Dench.com procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ The hosted Services run in the United States (AWS US East, Northern Virginia / us-east-1) . Customer Data at rest is stored in the United States, and our subprocessors that handle Customer Data are based in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your home country. Where we transfer personal data that is protected by the laws of the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized transfer mechanisms such as the EU, UK, and Swiss Standard Contractual Clauses, and applicable Data Privacy Framework certifications, as further described in our Data Processing Addendum .” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights over personal data we hold about you as a controller, subject to conditions and exceptions in applicable law: Access to, and a copy of, your personal data. Correction of inaccurate or incomplete data. Erasure of your data in certain circumstances. Restriction of, or objection to, certain processing. Data portability. Withdrawal of consent at any time, where processing is based on consent. The right to lodge a complaint with your local supervisory authority. To exercise these rights, contact privacy@dench.com . Where the data is Customer Data we process on behalf of an organization, we will refer your request to that organization.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We keep information for as long as needed to provide the Services, maintain security and billing records, resolve disputes, and meet legal obligations. Account, organization, authentication, and billing records are retained while your account is active and for a reasonable period afterward. Analytics and operational logs are retained for debugging, abuse prevention, financial reconciliation, and product improvement. For managed cloud workspaces, our current operational lifecycle may include stopping a canceled workspace, retaining the stopped environment for roughly 7 days, and retaining final recovery snapshots for up to roughly 90 days before final deletion. We may adjust these windows as the Services evolve or where law, security, or disaster recovery requires it. You are responsible for exporting any data you want to keep before cancellation or termination.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or complete a business transaction. We use vetted third-party providers (subprocessors) for hosting, AI inference, billing, email, analytics, sign-in, integrations, and messaging. Each is bound by data protection terms no less protective than ours. The current list, with each provider's purpose, location, and transfer mechanism, is maintained on our Subprocessors page . We may also disclose information to professional advisors, and to an acquirer or successor in connection with a merger, acquisition, financing, or sale of assets, and to regulators or authorities where required by law or to protect rights, safety, and security. Your use of third-party integrations you connect is also subject to those providers' own terms and privacy practices.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Privacy law treats us differently depending on whose data is involved, so it helps to separate two roles: Dench as a processor / service provider. For the CRM records, contacts, files, messages, prompts, and other content that a customer organization puts into the Services ("Customer Data"), the customer is the controller and decides what to collect and why. We process Customer Data only to provide the Services, on the customer's instructions, as described in our Data Processing Addendum . If you are an individual whose information appears in a customer's workspace, please direct privacy requests to that organization. Dench as a controller. For the account, billing, usage, device, support, and website-visitor data we collect to run and improve our business, we act as the controller. The rest of this Policy focuses on that controller role.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.