Lindy procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ For purposes of this Data Processing Terms section, the following definitions shall apply: (a) “ Controller ” means the party who determines the purposes and means of processing personal data; (b) “ Processor ” means the party who processes personal data on behalf of a Controller; (c) “ Data Protection Laws ” means any applicable data protection or privacy laws, rules and regulations, including as applicable: (i) the EU e-Privacy Directive 2002/58/EC as implemented by countries within the European Economic Area; and (ii) the EU General Data Protection Regulation 2016/679 (the “ GDPR ”); (d) “ Company Personal Data ” means personal data to the extent such personal data is processed by us as a result of our provision of the Services; (e) "Standard Contractual Clauses ( SCC ) " means the European Commission's standard contractual clauses for the transfer of personal data from the European Union to third countries (Modules One and/or Two, as applicable), as set out in the Annex to Commission Decision (EU) 2021/914 the terms; and (f) “ data subject ”, “ personal data ”, “ personal data breach ”, “ processing ”, and “ supervisory authority ” shall have the same meanings ascribed to them under Data Protection Laws. When and to the extent we are acting as a Processor in our provision of the Services, and you are acting as the Controller, the following provisions apply: We shall: (i) comply with all Data Protection Laws in the processing of Company Personal Data; (ii) not process Company Personal Data other than pursuant to Company’s instructions and in accordance with the Data Protection Laws; (iii) take reasonable steps to ensure the reliability of any employee, agent or contractor of ours who may have access to Company Personal Data, ensuring in each case that” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ access is limited to those individuals who have a need to know or access the relevant Company Personal Data for the purposes of providing the Services in accordance with these Legal Terms and to comply with applicable laws and regulations, and ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality; (iv) taking into account the then-current risks, implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate those measures in Article 32(1) of the GDPR; and (v) not appoint any person to process Company Personal Data on our behalf (each, a “ Subprocessor ”) unless required or authorized by Company. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Company hereby instructs us to process Company Personal Data as necessary to provide the Services in accordance with these Legal Terms. The subject matter, nature and purpose of our processing of Company Personal Data is the performance of the Services pursuant to these Legal Terms. The duration of our processing is the duration of our provision of the Services to you. We process all Company Personal Data provided to us via the Services, and Customer is solely responsible for determining the types of personal data to be processed. The categories of data subjects whose Company Personal Data may be processed are Company’s customers, vendors, services providers, employees, agents, and prospects. The categories of personal data which may be processed includes names, contact information (phone numbers, emails and physical addresses), and contact preferences. The rights and obligations of Company are stipulated in these Legal Terms. Company hereby authorizes all Subprocessors listed in in the “Vendors, Consultants, and Other Third-Party Service Providers” section of our Privacy Policy. Taking into account the nature of processing and the information available, we agree to reasonably assist Company in responding to requests to exercise data subject rights under the Data Protection Laws, including by promptly notifying Company of any requests we receive from a data subject under a Data Protection Law in respect of Company Personal Data and ensuring that we do not respond to any such request except on the documented instructions of Company or as required by applicable law. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ If any personal data transfer between Company and us requires execution of the Standard Contractual Clauses in order to comply with Data Protection Laws, you agree to immediately notify us and to execute the Standard Contractual Clauses with us and take all other actions required to legitimize the transfer. Upon becoming aware of a personal data breach affecting Company Personal Data, we shall: (i) promptly notify you; (ii) provide you with available information to allow you to meet your reporting and information obligations under Data Protection Laws; (iii) reasonably cooperate with you and take reasonable commercial steps as directed by you, to assist in the investigation, mitigation and remediation of each such personal data breach. We shall provide you with reasonable assistance in connection with any data protection impact assessments and consultations with supervising authorities as required by Data Protection Laws, in each case solely in relation to the processing of Company Personal Data by us. We shall promptly delete (and certify to such deletion upon your written request) all copies of Company Personal Data after the date of our cessation of the provision of the Services to you. We shall make available to you, upon your written request, all information necessary to demonstrate compliance with this Data Processing Terms section and shall allow for and contribute to audits, including inspections, by the Company or an auditor mandated by the Company in relation to the Processing of the Company Personal Data by us. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ For purposes of this section, the following definitions shall apply: (a) “ Controller ” means the party who determines the purposes and means of processing personal data;(b) “ Data Protection Laws ” means any applicable data protection or privacy laws, rules and regulations implemented by countries within the European Economic Area, including as applicable: (i) the EU e-Privacy Directive 2002/58/EC as implemented by countries within the European Economic Area; and (ii) the EU General Data Protection Regulation 2016/679 (the “ GDPR ”); ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ We care about data privacy and security. Please review our Privacy Policy: https://www.lindy.ai/privacy . By using the Services, you agree to be bound by our Privacy Policy, which is incorporated into these Legal Terms. Please be advised the Services are hosted in the United States. If you access the Services from any other region of the world with laws or other requirements governing personal data collection, use, or disclosure that differ from applicable laws in the United States, then through your continued use of the Services, you are transferring your data to the United States, and you expressly consent to have your data transferred to and processed in the United States. ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ 18. Data Protection Officer and Representative for Non-EU Controllers/Processors ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ PROVIDERS OF PRODUCTS OR SERVICES. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Please note that if a Third-Party Account or associated service becomes unavailable or our access to such Third-Party Account is terminated by the third-party service provider, then Social Network Content may no longer be available on and through the Site. You will have the ability to disable the connection between your account on the Site and your Third-Party Accounts at any time. PLEASE NOTE THAT YOUR RELATIONSHIP WITH THE THIRD-PARTY SERVICE PROVIDERS ASSOCIATED WITH YOUR THIRD-PARTY ACCOUNTS IS GOVERNED SOLELY BY YOUR AGREEMENT(S) WITH SUCH THIRD-PARTY SERVICE PROVIDERS. We make no effort to review any Social Network Content for any purpose, including but not limited to, for accuracy, legality, or non-infringement, and we are not responsible for any Social Network Content. You acknowledge and agree that we may access your email address book associated with a Third-Party Account and your contacts list stored on your mobile device or tablet computer solely for purposes of identifying and informing you of those contacts who have also registered to use the Site. You can deactivate the connection between the Site and your Third-Party Account by contacting us using the contact information below or through your account settings (if applicable). We will attempt to delete any information stored on our servers that was obtained through such Third-Party Account, except the username and profile picture that become associated with your account.” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.