ChatGPT procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Appeals. Depending on where you live, you may have the right to appeal a decision we make relating to requests to exercise your rights. To appeal a decision, please send your request to dsar@openai.com . ” | Captured 2026-08-17Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ OpenAI processes your Personal Data for the purposes described in this policy on servers located in various jurisdictions, including processing and storing your Personal Data in our facilities and servers in the United States, or in countries or territories where our affiliates and partners or our vendors and service providers are located. While data protection law varies by country, we apply the protections described in this policy to your Personal Data regardless of where it is processed, and only transfer that data pursuant to legally valid transfer mechanisms. ” | Captured 2026-06-10Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ If you live in the European Economic Area (EEA) or Switzerland, OpenAI Ireland Limited, with its registered office at 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, is the controller and is responsible for the processing of your Personal Data as described in this policy. ” | Captured 2026-08-17Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ If you live anywhere else, OpenAI OpCo, LLC, with its registered office at 1455 Third Street, San Francisco, California 94158, United States, is the controller and is responsible for the processing of your Personal Data as described in this policy. ” | Captured 2026-08-17Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Information we retain until you delete it: Some of our Services allow you to delete Personal Data stored in your account. For example, you can delete specific, or all, of your ChatGPT conversations, delete specific Saved Memories (opens in a new window) , or delete your account. Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to improve our models (opens in a new window) . Information we delete automatically: In some cases, Personal Data will be deleted automatically. For example, Temporary Chats (opens in a new window) will be automatically deleted within 30 days (unless we have to retain them for safety or legal reasons, as described further below), and your Atlas incognito browsing history (opens in a new window) won’t be saved after you end your session. Information we retain for longer for legitimate security, safety, or legal reasons: In some cases, we need to retain Personal Data for longer even after you delete it, for example because we are legally required to, to address fraud and abuse, for security reasons, or for financial record-keeping purposes. For instance: If specific Content, or your account, is banned because of violations of our usage policies , we may retain that data for to protect our services from fraud, abuse, or other violations of our policies; If we are legally required to retain your data (for instance, we receive a lawful subpoena) then we may retain it for the duration of the relevant legal or regulatory obligation; When we are a party to a financial transaction (for instance, when we process your payment for” | Captured 2026-08-17Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ Our purpose for processing the Personal Data (such as whether we need to retain it to provide our Services); The amount, nature, and sensitivity of the information; The potential risk of harm from unauthorized use or disclosure; Any legal requirements that we are subject to. ” | Captured 2026-06-10Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We’ll retain your Personal Data for only as long as we need in order to provide our Services to you, or for other legitimate business purposes such as resolving disputes, safety and security reasons, or complying with our legal obligations. How long we retain Personal Data depends on the type of data, how we use it, and in many cases your settings: ” | Captured 2026-06-10Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ Information we retain until you delete it: Some of our Services allow you to delete Personal Data stored in your account. For example, you can delete specific, or all, of your ChatGPT conversations, delete specific Saved Memories (opens in a new window) , or delete your account. Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to improve our models (opens in a new window) . Information we delete automatically: In some cases, Personal Data will be deleted automatically. For example, Temporary Chats (opens in a new window) will be automatically deleted within 30 days (unless we have to retain them for safety or legal reasons, as described further below), and your Atlas incognito browsing history (opens in a new window) won’t be saved after you end your session. Information we retain for longer for legitimate security, safety, or legal reasons: In some cases, we need to retain Personal Data for longer even after you delete it, for example because we are legally required to, to address fraud and abuse, for security reasons, or for financial record-keeping purposes. For instance: If specific Content, or your account, is banned because of violations of our usage policies , we may retain that data for to protect our services from fraud, abuse, or other violations of our policies; If we are legally required to retain your data (for instance, we receive a lawful subpoena) then we may retain it for the duration of the relevant legal or regulatory obligation; When we are a party to a financial transaction (for instance, when we process your payment for a” | Captured 2026-06-10Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ ChatGPT Plus or Pro account, or facilitate a purchase on ChatGPT), we may retain payment and transaction related information to meet our accounting, dispute resolution, and regulatory compliance purposes; When you ask us to delete your Personal Data, we retain the audit record of the erasure request to be able to verify that we have complied with the request. ” | Captured 2026-06-10Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ a ChatGPT Plus or Pro account, or facilitate a purchase on ChatGPT), we may retain payment and transaction related information to meet our accounting, dispute resolution, and regulatory compliance purposes; When you ask us to delete your Personal Data, we retain the audit record of the erasure request to be able to verify that we have complied with the request. ” | Captured 2026-08-17Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ In determining these retention periods, we consider a number of factors, such as: ” | Captured 2026-06-10Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We also aggregate or de-identify Personal Data so that it no longer identifies you and share it with third parties for the purposes described above, such as to help improve our Services. ” | Captured 2026-06-10Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Vendors, Service Providers, and Marketing Partners : To assist us in meeting business operations needs and to perform certain services and functions, we disclose Personal Data to vendors, service providers, and marketing partners, including providers of hosting services, customer service vendors, cloud services, content delivery services, support and safety services, email communication software, web analytics services, payment and transaction processors, search and shopping providers, and information technology providers. We also work with service providers who help us with age and identity verification, and you can learn more here (opens in a new window) . When we work with Service Providers, these parties will access, process, or store Personal Data based on our instructions and only in the course of performing their duties to us. We also share limited information with select marketing partners who are not service providers in order to promote our products and services on third-party properties and help us assess the effectiveness of those efforts. Some of these partners may receive information through cookies and similar technologies. Learn more about these practices and the choices available to you here (opens in a new window) . Business Transfers : If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a “Transaction”), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets. ” | Captured 2026-06-10Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We disclose your Personal Data in the following circumstances: ” | Captured 2026-06-10Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ OpenAI processes your Personal Data for the purposes described in this policy on servers located in various jurisdictions, including processing and storing your Personal Data in our facilities and servers in the United States, or in countries or territories where our affiliates and partners or our vendors and service providers are located. While data protection law varies by country, we apply the protections described in this policy to your Personal Data regardless of where it is processed, and only transfer that data pursuant to legally valid transfer mechanisms. ” | Captured 2026-08-17Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Parents or guardians of teen users for account linking purposes described above Other users and third parties you interact or share information with” | Captured 2026-06-10Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ For Free and Go users, subject to your controls, to personalize the ads you see on our Services and measure the effectiveness of ads shown on our Services. Learn more. Communicate with you, including to respond to your questions, and send you information about our Services and events, for example about changes or improvements to the Services or offers or information that may interest you To identify your contacts who use our Services when you choose to connect your contacts and update you if they join our Services later. Prevent fraud, illegal activity, or misuses of our Services, and to protect the security of our systems and Services, including by monitoring any Content submitted or exchanged on our platforms (learn more here ) Comply with legal obligations and protect the rights, privacy, safety, or property of our users, OpenAI, or third parties, for instance to prevent harm to you or others, and to estimate your age to give you an age-appropriate experience We may disclose this information in the following circumstances, as described above: Vendors, service providers, and affiliates to assist us in meeting business operations needs and to perform certain services and functions described above Government authorities or other third parties for the legal reasons described above” | Captured 2026-08-17Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Information We Receive from Other Sources: We receive information from other sources, such as our trusted security and safety partners to protect safety and prevent fraud, abuse, and other threats to our Services, and from marketing vendors who provide us with information about potential customers of our business services. ” | Captured 2026-06-10Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Parent or Guardian of a Teen : Teen users and their parents or guardians can choose to link their accounts, allowing the parent or guardian to manage certain settings, and receive alerts if we detect a serious safety concern. These accounts can be unlinked at any time. Learn more (opens in a new window) about account linking. Other Users and Third Parties You Interact or Share Information With : Certain Services allow you to interact or share information with other users or third parties. For example, you can share content like ChatGPT conversations (opens in a new window) or Sora videos (opens in a new window) and characters (opens in a new window) , or share information with third-party search (opens in a new window) and shopping (opens in a new window) partners. Information you share with third-party partners is governed by their own terms and privacy policies, and you should make sure you understand those terms and policies before sharing information with them. ” | Captured 2026-06-10Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.