEA, the United Kingdom and Switzerland is a transfer to a country outside their own.
Where such a transfer happens we rely on the European Commission's standard contractual clauses, together with the UK International Data Transfer Addendum for UK transfers and the Swiss addendum for Swiss transfers, and on an assessment of the safeguards in place. You can ask us for a copy of the clauses at privacy@buysidefintech.com.
For readers in Singapore, Hong Kong and Canada, the corresponding obligations to ensure a comparable standard of protection when information is transferred out of your jurisdiction are met by the same contractual protections. See the regional sections.
We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires.
| What | How long |
|---|---|
| Server access logs, containing IP addresses | 10 days, then deleted automatically as the logs rotate. |
| Sign-in session records | The session expires after 7 days. Expired and revoked session records are deleted. |
| Account | While your account is open. If you close it, we delete or anonymise the account within 30 days. |
| Published reviews | For as long as the review is published, which may be after your account closes. Reviews are published without your name or email address, so what remains is not ordinarily information that identifies you. You can ask us to remove a review under section 11. |
| Request for proposal, invitations and responses | While the RFP is open and for 24 months after it closes, so that both sides have a record of what was asked and answered. The private access link in an invitation expires after 45 days regardless. |
| Vendor directory records | For as long as the vendor is listed. Every fact carries the date it was checked. We correct a record whenever an error is reported to us, and whenever a vendor claims its listing and updates it. |
| Correspondence with us | 24 months from the last message, unless it relates to a dispute. |
| Anything needed for a legal claim | Until the claim and any appeal is finally resolved, or the limitation period expires. |
Where we no longer need information but cannot delete it immediately, for example because it sits in a backup, we isolate it and delete it when the backup cycle allows.
No service can promise perfect security. If a breach happens that is likely to result in a risk to you, we will notify you and the relevant authority within the time the law where you are requires — the regional sections give the specific obligations.
To report a vulnerability, see security.txt or write to security@buysidefintech.com. We will not pursue anyone who reports a problem in good faith.
We set one cookie, only after you sign in, and it does nothing but keep you signed in. There are no analytics cookies, no advertising cookies and no third-party cookies of any kind. The details are in our cookie policy.
Rendering a page on this site contacts no other company. Fonts, stylesheets, scripts and images are all served from this site, so your IP address is not passed to a third party simply because you read a page.
We send three kinds of email:
Every message we send identifies us and gives a way to contact us. We act on an unsubscribe request immediately, and in any event within the time the law where you are requires. To stop all non-essential email, write to privacy@buysidefintech.com.
Whoever and wherever you are, you may ask us to:
Write to privacy@buysidefintech.com. We may need to check who you are before we act, which protects you. Exercising a right costs nothing and we will never treat you worse for it.
The regional sections below set out the additional rights that apply where you are, and how to complain to your regulator if we get it wrong. Please come to us first if you can — we would rather fix it.
If we change this policy we will publish the new version here and change the date at the top. If a change materially affects how we use your information we will tell you by email before it takes effect, where we hold an address for you.
EEA · UK · Switzerland
This section applies if you are in the EEA, the United Kingdom or Switzerland. It adds to the rights in section 11; it does not replace them.
Your rights under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection are:
We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
Complaining. You may lodge a complaint with the supervisory authority in the EEA member state where you live, work or where the problem happened. In the United Kingdom that is the Information Commissioner's Office, ico.org.uk. In Switzerland it is the Federal Data Protection and Information Commissioner.
Our representative for the purposes of Article 27 is to be supplied: EEA representative for the EEA and to be supplied: UK representative for the United Kingdom.
Breach notification. We notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it where it is likely to result in a risk to people's rights, and we tell affected people without undue delay where the risk is high.
Singapore
This section applies if you are in Singapore, and reflects the Personal Data Protection Act 2012.
You may complain to the Personal Data Protection Commission at pdpc.gov.sg.
Hong Kong SAR
This section applies if you are in Hong Kong, and reflects the Personal Data (Privacy) Ordinance (Cap. 486) and its six data protection principles.
You may complain to the Office of the Privacy Commissioner for Personal Data at pcpd.org.hk.
Canada
This section applies if you are in Canada, and reflects the Personal Information Protection and Electronic Documents Act, Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, and the equivalent Alberta and British Columbia legislation.
You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial authority — in Quebec the Commission d'accès à l'information.
United States
This section applies if you are in the United States. It reflects the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states as they take effect. Where your state gives you a right listed here, you have it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months. We do not process personal information for targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects.
Categories collected in the last 12 months, in the terms the CCPA uses:
| CCPA category | Collected | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers — name, email address, IP address, account identifier | Yes | You; automatically from your browser | Run the service, security | Service providers; the RFP counterparty |
| Commercial information — your RFP requirements and responses | Yes | You | Run the RFP service | The RFP counterparty; service providers |
| Internet activity — pages requested, user-agent | Yes | Automatically | Security and fault diagnosis | Service providers |
| Professional or employment information — employer, job role, firm type and size band | Yes | You | Verify practitioner status; review bylines | Readers, in the anonymised form described in section 5 |
| Sensitive personal information | No | — | — | — |
| Biometric, geolocation, education, audio or visual information | No | — | — | — |
Your rights. You may ask us to: tell you what we have collected, the sources, the purposes and who we disclosed it to; give you a copy; correct it; delete it; and limit the use of sensitive personal information, though we do not collect any. You may exercise these rights twice in a 12-month period, free of charge, by writing to privacy@buysidefintech.com.
Authorised agents. You may use an authorised agent. We will ask for written proof of their authority and may ask you to confirm it directly.
Appeals. If we refuse a request, you may appeal by replying to our decision or writing to legal@buysidefintech.com. We will respond with our reasons within 45 days. If we deny your appeal you may contact your state attorney general.
No discrimination. We will not deny you service, charge you a different price or give you a lower quality of service because you exercised a privacy right.
California "Shine the Light". We do not share personal information with third parties for their own direct marketing purposes.
Do Not Track. We do not track you across other websites, so there is nothing for a Do Not Track signal to switch off. We honour opt-out preference signals such as Global Privacy Control by default, because we already do not sell or share.