Skip to main content
Platform Review
PricingSign in
← Klavis AI assessment

Klavis AI procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Klavis AI
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow“ f. SOC 2 Type 2 and GDPR Compliance: As a SOC 2 Type 2 certified and GDPR-compliant organization, we maintain comprehensive audit logs and data retention practices to ensure security, availability, and confidentiality of your data in accordance with the highest industry standards. Our controls are continuously monitored and validated over time to ensure ongoing effectiveness.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ c. Right to Delete/Erasure: Request deletion of your personal information, subject to legal retention requirements.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ b. Comprehensive Data Storage: By using our services, you acknowledge and agree that we will, by default, store all your data and all your interactions with our servers, our APIs, and our website. This includes but is not limited to: user conversations, API requests and responses, website interactions, usage patterns, metadata, and any content you create or upload. This comprehensive data storage is essential for providing our services, ensuring security, maintaining compliance with our SOC 2 Type 2 certification and GDPR requirements, and improving our platform.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“ Security Measures: As a SOC 2 Type 2 certified and GDPR-compliant organization, we implement comprehensive administrative, technical, and physical security measures to protect your personal information. Our security controls are continuously monitored and regularly audited by independent third parties to validate their ongoing effectiveness. We employ encryption, access controls, security monitoring, and incident response procedures. However, no security measures are perfect or impenetrable. Data Retention: We retain all your data and interactions by default for as long as necessary to provide our services, comply with legal obligations (including GDPR requirements), resolve disputes, enforce our agreements, and maintain audit logs as required by our SOC 2 Type 2 certification. This includes retaining comprehensive logs of all API interactions, user activities, and system events for security and compliance purposes. You may request deletion of your personal data as described in Section 5 below, subject to our legal retention obligations. Logging Preferences: If you have disabled logging in your account settings (available for both personal and team accounts), we will minimize the data we retain from your interactions. However, even with logging disabled, we may still retain certain information required for: (i) security and fraud prevention, (ii) legal and regulatory compliance, (iii) billing and payment processing, and (iv) maintaining basic service functionality. Your logging preferences will be applied to all future interactions from the time the setting is changed.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ If you use our integrations with third-party services (e.g., Google Docs, Google Drive, GitHub, Slack, Discord, Supabase), you authorize us to store necessary access tokens, cookies, or other credentials required for the integration to function. By using these integrations, you acknowledge that we may access data within those connected services as needed to provide the features you use. Your use of third-party services through our integrations is also subject to the terms and privacy policies of those respective services.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ e. OAuth Logins: If you log in using third-party services like Google or GitHub, we will collect necessary information from those services as permitted by their terms and your privacy settings.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ a. By Law or to Protect Rights: When required by legal process or to protect rights, property, and safety.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ e. International Data Transfers: Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. If you are located in the EEA, UK, or Switzerland, we ensure appropriate safeguards are in place for such transfers in accordance with GDPR requirements, including standard contractual clauses approved by the European Commission.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ If you subscribe to our paid services, you agree to provide accurate payment information (e.g., credit card details). We use third-party payment processors to handle transactions. Your payment information is subject to the privacy policies and terms of our payment processors. All fees are non-refundable unless otherwise stated.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ d. With Your Consent: For any other purpose with your explicit consent.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ b. Third-Party Service Providers: With vendors and consultants who perform services for us, including payment processors and hosting services.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ c. Business Transfers: In connection with mergers, acquisitions, or sale of company assets.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ d. Third-Party Sharing: We may share your data with third-party service providers as necessary to provide and improve our services, or as required by law.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.