Dropstone 的法律文件和认证在哪里?
所有法律文件都在 dropstone.io 上:条款、隐私政策、Cookie 政策、DPA、子处理者列表、EULA 以及信任页面。认证答案也明确说明,包括 Dropstone 自身不持有的认证。
它们都在 dropstone.io 上,每个文档一个链接:
| 文档 | 位置 | 涵盖内容 |
|---|---|---|
| 服务条款 | dropstone.io/terms | 使用 Dropstone 的协议 |
| 隐私政策 | dropstone.io/privacy | 收集了什么、为什么收集,以及你对这些数据的权利 |
| 数据处理协议 | dropstone.io/dpa | 组织签署的处理者条款,GDPR 第 28 条 |
| 子处理者 | dropstone.io/subprocessors | 每一家接触客户数据的公司,以及各自持有的认证 |
| 信任页面 | dropstone.io/trust | 请求在哪里运行、保留了什么、认证了什么 |
| Cookie 政策 | dropstone.io/cookies | 网站设置的 Cookie,以及同意控制 |
| 最终用户许可协议 | dropstone.io/eula | Dropstone 软件的许可条款 |
关于认证,明确的答案是:推理运行在通过 SOC 2 和 ISO 27001 认证的美国提供商上,并且 Dropstone 自身不持有 SOC 2 认证。面向企业正式发布的 Dropstone 级 SOC 2 Type I 审计已计划进行,也可以应要求提前委托;请发送邮件至 enterprise@blankline.org。
Related articles
- How Dropstone handles your dataWhat Dropstone stores, for how long, who can see it, whether it is used to improve the models, and the commitments that apply to every account. A plain-language summary of Dropstone's data practices.
- Where your requests runDropstone's servers and the inference providers that run its models are hosted in the United States. Requests are never routed through providers outside the US. What that means for your data.
- Security, SSO, and SCIM for an organizationThe five controls on the organization's Security page: an identity provider, requiring single sign-on, provisioning on first sign-in, directory sync over SCIM, and emergency access.
- Is your data used to train models?On an organization account, never. On a personal account, only if you leave the setting on. What is collected, what is never collected, and what deletion can and cannot undo.
- How to get supportHow to reach Dropstone support, what to include so we can help quickly, and the right address for billing, privacy, security, and enterprise questions.
Ctrl+I