Capitol AI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ If you are a Company (or its authorized representative) and would like to correct or update certain personal information (such as your or an Authorized Users’ contact information) please contact us at security@capitol.ai and we will use reasonable efforts to correct and/or update such information. If you are an Authorized User, you must contact the Company to request corrections or updates to personal information of yours we may process on behalf of the Company.” | Captured 2026-09-24Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ The Capitol Services and servers are operated in the United States. If you are located outside of the United States, please be aware that your information, including your personal data, may be transferred to, processed, maintained, and used on computers, servers, and systems located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. If you are located outside the United States and choose to use the Capitol Services, you hereby irrevocably and unconditionally consent to such transfer, processing, and use in the United States and elsewhere.” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Personal information is processed for the period necessary to fulfill the purposes for which it is collected (for example, in connection with the Capitol Services provided to Company pursuant to the Agreement), to comply with legal and regulatory obligations and for the duration of any period necessary to establish, exercise or defend any legal rights. In order to determine the most appropriate retention periods for your personal information, we consider the amount, nature and sensitivity of your information, the reasons for which we collect and process your personal information, and applicable legal requirements. In some instances, we may choose to anonymize personal information instead of deleting it, for statistical use, for instance. When we choose to anonymize, we make sure that there is no way that the personal information can be linked back to any specific individual. If you are an Authorized User, contact the applicable Company if you wish to request the removal of personal information under their control.” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “All provisions of this Agreement which by their nature should survive termination shall survive termination, including, without limitation, accrued payment obligations, ownership provisions, warranty disclaimers, indemnity and limitations of liability. For clarity, any services provided by Capitol to Customer, including any assistance in exporting the Customer Data, shall be billable at Capitol’s standard rates then in effect.” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Perform other similar functions. We may use third party tools and technologies to help us gather this information discussed above. For instance, we use products provided by Google, Inc., which includes Google Analytics to collect and process certain analytics data with technologies such as tracking pixels. Google provides some additional privacy options described at www.google.com/policies/privacy/partners/ with respect to Google Analytics cookies. To opt out from Google Analytics, you can download a plug-in from http://tools.google.com/dlpage/gaoptout. We also use Cloud Flare and Amazon Web Services to provide secure websites, APIs, and applications in the deployment and hosting of our software. 3.c Information Collected from Third Parties In some instances, we process personal information from third parties other than from you directly, which consists of: Data from our partners, such as transactional data from providers of payment services or location data from Google Maps; Data from the Company who authorize you to access and use the Capitol Services as an Authorized User; Data submitted by the applicable Company and/or Authorized Users; In addition, we may collect certain information from third party databases to provide the Capitol services that does not identify any person or individual, for example, national databases of speed limits; however, if we combine or connect such information with personal data so that it can directly or indirectly identify you, we treat the combined data as personal data, which will be processed in accordance with this Privacy Notice. ” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ For a list of all third-party service providers we use, please contact us. We require all third parties to respect the security of personal information and to treat it in accordance with the law. We do not allow our third-party service providers to use personal information for their own purposes and only permit them to process personal information for specified purposes and in accordance with our instructions, unless the data is rendered fully anonymous. 5.c Business Transfers We may also share data with third parties to whom we choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use personal information in the same way as set out in this Privacy Notice. 5.d Affiliates and Subsidiaries Personal information that we collected through the Capitol Services may be shared with the employees, contractors, and agents of Capitol and our affiliated and subsidiary entities (“ Affiliates”) who are involved in providing or improving the Capitol Services. We obligate the employees, contractors and agents of Capitol and our Affiliates to ensure the security and confidentiality of personal information and to act on that personal information only in a manner consistent with this Privacy Notice. 5.e Legal Obligations and Security If we are required to disclose personal information by law, such as pursuant to a subpoena, warrant or other judicial or administrative order, our policy is to respond to requests that are properly issued by law enforcement within the United States. ” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “Neither party may assign any of its rights or obligations hereunder without the other party’s consent; provided that (i) either party may assign all of its rights and obligations hereunder without such consent to a successor-in-interest in connection with a sale of substantially all of such party’s business relating to this Agreement, and (ii) Capitol may utilize subcontractors in the performance of its obligations hereunder. Customer agrees that Capitol may use Customer’s name and logo to refer to Customer as a customer of Capitol on its website and in marketing materials. No agency, partnership, joint venture, or employment relationship is created as a result of this Agreement and neither party has any authority of any kind to bind the other in any respect. In any action or proceeding to enforce rights under this Agreement, the prevailing party shall be entitled to recover costs and attorneys’ fees. If any provision of this Agreement is held to be unenforceable for any reason, such provision shall be reformed only to the extent necessary to make it enforceable. The failure of either party to act with respect to a breach of this Agreement by the other party shall not constitute a waiver and shall not limit such party’s rights with respect to such breach or any subsequent breaches.” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We do not directly collect or store any payment information. We use third-party, PCI-compliant, payment processors, which collect payment information on our behalf in order to complete transactions. Our administrators are only able to view limited transaction information via our payment processors’ portals.” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “Under such circumstances, unless prohibited by applicable law, we will attempt to provide the Company with prior notice that a request for personal information has been made. We will attempt to provide this notice by email, if the Company has given us an email address. However, government requests may include a court-granted non-disclosure order, which prohibits us from giving notice to the affected individual. In cases where we receive a non-disclosure order, we will notify the Company when it has expired or once we are authorized to do so. Note that if we receive information that provides us with a good faith belief that there is an exigent emergency involving the danger of death or serious physical injury to a person, we may provide information to law enforcement trying to prevent or mitigate the danger (if we have it), to be determined on a case-by-case basis. If you are an Authorized User, please consult with your Company to learn more about how your Company responds to requests for information pursuant to legal orders.” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Aside from disclosing personal information to those of our personnel who are authorized to process the information in order to provide the Capitol Services and who are committed to confidentiality, we disclose personal information only to the third parties as described below. 5.a Companies We will share and disclose personal information of Authorized Users with the Company. In addition, we will share and disclose personal information of Authorized Users in accordance with the Company’s instructions, including any applicable terms in the Agreement, and in compliance with applicable law and legal process. If you are an Authorized User, please consult with the Company to learn more about how your information may be used, shared and/or disclosed by us and the Company. 5.b Third-Party Service Providers We share personal information with third parties that provide services to help us provide the Capitol Services, and to otherwise operate our business. The following categories of third parties collect data on our behalf or receive personal information: Hosting services providers; Analytics providers; Payment service providers; Providers of business operations and communication tools; Other third-party service providers that help us provide features and functions for the Capitol Services (e.g., customer support providers); and Professional service providers, such as auditors, lawyers, consultants, accountants and insurers. ” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Third Party Integrations. Customer acknowledges and agrees that (i) the Service may operate on, with or using application programming interfaces (APIs) and/or other services operated or provided by third parties (e.g., other vendors of Customer) (“Third Party Integrations”), (ii) the availability and operation of the Service or certain portions thereof may be dependent on Capitol’s ability to access such Third Party Integrations, and (iii) Customer’s failure to provide adequate access or any retraction of permissions relating to such Third Party Integrations may result in a suspension or interruption of the Service. Customer hereby represents and warrants that it has all rights, licenses, permissions and consents necessary to connect, use and access any Third Party Integrations that it integrates with the Service, and Customer shall indemnify, defend and hold harmless the Capitol for all claims, damages and liabilities arising out of Customer’s use of any Third Party Integrations in connection with or through the Service. Capitol cannot and does not guarantee that the Service shall incorporate (or continue to incorporate) any particular Third Party Integrations and does not make any representations or warranties with respect to Third Party Integrations. Customer is solely responsible for procuring any and all rights necessary for it to access Third Party Integrations (including any Customer Data or other information relating thereto) and for complying with any applicable terms or conditions thereof. Any exchange of data or other interaction between Customer and a third party provider is solely between Customer and such third party provider and is governed by such third party’s terms and conditions.” | Captured 2026-09-24Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.