Fabraix procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “**Europe, the UK, and Switzerland (GDPR).** Where it applies, we process personal data based on contractual necessity, our legitimate interests in running and securing the Services, your consent, or legal obligations. You may also complain to your local data protection authority.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “**California (CCPA/CPRA).** You can ask what we collect, request correction or deletion, and opt out of any "sale" or "sharing" of personal information. We do not sell your data and will not treat you differently for exercising these rights.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “We operate internationally, so your information may be processed in countries other than the one you live in. When the law requires it, we put appropriate safeguards in place (such as Standard Contractual Clauses) to protect data moved across borders.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “We hold personal information only as long as it serves the purposes in this policy or as the law requires for legal, accounting, or security reasons. Account information lasts for the life of your account. Customer Data and testing inputs follow the terms of your agreement with us; without a specific agreement, we keep them only as long as needed to run and support the Services, then securely delete or anonymize them.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- **In a corporate transaction**, such as a merger, financing, acquisition, or asset sale, subject to this policy.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “Our site and Services may link to or connect with services we do not control. Their data practices are their own, and we encourage you to read their privacy policies before sharing information with them.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- **To service providers and sub-processors** acting on our behalf (for example, cloud infrastructure and the AI model providers that power testing), each bound by contract to safeguard it. You can request our current sub-processor list by emailing [grc@fabraix.com](mailto:grc@fabraix.com).” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.