Iterable procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Iterable commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Iterable at privacy@iterable.com ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Iterable complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Iterable has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) and the the UK Extension to the EU-U.S. DPF, with regard to the processing of personal data received from the European Union and the United Kingdom.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Iterable’s security design and requirements are guided by industry defined best practices, including NIST and ISO 27001. Iterable is both ISO 27001 and SOC 2 Type II certified. Internal Information Security policies and procedures, control framework, and risk matrix are defined and regularly reviewed to monitor coverage and effectiveness.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Iterable has obtained APEC Privacy Recognition for Processors (“PRP”) certification and the APEC Cross Border Privacy Rules (“CBPR”) and shall process personal data in accordance with this privacy notice and the scope of its certification. The CBPR Notice can be accessed here and the PRP notice can be accessed here ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Iterable has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/ ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Non-EEA countries do not have the same data protection laws as the UK and the EEA. In particular, non-EEA countries may not provide the same degree of protection for your personal data. However, when transferring your personal data outside the UK or the EEA, we will ensure that, where required by applicable law, at least one of the following safeguards is implemented: (1) we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government or the European Commission; or (2) where we use certain service providers, we may use specific contracts approved by the UK Government or the European Commission referred to as the “Standard Contractual Clauses” or “SCCs” which give personal data the same protection it has in the UK and EU. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ To find out more about the SCCs we use, please see: Standard contractual clauses for international transfers | European Commission (europa.eu) or please email us at privacy@iterable.com ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Iterable commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), the UK Information Commissioner’s Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ If you have any Data Privacy Framework questions, concerns or complaints please contact us on privacy@iterable.com” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Post EU GDPR Representative Lionheart Squared (Europe) Ltd2 Pembroke HouseUpper Pembroke Street 28-32DublinD02 EK84Republic of Ireland UK GDPR Representative Lionheart Squared Ltd17 Glasshouse StudiosFryern Court RoadFordingbridgeHampshireSP6 1QXUnited Kingdom ” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Prospective customers: We only keep data obtained from our third party service providers for B2B prospecting for 24 months from the last interaction you have had with us. If you wish to exercise any of your rights regarding this data please refer to the Your Data Protection Rights section.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Sales and Marketing Data: If you are a Customer we will retain your data for the duration of your contract with us, unless you have unsubscribed.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Service Data: We will keep certain Customer personnel personal data and other personal data related to the provision of a Service for as long as we have an active contract with the Customer. We are entitled to retain such personal data if required by EU/UK law and often data will be kept for audit purposes. Iterable must retain certain financial and corporate data under national regulations and laws. This can include invoices, tax information, banking information. This data is held for a minimum of 7 years.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ If you have opted out of receiving marketing communications from us, we will need to retain certain personal data on a suppression list so that we know not to send you further marketing communications in the future.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ If any personal data is only useful for a short period (e.g. for a specific event or marketing campaign), we will delete it at the end of that period. ” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ In some circumstances we are required to hold onto a copy of your personal information for business or legal purposes, this can include billing, technical support, law enforcement or litigation. When we no longer need this information we will delete the information if we are legally able to. ” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain personal data only for as long as is necessary for the purposes described in this Privacy Notice, after which it is deleted from our systems.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ End User Data: Iterable will act on the instructions of the Customer and contractual obligations when deleting End User personal data at the conclusion of a contract. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ When processing your personal data, we may need to share it with third parties (including other Group Companies), as set out in the table below. This list is non-exhaustive and there may be circumstances where we need to share personal data with other third parties . ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Iterable enters into contractual agreements with each sub processor, who can only process data in accordance with the relevant agreement. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Iterable relies on other third party processors to process personal data of Site visitors, Customer personnel and End Users. Our subprocessor list can be accessed at the following link . ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ If you are an EU, UK, or Swiss Individual, where we transfer your personal data to third party services providers who perform services for us or on our behalf, we are responsible for the processing of that data by them and will remain liable if they process your personal data in a manner inconsistent with the EU-GDPR, UK-GDPR, or Swiss-FADP, as applicable, or the DPF Principles referred to in this section, unless we prove that we are not responsible for the event giving rise to the damage.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Please see the “Insight and analysis -Site” section above to learn more about how we personalise advertising to you. This activity is also subject to the privacy choices you have elected to make on such Social Platforms.Our legal basis for processingWe will only share your personal data with the third-party providers of the Social Platforms, so that we can advertise our Products and Services to you when you use those Platforms, where you have provided your consent. If we advertise to other people who share similar interests and characteristics to you We will provide your personal data to third-party providers of other services as described in the “If we advertise to you on social media and other platforms” and the “Insight and analysis – Site” sections. If you are a user of those third-party services, we may ask the third-party providers of those services to find other registered users of their services who share similar interests and characteristics to you, which will be based on information that the third party holds about you and its other registered users.This is known as “lookalike” audience advertising because we are trying to show our advertising to people who “look like” you. Please note that such activity is also subject to the privacy choices you have elected to make on such third-party services.Our legal basis for processingIt is in our legitimate interests to share your personal data with the third-party providers of other services so that we can advertise our Services to other individuals that use those services and share similar interests and characteristics with you, although where this activity is undertaken through the use of Cookies please see the “Insight, and analysis – Site” section above) to learn about the legal basis that we rely on. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ When you use a link to go from our Site to another website (even if you don’t leave our Site) or you request a service from a third party, your browsing and interactions on any other websites, or your dealings with any other third-party service provider, is subject to that website’s or third-party service provider’s own rules and policies. For example, our Site invites you to connect with us on social media platforms such as Facebook and LinkedIn. When you click on the links we provide to such third-party platforms, you will be transferred from our Site to the relevant third-party platform and the privacy notice (and other terms and conditions) of that platform will apply to you.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality and security standards and obligations. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “This data is used to provide you with, and measure the effectiveness of, online personalised advertising and for other advertising related activities. Third-party post/email marketing and CRM specialists We may share personal data with specialist suppliers who assist us in managing our marketing database and sending out email marketing communications. Partners We operate a partner ecosystem. When a Customer signs up with a partner it must agree to partner the terms of service and it will obtain the appropriate consents in order for us to share End User data with them. Auditors, lawyers, accountants and other professional advisers We may share personal data with professional services firms who advise and assist us in relation to the lawful and effective management of our organisation and in relation to any disputes we may become involved in. Law enforcement or other government and regulatory agencies and bodies We may share personal data with law enforcement or other government and regulatory agencies or other third parties as required by, and in accordance with, applicable law or regulation. Other third parties Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, or to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Our legal basis for processing Please see the “Insight and analysis – Site” section above to learn about the legal basis that we rely on to collect data via the use of Cookies.Where we use your personal data to display online personal advertising to you, we rely on the consent that you have provided in respect of the collection of such data, or it is otherwise in our legitimate interests to promote our Site and Services to you.Our third party partners may rely on a different lawful basis in respect of their use of your personal data. Please read the privacy policy of the relevant third-party provider, as set out in our Cookie Policy and/or our Cookie preference centre. If we advertise to you on social media and other platforms We share your email address (usually in an encrypted or ‘hashed’ form) with third-party providers of social media platforms and other services, such as Facebook and LinkedIn and other similar platforms (“Social Platforms”), so that the third party providers can try to “match” your data with the data of their registered users of their Social Platforms. Where there is a successful match, we will display our advertising to you when you use the relevant Social Platform (e.g. on your LinkedIn newsfeed). This is known as “custom audience” advertising, because we “customise” the audience that we want to reach on the relevant service.Some of the advertising that you see may be personalised to you. The data that we use to personalise our advertising, such as your Profile Data and Behavioural Data, will not be provided to the third-party providers of the Social Platforms. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ ITRBL, UNIPESSOAL Edificio Amoreiras Square Rua Carlos Alberto Da Mota 17 2 Floor, Lisbon Portuga l Responsible for: Provision of Services to Customers Management of the EU site ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Iterable, Inc. 201 Spear Street, Suite 1050 San Francisco, CA 94105 Responsible for: Provision of Services to Customers Management of the Site ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may transmit personal data outside the UK and the EEA to certain categories of third parties (as listed above in SHARING YOUR PERSONAL DATA) and to our Group Companies, more specifically to our headquarters in San Francisco (“US”).” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Our legal basis for processingIt is in our legitimate interests to process personal data in this way for security reasons. Where we process personal data in connection with providing access to our free Wi-Fi service, it is in our legitimate interests to process personal data in this way to provide the service. Where we monitor use of our free Wi-Fi service to ensure proper use of the system, we process personal data for monitoring and record-keeping purposes based on guest user consent. Business administration, finance, and legal compliance We may use an individual’s personal data (including Identity Data, Contact Data, Financial Data, Transaction Data, Publicly Available Data) for the following business administration and legal compliance purposes:to facilitate the operation or effective management of our group of businesses;for financial, accounting and tax purposes;to comply with our legal obligations;to comply with enforceable governmental requests and subpoenas; for privacy and insurance purposes;receipt of professional services such as legal, accounting, financial, auditing and insurance;to enforce or protect our legal rights;to deal with complaints;to protect the rights of third parties (including where health or security of an individual is endangered (e.g. a fire); andin connection with a business transition or sale such as a merger, re-organisation, acquisition by another company, or sale of all or a portion of our assets.Our legal basis for processingWhere we use personal data in connection with a business transition, to enforce our legal rights or to protect the rights of third parties, it is in our legitimate interest to do so. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not monitor, control or endorse the privacy practices of any third parties. We encourage you to become familiar with the privacy practices of every website you visit or third-party service provider that you use in connection with your interaction with us and to contact them if you have any questions about their respective privacy notices and practices.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Iterable does not sell your personal information or share information for cross context behavioural advertising. You can exercise your rights at this link . ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Iterable, Ireland. 8th Floor, Block E, Iveagh Court, Harcourt Road, Dublin 2, Ireland Responsible for: Provision of Services to Customers Management of the EU site ” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.