Privacy facts at a glance
- Jurisdictions
- US · AU · BR · CA · FR · DE · IN · ID · IE · IT · JP · MX · NL · NO · PL · SG · ZA · KR · ES · SE · CH · AE · GB · FI · MY · PH
- Subprocessors
- 19
- Retention
- The policy has a dedicated Retention section but no specific number of days is stated in the excerpts provided.
- Breach notification
- OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach.
- Transfer mechanism
- Standard Contractual Clauses used among OpenAI affiliate entities for cross-border transfers.
- DPA available
- Yes
- Certifications
- SOC 2 Type 2 · ISO 27001 · ISO 27017 · ISO 27018 · ISO 27701 · ISO 42001 · PCI-DSS · CSA STAR Level 1
- GDPR addressed
- Yes
- CCPA addressed
- Yes
Named subprocessors
Cloudflare, Ltd.
Microsoft Corporation
CoreWeave, Inc.
Oracle Cloud Infrastructure
Google Cloud Platform
Amazon Web Services, Inc.
Cerebras
Snowflake, Inc.
TaskUs, LLC
Intercom, Inc.
Salesforce
Pylon Labs
Accenture International Limited
Fivetran, Inc.
Confluent
Cinder Technologies, Inc.
WorkOS, Inc.
Okta, Inc.
Merge API, Inc.
Tracked documents
Recent changes
Public summary; per-account review history visible to subscribers tracking this vendor.
Track OpenAI in your workspace.
Get notified when OpenAI adds a subprocessor, changes retention, updates their DPA, or quietly amends their privacy posture.
Start tracking — 14-day trialNo card required.