Appian procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ We are subject to the provisions of the General Data Protection Regulation that protects your Personal Data. Where we transfer your data to third parties outside of the EEA, we will ensure that certain safeguards are in place to ensure a similar degree of security for your Personal Data. As such: We may transfer your Personal Data to countries that the European Commission have approved as providing an adequate level of protection for Personal Data by; or We may transfer your Personal Data to affiliates or service providers who are established outside of the EEA, using Standard Contractual Clauses or certification mechanisms approved by the European Commission which give Personal Data the same protection it has in Europe.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ If there is any conflict between the terms in this notice and the Data Privacy Framework Principles, the Data Privacy Framework Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit https://www.dataprivacyframework.gov/s/ .” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the SwissU.S. DPF, Appian commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The Federal Trade Commission has jurisdiction over Appian’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ For the purposes of the processing envisaged in this Policy, with regards to personal data transferred the the United States from the European Union, Switzerland, or the UK, Appian is a participant in and adheres to the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and, as applicable the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). Appian has certified to the Department of Commerce that it adheres to the Data Privacy Framework Principles with respect to such processing activities.</p>\r\n<p>If there is any conflict between the terms in this notice and the Data Privacy Framework Principles, the Data Privacy Framework Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit <a href=\"https://www.dataprivacyframework.gov/s/.\" target=\"_blank\" rel=\"noopener noreferrer\">https://www.dataprivacyframework.gov/s/</a>.</p>\r\n<p>The Federal Trade Commission has jurisdiction over Appian’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).</p>\r\n<p>In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the SwissU.S. DPF, Appian commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.</p>\r\n<p>EU, UK and Swiss individuals also have the possibility, under certain conditions, to invoke binding arbitration for complaints regarding Appian’s compliance with the Data Privacy Framework Principles, which have not been resolved by any of the other Data Privacy Framework mechanisms. You can find additional information here: <a href=\"https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction\" target=\"_blank\">https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction</a></p>\r\n<p>As explained above Appian sometimes provides personal information to third parties to perform services on our behalf. If we transfer personal information received under the Data Privacy Framework to a third party, the third party's access, use, and disclosure of the personal information must also be in compliance with our Data Privacy Framework obligations, and we will remain liable under the Data Privacy Framework for any failure to do so by the third party unless we prove we are not responsible for the event giving rise to the damage.</p>\r\n"}}" id="rich-text-d576e38399" class="cmp-text"> For the purposes of the processing envisaged in this Policy, with regards to personal data transferred the the United States from the European Union, Switzerland, or the UK, Appian is a participant in and adheres to the EU-U.S. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Data Privacy Framework (EU-U.S. DPF) and, as applicable the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). Appian has certified to the Department of Commerce that it adheres to the Data Privacy Framework Principles with respect to such processing activities.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ We share your Personal Data within our group of companies or service providers which involves transferring your data outside the European Economic Area (EEA).</p>\r\n<ul>\r\n<li>We are subject to the provisions of the General Data Protection Regulation that protects your Personal Data. Where we transfer your data to third parties outside of the EEA, we will ensure that certain safeguards are in place to ensure a similar degree of security for your Personal Data. As such:</li>\r\n<li>We may transfer your Personal Data to countries that the European Commission have approved as providing an adequate level of protection for Personal Data by; or</li>\r\n<li>We may transfer your Personal Data to affiliates or service providers who are established outside of the EEA, using Standard Contractual Clauses or certification mechanisms approved by the European Commission which give Personal Data the same protection it has in Europe.</li>\r\n</ul>\r\n<p>If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time. </p>\r\n"}}" id="rich-text-9c032321f7" class="cmp-text"> We share your Personal Data within our group of companies or service providers which involves transferring your data outside the European Economic Area (EEA).” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We will only retain your Personal Data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.</p>\r\n<p>When deciding what the correct time is to keep the data for we look at its amount, nature and sensitivity, potential risk of harm from unauthorized use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements.</p>\r\n"}}" id="rich-text-637886f68e" class="cmp-text"> We will only retain your Personal Data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ When deciding what the correct time is to keep the data for we look at its amount, nature and sensitivity, potential risk of harm from unauthorized use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time. ” | Captured 2026-07-19Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ As a convenience to our visitors, our Websites may include links to third-party websites, plugins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit, as the Policies and procedures we described here do not apply to those sites.</p>\r\n<p>We may also make chat rooms, forums, message boards, and news groups available to you. Please understand that any information you disclose in such areas becomes public information. We have no control over its use and encourage you to exercise caution when deciding what information to share. These sites and message boards, chat rooms and forums are not intended for, or designed to attract, individuals under the age of 18.</p>\r\n"}}" id="rich-text-b171f09224" class="cmp-text"> As a convenience to our visitors, our Websites may include links to third-party websites, plugins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit, as the Policies and procedures we described here do not apply to those sites.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ As explained above Appian sometimes provides personal information to third parties to perform services on our behalf. If we transfer personal information received under the Data Privacy Framework to a third party, the third party's access, use, and disclosure of the personal information must also be in compliance with our Data Privacy Framework obligations, and we will remain liable under the Data Privacy Framework for any failure to do so by the third party unless we prove we are not responsible for the event giving rise to the damage.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We require all third parties to whom we transfer your data to respect the security of your Personal Data and to treat it in accordance with the law. We only allow such third parties to process your Personal Data for specified purposes and in accordance with our instructions. You can ask our partners to stop sending you communications at any time by sending a message through our Privacy Portal and selecting “Other” ( https://portals.appian.com/data-privacy ).” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We share your Personal Data within our group of companies or service providers which involves transferring your data outside the European Economic Area (EEA).</p>\r\n<ul>\r\n<li>We are subject to the provisions of the General Data Protection Regulation that protects your Personal Data. Where we transfer your data to third parties outside of the EEA, we will ensure that certain safeguards are in place to ensure a similar degree of security for your Personal Data. As such:</li>\r\n<li>We may transfer your Personal Data to countries that the European Commission have approved as providing an adequate level of protection for Personal Data by; or</li>\r\n<li>We may transfer your Personal Data to affiliates or service providers who are established outside of the EEA, using Standard Contractual Clauses or certification mechanisms approved by the European Commission which give Personal Data the same protection it has in Europe.</li>\r\n</ul>\r\n<p>If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time. </p>\r\n"}}" id="rich-text-9c032321f7" class="cmp-text"> We share your Personal Data within our group of companies or service providers which involves transferring your data outside the European Economic Area (EEA).” | Captured 2026-07-19Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may have to share your Personal Data with, for example:</p>\r\n<ul>\r\n<li>Other companies in our group who provide services to us.</li>\r\n<li>Service providers who provide IT, system administration and other centralized services.</li>\r\n<li>Service providers who provide marketing, research, events planning and hosting, and data enrichment.</li>\r\n<li>Professional advisers including lawyers, bankers, auditors and insurers.</li>\r\n<li>Government bodies that require us to report processing activities, or as otherwise required by law or to respond to legal processes.</li>\r\n<li>Our partners, for the purposes of enabling our partners to contact you about our services. You can find more information about the partners that we work with <a href=\"https://appian.com/partners/partner-program/find-a-partner\" target=\"_blank\">here</a>.</li>\r\n</ul>\r\n<p>We require all third parties to whom we transfer your data to respect the security of your Personal Data and to treat it in accordance with the law. We only allow such third parties to process your Personal Data for specified purposes and in accordance with our instructions. You can ask our partners to stop sending you communications at any time by sending a message through our Privacy Portal and selecting “Other” (<a href=\"https://portals.appian.com/data-privacy\" target=\"_blank\" rel=\"noopener noreferrer\">https://portals.appian.com/data-privacy</a>).</p>\r\n"}}" id="rich-text-b6b38547ea" class="cmp-text"> We may have to share your Personal Data with, for example:” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We are subject to the provisions of the General Data Protection Regulation that protects your Personal Data. Where we transfer your data to third parties outside of the EEA, we will ensure that certain safeguards are in place to ensure a similar degree of security for your Personal Data. As such: We may transfer your Personal Data to countries that the European Commission have approved as providing an adequate level of protection for Personal Data by; or We may transfer your Personal Data to affiliates or service providers who are established outside of the EEA, using Standard Contractual Clauses or certification mechanisms approved by the European Commission which give Personal Data the same protection it has in Europe.” | Captured 2026-07-19Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Other companies in our group who provide services to us. Service providers who provide IT, system administration and other centralized services. Service providers who provide marketing, research, events planning and hosting, and data enrichment. Professional advisers including lawyers, bankers, auditors and insurers. Government bodies that require us to report processing activities, or as otherwise required by law or to respond to legal processes. Our partners, for the purposes of enabling our partners to contact you about our services. You can find more information about the partners that we work with here .” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ 9. We reserve the right to release information to the proper authorities, as a result of a violation of these Terms, our standards, or unlawful acts, if the information is subpoenaed and/or if we deem it necessary and/or appropriate. Further, you agree that Appian may, in its sole discretion, at any time terminate your access to this website and any account(s) you may have in connection with this website. Access to this website may be monitored by Appian.” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.