Skip to main content
Platform Review
PricingSign in
← Userlens assessment

Userlens procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Userlens
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow“ Userlens and its service providers may process information in countries other than the country where it was collected. Our primary service infrastructure is hosted in AWS regions in Frankfurt and Stockholm. Some providers, including website analytics and AI providers, may process information in the United States or other countries. When required, we use recognized safeguards for international transfers, such as adequacy decisions or standard contractual clauses.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow“ 11.1 No more than once per contract year, Customer may use a reputable independent auditor that is not a Userlens competitor to audit records materially related to the Service when reasonably required for Customer's internal or external audit purposes. The auditor must sign an appropriate confidentiality agreement. The Parties will agree the timing, scope, method, and security conditions in advance. An audit may not unreasonably burden Userlens or endanger its delivery, quality, security, or other customers' confidentiality. Customer will provide Userlens a copy of the audit report. 11.2 Customer bears its own audit costs and the auditor's costs. Userlens bears its reasonable internal costs unless the audit is unusually burdensome, repeated, or reveals no material non-compliance, in which case Userlens may charge reasonable costs as agreed or permitted by the Agreement.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tierslow“ We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the Services, meeting contractual commitments, resolving disputes, and complying with law. Customer data is retained according to the applicable agreement and customer instructions. Unless otherwise agreed, the standard service retention period covers the current rolling year and the two previous calendar years. We delete or return customer personal data after termination or a valid customer request, subject to legal requirements and limited backup retention. Consent preferences remain in your browser until they are cleared or replaced. PostHog analytics identifiers may remain for up to one year after consent. Aggregated or de-identified information that can no longer identify a person may be kept longer.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ The Services use artificial intelligence to analyze product context and behavior, identify adoption opportunities, and prepare personalized guidance. We may use AI service providers, including Anthropic, to process information only as needed to provide these features. Customers determine which data is connected, define campaign goals and boundaries, and authorize campaigns. Userlens is not intended to make decisions that produce legal or similarly significant effects about website visitors or our customers' end users.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ We do not sell personal information. We may share information in these circumstances: Service providers: providers of hosting, analytics, AI, payments, email delivery, communications, support, and security that process information for us under appropriate obligations. Customer-selected integrations: third-party services a customer chooses to connect. The customer controls these connections and can disconnect them. Legal and safety reasons: when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Services. Business transactions: in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and data protection measures. With your direction or consent: when you ask us to share information or otherwise authorize us to do so.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.

Userlens procurement policy evidence — AIRIN