Resources Compliance

EU-hosted, GDPR & the data wall

Where your data physically sits, what GDPR actually demands, and the data wall that seals every lead to the supplier who earned it. The dull stuff that quietly decides deals.

The ZoraMatch team 4 min read Compliance

Nobody picks a sourcing platform because the privacy policy reads nicely. They leave one, fast and for good, the day a competitor sees a lead that should have been theirs. That is why the dull compliance section decides more deals than the feature list ever does. So let me be exact about where your data sits, what the rules actually demand, and the one architectural promise that keeps your leads yours.

Data residency

Where the data physically is

All of it runs inside the European Union. Accounts, profiles, the conversations, the files you upload, stored in Frankfurt. The application runs in EU regions. Product analytics are EU-hosted and cookie-light: aggregate counts so we can see what's working, not ad-tech that trails your staff around the web afterwards. We don't sell data. We don't hand it to third parties for marketing. Not for a fee, not ever.

That reads like boilerplate right up until you ask a platform where its database actually lives and the answer comes back "us-east-1." Region is a physical fact, not a checkbox in a settings panel.

Data residency ZM / VAULT-01 EU-DC
Fig. 01 Every route lands in one region; the data stays inside the EU.
The principles

What GDPR actually asks

The GDPR (the AVG, in Dutch) is less mysterious than the consultants selling readiness audits would like you to believe. A handful of principles do most of the work. They're cheap to build in from the first line of code and painful to bolt on later, which is the real reason so many platforms skip them.

Collect only what's needed Company, contact, product, volumes. Nothing extra to resell.
Keep it only while useful Capped retention, written into policy, cleared automatically.
People stay in control Access, correction, deletion. Guests via revocable links.
  • Collect only what the job needs. A screening conversation gathers what it takes to write your report, company, contact, product, volumes, certifications, timeline, and not one extra field to resell down the line.
  • Keep it only while it's useful. Retention is capped and written into the privacy policy. Waitlist and prospect data clears out after a set stretch of silence, automatically, without anyone having to remember to do it.
  • Leave people in control. Access, correction and deletion land inside the statutory deadlines. Guests take part through signed links that expire and can be revoked, no account required.

Which AI providers see conversation text, and the terms they work under, is listed in the privacy policy. Your negotiations don't get fed into anyone's public model.

By construction

The data wall

Here's the promise I'd actually check if I ran a factory. When a buyer reaches you through your widget or your screening link, that lead is yours alone. Concretely, it is never shown to another supplier, ever. Not in marketplace search. Not visible to the competitor two towns over, and never quietly slipped into the matching pool to sharpen somebody else's ranking.

The data wall ZM / VAULT-02 RLS · APP
Supplier A SEALED LEAD LEAD LEAD Supplier B SEALED LEAD LEAD LEAD Supplier C SEALED LEAD LEAD LEAD ENFORCED AT TWO LAYERS RLS Row-level security · database APP Application check · every query MARKETPLACE SEARCH · MATCHING POOL no widget lead ever enters here
Fig. 02 A widget lead stays in its own lane, by construction.

It holds at two layers at once, deliberately. Row-level security in the database refuses to return the row. The application refuses again on top of that. So a bug in the interface still can't drag a lead across the wall, because the database underneath simply won't serve it. Belt and suspenders, because a promise you can switch off with a config flag was never worth much to begin with.

Row-level security refuses the row 01 · Database. The row is never returned, full stop.
The application refuses again 02 · A bug in the interface still can't drag it across.

For a supplier, this is the whole basis for putting your inbound leads on someone else's platform at all. Break it once and there's no coming back from it. So we built it to leak nowhere by construction. Good intentions don't survive a busy quarter. The schema does.

The part that decides deals

Where your data lives and who can see your leads is the boring stuff that quietly wins or loses the sale. We wrote it into the architecture so it can't be downgraded to a marketing line. The full detail sits on the Trust & Security page.

Fair by default

Ranking you're allowed to read

Fairness rides the same track. Matching runs hard filters first, sector, certifications, country, capacity, minimum order quantity, then text relevance, then an AI pass that pins a written reason to every supplier it ranks. Ranking can't be bought. A verified badge is earned through identity and quality checks, never bought off a rate card. If any of that ever changes, you'll read about it here before it ships, not after.

Want the rest, security practices and all? The ranking transparency page walks through matching end to end, and the privacy policy names every provider that touches your text.

The ZoraMatch team

We build ZoraMatch. EU-hosted AI sourcing that turns a plain-English brief into a ranked, explained shortlist, then helps you close it in a shared workspace.

All resources
Free during early access

Put a sharper brief to work.

Describe what you need in plain English. Zora turns it into a structured brief, finds the fits, and explains every match.

Free during early access · EU-hosted · no credit card