TrainLoop procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ As we primarily process data on behalf of our customers, individuals seeking to exercise rights (Access, Correction, Deletion) regarding data processed by TrainLoop should first contact the customer (the "Data Controller") who directed their data through our service. We will assist our customers in responding to these requests as required by our agreements.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Maintaining audit trails of data access and transmission for compliance monitoring” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Upon expiration of the retention period or customer request, data is securely deleted using industry- standard cryptographic erasure or overwriting methods to ensure it cannot be recovered.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Trace Data: Retained according to the specific configuration and agreement with each customer.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ At Rest: Any stored traces or logs containing sensitive data are encrypted using AES-256.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ System Logs: Retained for 1 year to support security audits and SOC 2 requirements.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ PHI: Retained for a minimum of 6 years as required by HIPAA, or as specified in the BAA.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Ensure any subcontractors that create, receive, maintain, or transmit ePHI on our behalf agree to the same restrictions.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Sub-processors: Cloud infrastructure providers (e.g., AWS) used to host our proxy layer” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We share information only as necessary to provide our services or as required by law” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.