Eloquent AI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ As a company based in the United States, we may process and store your personal data in the U.S. or other countries outside of your jurisdiction, including the European Economic Area (EEA) and the United Kingdom. When we transfer personal data internationally, we ensure that appropriate safeguards are in place, in accordance with applicable data protection laws. Depending on the destination, these safeguards may include participation in the EU-U.S. Data Privacy Framework, the UK Extension to the DPF, or successor adequacy mechanisms approved by relevant authorities. These may include: Standard Contractual Clauses (SCCs) approved by the European Commission or UK Information Commissioner Data processing agreements with all relevant third-party service providers” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Where data forms part of security logs or backups, it may be retained for up to 90 days before automated deletion or anonymisation.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We regularly review and delete or anonymise personal data that is no longer needed. Where full deletion is not immediately feasible (e.g. in backups), we isolate the data and restrict access.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Client and user account data – retained while the account is active and for up to 30 days after cancellation, unless required for legal or auditing purposes Support and communications records – retained for up to 24 months to improve service and resolve issues Analytics and technical data – retained in aggregated or anonymised form, where possible, for trend analysis and platform optimisation” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including providing our services, meeting legal and regulatory requirements, resolving disputes, and enforcing our agreements.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may receive personal data from: Service providers (e.g. analytics, CRM platforms) Public sources (e.g. LinkedIn or company websites)” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If you are an authorised user of a client (e.g. your employer), certain data such as usage activity or support interactions may be shared with that client.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may disclose your data if required to comply with legal obligations, enforce our agreements, respond to lawful requests from public authorities (including to meet national security or law enforcement requirements), or protect rights and safety.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We only share your personal data when necessary and in line with this Privacy Policy. This may include sharing with:” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may share data with legal, financial, or compliance advisors where necessary for our business operations and regulatory obligations.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not sell your personal data to third parties.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ In the event of a merger, acquisition, financing, or sale of assets, your personal data may be disclosed or transferred as part of that transaction — subject to safeguards and notification where required by law. We do not sell personal data in exchange for monetary consideration. We do not share it with third parties for their own marketing purposes. Any such transfer will occur under confidentiality obligations and safeguards consistent with this Privacy Policy and applicable data protection laws.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We use trusted third-party providers to support our operations — including infrastructure hosting, analytics, customer support tools, communication platforms, and CRM systems. These providers are contractually bound to protect your data and may only use it to perform services on our behalf.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.