BuyerNetwork globe logoBuyerNetwork
Privacy & ComplianceBuyerNetwork Technology

Compliant by design.

CCPA, GDPR, and SOC 2 Type II are not afterthoughts at BuyerNetwork — they are architectural requirements. Every data pipeline, identity graph, and delivery mechanism is built to meet the highest global privacy standards.

SOC 2Type II Certified
CCPAFully Compliant
GDPRArticle 6 Aligned
256-bitAES Encryption at Rest
TLS 1.3Transport Security
72hrsBreach Notification SLA
Compliance Pillars

Four frameworks. One unified architecture.

CCPA Compliance

Opt-out signal processing (GPC)
Data subject access requests (DSAR) API
Right to deletion automated workflows
California Privacy Rights Act (CPRA) ready
Do Not Sell / Do Not Share controls

GDPR Alignment

Lawful basis documentation (Article 6)
Data Processing Agreements (DPAs) available
Cross-border transfer mechanisms (SCCs)
Data minimization by design
Right to erasure request handling

SOC 2 Type II

Annual third-party audit
Security, Availability & Confidentiality TSCs
Penetration testing (bi-annual)
Vendor risk management program
Employee security training & background checks

Data Architecture

AES-256 encryption at rest
TLS 1.3 for all data in transit
Role-based access control (RBAC)
Immutable audit logging
Data residency options (US, EU)
Compliance FAQ

Common compliance questions

Is visitor identification legal in the US?

Yes. BuyerNetwork operates exclusively on data collected through lawful, consent-based channels. Our identity graph is built from opt-in data sources and complies with federal law and all 50 state privacy statutes.

How do you handle CCPA opt-out requests?

We automatically process Global Privacy Control (GPC) signals and provide a dedicated DSAR API for programmatic opt-out and deletion requests. Suppression lists are propagated across all platforms within 24 hours.

Where is my data stored?

All customer data is stored in US-based data centers by default. EU data residency is available for enterprise accounts. Data is never sold or shared with third parties outside of your configured integrations.

Do you sign Data Processing Agreements?

Yes. DPAs are available for all customers and are required for any EU-based operations. Contact our compliance team via the IR page for enterprise DPA requests.

Compliance Documentation

Need our full compliance package?

Our compliance team can provide SOC 2 reports, DPAs, CCPA addendums, and security questionnaires for enterprise procurement and due diligence.