Surface Labs procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Individuals may request access, amendments, or deletion of personal data under applicable privacy laws including GDPR and CCPA. To exercise your rights, please contact us at privacy@withsurface.com .” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain personal data for as long as necessary to provide our services and comply with legal obligations. You may request deletion of your data at any time.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share data with trusted service providers who assist in operating our platform, subject to confidentiality agreements. We may also disclose data when required by law.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.