Privacy

A vendor dossier comes together in four stages.

At each stage, your team keeps control of what is shared, validated, and sent.

This is a courtesy translation. Only the French version is legally binding. Read the French version.
No sensitive documentsNon-disclosure agreement if neededProject use onlyValidation on your side

The dossier in 4 stages

Before

Start without sensitive documents.

Five to ten representative questions are enough to start the pre-audit. No internal document is required to begin: an excerpt of the questionnaire is enough.

Before sharing anything sensitive

Sign a non-disclosure agreement if needed.

Before any sensitive supporting evidence or before a Full dossier, an agreement can frame the sharing, at the request of your chief information security officer, your data protection officer, or ahead of the project.

During

Keep documents confined to the project.

The items you send are used only to prepare the dossier concerned. Isolated storage, access limited to the people assigned, deletion on simple request.

Before the final send

Review, validate, then send it yourself.

Prova prepares. Your team remains the final sender to your customer. No answer goes out without your review. You decide what goes out, to whom, and when.

01Prova does not send your answers to the customer.
02Prova does not replace your chief information security officer, your data protection officer, or your legal team.
03Prova does not ask for sensitive documents to get started.
04Prova does not reuse your documents outside the project.

Start with an excerpt. Keep the rest under control.

No sensitive document is required for the pre-audit. Any further sharing is framed afterward, if needed.

Policy updated July 2026 · quarterly review