Skip to main content
Platform Review
PricingSign in
Freepik AI assessment

Freepik AI procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Freepik AI
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow There’s also another itty-bitty-tinsy issue:  It doesn’t comply with GDPR.  Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmedium How long personal information is stored Yes. However, the Privacy Policy requires you to fill in the exact period of data retention for account and billing data. It also assumes that marketing data will be kept until the individual withdraws their consent, which may not be accurate. For example, some companies may delete marketing data if an individual has not opened marketing emails for a certain period of time (e.g. 2 years), even if consent has not been withdrawn. If personal information is used for automated decision making or profiling, then the logic behind such automated decision making or profiling No (if you do use the personal information for automated decision making or profiling). Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium The categories or names of the third parties with whom personal information will be shared Yes. However, the list does not include sufficient detail to satisfy GDPR requirements. Due to the “e.g.” listed in the policy, this appears to be a list of examples but that other third parties may receive personal information. GDPR requires you to provide an exhaustive and exact list of the categories (or names) of the third parties with whom you may share personal information. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow For example, CalOPPA (a relatively simple privacy law) requires a Privacy Policy to disclose how a website will respond to Do Not Track signals and the categories of  third parties it will share personal information with. While ChatGPT’s Privacy Policy states that we share personal information with “service providers,” this is way too vague to satisfy this requirement.Captured 2026-06-08Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.