Hessian procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ To the extent Customer Data contains personal data, you are the controller and we are the processor; our processing is governed by our Data Processing Addendum , which is incorporated into these Terms. Our processing of personal data as a controller (e.g. for account administration and business-contact marketing to your representatives) is described in our Privacy Policy .” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ On termination, you have 90 days to export your Customer Data using the Service's standard mechanisms; after that, we may delete it. Any provisions that by their nature should survive termination do so, including accrued payment obligations and the provisions on intellectual property, confidentiality, AI Output, disclaimers, limitation of liability, indemnification, and governing law.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ You are responsible for maintaining your own backups of Customer Data. We are not liable for loss, alteration, or deletion of Customer Data, except where caused by our gross negligence or willful misconduct.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.