Skip to main content
Platform Review
PricingSign in
Balance assessment

Balance procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Balance
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown Denmark: Datatilsynet (Danish Data Protection Agency) — datatilsynet.dkCaptured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Balance Technologies, Inc. is incorporated in the United States. However, all primary data storage (databases and document storage) is hosted within the European Economic Area (EU, Amsterdam region). Customer data at rest remains within the EEA. Limited transfers of personal data to the United States occur in the following circumstances: AI processing: when documents are analysed by our AI providers, data is transmitted to US-based API servers for processing. These providers operate under zero data retention (ZDR) agreements — no customer data is stored after the API call completes.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Right to restrict processing: request limitation of how we use your data.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown AI agent execution: our AI assistant (Bea) runs tasks in isolated cloud sandboxes provided by E2B (FoundryLabs, Inc.), which may be hosted in the United States. Sandboxes are ephemeral and destroyed after each task.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown If you have questions about this Privacy Policy or our data protection practices: Email: privacy@getbalance.aiCaptured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Right to erasure: request deletion of your data (subject to legal obligations).Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority: United Kingdom: Information Commissioner's Office (ICO) — ico.org.ukCaptured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Right to object: object to processing based on legitimate interests.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Under the UK GDPR and EU GDPR, you have the following rights: Right of access: request a copy of the personal data we hold about you.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown To exercise any of these rights, contact us at privacy@getbalance.ai. We will respond within one month as required by law. If we process your data as a Processor on behalf of one of our customers, we will direct your request to the relevant Controller. . How We Protect Your DataCaptured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Authentication: Firebase Authentication (Google) processes login credentials, which may transit US infrastructure.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Right to rectification: request correction of inaccurate data.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown We encourage you to contact us first at privacy@getbalance.ai so we can attempt to resolve your concern. . Contact UsCaptured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. The effective date at the top of this policy indicates when it was last revised. . ComplaintsCaptured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown AI processing logs: 12 months, with automated deletion.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersmedium We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown Financial documents and transaction data: retained as directed by the customer (Controller) under the DPA, or for a default period of 7 years for tax/regulatory compliance.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We share personal data with third-party service providers (sub-processors) who assist us in delivering the Service. A complete list of our sub-processors is maintained separately and available upon request. Key categories include: Cloud infrastructure providers (hosting, storage, databases).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Accounting software providers (integration partners such as E-conomic, Xero, and QuickBooks).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown For all transfers to the United States, we ensure appropriate safeguards are in place, including: Standard Contractual Clauses (SCCs) approved by the European Commission.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Communication providers (Slack, email, WhatsApp for notifications).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Where applicable, participation in the EU-US Data Privacy Framework.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown When we process financial data on behalf of our customers (such as bank transactions, receipts, and invoices belonging to their clients), we act as a Data Processor. In that case, our customer is the Data Controller, and processing is governed by our Data Processing Agreement (DPA).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Authentication providers (identity verification).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown AI providers (document analysis, categorisation).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow We do not sell personal data to third parties. We do not share personal data for advertising purposes.Captured 2026-07-19Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.