Cuckoo Labs procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Cuckoo complies with EU-U.S. and Swiss-U.S. Privacy Shield Frameworks set by the U.S. Department of Commerce regarding Personal Data transfer from the EU, United Kingdom, EEA, and Switzerland to the United States. The company has certified adherence to Privacy Shield Principles, including Supplemental Principles. Conflicts between this Policy and the Privacy Shield Principles are resolved in favor of the Principles. 12.a. Accountability for Onward Transfer Cuckoo is responsible for processing Personal Data received under Privacy Shield Frameworks and subsequent third-party transfers. The company complies with onward transfer principles including liability provisions. Personal Data may be disclosed responding to lawful public authority requests, national security, law enforcement, or legal compliance requirements. 12.b. Security The company uses reasonable and appropriate physical, electronic, and administrative safeguards to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, and destruction, taking into account the nature of the Personal Data and risks involved in processing that information. 12.c. Data Integrity and Purpose Limitation Cuckoo collects only Personal Data relevant to Services provision and processes it compatibly with Services or authorization. The company takes reasonable steps ensuring data reliability, accuracy, completeness, and currency, adhering to Privacy Shield Principles throughout retention. ” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ 12.d. Access to Personal Data Users wishing to review, correct, delete, or update previously disclosed Personal Data should email legal@cuckoo.so. Access may be limited or denied where unreasonably burdensome or expensive. Customers receive assistance responding to EU/EEA, United Kingdom, and Swiss individuals exercising Privacy Shield rights. Subscribers should contact their Customer directly regarding access or disclosure limitation requests. 12.e. Recourse, Enforcement, and Dispute Resolution EU/EEA, United Kingdom, or Swiss individuals with Privacy Shield compliance questions or complaints may email legal@cuckoo.so. If unresolved, contact JAMS, an independent U.S.-based dispute resolution provider. Binding arbitration may be available for unresolved complaints. Cuckoo is subject to Federal Trade Commission investigatory and enforcement powers. 12.f. Data Processing Agreement Cuckoo offers Data Processing Agreements for Customers processing EU/EEA and Swiss individual data. Request via legal@cuckoo.so. 12.g. Notice and Choice The types of Personal Data we collect are described in Section 2 The purposes for which we collect and use Personal Data are described in Sections 3 and 4 The choices we offer individuals for limiting use and disclosure are described in Section 5” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ The company will retain Personal Data for the period necessary to fulfill Policy purposes unless longer retention is required or allowed by law.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Third parties as we believe necessary or appropriate under applicable law, including to comply with legal process, respond to government authorities, enforce agreements, protect operations, protect rights, privacy, safety, or property, and pursue available remedies We will never sell, rent, or lease your Personal Data to a third party. 4.b. Non-Personal Data The company may disclose Non-Personal Data for any purpose, as it does not and cannot identify individual persons.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ 4.a. Personal Data The company may disclose Personal Data to: Service Providers and others who help with our business operations, including application development, hosting, maintenance, data analysis, infrastructure, IT services, customer service, email delivery, payment processing, marketing, analytics, and agreement enforcement Third parties in the event of a reorganization, merger, sale, asset financing, joint venture, assignment, transfer, or business disposition (including insolvency, bankruptcy, or receivership)” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ 6.a. Our Relationship with Subscribers Customers may import Personal Data collected from Subscribers or other individuals. Cuckoo has no direct relationship with Subscribers or non-Customer individuals. Customers are responsible for ensuring necessary permissions for data collection, storage, and processing. Subscribers should unsubscribe directly from Customer newsletters or contact Customers to modify data. Subscriber inquiries are referred to their respective Customers. 6.b. Use and Transfer of Data Personal Data may be transferred to entities helping promote, provide, or support Services (“Service Providers”). All Service Providers agree to protect Personal Data per this Privacy Policy. The company will never sell, rent, or lease Customer Distribution Lists.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Other users of the Services to identify you to anyone to whom you send messages or comments Persons or entities with whom you consent to have your Personal Data shared Third parties in order to prevent damage to our property, for safety reasons, or to collect amounts owed to us” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.