SureBright procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “8.4 Monitoring and Compliance Verification SureBright may monitor, review, audit, and analyse, including through automated means, the Seller’s implementation, integrations, workflows, communications, sales practices, and use of the Program for operational, compliance, fraud prevention, security, servicing, underwriting, regulatory, and customer experience purposes. Seller shall reasonably cooperate with compliance reviews, operational reviews, investigations, remediation efforts, and requests relating to Program compliance or Customer protection. ” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We employ industry-leading security measures to protect your personal information, including: Encryption: Data is encrypted in transit and at rest. Access Controls: Only authorized personnel have access to customer data. Regular Audits: We conduct security assessments and maintain compliance with relevant data protection laws. We retain personal data only for as long as necessary to fulfill warranty services, legal obligations, or business operations. Once no longer needed, data is securely deleted or anonymized. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “SureBright may utilize one or more Underwriting Partners, administrators, obligors, insurers, reimbursement insurers, claims handlers, or service providers in connection with the Program.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share your personal information with: Business Partners: Merchants, brands, and manufacturers from whom you purchased your warranty to ensure seamless service delivery. Legal and Regulatory Authorities: When required by law, to comply with legal obligations, respond to subpoenas, or protect the rights and safety of SureBright and our users. Service Providers: Trusted third-party vendors who assist with payment processing, IT support, customer service, warranty operations, and email communications. These partners are contractually obligated to protect your data. We do not sell or trade customer data to advertisers or third parties. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Merchant and Manufacturer Data: Information provided by our partner merchants, brands, and manufacturers regarding your warranty purchase, including product details and transaction records. ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ As a company operating in the United States and Canada , we may transfer and store data across borders. We comply with applicable laws governing international data transfers and ensure appropriate safeguards, such as: ” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.