CopyCat procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ For customers processing Protected Health Information (PHI), CopyCat AI is HIPAA compliant and will enter into a Business Associate Agreement (BAA) as required.” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ CopyCat AI maintains SOC 2 Type II certification, demonstrating our commitment to security, availability, and confidentiality controls. Audit reports are available upon request under NDA.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We implement industry-standard technical and organizational measures to protect Customer Data, including encryption in transit and at rest, access controls, audit logging, and regular security assessments. For customers processing Protected Health Information (PHI), we enter into a Business Associate Agreement in compliance with HIPAA.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain your information for as long as necessary to provide the Services and fulfill the purposes described in this policy. Automation execution logs are retained for the duration of your subscription unless you request earlier deletion. Upon termination of your account, we will delete your data within thirty (30) days, unless retention is required by law or our contractual obligations.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Business transfers in connection with a merger, acquisition, or sale of assets, with notice to affected users” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We do not sell your personal information or Customer Data. We may share information with: Service providers who assist in operating our platform (hosting, analytics, communication tools), subject to confidentiality obligations Professional advisors (lawyers, accountants, auditors) as needed for business operations” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.