Cignara procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ • Contractual necessity — to provide the Service you have requested or that your organization has signed up for. • Legitimate interests — to operate, secure, and improve the Service, to communicate about our products, and to prevent fraud, provided those interests are not overridden by your rights and freedoms. • Consent — where you have given us specific consent, for example, for certain marketing communications or cookies. You may withdraw consent at any time. • Legal obligation — to comply with applicable laws and lawful requests. ” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process personal information on the following legal bases under the EU/UK GDPR:” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cignara is headquartered in the United States, and the Service may be operated from data-center regions in the United States and other jurisdictions. When we transfer personal information across borders, we rely on appropriate safeguards as required by applicable law, including European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms. Where customers select a specific region for their deployment under a separate written agreement, we process customer conversation data within that region as agreed.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We retain personal information for as long as needed to fulfill the purposes described in this Policy, to comply with our legal, accounting, or reporting obligations, to resolve disputes, and to enforce our agreements. When personal information is no longer required, we delete or anonymize it in accordance with our retention schedule. For customer conversation data processed on behalf of a customer, retention is governed by the customer's own retention settings and the contract between us, including any data processing addendum.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ 2.3 Information from other sources. We may receive information about you from:” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We share personal information only as described below. 6.1 Service vendors and sub-processors. We rely on a limited number of trusted vendors who help us operate the Service, including cloud-infrastructure providers, communications vendors, model and speech vendors, analytics and customer-support tools, billing vendors, and security and compliance vendors. These vendors are contractually bound to use personal information only to perform services for us and to maintain appropriate security and confidentiality. A current list of material sub-processors used for the production Service can be made available to customers on request to compliance@cignara.com . We provide customers with notice of changes to our sub-processor list as required under the relevant data processing agreement. 6.2 Legal compliance and protection. We may disclose personal information when we believe in good faith that disclosure is required:” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ 6.3 Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will require the receiving entity to honor this Policy with respect to information transferred to it. 6.4 With your consent. We may share personal information for any other purpose disclosed to you at the time of collection or with your consent. We do not sell or "share" personal information for cross-context behavioral advertising as defined under California law.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ (a) to comply with applicable law, legal process, or lawful government requests; (b) to enforce our Terms of Use and other agreements; (c) to detect, prevent, or address fraud, security, compliance, or technical issues; or (d) to protect the rights, property, or safety of Cignara, our customers, our employees, or the public. ” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ • Service vendors who help us deliver the Service (for example, cloud-infrastructure providers, communications vendors, and analytics or marketing partners). • Publicly available sources, including business directories and social-media profiles you have made public. • Customers or partners that refer you to us. ” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.