Clarm procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ Clarm is based in the United States and may process Personal Data in the United States, the European Economic Area, the United Kingdom, Switzerland, and other countries where we or our service providers operate. When Personal Data is transferred from the EEA, United Kingdom, or Switzerland to a country that has not been found to provide an adequate level of protection, we use appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, transfer-impact assessments where required, and technical and organizational measures designed to protect the data.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We will only retain your Personal Data for as long as necessary for the purpose for which that data was collected and to the extent required by applicable law. When we no longer need Personal Data, we will remove it from our systems and/or take steps to anonymize it. Retention periods vary by category. Account and billing records are retained while your account is active and as needed for tax, accounting, dispute, and legal requirements. Security logs and audit records are retained as needed to protect the service and preserve evidence. Website and widget analytics are retained according to the workspace configuration and our documented retention schedules, unless a longer period is required for security, legal, or fraud-prevention reasons.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may disclose Personal Data to the following categories of recipients: Hosting, infrastructure, database, storage, monitoring, logging, and security providers. Payment, billing, tax, accounting, and customer-support providers. Analytics and website-intelligence providers, including PostHog, Cloudflare Web Analytics, and RB2B where enabled. Enrichment providers used for company-level visitor intelligence, such as People Data Labs, Clearbit, 6sense, IPinfo, or similar services where configured. Customer-configured destinations, including Slack, HubSpot, webhooks, email providers, CRMs, and connected knowledge or workflow systems. Professional advisors, authorities, or third parties when required by law, to protect rights and security, or in connection with a corporate transaction. We require service providers and processors to protect Personal Data and process it only for the purposes we authorize or the customer instructs, as applicable.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.