Skip to main content
Platform Review
PricingSign in
← telli assessment

telli procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for telli
TopicPlan or tierRiskTheir wordsSource
Data retentionAll applicable tiersunknown“ Unless expressly stated within this privacy notice, the data stored by us is erased as soon as it is no longer necessary for its intended purpose and no statutory retention obligations preclude erasure. Insofar as the data is not erased because it is necessary for other legally permissible purposes, its processing is restricted, i.e. the data is blocked and not processed for other purposes. This applies, for example, to data that we are required to retain for reasons of commercial or tax law.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ If, following the application procedure, we enter into an employment relationship with the applicant, we do not erase the data until after the end of the employment relationship. Otherwise, we erase the data at the latest six months after the rejection of an applicant. If applicants have given us their consent to also use their data for further application procedures, we do not erase their data until one year after receipt of the application.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ date and time of the request time zone difference to Greenwich Mean Time (GMT) content of the request (specific page) access status/HTTP status code amount of data transferred in each case website from which the request originates browser operating system and its interface language and version of the browser software. This data is also stored in log files. It is erased when its storage is no longer necessary, at the latest after 14 days.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ When you contact us via the contact form on our website, we store the data requested there and the content of the message. The legal basis for the processing is our legitimate interest in answering enquiries addressed to us. The legal basis for the processing is therefore Art. 6(1)(f) GDPR. We erase the data arising in this context once its storage is no longer necessary, or we restrict the processing if statutory retention obligations exist.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ In order to analyse the use of our app (app.telli.com) and to improve our product, we use the tool PostHog. The processing takes place on the basis of our legitimate interest in product optimisation pursuant to Art. 6(1)(f) GDPR.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ Insofar as we transfer data to service providers or other third parties outside the EEA, adequacy decisions of the EU Commission pursuant to Art. 45(3) GDPR guarantee the security of the data during the transfer, where such decisions exist, as is the case, for example, for the United Kingdom, Canada and Israel. When transferring data to service providers in the USA, the legal basis for the data transfer is an adequacy decision of the EU Commission, provided that the service provider has additionally certified itself under the EU-US Data Privacy Framework. In other cases (e.g. where no adequacy decision exists), the legal basis for the data transfer is, as a rule, i.e. unless we provide a differing notice, standard contractual clauses. These are a set of rules adopted by the EU Commission and form part of the contract with the respective third party. Pursuant to Art. 46(2)(b) GDPR, they ensure the security of the data transfer. Many of the providers have provided contractual guarantees going beyond the standard contractual clauses, which protect the data beyond the standard contractual clauses. These include, for example, guarantees regarding the encryption of the data or regarding an obligation on the part of the third party to notify data subjects if law enforcement authorities seek to access data.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available here: https://www.linkedin.com/legal/privacy-policy?_l=de_DE. An option to object to the data processing is available via the advertising settings: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We are present on social media networks in order to present our organisation and our services there. The operators of these networks regularly process their users' data for advertising purposes. Among other things, they create user profiles from users' online behaviour, which are used, for example, to display advertising on the networks' pages and elsewhere on the internet that corresponds to the users' interests. For this purpose, the operators of the networks store information on usage behaviour in cookies on the users' computers. It also cannot be ruled out that the operators combine this information with further data. Users can obtain further information, as well as guidance on how users can object to the processing by the site operators, in the privacy policies of the respective operators listed below. It may also be the case that the operators or their servers are located in non-EU states, so that they process data there. This may give rise to risks for users, e.g. because the enforcement of their rights is made more difficult or state authorities gain access to the data. When users of the networks contact us via our profiles, we process the data provided to us in order to answer the enquiries. This constitutes our legitimate interest, so that the legal basis is Art. 6(1)(f) GDPR.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use Webflow for the design and provision of our website. The provider is Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the USA. The legal basis for the processing is Art. 6(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects can withdraw their consent at any time, e.g. by contacting us using the contact details provided in our privacy notice. The withdrawal does not affect the lawfulness of the processing up to the withdrawal. The legal basis for the transfer to a country outside the EEA is standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is ensured by standard data protection clauses adopted in accordance with the examination procedure pursuant to Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider. The data is erased once the purpose of its collection ceases to apply and no retention obligation precludes this. Further information is available in the provider's privacy policy at https://webflow.com/legal/eu-privacy-policy.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“The legal basis for the data processing described is therefore Art. 6(1)(f) GDPR. The legal basis for the transfer to a country outside the EEA is an adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is ensured because the EU Commission has decided, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country offers an adequate level of protection.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Insofar as you have given us your consent via our cookie banner, we use Google Tag Manager to manage website tags as well as the Meta Pixel for analysis and for targeted marketing. The processing takes place exclusively on the basis of your consent pursuant to Section 25 TDDDG in conjunction with Art. 6(1)(a) GDPR. Any transfer of data to third countries (e.g. the USA) is safeguarded by appropriate guarantees such as the EU-US Data Privacy Framework.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Our website is hosted by Webflow. The provider is Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. In doing so, the provider processes the personal data transmitted via the website, e.g. content, usage, meta/communication data or contact data in the USA. Further information can be found in the provider's privacy policy at https://webflow.com/legal/eu-privacy-policy. It is our legitimate interest to provide a website, so that the legal basis for the data processing described is Art. 6(1)(f) GDPR. The legal basis for the transfer to a country outside the EEA is standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is ensured by standard data protection clauses adopted in accordance with the examination procedure pursuant to Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider. We use the content delivery network Vercel for our website. The provider is Vercel Inc., 340 S Lemon Ave Unit 4133 Walnut, CA, USA. In doing so, the provider processes the personal data transmitted via the website, e.g. content data, usage data, meta/communication data or contact data, in the USA. Further information can be found in the provider's privacy policy at https://vercel.com/legal/privacy-policy. We have a legitimate interest in using sufficient storage and delivery capacities in order to ensure optimal data throughput even during high load peaks. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We have embedded a data protection seal on our website. The provider is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. The provider processes meta/communication data (e.g. IP addresses) in the EU. The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in providing website visitors with confirmation of our data protection compliance. At the same time, the provider has a legitimate interest in ensuring that only customers with existing contracts use its seals, which is why a mere image copy of the certificate does not constitute a viable alternative for such confirmation. The data is masked after collection so that there is no longer any personal reference. Further information is available in the provider's privacy policy at https://heydata.eu/datenschutzerklaerung.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.