Crimson procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Under applicable data protection laws, you have the following rights: Access: Request access to the personal data we hold about you. Correction: Request corrections to inaccurate or incomplete data. Erasure: Request the deletion of your data, subject to legal retention requirements. Restriction: Request limits on how we process your data. Portability: Request a copy of your data in a machine-readable format. Objection: Object to certain data processing activities, including marketing. Withdraw consent: Where processing is based on your consent, you can withdraw it at any time. To exercise your rights, contact us at privacy@crimson.law . If you believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority. For UK residents, this is the Information Commissioner's Office (ICO).” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain your data only as long as necessary to fulfil the purposes outlined in this policy or comply with legal obligations.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not sell your information. We only share it in the following circumstances: Service providers: With trusted vendors who assist with hosting, analytics, payment processing or marketing. Legal compliance: When required by law, regulation or court order. Business transfers: In connection with a merger, acquisition or sale of assets, subject to confidentiality obligations. With your consent: In specific instances where you have agreed to data sharing. Where data is transferred outside the EEA/UK, Crimson ensures that appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions in line with GDPR.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.