WellSaid Labs procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “To the extent Company receives Personal Information from EEA residents for processing as Processor as defined in the GDPR, it will receive and process such information based on the lawful bases for which the Controller originally collected and shared such Personal Information for processing. You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you, unless additional time is needed, in which case we will let you know. You may exercise your rights by submitting a request using the information in the Contact section below.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We use certain physical, managerial, and technical safeguards that are designed to ensure the integrity and security of information that we collect and maintain. The measures we use are designed to provide a level of security appropriate to the risk associated with processing your Personal Information. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. Company will retain your Personal Information for as long as needed based on the following criteria: to provide you with the products or services you have requested, as needed for the purposes outlined in this Notice or at the time of collection, as necessary to comply with our legal obligations (for example, to comply with opt-out requests), to resolve disputes and enforce our agreements, or to the extent permitted by law.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Third-party content may use cookies, web beacons, or other mechanisms for obtaining data in connection with your viewing of the third party content on the Service. Additionally, we may implement third party buttons (such as Facebook “like” or “share” buttons) that may function as web beacons even when you do not interact with the button. Information collected through third-party web beacons and buttons is collected directly by these third parties, not by WellSaid. Information collected by a third party in this manner is subject to that third party’s own data collection, use, and disclosure policies. We may combine information that we receive from the different sources described above; for example, we may create a profile based on Personal Information provided directly from you and input information regarding your interaction history with sales representatives into that profile.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ When We Disclose/Share Personal Information. We may disclose information to third parties if you consent to us doing so and in the following circumstances: Any information that you voluntarily choose to include in a publicly accessible area of the Service will be available to anyone who has access to that content, including other users. We work with third party service providers to provide website, application development, hosting, maintenance, and other services for us. These third parties may have access to or process information about you as part of providing those services for us. Generally, we limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions, and we require them to agree to maintain the confidentiality of such information. To our affiliates and subsidiaries, corporate parents, affiliates, subsidiaries, business units, and other companies that share common ownership with Company. If you interact with Company in connection with your employment, we may share Personal Information with other individuals designated by your organization. We may disclose information about you if required to do so by law or in the good-faith belief that such action is necessary to comply with state and federal laws, in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies. ” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We also reserve the right to disclose information about you that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Service and any facilities or equipment used to make the Service available, or (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others. Information about our users may be disclosed and otherwise transferred to an acquirer, successor, or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, or in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets. We may make certain aggregated, automatically-collected, or otherwise non-personal information available to third parties for various purposes, including (i) compliance with various reporting obligations; (ii) for business or marketing purposes; or (iii) to assist such parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the Service.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ The Service may contain features or links to websites and services provided by third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Service. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Service. We encourage you to learn about third parties’ privacy and security policies before providing them with information.” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.