Skip to main content
Platform Review
PricingSign in
Napkin AI assessment

Napkin AI procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Napkin AI
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow (a) Module Two (Controller to Processor) of the EU SCCs applies where the Customer is a Controller and Napkin AI is a Processor;Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The following table sets out the details of Processing activities required by Article 28(3) of the GDPR and Clause 1 of the EU SCCs.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The following technical and organizational measures are implemented by Napkin AI (Second Layer, Inc.) in accordance with Article 32 of the GDPR and Annex II of the EU SCCs.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 2.1 Napkin AI shall Process Customer Personal Data only on the Customer’s documented instructions as set out in this DPA, in Annex 1, and as further specified in the Agreement, except where required to do so by applicable law, in which case Napkin AI shall, to the extent permitted by law, inform the Customer of that legal requirement before Processing.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow (c) Clause 17 (governing law) – the laws of France shall govern the EU SCCs; andCaptured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The parties acknowledge that: (a) the Customer acts as a Controller with respect to Customer Personal Data; (b) Napkin AI acts as a Processor with respect to Customer Personal Data; (c) this DPA does not establish a joint controllership arrangement under Article 26 of the GDPR; and (d) each party remains solely responsible for its own compliance obligations.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “Controller” has the meaning given in Article 4(7) of the GDPR. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow All production infrastructure hosted on GCP; physical security managed by respective cloud providers per ISO 27001 and SOC 2 Type II standards. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In the event of any conflict between this DPA and the Agreement, the provisions of this DPA shall prevail with respect to the subject matter hereof.Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 5.3 Transfer Impact Assessment. The Customer acknowledges that Napkin AI, as the data importer, has implemented the technical and organizational measures described in Annex 3 as supplementary measures to address any residual risks identified in connection with the transfer of Customer Personal Data to the United States.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Documented incident response plan tested annually; escalation paths to CTO and DPO; post-incident reviews for all severity-1 events. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “UK GDPR” means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow This Data Processing Agreement (“DPA”) forms part of the Napkin AI Terms of Service available at https://www.napkin.ai/terms-conditions/ (the “Agreement”) and sets out the terms on which Napkin AI processes Customer Personal Data on behalf of the Customer. This DPA is effective as of the date Customer creates an account, accepts the Terms of Service, or first accesses the Services, whichever occurs first.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow audit our internal processes for compliance with legal and contractual requirements or our internal policies;Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.3 Amendments. Napkin AI may update this DPA from time to time. For changes required by applicable law or that expand privacy protections for Customers, updates take effect immediately upon publication at https://www.napkin.ai/data-processing-agreement/ . For material changes; defined as changes that (a) add new categories of personal data processed, (b) add new purposes of processing, or (c) materially reduce Customer rights under this DPA, Napkin AI will provide at least thirty (30) days' notice by updating the DPA page at https://www.napkin.ai/data-processing-agreement/ with a summary of the changes and the date they take effect. Enterprise customers with separately executed DPAs will receive direct email notice of material changes. Continued use of the Services after the effective date of any update constitutes acceptance. Sub-processor changes are governed exclusively by Section 3.3.1 and are not subject to this Section 12.3.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “Supervisory Authority” means the competent data protection supervisory authority having jurisdiction over the relevant party under Applicable Data Protection Laws. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 4.4 The Customer shall promptly notify Napkin AI of any changes to its instructions that may affect the lawfulness of Processing and shall cooperate with Napkin AI in implementing any required changes.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 11.1 This DPA shall come into effect on the Effective Date and shall remain in force for the duration of the Agreement. This DPA shall terminate automatically upon the expiry or termination of the Agreement.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow (b) Option 2 of Clause 9 (general written authorization) is selected, with a ten (10) calendar day notice period;Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 2.3 Napkin AI shall promptly inform the Customer if, in Napkin AI’s opinion, any instruction from the Customer infringes Applicable Data Protection Laws, provided that Napkin AI shall have no obligation to conduct legal analysis on behalf of the Customer.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Napkin provides an AI-powered platform that generates visual materials including but not limited to business visuals, infographics, data charts, etc. This Privacy Policy applies to individual users and Team plan customers, except where organizations may have separate data processing agreements with us.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown “UK Personal Data” means Personal Data subject to the UK GDPR. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “U.S. Privacy Laws” means the collective privacy, data protection, and data security laws and regulations issued by governmental authorities of any US state jurisdiction applicable to the Processing of Customer Personal Data under this DPA, including the CCPA/CPRA. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow All sub-processors subject to data processing agreements with equivalent obligations; sub-processor list maintained per Annex 2; annual security reviews of critical sub-processors. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Production environment isolated; web application firewall (WAF) deployed; DDoS protection enabled. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 8.3 Consumer Requests. Napkin AI shall, upon the Customer’s written request, assist the Customer in fulfilling its obligations to respond to verifiable consumer requests under U.S. Privacy Laws, including requests for access, deletion, correction, and opt-out of sale or sharing, within the timelines required by applicable law.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 3.2.2 Napkin AI may update or modify the technical and organizational measures from time to time provided the updated measures afford at least equivalent protection.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 7.3.1 Napkin AI’s Services do not, as of the Effective Date, deploy AI systems classified as high-risk under Regulation (EU) 2024/1689 (the “EU AI Act”). Napkin AI shall notify the Customer if this position changes and shall work with the Customer to address any resulting compliance obligations.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “UK IDTA” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office (ICO) Version B1.0, in force 21 March 2022, as may be updated from time to time. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 3.4.1 Napkin AI shall, taking into account the nature of the Processing, promptly assist the Customer by appropriate technical and organizational measures to fulfil the Customer’s obligations to respond to Data Subject requests under Applicable Data Protection Laws, including requests for access, rectification, erasure, restriction, portability, and objection.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 3.4.2 If Napkin AI receives a request from a Data Subject in respect of Customer Personal Data, Napkin AI shall promptly forward that request to the Customer and shall not respond to such requests directly except as directed in writing by the Customer or as required by law.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “EU SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries approved by the European Commission under Decision 2021/914 of 4 June 2021, as may be amended or replaced from time to time. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow DATA CONTROLLER: The entity or individual (“Customer”) that accepts the Napkin AI Terms of Service or executes an enterprise agreement with Napkin AI.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown “Agreement” means the Napkin AI Terms of Service available at https://www.napkin.ai/terms-conditions/ , as accepted by the Customer upon account creation or use of the Services, together with any applicable enterprise agreement, Order Form, or addenda executed between the parties. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.6 Notices. All notices under this DPA shall be in writing. Notices to Napkin AI shall be sent to: Data Protection Officer, Napkin AI (Second Layer, Inc.), 626 Jay Street, Los Altos, CA 94022, [email protected] . Notices to Customer shall be sent to the email address associated with the Customer’s account.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.4 Severability. If any provision of this DPA is held invalid, unlawful, or unenforceable, the remaining provisions shall continue in full force and effect. The parties shall, in good faith, negotiate a replacement provision that is valid, lawful, and enforceable and that achieves, to the greatest extent possible, the original intention of the replaced provision.Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 8.5 Certification. Napkin AI certifies that it understands and will comply with its obligations as a service provider and contractor under the CCPA/CPRA, including the restrictions on use and disclosure of Customer Personal Data set forth in this Section 8.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Note: If you are part of an organization that has a separate data processing agreement with us, please also refer to that agreement for any additional rights or procedures that may applyCaptured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 5.4 Mechanism Invalidity. If any transfer mechanism relied upon under this Section 5 becomes invalid, suspended, or otherwise unavailable, the parties shall cooperate in good faith to implement a lawful alternative transfer mechanism without undue delay. Napkin AI may suspend the relevant transfers until such mechanism is in place, without such suspension constituting a breach of this DPA or the Agreement.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 2.4 This DPA shall remain in effect for the duration of the Agreement and shall terminate automatically upon expiry or termination of the Agreement, subject to the survival provisions set out in Section 11.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.1 Order of Precedence. In the event of any inconsistency between this DPA and the Agreement with respect to data protection matters, this DPA shall prevail. In the event of any inconsistency between this DPA and the EU SCCs, the EU SCCs shall prevail.Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “Processor” has the meaning given in Article 4(8) of the GDPR. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “Applicable Data Protection Laws” means, collectively, all laws and regulations applicable to the processing of personal data under this DPA, including, without limitation, the GDPR, the UK GDPR, the CCPA/CPRA, and all other applicable national, federal, or state privacy and data protection statutes in force during the term. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown All data encrypted in transit using TLS 1.2 or higher; all data encrypted at rest using AES-256; encryption key management via Google Cloud KMS with automatic key rotation. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 5.1 EU Standard Contractual Clauses. To the extent that Napkin AI Processes Customer Personal Data originating from the European Economic Area (“EEA”) and transfers such data to the United States or any other country that has not been the subject of an adequacy decision by the European Commission, the parties agree that such transfers are made pursuant to the EU SCCs, which are incorporated into this DPA by reference, and completed as follows:Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.7 Acceptance. By creating a Napkin AI account, accepting the Terms of Service, or using the Services, the Customer acknowledges that it has read, understood, and agrees to be bound by this DPA. For enterprise customers with separately executed agreements, this DPA may also be executed in counterparts, including by electronic signature via DocuSign or equivalent platform.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 12.2 Entire Agreement. This DPA, together with the Agreement and the Annexes hereto, constitutes the entire agreement between the parties with respect to the processing of Customer Personal Data and supersedes all prior or contemporaneous agreements, representations, and understandings relating to the same subject matter.Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 4.1 The Customer represents and warrants that: (a) it has a valid lawful basis under Applicable Data Protection Laws for Processing each category of Customer Personal Data; (b) it has provided all required privacy notices to Data Subjects and obtained all required consents; and (c) it has the authority to provide Customer Personal Data to Napkin AI for Processing under this DPA.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 2.2 The details of the Processing activities, including the subject matter, nature, purpose, categories of Personal Data, and categories of Data Subjects, are set out in Annex 1 to this DPA.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 5.2 UK Transfers. To the extent that Napkin AI Processes UK Personal Data and transfers such data outside the United Kingdom, the parties agree that such transfers are governed by the UK IDTA. The UK IDTA is hereby incorporated into this DPA by reference, with: (a) Table 1 completed by reference to the party and transfer details set out in Annex 1; (b) Table 2 selecting the EU SCCs (Module Two, Controller to Processor) as completed in Section 5.1 of this DPA as the Linked Agreement; (c) Table 3 completed by reference to Annexes 1, 2, and 3 of this DPA; and (d) Table 4 selecting that either party may end the UK Addendum in accordance with Section 19 of the UK IDTA. By accepting this DPA, the Customer is deemed to have executed the UK Addendum. The EU SCCs form the Linked Agreement for the purposes of the UK Addendum.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown “Effective Date” means the date on which the Customer first accepts the Napkin AI Terms of Service, creates an account, or accesses the Services, whichever occurs first. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 3.6.1 Napkin AI shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits and inspections conducted by the Customer or a qualified third-party auditor appointed by the Customer. The Customer shall provide at least thirty (30) days’ prior written notice of any audit request; audits shall be conducted during normal business hours, no more than once per calendar year, absent a confirmed Personal Data Breach, and the Customer shall bear all costs of such audit.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium 3.6.2 Napkin AI may satisfy the audit obligations under this Section 3.6 by providing the Customer with a current SOC 2 Type II report or equivalent third-party audit report, subject to the Customer’s written agreement to maintain such report as confidential.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium ISO 27001 certification work in progress, SOC 2 Type II audit planned for Q3 2026; GCP and other sub-processors maintain ISO 27001 and SOC 2 Type II certifications. Reports available upon written request. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium United States (primary). Sub-processor locations are listed in Annex 2. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The information required by Annex I, II, and III of the EU SCCs is set out in Annexes 1, 2, and 3 of this DPA, respectively.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow DATA PROCESSOR: Second Layer, Inc. dba Napkin AI, a Delaware corporation, with registered address at 626 Jay Street, Los Altos, CA 94022, USA.Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmediumWe may use service providers that operate in various countries, and your personal information may be transferred to locations where privacy laws may differ from those in your jurisdiction.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmediumWe are based in the United States and our data is currently hosted on secure cloud infrastructure based in the United States. This means that if you use the Service, your personal information will be transferred to and processed in the United States.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown “Services” means the Napkin AI visual communication and diagramming platform and any related professional services provided to the Customer under the Agreement. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Role-based access control (RBAC); principle of least privilege enforced; multi-factor authentication (MFA) required for all privileged access; quarterly access reviews; immediate revocation upon termination. Captured 2026-08-17Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “DPA” means this Data Processing Agreement, including all Annexes. Captured 2026-06-10Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 3.5.1 Napkin AI shall reasonably assist the Customer in ensuring compliance with the Customer’s security obligations under Article 32, breach notification obligations under Articles 33 and 34, data protection impact assessment obligations under Article 35, and prior consultation obligations under Article 36 of the GDPR, taking into account the nature of the Processing and the information available to Napkin AI. Napkin AI may charge reasonable, documented fees for compliance assistance that exceed Napkin AI’s ordinary course of business.Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tiersmedium 11.4 Where fulfilment of a data return or deletion request under Section 11.2 requires manual work exceeding two (2) person-hours, Napkin AI may charge the Customer its reasonable, documented costs at then-current professional services rates, except where such charges are prohibited by Applicable Data Protection Laws.Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tierslow 11.3 Napkin AI shall, upon the Customer’s written request, provide written certification that all Customer Personal Data has been deleted or returned in accordance with this Section 11.2.Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tiersunknown 11.1 This DPA shall come into effect on the Effective Date and shall remain in force for the duration of the Agreement. This DPA shall terminate automatically upon the expiry or termination of the Agreement.Captured 2026-08-17Open source →Finding permalink →
Data retentionAll applicable tiersmedium Usage data and analytics may be retained in aggregate or anonymized form for product improvement and reporting.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium When you ask us to delete your account , most personal data is scheduled for deletion immediately from active systems and you will no longer appear in any user-facing parts of the Service. However, some data may be temporarily retained in secure backups for a limited period for operational, legal, or security reasons such as fraud prevention or dispute handling. These backups are automatically purged after our standard retention window, and the data is not actively used during that time. No personal data is kept longer than necessary, and we will not retain data beyond what is required by law or for legitimate business purposes.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow Business Continuity Plan (BCP) reviewed annually; daily automated backups with 30-day retention; RTO: 24 hours; RPO: 24 hours. Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tiersmedium Account-related data (such as email, preferences, visuals, input text) is kept as long as your account is active.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow For the term of the Agreement and until all Customer Personal Data has been deleted or returned in accordance with Section 11 of this DPA. Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tierslow 11.5 The following provisions shall survive termination of this DPA: Section 1 (Definitions), Section 9 (Customer Indemnity), Section 10 (Liability), Section 11.2 to 11.4 (Return and Deletion), and Section 12 (General Provisions).Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tiersmedium Support and communication records are stored to maintain service continuity and historical context.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersunknown 2.4 This DPA shall remain in effect for the duration of the Agreement and shall terminate automatically upon expiry or termination of the Agreement, subject to the survival provisions set out in Section 11.Captured 2026-08-17Open source →Finding permalink →
Data retentionAll applicable tiersmedium When we no longer require the personal information we have collected about you, we may either delete it, anonymize it, or isolate it from further processing.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow 11.2 Return and Deletion. Upon expiry or termination of the Agreement, Napkin AI shall, at the Customer’s election: (a) return all Customer Personal Data in a structured, commonly used, machine-readable format; or (b) securely delete or destroy all Customer Personal Data. Such return or deletion shall be completed within seven (7) calendar days for data held in active production systems and within thirty (30) calendar days for data held in backup systems and operational logs, unless applicable law requires Napkin AI to retain such data for a longer period.Captured 2026-06-10Open source →Finding permalink →
Data retentionAll applicable tiersmedium We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown All sub-processors subject to data processing agreements with equivalent obligations; sub-processor list maintained per Annex 2; annual security reviews of critical sub-processors. Captured 2026-08-17Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium protect our, your or others' rights, privacy, safety or property (including by making and defending legal claims);Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 5.5 Government Agency Requests. As of the Effective Date of this DPA, Napkin AI (and Second Layer, Inc.) has not received any formal legal requests from any government intelligence or security agency for access to Customer Personal Data. If Napkin AI receives any such request after the Effective Date, Napkin AI shall: (a) to the extent permitted by applicable law, promptly notify the Customer; (b) use commercially reasonable efforts to redirect the relevant law enforcement or government agency to request that data directly from the Customer; and (c) provide the Customer with reasonable notice of any such demand unless legally prohibited from doing so by a court of competent jurisdiction or applicable law.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium 7.2.1 Napkin AI currently uses Google Cloud AI (Vertex AI) and OpenAI, L.L.C., as AI inference sub-processors. These providers process Customer prompts and content in the ordinary course of delivering AI-powered features.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow NOTE RE: AI SUB-PROCESSORS – ZERO DATA RETENTION: Napkin AI maintains zero-data-retention (ZDR) agreements with all AI inference sub-processors (currently Google Cloud AI and OpenAI). Customer Personal Data submitted to these providers is not retained beyond the immediate processing request and is not used for model training by those providers.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow https://www.twilio.com/legal/privacy Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Twilio SendGrid, Inc. Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmediumService providers. Third parties that provide services on our behalf or help us operate the Service or our business, such as: Google Cloud Platform (hosting and infrastructure) Intercom (customer support and communication) Sendgrid and Mailmodo (email delivery) Sentry (error and performance monitoring) Google Analytics (product analytics) OpenAI and Gemini (AI-powered generation and processing services) These service providers process personal data only on our instructions and under strict confidentiality agreements.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow The following Sub-Processors are authorized by the Customer pursuant to Section 3.3.1 of this DPA. This list reflects the Sub-Processors engaged as of the Effective Date. The most current list is also referenced in the Napkin AI Privacy Policy at https://www.napkin.ai/privacy-policy/ .Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Collaborative content: When you collaborate with other users, they will have access to the content you choose to share with them.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 3.3.1 The Customer grants Napkin AI general written authorization to engage the Sub-Processors listed in Annex 2 and at https://www.napkin.ai/sub-processors . Napkin AI shall provide at least ten (10) calendar days' prior notice of any intended addition or replacement of a Sub-Processor by updating the Sub-Processor page at https://www.napkin.ai/sub-processors and, where the Customer has subscribed to notifications, by email to the Customer's registered account address. The Customer may subscribe to Sub-Processor change notifications at https://www.napkin.ai/sub-processors .Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities;Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may share your personal information with the following parties and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Professional advisors. Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Payment processors. Any payment card information you use to make a purchase on the Service is collected and processed directly by our payment processors, such as Stripe. Stripe may use your payment data in accordance with its privacy policy, https://stripe.com/privacy .Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Affiliates. Our corporate parent, subsidiaries, and affiliates.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Third parties designated by you. We may share your personal information with third parties where you have instructed us or provided your consent to do so, such as when you share content with collaborators, or connect third-party services. We only share information that is needed for these other companies to provide the services that you have requested.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Linked third-party platforms. If you choose to connect to the Service through your social media account or other third-party platform, you may be able to use your settings in your account with that platform to limit the information we receive from it. If you revoke our ability to access information from a third-party platform, that choice will not apply to information that we have already received from that third party.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Note: Organizations with separate data processing agreements may have different data sharing arrangements as specified in their agreements.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Private sources , such as data providers and data licensors.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Business transferees. We may disclose personal information in the context of actual or prospective business transactions (e.g., investments in Napkin, financing of Napkin, public stock offerings, or the sale, transfer or merger of all or part of our business, assets or shares), for example, we may need to share certain personal information with prospective counterparties and their advisers. We may also disclose your personal information to an acquirer, successor, or assignee of Napkin as part of any merger, acquisition, sale of assets, or similar transaction, and/or in the event of an insolvency, bankruptcy, or receivership in which personal information is transferred to one or more third parties as one of our business assets.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow “Sub-Processor” means any Processor engaged by Napkin AI to process Customer Personal Data on behalf of the Customer. Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 3.3.3 Napkin AI shall impose on all Sub-Processors data protection obligations that are no less protective than those set out in this DPA by way of written contract. Napkin AI remains liable to the Customer for the performance of each Sub-Processor’s obligations to the extent Napkin AI performs such obligations itself.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow https://stripe.com/privacy Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Stripe, Inc. Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow These service providers process personal data only on our instructions and under strict confidentiality agreements.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 7.1.4 Content submitted by users may be processed through third-party AI inference APIs as necessary to provide the Services, subject to the sub-processor agreements in Annex 2 and the zero-data-retention commitments in Section 7.2.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown The Customer, being the entity that has accepted the Napkin AI Terms of Service or executed an enterprise agreement. Captured 2026-08-17Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Service providers. Third parties that provide services on our behalf or help us operate the Service or our business, such as:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 3.3.2 The Customer may object to a new or replacement Sub-Processor on reasonable data protection grounds within the ten (10) day notice period by providing written notice to Napkin AI at [email protected] . The parties shall cooperate in good faith to resolve the objection. If the parties cannot resolve the objection within a reasonable timeframe, either party may terminate the affected Services upon written notice.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow 8.2 Service Provider Designation. For purposes of the CCPA/CPRA, Napkin AI is a “service provider” and “contractor” with respect to Customer Personal Data. Napkin AI shall not: (a) sell or share Customer Personal Data (as those terms are defined under CCPA/CPRA); (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement; or (c) combine Customer Personal Data received from the Customer with personal information received from other sources except as permitted by U.S. Privacy Laws.Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow https://sentry.io/privacy Captured 2026-06-10Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Our affiliate partners , such as our affiliate network provider and publishers, influencers, and promoters who participate in our paid affiliate programs.Captured 2026-06-07Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.