Vendon
Latvia · vendon.net · 15 vendors
Vendon provides IoT, telemetry, and payment solutions for the vending and coffee machine industry. Their Vendon Cloud platform enables remote monitoring, management, and optimization of machine fleets. The company's solutions help operators streamline operations, reduce costs, and increase profitability through real-time data insights, payment processing, and tools for route planning and preventative maintenance.
Resilience scores
- Digital Sovereignty: 47
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- GetSwish AB — Financial Services — Sweden
- Netlify, Inc. — Technology — United States
- The Apache Software Foundation — Technology — United States
- and 12 more
Services catalogue
3 services in catalogue across 2 categories; runs on 15 sub-vendors.
- Payment Processing
- Telemetry
- Vending Management
Insights
Last updated 2026-07-30 · revision 2
15 direct vendors, 184 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Israel: 1
- Turkey: 1
Subvendors by controlling owner country (sample)
- Slovenia: 1
- Switzerland: 1
- Germany: 6
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Vendon exhibits good migration readiness, largely driven by its core product, Vendon Cloud, being a 'Cloud-based SaaS Platform' with 'REST API / API Integrations'. This suggests a modern, modular architecture that is inherently well-suited for migration to new cloud environments or services. The absence of specified 'Data Residency Requirements' provides significant flexibility, simplifying potential migration efforts by removing a common regulatory hurdle. Assuming the vendor data (16 services across 8 countries) indicates a diverse vendor base despite the 'Total Vendors: 0' contradiction, this diversity generally reduces overall vendor lock-in risk, which is beneficial for migration. However, several factors temper the readiness score. The 'PCI DSS Level 1 Payment Security' compliance, while a strength for resilience, introduces complexity for migration as any new environment must also meet these stringent requirements. The lack of financial stability data (revenue concentration, growth history) makes it impossible to assess their capacity to fund a significant migration initiative. Additionally, the 'Vendor Lock-in Risk' remains unknown, which could present unforeseen challenges and costs during a migration. While the architecture appears modern, explicit mention of containerization or microservices would further solidify the assessment of high readiness.
Compliance
11 in-scope frameworks identified; showing 3.
EU Payment Services Directive 2 — Assessment Required
Vendon provides cashless payment solutions including card readers and a loyalty/payment app (QuickPik). PSD2 regulates payment services in the EU and may apply if Vendon acts as a Payment Institution or Electronic Money Institution, or if it provides payment initiation or account information services. However, Vendon likely operates as a payment technology provider/acquirer agent rather than a licensed payment institution — meaning PSD2 licensing obligations may fall on its payment processing partners rather than Vendon directly. Risk is Medium because the boundary between payment technology provider and regulated payment service provider can be complex, and misclassification could result in unlicensed payment service provision.
Evidence: https://vendon.net/products/card-reader/, https://vendon.net/products/vendon-cloud/, https://www.fktk.lv/en/
SOC 2 (source) — Assessment Required
Vendon operates Vendon Cloud, a SaaS/cloud platform used by 2,000+ operators worldwide for real-time machine monitoring, payment processing, and data analytics. SOC 2 is a voluntary framework but is increasingly required by enterprise customers (especially in the US and UK) as a condition of vendor onboarding. Given Vendon's global reach (90+ countries, including likely US and UK enterprise clients such as Nestlé Professional), the absence of a publicly disclosed SOC 2 report represents a medium business risk — particularly as enterprise procurement teams increasingly mandate SOC 2 Type II reports. Risk is Medium rather than High because SOC 2 is voluntary and Vendon's primary markets are EU-based where ISO 27001 is more commonly required.
Evidence: https://vendon.net/products/vendon-cloud/, https://vendon.net/
GDPR (source) — Partially Compliant
GDPR is universally applicable to Vendon as an EU/EEA-headquartered company (Latvia) that processes personal data of employees, customers (2,000+ operators worldwide), end-users of its loyalty app (QuickPik), and payment card data. Vendon operates a cloud platform, a loyalty/payment mobile app, and card readers — all of which collect and process personal data at scale. The company explicitly references GDPR (EU Regulation 2016/679) in its Whistleblowing Channel Joint Processing Agreement with Azkoyen SA, demonstrating awareness of the regulation. However, no public evidence of a formal GDPR audit, Data Protection Officer (DPO) appointment, or Records of Processing Activities (RoPA) disclosure was found. The risk level is High because: (1) Vendon processes payment card data and loyalty/consumer behavioral data across 90+ countries; (2) non-compliance fines can reach €20M or 4% of global annual turnover; (3) Latvia's Data State Inspectorate (Datu valsts inspekcija) actively enforces GDPR; (4) the company's cloud platform and mobile app create significant data processing obligations; (5) as a data processor for its 2,000+ operator clients, Vendon must maintain Data Processing Agreements (DPAs) with each client.
Evidence: https://vendon.net/compliance-and-whistleblowing-channel/, https://vendon.net/privacy-policy/, https://vendon.net/cookie-policy/, https://vendon.net/wp-content/uploads/2024/11/Joint-Processing-Agreement.pdf, https://vendon.net/wp-content/uploads/2024/11/Privacy-Policy-of-the-whistleblowing-channel.pdf, https://www.dvi.gov.lv/en
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
Vendon's financial resilience is bolstered significantly by its ownership structure as a wholly-owned subsidiary of Grupo Azkoyen, a Spanish publicly listed industrial group (CNMV: AZK) with consolidated revenue historically in the range of €140–170 million. This parent backing provides capital access, cross-selling opportunities through Azkoyen's global installed base (including sister brands Coffetek, Ascaso, Coges, and Cashlogy), and shared R&D resources. Vendon's business model benefits from a recurring SaaS-like revenue profile via Vendon Cloud, which typically produces sticky, high-margin subscription revenue on top of hardware sales. The company serves customers in over 90 countries with more than 2,000 clients including blue-chip references like Nestlé Professional, providing geographic diversification that reduces country-specific concentration risk. However, standalone financials are not publicly disclosed as investor-grade reports, being only filed as statutory accounts with the Latvian Enterprise Register. The business faces cyclicality tied to office attendance and out-of-home consumption trends, hardware dependency exposing it to component costs and BOM inflation, and competition from Nayax, Cantaloupe, Televend, and captive OEM telemetry solutions in a fragmenting IoT/payments market.
Key strengths: Parent backing from listed Grupo Azkoyen (CNMV: AZK) with ~€140-170M consolidated revenue, Recurring SaaS-like revenue from Vendon Cloud IoT platform, Geographic diversification across 90+ countries, 2,000+ clients including blue-chip Nestlé Professional, Access to Azkoyen's global sales channels and OEM relationships, Sister brand cross-selling (Coffetek, Ascaso, Coges, Cashlogy)
Risk factors: End-market cyclicality tied to office attendance and out-of-home consumption, Impact of remote-work trends on vending/OCS demand, Hardware dependency exposing to component costs and semiconductor supply, Competitive IoT/payments landscape (Nayax, Cantaloupe, Televend), Small national entity with limited statutory reporting transparency, PSD2/PCI-DSS compliance costs for payment services, EU interchange regulations affecting card-reader business, COVID-19 style shocks to vending industry
Workforce by country
- Latvia: 75
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.