n8n procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “Such disclosures are carried out strictly in accordance with applicable legal provisions. Where legally permissible, we aim to ensure transparency towards data subjects. Some of the recipients listed above may be located outside the European Union (EU) or the European Economic Area (EEA), in particular in the United States. Where personal data is transferred to third countries, such transfers are carried out only where permitted under Articles 44 et seq. GDPR and are subject to appropriate safeguards. These safeguards include in particular reliance on adequacy decisions, such as the EU–U.S. Data Privacy Framework, where applicable, the use of Standard Contractual Clauses (SCCs) approved by the European Commission, and additional technical and organizational measures to ensure an adequate level of data protection. We assess the data protection and security posture of each recipient together with our Privacy Office and ensure that appropriate technical safeguards (such as encryption and access controls) are implemented. These safeguards are reviewed on an ongoing basis and updated as necessary to reflect legal or regulatory developments.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ How long do we keep your data for? What are my rights under data protection laws? ” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We store your personal information for no longer than necessary for the purposes for which it was processed, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data; the potential risk of harm from unauthorized use or disclosure of your personal data; the purposes for which we process your personal data; and the applicable legal requirements. In some circumstances we may carefully anonymise your personal data so that it can no longer be associated with you, and we may use this anonymised information indefinitely without notifying you. We use this anonymised information to analyse our programmes and support other similar programmes around the world.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We use an external payment service provider for the processing of online payments and, where applicable, invoicing and tax handling for digital products. The legal basis for the processing of personal data is Art. 6 (1) b) GDPR, as the processing is necessary for the implementation of pre-contractual measures and for the performance of a contract. This includes, in particular, name, email address, billing address, payment information (e.g., credit card details or other payment details), IP address, transaction data, and, where applicable, company-related information. The processing is carried out for the purpose of payment processing, fraud prevention, invoicing and tax compliance (e.g., VAT determination) The payment service provider may act as an independent controller within the meaning of Art. 4 No. 7 GDPR, in particular where it processes payment data in its own name as a so-called “merchant of record.” The payment service provider may also process personal data in order to comply with legal obligations (e.g., commercial and tax law retention requirements) and for fraud prevention or the assertion and defense of legal claims. Personal data will only be disclosed to third parties if this is necessary for contract processing, required by law, or carried out within the framework of commissioned data processing. The storage period for personal data is determined by statutory retention obligations and contractual requirements. Data relevant under commercial and tax law is generally stored for the duration of the applicable statutory retention periods.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share personal data with carefully selected service providers that support our business operations. These include, in particular, providers of IT hosting and infrastructure services (e.g. cloud hosting and content delivery networks), cybersecurity and fraud prevention solutions, data storage and backup services, website analytics and performance monitoring tools, marketing and advertising platforms, subscription management, billing and revenue analytics systems, payment processing services, as well as customer relationship management software, internal collaboration and productivity tools, document management systems, and customer support and communication services (e.g. ticketing systems, live chat and email services). Where such service providers process personal data on our behalf, we conclude data processing agreements pursuant to Article 28 GDPR, ensuring that personal data is processed solely in accordance with our instructions and in compliance with applicable data protection standards. In some cases, third parties process personal data as independent controllers or joint controllers, in particular in the context of advertising and social media services. We may disclose personal data where required by law or where such disclosure is necessary to comply with legal obligations or lawful requests by public authorities, courts, or law enforcement agencies, enforce our commercial contracts or other agreements, investigate potential violations, prevent or address fraud, security, or technical issues, or protect our rights, property, users, or the public. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “The processing of data for the provision of the website and the storage of data in log files is essential for the operation of our website. Consequently, there is no possibility of objection. The use of the CDN and security service provider also serves the purposes of load balancing, protection against distributed denial-of-service (DDoS) attacks, bot detection, and safeguarding the integrity and confidentiality of our information technology systems. Insofar as personal data is processed by the CDN provider in its own responsibility (e.g., for network security purposes), the provider acts as an independent controller within the meaning of Art. 4 No. 7 GDPR. Where processing is carried out on our behalf, this is based on a data processing agreement pursuant to Art. 28 GDPR.” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.