Skip to main content
Platform Review
PricingSign in
Doe assessment

Doe procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Doe
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown 9.3 Supplementary Measures. Where required by applicable data protection law, Doe Labs implements supplementary technical and organizational measures (TOMs) to ensure an essentially equivalent level of protection for transferred Personal Information, consistent with the recommendations issued by the European Data Protection Board.Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.1 DPA Availability. Enterprise customers who execute a Doe Labs Pilot Master Services Agreement receive a Data Processing Addendum (“DPA”) as Exhibit B to that agreement. The DPA governs the processing of Personal Data by Doe Labs as data processor on behalf of Customer, and incorporates applicable Standard Contractual Clauses for cross-border transfers. Enterprise customers without an executed Master Services Agreement may request a standalone DPA by contacting legal@doe.so .Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown 9.1 Primary Processing Location. Doe Labs’ primary data processing infrastructure is located in the United States. Enterprise customers contracting with Doe Labs from outside the United States should be aware that their information may be transferred to, stored, and processed in the United States.Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown 7.2 SOC 2 Type II. Doe Labs maintains SOC 2 Type II certification, evidencing our compliance with the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. A copy of our current SOC 2 Type II report is available to enterprise customers under NDA upon request.Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.2 Standard Contractual Clauses. The DPA (Exhibit B of the Pilot Master Services Agreement) includes the EU Standard Contractual Clauses (Module 2: Controller-to-Processor), as adopted by the European Commission, as well as the UK International Data Transfer Agreement (IDTA), as applicable. These mechanisms govern cross-border transfers of Personal Data from the EEA, UK, and Switzerland to the United States.Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 9.2 Transfer Mechanisms. For transfers of Personal Information from the EEA, UK, or Switzerland to the United States, Doe Labs relies on: (a) the EU Standard Contractual Clauses (SCCs) as adopted by the European Commission; (b) the UK International Data Transfer Agreement (IDTA) as applicable; and (c) other legally recognized transfer mechanisms. Enterprise customers requiring a Data Processing Addendum incorporating SCCs should contact legal@doe.so .Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown 6.1 Retention Periods. We retain Customer Data for the duration of the active enterprise agreement plus thirty (30) days following termination or expiration, unless a longer retention period is required by law or agreed in writing. Following the retention period, Customer Data is securely deleted or anonymized.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown 6.3 Usage Data. Aggregated and de-identified Usage Data may be retained for longer periods for analytics, product development, and business purposes. This data is not associated with individual users or enterprise accounts.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown 15.2 Prior Versions. Prior versions of this Policy will be archived and available upon request.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown 7.4 Effect of Termination. Upon any termination or expiration: (a) all rights and licenses granted to Customer will immediately terminate; (b) Doe Labs will make Customer Data available to Customer for electronic retrieval for a period of thirty (30) days following termination; (c) Customer will remain liable for all Fees accrued through the last day on which the Services were provided; and (d) sections which by their nature should survive termination shall survive, including accrued rights to payment, confidentiality obligations, warranty disclaimers, and limitations of liability.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown 6.4 Deletion Requests. Enterprise customers may request deletion of Customer Data prior to the end of the standard retention period by submitting a written request to legal@doe.so . We will complete deletion within thirty (30) days of receiving a verified request, subject to legal hold obligations.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown 6.2 Account Information. We retain account registration and billing information for the period required by applicable tax and accounting laws, typically seven (7) years following the end of the business relationship.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium 5.6 With Consent. We may share information with third parties when you have provided explicit consent or instructed us to do so.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 5.1 No Sale of Personal Information. Doe Labs does not sell Personal Information to third parties for monetary or other valuable consideration, consistent with the definition of “sale” under the CCPA.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium 5.3 Subprocessors. A current list of our subprocessors is available upon request at legal@doe.so . We will provide at least thirty (30) days’ advance notice of material changes to our subprocessor list, allowing enterprise customers to raise objections in accordance with any applicable Data Processing Addendum.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 12.3 CCPA Service Provider. For purposes of the CCPA, Doe Labs acts as a “service provider” with respect to Personal Information processed on behalf of enterprise customers. Doe Labs does not sell or share such Personal Information for cross-context behavioral advertising.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown 11.3 AI Data Usage Restrictions. Doe Labs does not: (a) use Customer Data to train general-purpose AI models for use with other customers; (b) share Customer Data with third-party AI model providers beyond what is necessary to deliver the Services; or (c) retain AI interaction data for longer than necessary to provide the requested service, unless required by law or agreed otherwise. Any AI model fine-tuning that uses Customer Data requires explicit written consent.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown 5.5 Legal Requirements. We may disclose information if we believe disclosure is required by applicable law, regulation, legal process, or government request, or to protect the safety, rights, or property of Doe Labs, our users, or the public. Where permitted, we will notify affected enterprise customers prior to disclosure.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium 5.2 Service Providers. We engage trusted third-party vendors to perform services on our behalf, including cloud hosting (e.g., AWS, GCP), payment processing, customer support software, analytics tools, and security services. These vendors are contractually bound to process data only as directed by Doe Labs and to maintain appropriate security measures.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown 5.4 Business Transfers. If Doe Labs is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, information may be transferred as part of that transaction. We will provide notice before Personal Information is transferred and becomes subject to a different privacy policy.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown 11.2 Privacy Policy. Doe Labs will process Customer Data in accordance with its Privacy Policy and the Data Processing Addendum (Exhibit B of any applicable Master Services Agreement). For customers without an executed MSA, Doe Labs offers a standalone Data Processing Addendum upon request at legal@doe.so .Captured 2026-07-20Open source →Finding permalink →
Tier differencesAll applicable tiersmedium Enterprise customers may also request our Data Protection Officer contact information.Captured 2026-07-20Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.