Wo befinden sich die Rechtsdokumente und Zertifizierungen von Dropstone?
Jedes Rechtsdokument ist auf dropstone.io zu finden: AGB, Datenschutzerklärung, Cookie-Richtlinie, DPA, Liste der Unterauftragsverarbeiter, EULA und die Trust-Seite. Und die Antwort zur Zertifizierung wird klar formuliert, einschließlich dessen, was Dropstone selbst nicht besitzt.
Sie sind alle auf dropstone.io zu finden, jeweils ein Link:
| Dokument | Ort | Was es abdeckt |
|---|---|---|
| Nutzungsbedingungen | dropstone.io/terms | Die Vereinbarung zur Nutzung von Dropstone |
| Datenschutzerklärung | dropstone.io/privacy | Was erfasst wird, warum, und Ihre Rechte darüber |
| Auftragsverarbeitungsvertrag | dropstone.io/dpa | Die Auftragsverarbeiter-Bedingungen, die eine Organisation unterzeichnet, GDPR Artikel 28 |
| Unterauftragsverarbeiter | dropstone.io/subprocessors | Jedes Unternehmen, das mit Kundendaten in Berührung kommt, und wofür jedes zertifiziert ist |
| Trust-Seite | dropstone.io/trust | Wo Anfragen ausgeführt werden, was aufbewahrt wird und was zertifiziert ist |
| Cookie-Richtlinie | dropstone.io/cookies | Die Cookies, die die Website setzt, und die Einwilligungssteuerung |
| Endbenutzer-Lizenzvertrag | dropstone.io/eula | Die Lizenzbedingungen für die Dropstone-Software |
Zu den Zertifizierungen lautet die klare Antwort: Inferenz läuft auf US-Anbietern, die nach SOC 2 und ISO 27001 zertifiziert sind, und Dropstone besitzt selbst keine SOC-2-Zertifizierung. Ein SOC-2-Typ-I-Audit auf Dropstone-Ebene ist für die allgemeine Verfügbarkeit im Enterprise-Bereich geplant und kann auf Anfrage früher in Auftrag gegeben werden; schreiben Sie an enterprise@blankline.org.
Related articles
- How Dropstone handles your dataWhat Dropstone stores, for how long, who can see it, whether it is used to improve the models, and the commitments that apply to every account. A plain-language summary of Dropstone's data practices.
- Where your requests runDropstone's servers and the inference providers that run its models are hosted in the United States. Requests are never routed through providers outside the US. What that means for your data.
- Security, SSO, and SCIM for an organizationThe five controls on the organization's Security page: an identity provider, requiring single sign-on, provisioning on first sign-in, directory sync over SCIM, and emergency access.
- Is your data used to train models?On an organization account, never. On a personal account, only if you leave the setting on. What is collected, what is never collected, and what deletion can and cannot undo.
- How to get supportHow to reach Dropstone support, what to include so we can help quickly, and the right address for billing, privacy, security, and enterprise questions.