Theta procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Theta operates globally, which means your Personal Information may be transferred, stored, or processed outside your country or region. These locations may have different data protection laws. By using our Services, you consent to such transfers. We ensure that appropriate safeguards and protections are in place consistent with this Policy.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ If you are located in the European Economic Area (the "EEA"), Switzerland, or the United Kingdom (the "UK"), our legal basis for collecting and using the Personal Information described in this Policy will depend on the Personal Information concerned and the specific context in which we collect it. We will normally collect Personal Information from you only where we have your consent to do so, where we need the Personal Information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect Personal Information from you. We may share information internally or with third parties as described in this Policy. When we share Personal Information of individuals in the EEA, Switzerland, or UK with third parties, we utilize a variety of legal mechanisms to safeguard the transfer, including the European Commission-approved standard contractual clauses and additional safeguards where appropriate.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain your Personal Information only for as long as necessary to fulfill the purposes outlined in this Policy. In some cases, we may need to retain it for a longer period, such as to comply with legal requirements, resolve disputes, or enforce our agreements. Once the information is no longer required, we will either delete it or take steps to de-identify it so it can no longer be linked back to you. De-identified data may be used to improve our Services, such as enhancing system performance or developing new features. We also retain Usage Data (information about how you interact with the Services) for internal analysis. This type of data is generally kept for shorter periods unless it is needed to strengthen security, improve functionality, or comply with legal obligations.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Our service providers (Cal.com, Unicorn Studio) may use standard web technologies to deliver their services, but we do not use cookies for tracking or analytics purposes.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ When you interact with our Services, you may choose to provide the following information: Name and email address when you submit a contact request or book a demo Company name and website (optional) when requesting more information about our services Use case details and additional notes (optional) to help us understand your needs This information is submitted directly to Cal.com, our contact form processing service, when you request a demo or consultation.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We use the following third-party services to deliver our website and process inquiries: Cal.com (https://cal.com/) Processes contact form submissions when you request a demo or consultation. Cal.com receives your name, email, company information, and any additional notes you provide. Privacy Policy: https://cal.com/privacy ” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ At Theta, your Personal Information is never for sale. We value your trust and only share your information when it is necessary to deliver and improve our Services, when required by law, or when you grant us permission. We may engage carefully selected partners and service providers who help us maintain platform operations, strengthen security, prevent fraud, improve user experience, or analyze how our Services are used. These third parties are bound by strict confidentiality obligations and are required to protect your information. There may be times when we are legally required to share your Personal Information, such as in response to a subpoena, court order, or other lawful government request. We may also disclose your Personal Information when necessary to detect, prevent, or address fraud, misuse, or harmful activity. If Theta participates in a corporate transaction, such as a merger, acquisition, restructuring, or sale of assets, your Personal Information may be transferred as part of that process. In such cases, we will ensure that appropriate confidentiality protections are maintained. If we wish to use your Personal Information in a manner not covered by this Policy, we will request your permission prior to doing so.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.