Complir procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “**Data Processor:** When you use the Complir platform as an employee, contractor, or representative of a customer organization, Complir processes personal data on behalf of that organization. In this context, the customer organization is the data controller and Complir acts as a data processor. Such processing is governed by a Data Processing Agreement between Complir and the customer.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Where personal data is transferred outside the EU/EEA, such transfers are conducted in accordance with Chapter V GDPR, including the use of the European Commission's Standard Contractual Clauses and supplementary safeguards.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “- Website and contact data is retained as long as needed to manage the relationship or request.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “- Platform account data is retained for the duration of the customer relationship.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “When personal data is no longer required, it is securely deleted or anonymized.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “- Uploaded documents and files remain on the platform until deleted by the customer.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “We retain personal data only for as long as necessary for the purposes described in this policy:” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “- Certain records, such as accounting and transaction data, are retained for a minimum of five years in accordance with applicable EU accounting and financial regulations.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “These parties act as processors or sub-processors and are bound by contractual obligations to process personal data only as instructed and to implement appropriate security measures.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Email and communication service providers” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Hosting and cloud infrastructure providers” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We may share personal data with trusted third parties that assist us in operating our services, such as:” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.