Deepgram procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “We process, retain, use, and disclose personal information only as necessary to provide the Services. In other words, we use the Customer Data strictly for business purposes (as defined by the CCPA). We enter into data processing agreements with our customers which set out our obligations under the CCPA, which includes forwarding our customers any end user individual rights requests and providing reasonable and timely assistance to our customers in complying with our customer’s obligations with respect to consumer access and deletion requests under the CCPA.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In providing our Service, our customers may upload data to our Service, or we may collect data on their behalf, which may include personal information or data about our customers’ end users (“ Customer Data ”). We collect and process Customer Data as needed to provide our Services to our customers in accordance with our customer agreements. This Privacy Notice does not apply to the processing of Customer Data. European Economic Area, United Kingdom or Switzerland Customers: Deepgram acts as a data “processor” for purposes of Regulation (EU) 2016/679 (the “ EU GDPR “) or, where applicable, the “ UK GDPR ” as defined in the UK Data Protection Act (collectively “ GDPR ”). As such, our customers act as data “controllers” in relation to the data processed by Deepgram in the performance of the Services. We process Customer Data solely on behalf of, and as directed by, our customers. We enter into data processing agreements with our customers which set out our obligations under the GDPR, including to direct any end user individual rights requests to our customers. In addition, we frequently enter into the EU Commission’s Standard Contractual Clauses with our customers in order to legitimize the transfer of Customer Data outside of the European Economic Area, United Kingdom or Switzerland to the US. California (United States) Customers: For purposes of the California Consumer Privacy Act (“ CCPA ”), in the same way as we act as a data “processor” for GDPR purposes, Deepgram acts as a “service provider” in relation to the Customer Data we process in the performance of the Services. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | Enterprise | low | “For purposes of the California Consumer Privacy Act (“ CCPA ”), in the same way as we act as a data “processor” for GDPR purposes, Deepgram acts as a “service provider” in relation to the Customer Data we process in the performance of the Services. We process, retain, use, and disclose personal information only as necessary to provide the Services. In other words, we use the Customer Data strictly for business purposes (as defined by the CCPA). We enter into data processing agreements with our customers which set out our obligations under the CCPA, which includes forwarding our customers any end user individual rights requests and providing reasonable and timely assistance to our customers in complying with our customer’s obligations with respect to consumer access and deletion requests under the CCPA.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | Enterprise | low | “Deepgram acts as a data “processor” for purposes of Regulation (EU) 2016/679 (the “ EU GDPR “) or, where applicable, the “ UK GDPR ” as defined in the UK Data Protection Act (collectively “ GDPR ”). As such, our customers act as data “controllers” in relation to the data processed by Deepgram in the performance of the Services. We process Customer Data solely on behalf of, and as directed by, our customers. We enter into data processing agreements with our customers which set out our obligations under the GDPR, including to direct any end user individual rights requests to our customers. In addition, we frequently enter into the EU Commission’s Standard Contractual Clauses with our customers in order to legitimize the transfer of Customer Data outside of the European Economic Area, United Kingdom or Switzerland to the US.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ 9. Data Retention” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We will retain your personal information for the length of time needed to fulfill our business purposes unless otherwise required or permitted by law. Any Customer Data that we have access to shall be retained, stored, and deleted according to our agreement with our business customer. We store data on servers in the U.S.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share with other companies and brands owned or controlled by Deepgram, and other companies owned by or under common ownership as Deepgram. These companies will use your personal information in the same way as we can under this Privacy Notice; We may transfer any information we collect in the event we sell or transfer all or a portion of our business or assets (including any shares in the company) or any portion or combination of our products, services, businesses and/or assets. Should such a transaction occur (whether a divestiture, merger, acquisition, bankruptcy, dissolution, reorganization, liquidation, or similar transaction or proceeding), we will use reasonable efforts to ensure that any transferred information is treated in a manner consistent with this Privacy Notice. With other third parties, with your consent or at your direction, including as part of collaborations you choose to engage in through the Service. If you provided a testimonial, including as part of a customer satisfaction survey, with your consent, we may post your testimonial on our Site. The testimonial, including your name, will be posted publicly and visible to any visitor of our Site. With others in an aggregated or otherwise anonymized form that does not reasonably identify you directly as an individual.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ with third parties. ” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ To view our current subprocessor list, please click HERE . This list may change over time.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We may transfer any information we collect in the event we sell or transfer all or a portion of our business or assets (including any shares in the company) or any portion or combination of our products, services, businesses and/or assets. Should such a transaction occur (whether a divestiture, merger, acquisition, bankruptcy, dissolution, reorganization, liquidation, or similar transaction or proceeding), we will use reasonable efforts to ensure that any transferred information is treated in a manner consistent with this Privacy Notice.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year. To opt out of having your information shared in this manner, please email us at security@deepgram.com .” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ 4. How We Share Personal Information” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ 2. Subprocessor List” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may receive personal information about you from our business partners and service providers and combine this information with other data we collect from you. The third parties may include website and service operators, payment processors, marketing partners, and shipping providers. The information may include contact information, demographic information, information about your communications and related activities, and information about your orders. We may use this information to administer and facilitate our services, your orders, and our marketing activities. Single Sign-On. We may use single sign-on (“ SSO “) to allow a user to authenticate their account using one set of login information, including through Google and GitHub. We will have access to certain information from those third parties in accordance with the authorization procedures determined by those third parties, which may include , for example, your name, username, email address, language preference, and profile picture. We use this information to operate, maintain, and provide to you the features and functionality of the Service. We may also send you service-related emails or messages (e.g., account verification, purchase confirmation, customer support, changes, or updates to features of the Site, technical and security notices). Social Media. When you interact with our Site through various social media, such as when you click on the social media icon on the Site, follow us on a social media Site, or post a comment to one of our pages, we may receive information from the social network such as your profile information, profile picture, gender, username, user ID associated with your social media account, age range, language, country, and any other information you permit the social network to share” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.