PermitPortal procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ We operate primarily in the United States, and information we process may be stored and processed in the United States or other countries where our sub-processors operate. Where required, we rely on appropriate safeguards for cross-border transfers.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We retain personal information for as long as your account is active or as needed to provide the Service. Customer content is deleted within ninety (90) days of contract termination once it is no longer needed for a legitimate business or legal purpose, unless a longer retention period is required by law. We will delete or return customer content earlier upon a verified request, subject to our agreements.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We do not sell personal information. We share information only as described here: Sub-processors. Service providers that process data on our behalf under contractual confidentiality and security obligations (see the table below). Within your organization. Customer content may be visible to other authorized users in your account or workspace according to the access controls you configure. Legal and safety. When required by law, legal process, or to protect the rights, property, or safety of PermitPortal, our users, or others. Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The Service integrates with third-party services and data sources. We are not responsible for third-party services, and your use of them may be governed by separate terms. Our Privacy Policy lists the sub-processors we use to operate the Service.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ To operate the Service, we engage a limited number of service providers (sub-processors) that process data on our behalf under contractual confidentiality and security obligations. They fall into the following categories: Cloud hosting & infrastructure — application hosting, content delivery, and supporting cloud services. Database, authentication & storage — managed database, user authentication, and file storage. Background processing — execution of background jobs and data pipelines. AI & large language model providers — research, analysis, and document-processing features. We use these providers under terms that prohibit training their models on our data. Product analytics — usage telemetry to operate and improve the Service. Maps & geospatial — interactive maps and geospatial rendering. Authentication / single sign-on — optional federated login. Email delivery — transactional and notification email. A current list of the specific sub-processors we use is available to customers on request at founders@permitportalapp.com .” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.