Skip to main content
Platform Review
PricingSign in
Databricks (DBRX / Foundation) assessment

Databricks (DBRX / Foundation) procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Databricks (DBRX / Foundation)
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslowDatabricks complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Databricks has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Databricks complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Databricks has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Databricks has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. The following Databricks entities are covered by the DPF certification: Databricks, Inc., Neon, LLC. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/. To learn more, visit our Data Privacy Framework Notice here .Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Databricks may transfer your personal information to countries other than your country of residence. In particular, we may transfer your personal information to the United States and other countries where our affiliates, business partners and services providers are located. These countries may have different data protection laws to the country where you reside. Wherever we process your personal information, we take appropriate steps to ensure it is protected in accordance with this Privacy Notice and applicable data protection laws. The safeguards we use include implementing the European Commission’s Standard Contractual Clauses for transfers of personal information from the EEA or Switzerland between us and our business partners and service providers, and equivalent measures for transfers of personal information from the United Kingdom and other global jurisdictions with similar transfer requirements. Databricks also offers our Customers the ability to enter into a data processing addendum (DPA) that contains standard contractual clauses, for transfers between us and our Customers. We also make use of supplementary measures to ensure your information is adequately protected.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmediumDatabricks may transfer your personal information to countries other than your country of residence. In particular, we may transfer your personal information to the United States and other countries where our affiliates, business partners and services providers are located. These countries may have different data protection laws to the country where you reside.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyEnterpriselowDatabricks also offers our Customers the ability to enter into a data processing addendum (DPA) that contains standard contractual clauses, for transfers between us and our Customers.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmediumDatabricks retains the personal information described in this Privacy Notice for as long as you use our Services, as may be required by law (for example, to comply with applicable legal tax or accounting requirements), as necessary for other legitimate business or commercial purposes described in this Privacy Notice (for example, to resolve disputes or enforce our agreements), or as otherwise communicated to you. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium when authorized by law or we deem necessary in good faith to comply with legal process; when required to protect and defend the rights or property of Databricks or our Customers, including the security of our Sites, products and services (including the Platform Services); or when necessary to protect the personal safety, property or other rights of the public, Databricks or our Customers; With your consent: when you instruct us to do so or where you have consented to the disclosure of your information with third parties; or Business Transactions: we may engage in transactions with other companies involving the sale of assets or parts of our business. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Legal and Security Purposes to investigate security issues, prevent fraud, or combat the illegal or controlled uses of our products and services, including within our learning and certification programs; to comply with our obligations under applicable law, legal process, or government regulation;Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Our Services may contain links to third-party websites, applications, services, or social networks (including co-branded websites or products that are maintained by one of our business partners). We may also make available certain features that allow you to sign into our Sites using third-party login credentials (such as LinkedIn, Facebook, Twitter and Google+) or access third-party services from our Platform Services (such as Github). Any information that you choose to submit to third-party services is not covered by this Privacy Notice. We encourage you to read the terms of use and privacy notices of use of such third-party services before disclosing your information with them to understand how your information may be collected and used.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmediumWe may disclose your information as part of, or in contemplation of, such transactions. If a portion of or all of our assets are transferred to a third party in connection with such transactions, your information may be among the transferred assets, including in the course of activities leading up to such transactions (e.g., transaction diligence).Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmediumBusiness Transactions: we may engage in transactions with other companies involving the sale of assets or parts of our business. We may disclose your information as part of, or in contemplation of, such transactions. If a portion of or all of our assets are transferred to a third party in connection with such transactions, your information may be among the transferred assets, including in the course of activities leading up to such transactions (e.g., transaction diligence).Captured 2026-06-07Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.