Webex AI (Cisco) procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ Pursuant to the DPF Principles, Cisco-U.S. commits to the following:” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “A copy of our EU BCR-C can be found in our Global Privacy Policy . More information about EU BCRs can be found on the European Commission site .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “A summary of our U.K. BCR-C can be found [here](https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-uk-binding-corporate-rules-summary-controller.pdf). More information about U.K. BCRs can be found on the [U.K.’s Information Commissioner’s Office site](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/guide-to-binding-corporate-rules/).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “In compliance with the EU-U.S. DPF Principles, the U.K. Extension to the EU-U.S. DPF Principles, and/or the Swiss-U.S. DPF Principles, Cisco-U.S. commits to resolve complaints about your privacy and our collection or use of your Personal Data transferred to the U.S. pursuant to the DPF Principles. EU, EEA, U.K. (and Gibraltar), and Swiss individuals with DPF inquiries or complaints, or any questions or concerns regarding Cisco-U.S. processing or international transfer of their Personal Data should first contact Cisco-U.S. by submitting a [Privacy Request](https://privacyrequest.cisco.com/) online.” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “To submit a privacy inquiry through Schellman, our Accountability Agent, please complete the [Schellman compliance inquiry form](https://www.schellman.com/compliance-inquiry-form).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ As Cisco is a global organization, Personal Data may be transferred to Cisco in the United States of America, to any Cisco subsidiary worldwide, or to third parties and business partners as described above, that are located in various jurisdictions around the world. Similarly, Personal Data may be accessed from countries where Cisco or its subsidiaries have operations. Cisco will transfer your Personal Data in accordance with approved transfer mechanisms as well as any applicable local legal requirements.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “A copy of our EU BCR-C can be found in our [Global Privacy Policy](https://www.cisco.com/c/en/us/about/trust-center/global-privacy-policy.html). More information about EU BCRs can be found on the [European Commission site](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/binding-corporate-rules-bcr_en).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “(and Gibraltar), and Swiss individuals to request access to their data while it is in the U.S. and to correct, amend, and supplement inaccurate or incomplete data. Said individuals also have the right to request erasure of Personal Data that has been handled in violation of the DPF Principles. Subject individuals interested in accessing their data should see [Disclosing your Personal Data](https://www.cisco.com/c/en/us/about/legal/privacy-full.html#spi) for information on how to contact us, or submit a [Privacy Request online](https://privacyrequest.cisco.com/).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “Cisco-U.S. is responsible for the processing of Personal Data it receives under the DPF, and subsequently may transfer it to third parties acting as agents on its behalf. Cisco-U.S. complies with the DPF Principles for all onward transfers of Personal Data from the EU, EEA, U.K. (and Gibraltar), and Switzerland (for examples of such transfers, see [Disclosing your Personal Data](https://www.cisco.com/c/en/us/about/legal/privacy-full.html#spi)), including the onward transfer liability provisions. In certain situations, Cisco-U.S. may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Further, Cisco-U.S. is committed to protecting Personal Data received from EU and EEA member countries, Switzerland, and the U.K. (and Gibraltar) (see [Collection and use of your Personal Data](https://www.cisco.com/c/en/us/about/legal/privacy-full.html#personal-information) for examples of the Personal Data Cisco processes when you use our websites and Solutions and interact with us) in accordance with the DPF's applicable Principles and to help ensure Personal Data collected from individuals is accessible to them as part of their individual rights when Cisco is the Controller of the Personal Data (see [Your privacy rights](https://www.cisco.com/c/en/us/about/legal/privacy-full.html#privacy-rights)). Furthermore, Cisco acknowledges the right of EU, EEA, U.K. ” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cisco-U.S. is responsible for the processing of Personal Data it receives under the DPF, and subsequently may transfer it to third parties acting as agents on its behalf. Cisco-U.S. complies with the DPF Principles for all onward transfers of Personal Data from the EU, EEA, U.K. (and Gibraltar), and Switzerland (for examples of such transfers, see Disclosing your Personal Data ), including the onward transfer liability provisions. In certain situations, Cisco-U.S. may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Further, Cisco-U.S. is committed to protecting Personal Data received from EU and EEA member countries, Switzerland, and the U.K. (and Gibraltar) (see Collection and use of your Personal Data for examples of the Personal Data Cisco processes when you use our websites and Solutions and interact with us) in accordance with the DPF's applicable Principles and to help ensure Personal Data collected from individuals is accessible to them as part of their individual rights when Cisco is the Controller of the Personal Data (see Your privacy rights ). Furthermore, Cisco acknowledges the right of EU, EEA, U.K. (and Gibraltar), and Swiss individuals to request access to their data while it is in the U.S. and to correct, amend, and supplement inaccurate or incomplete data. Said individuals also have the right to request erasure of Personal Data that has been handled in violation of the DPF Principles. Subject individuals interested in accessing their data should see Disclosing your Personal Data for information on how to contact us, or submit a Privacy Request online .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ For complaints or concerns about your privacy and our collection or use of your Personal Data transferred to the U.S. pursuant to the DPF Principles, please see Data Privacy Framework .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cisco’s global privacy program, described in this Privacy Statement, complies with the Global Cross-Border Privacy Rules (CBPR) and the Privacy Recognition for Processors (PRP) program requirements. The Global CBPR and PRP system provide a framework for organizations to ensure the protection of Personal Data transferred between participating Global economies. More information about the Global Privacy Framework, CBPRs, and PRP can be found on the Global CBPR Forum site . Our certification applies to our business processes across our global operations that process and transfer Personal Data to and from our affiliates around the world. To view our certifications, please see the Global CBPR System Directory and the Global PRP Directory .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “Cisco’s global privacy program, described in this Privacy Statement, complies with the Global Cross-Border Privacy Rules (CBPR) and the Privacy Recognition for Processors (PRP) program requirements. The Global CBPR and PRP system provide a framework for organizations to ensure the protection of Personal Data transferred between participating Global economies. More information about the Global Privacy Framework, CBPRs, and PRP can be found on the [Global CBPR Forum site](https://www.globalcbpr.org/). Our certification applies to our business processes across our global operations that process and transfer Personal Data to and from our affiliates around the world. To view our certifications, please see the [Global CBPR System Directory](https://www.globalcbpr.org/privacy-certifications/directory/) and the [Global PRP Directory](https://www.globalcbpr.org/privacy-certifications/directory/).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cisco-U.S. has further committed to refer unresolved privacy complaints under the DPF Principles to a U.S.-based independent third-party dispute resolution mechanism, DPF Services, operated by JAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by Cisco, please visit https://www.jamsadr.com/file-a-dpf-claim for more information and to file a complaint. This service is provided free of charge to you.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “Cisco Systems, Inc. and its [U.S. based subsidiaries](https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000GnJ2AAK&status=Active) — Amorblox, Inc.; AppDynamics LLC; Broadsoft, Inc.; Cisco OpenDNS LLC; Cisco Systems Capital Corporation; Duo Security LLC; Fluidmesh Networks LLC; Isovalent LLC; Jasper Technologies LLC; Kenna Security, Inc.; Meraki, LLC; Socio Labs LLC; Splunk LLC; Thousand Eyes LLC; and Valix, Inc. — (collectively "Cisco-U.S.") has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regards to the processing of Personal Data received from the EU and EEA in reliance on the EU-U.S. DPF and from the U.K. (and Gibraltar) in reliance on the U.K. Extension to the EU-U.S. DPF. Cisco-U.S. has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. DPF Principles with regards to the processing of Personal Data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Statement and the EU-U.S. DPF Principles, the U.K. Extension to the EU-U.S. DPF Principles, and/or the Swiss-U.S. DPF Principles, the DPF Principles shall govern. For more information about the DPF program, and to view our certification, please visit the [DPF Website](https://www.dataprivacyframework.gov/).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cisco's global privacy program and policies have been approved by U.K.’s Information Commissioner’s Office, as providing additional safeguards for the protection of privacy, fundamental rights, and freedoms of individuals for transfers of Personal Data protected under U.K. law. Cisco's U.K. Binding Corporate Rules—Controller (U.K. BCR-C) provide that international transfers made worldwide by Cisco entities bound by these rules as a controller of U.K. Personal Data benefit from appropriate safeguards.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ When Cisco is acting as a "data processor," and you wish to exercise your rights of access and request corrections, suppression, or deletion, Cisco will direct you to the data controller under the applicable data protection laws.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Alternatively, you can contact the data protection supervisory authority in your jurisdiction for assistance. (Note, Cisco's main establishment in the EU is in the Netherlands. As such, our EU lead authority is the Dutch Autoriteit Persoonsgegevens .)” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “For complaints or concerns about your privacy and our collection or use of your Personal Data transferred to the U.S. pursuant to the DPF Principles, please see [Data Privacy Framework](https://content/en/us/about/legal/privacy-full.html#data).” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Cisco's global privacy program and policies have been approved by the Dutch, Polish, Spanish, and other relevant European privacy regulators as providing additional safeguards for the protection of privacy, fundamental rights, and freedoms of individuals for transfers of Personal Data protected under European law. Cisco's EU Binding Corporate Rules—Controller (EU BCR-C) provide that international transfers made worldwide by Cisco entities bound by these rules as a controller of European Personal Data benefit from appropriate safeguards.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ When we transfer Personal Data out of the jurisdiction in which it was collected to countries that do not benefit from an adequacy decision, other transfer mechanism, or exemption, we may rely on Standard Contractual Clauses where applicable (ie, Brazil, EU and EEA, Kingdom of Saudi Arabia, the U.K., and Switzerland) with appropriate safeguards in place to protect Personal Data.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In compliance with the EU-U.S. DPF Principles, the U.K. Extension to the EU-U.S. DPF Principles, and/or the Swiss-U.S. DPF Principles, Cisco-U.S. commits to resolve complaints about your privacy and our collection or use of your Personal Data transferred to the U.S. pursuant to the DPF Principles. EU, EEA, U.K. (and Gibraltar), and Swiss individuals with DPF inquiries or complaints, or any questions or concerns regarding Cisco-U.S. processing or international transfer of their Personal Data should first contact Cisco-U.S. by submitting a Privacy Request online.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cisco Systems, Inc. and its U.S. based subsidiaries — Amorblox, Inc.; AppDynamics LLC; Broadsoft, Inc.; Cisco OpenDNS LLC; Cisco Systems Capital Corporation; Duo Security LLC; Fluidmesh Networks LLC; Isovalent LLC; Jasper Technologies LLC; Kenna Security, Inc.; Meraki, LLC; Socio Labs LLC; Splunk LLC; Thousand Eyes LLC; and Valix, Inc. — (collectively "Cisco-U.S.") has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regards to the processing of Personal Data received from the EU and EEA in reliance on the EU-U.S. DPF and from the U.K. (and Gibraltar) in reliance on the U.K. Extension to the EU-U.S. DPF. Cisco-U.S. has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. DPF Principles with regards to the processing of Personal Data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Statement and the EU-U.S. DPF Principles, the U.K. Extension to the EU-U.S. DPF Principles, and/or the Swiss-U.S. DPF Principles, the DPF Principles shall govern. For more information about the DPF program, and to view our certification, please visit the DPF Website .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “Alternatively, you can contact the data protection supervisory authority in your jurisdiction for assistance. (Note, Cisco's main establishment in the EU is in the Netherlands. As such, our EU lead authority is the [Dutch Autoriteit Persoonsgegevens](https://autoriteitpersoonsgegevens.nl/en).)” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ A summary of our U.K. BCR-C can be found here . More information about U.K. BCRs can be found on the U.K.’s Information Commissioner’s Office site .” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We will not retain Personal Data in identifiable form when the purpose(s) for which the Personal Data was collected have been achieved and there is no legal or business need to retain such Personal Data. Thereafter, the data will either be destroyed, deleted, anonymized, and/or removed from our systems.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ In aggregated, anonymized, and/or de-identified form that cannot reasonably be used to identify you” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “We will retain your Personal Data as needed to fulfill the purposes for which it was collected. We will retain and use your Personal Data as necessary to comply with our business requirements and legal obligations, resolve disputes, protect our assets, and enforce our rights and agreements.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- If we otherwise notify you and you consent to the disclosure” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ These choices do not apply to service notifications or other required communications that are considered part of certain programs, websites, and Solutions which you may receive periodically unless you cancel or stop use in accordance with its terms and conditions. Your Personal Data may be disclosed to third parties (such as Cisco business partners or vendors) so that they may inform you about websites, programs, products, or services that may be of interest to you. To opt out of Cisco disclosing to third parties for their marketing purposes, please submit a Privacy Request .” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- In aggregated, anonymized, and/or de-identified form that cannot reasonably be used to identify you” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ With your permission, application usage and performance data with third-party Developers to help support and improve the use and performance of their Apps” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ If we otherwise notify you and you consent to the disclosure” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Cisco-U.S. is responsible for the processing of Personal Data it receives under the DPF, and subsequently may transfer it to third parties acting as agents on its behalf. Cisco-U.S. complies with the DPF Principles for all onward transfers of Personal Data from the EU, EEA, U.K. (and Gibraltar), and Switzerland (for examples of such transfers, see Disclosing your Personal Data ), including the onward transfer liability provisions. In certain situations, Cisco-U.S. may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Within Cisco and any of our worldwide subsidiaries for the purposes of data processing, such as marketing, business operations, compliance, security, website or Solution functionality, or storage” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ With law enforcement officials, government authorities, or other third parties as necessary to comply with legal process or meet national security requirements; protect the rights, property, or safety of Cisco, our business partners, you, or others; or as otherwise required by applicable law” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ With business partners, service vendors, authorized third-party agents, or contractors to provide a requested website, Solution, service, or transaction. Examples include processing of orders and credit card transactions, hosting websites, seminar registration, assisting with sales-related efforts or pre/post-sales support, and providing customer support” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “In some instances, Cisco and the third parties we engage may automatically collect data through cookies, web logs, web beacons, and other similar applications. Please read the [Use of cookies and similar technologies](https://www.cisco.com/c/en/us/about/legal/privacy-full.html#cookies) section below for more information.” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Personal Data may be processed by third parties for the purposes of operating our business; delivering, analyzing, improving, securing, and customizing our interactions, websites and Solutions; sending marketing and other communications related to our business; and for other legitimate purposes permitted by applicable law(s); or otherwise with your consent.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Cisco does not sell the Personal Data of California consumers.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We may provide access or links to third-party websites, Apps, and services that are outside Cisco's control and governed by the respective third party’s privacy policy, not by this Privacy Statement. We encourage you to review the privacy statements posted on the websites you visit and in the applications you use.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “These choices do not apply to service notifications or other required communications that are considered part of certain programs, websites, and Solutions which you may receive periodically unless you cancel or stop use in accordance with its terms and conditions. Your Personal Data may be disclosed to third parties (such as Cisco business partners or vendors) so that they may inform you about websites, programs, products, or services that may be of interest to you. To opt out of Cisco disclosing to third parties for their marketing purposes, please submit a [Privacy Request](https://privacyrequest.cisco.com/).” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- With law enforcement officials, government authorities, or other third parties as necessary to comply with legal process or meet national security requirements; protect the rights, property, or safety of Cisco, our business partners, you, or others; or as otherwise required by applicable law” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ With Cisco business partners or vendors, so that they may share information with you about their products or services. To opt out of Cisco disclosing to third parties for their marketing purposes, please submit a Privacy Request ” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ In response to a request for information by a competent authority or third party if we believe the disclosure is in accordance with, or is otherwise required by, any applicable law, regulation, or legal process” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ In connection with, or during negotiations of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or to another company” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Residents of the State of California, under California Civil Code § 1798.83, have the right to request from companies conducting business in California a list of all third parties to which the company has disclosed Personal Data during the preceding year for direct marketing purposes. Alternatively, the law provides that if the company has a privacy policy that gives either an opt out or opt in choice for use of your Personal Data by third parties (such as advertisers) for marketing purposes, the company may instead provide you with information on how to exercise your disclosure choice options.” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- With Cisco business partners or vendors, so that they may share information with you about their products or services. To opt out of Cisco disclosing to third parties for their marketing purposes, please submit a [Privacy Request](https://privacyrequest.cisco.com/)” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Cisco has a comprehensive Privacy Statement and provides you with details on how you may either opt-out or opt-in to the use of your Personal Data by third parties for direct marketing purposes. Therefore, we are not required to maintain nor disclose a list of the third parties that received your Personal Data for marketing purposes during the preceding year.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “As Cisco is a global organization, Personal Data may be transferred to Cisco in the United States of America, to any Cisco subsidiary worldwide, or to third parties and business partners as described above, that are located in various jurisdictions around the world. Similarly, Personal Data may be accessed from countries where Cisco or its subsidiaries have operations.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “We partner with third parties to display advertising on our website and to manage our advertising on other sites. Our third-party partners may use cookies or similar technologies to provide you with advertising based on your browsing activities and interests. Where this type of third-party advertising is disabled, generic, non-personalized ads will continue to be displayed.” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ For business purposes in the last 12 months, Cisco may have collected, used, and shared Personal Data about you as described in this Privacy Statement. Each category of data that may be used by Cisco or shared with third parties is categorically outlined in this Privacy Statement. Cisco does not sell Personal Data as the term “sell” is traditionally understood.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Within Cisco and any of our worldwide subsidiaries for the purposes of data processing, such as marketing, business operations, compliance, security, website or Solution functionality, or storage” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- In response to a request for information by a competent authority or third party if we believe the disclosure is in accordance with, or is otherwise required by, any applicable law, regulation, or legal process” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- With your permission, application usage and performance data with third-party Developers to help support and improve the use and performance of their Apps” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- With business partners, service vendors, authorized third-party agents, or contractors to provide a requested website, Solution, service, or transaction. Examples include processing of orders and credit card transactions, hosting websites, seminar registration, assisting with sales-related efforts or pre/post-sales support, and providing customer support” | Captured 2026-08-12Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.