Dropstone 的法律文件與認證在哪裡?
所有法律文件都在 dropstone.io:條款、隱私權政策、Cookie 政策、DPA、子處理者清單、EULA,以及信任頁面。認證的答案也清楚說明,包括 Dropstone 本身未持有的認證。
它們全部都在 dropstone.io 上,每個文件一個連結:
| 文件 | 位置 | 涵蓋內容 |
|---|---|---|
| 服務條款 | dropstone.io/terms | 使用 Dropstone 的協議 |
| 隱私權政策 | dropstone.io/privacy | 收集了什麼、為何收集,以及你對這些資料的權利 |
| 資料處理協議 | dropstone.io/dpa | 組織簽署的處理者條款,GDPR 第 28 條 |
| 子處理者 | dropstone.io/subprocessors | 每個會接觸客戶資料的公司,以及各自持有的認證 |
| 信任頁面 | dropstone.io/trust | 請求在哪裡執行、保留什麼資料,以及持有什麼認證 |
| Cookie 政策 | dropstone.io/cookies | 網站設定的 Cookie,以及同意控制選項 |
| 終端使用者授權協議 | dropstone.io/eula | Dropstone 軟體的授權條款 |
關於認證,直接的答案是:推論在通過 SOC 2 與 ISO 27001 認證的美國供應商上執行,且 Dropstone 本身未持有 SOC 2 認證。Dropstone 層級的 SOC 2 Type I 稽核計畫於企業版正式發布時進行,也可應要求提前委託執行;請寫信至 enterprise@blankline.org。
Related articles
- How Dropstone handles your dataWhat Dropstone stores, for how long, who can see it, whether it is used to improve the models, and the commitments that apply to every account. A plain-language summary of Dropstone's data practices.
- Where your requests runDropstone's servers and the inference providers that run its models are hosted in the United States. Requests are never routed through providers outside the US. What that means for your data.
- Security, SSO, and SCIM for an organizationThe five controls on the organization's Security page: an identity provider, requiring single sign-on, provisioning on first sign-in, directory sync over SCIM, and emergency access.
- Is your data used to train models?On an organization account, never. On a personal account, only if you leave the setting on. What is collected, what is never collected, and what deletion can and cannot undo.
- How to get supportHow to reach Dropstone support, what to include so we can help quickly, and the right address for billing, privacy, security, and enterprise questions.
Ctrl+I