Compliance Overview
How Roundtable AI approaches privacy law, AI-provider governance, data protection, and vendor transparency.
Last updated August 16, 2026
Roundtable is a product and brand owned and operated by Webb Technologies LLC (“Webb Technologies,” “we,” “us,” or “our”). We keep our compliance posture honest: this page distinguishes practices in operation from mandatory controls for services that have not launched. It is not a certification or a substitute for your own legal review. For procurement or legal questions, email compliance@round-table.ai.
Our Role Depends on the Service
Webb Technologies may act as a business/controller for account, purchase, eligibility, security, and direct-customer administration information. When an organizational customer submits personal information for processing through the Roundtable platform, Webb Technologies may instead act as that customer's service provider/processor for that content. The actual role depends on the information, purpose, contract, and applicable law.
We provide an appropriate Data Processing Addendum when required and supported for the service. Where a covered transfer of personal data leaves the EEA or UK, the applicable vendor and customer agreements use a recognized transfer mechanism, such as the Standard Contractual Clauses, where required.
Data Handling and Access
- Webb Technologies uses contracted cloud infrastructure, including Amazon Web Services, for Roundtable application hosting and storage.
- Access to production data is limited by role, and privileged access is logged.
- We encrypt application data in transit and at rest and manage service credentials separately from application content.
- We minimize information before sending it to an AI provider and prohibit regulated, privileged, credential, and highly sensitive content from the Second Opinion.
- We publish collection purposes, recipient categories, retention, and no-account rights in the Privacy Policy.
Privacy Regulations and Choices
- GDPR / UK GDPR: applicable rights requests and processor obligations are handled according to Webb Technologies' role for the relevant processing. Covered transfers use the contractual safeguard described above.
- CCPA / CPRA and similar U.S. state laws: we do not sell personal information for money. Some analytics or advertising disclosures may constitute “sharing” or targeted advertising. Use “Your Privacy Choices” or Global Privacy Control (GPC) to opt out where applicable; GPC also suppresses applicable Second Opinion advertising signals.
- Other regional laws: access, correction, deletion, portability, objection, and appeal requests are handled through the privacy inbox according to the law that applies.
The Second Opinion is initially limited to U.S.-based businesses with adult participants physically located in the United States. That limit is a launch control; it does not change rights that apply to information Webb Technologies already holds through another Roundtable service.
To exercise a right, including for a no-account Second Opinion purchase, email privacy@round-table.ai. We verify the request using the account or purchase email and respond within the period required by applicable law.
Second Opinion AI-Provider Controls
The Second Opinion intentionally compares results from four commercial AI-provider categories. It is not fulfilled through a facilitator's personal or free consumer chat accounts. The service will not launch until the organization-owned accounts, contracts, settings, and technical checks below are verified.
| Provider category | Required launch configuration | Retention and feature limitation to understand |
|---|---|---|
| Anthropic Claude commercial API | Organization-owned commercial API workspace; training/feedback use disabled; approved zero-data-retention configuration where contracted | Ordinary commercial API inputs and outputs are generally deleted within 30 days; safety-flagged content, feedback, files, caching, batch, beta, and search features can follow different rules |
| OpenAI API | Paid organization/project; training, feedback, evaluation, and data-sharing opt-ins disabled; stateless calls with storage disabled; approved zero-data-retention or modified abuse-monitoring terms where required | API business data is not used for training by default, but abuse-monitoring logs can retain content for up to 30 days; stored responses, files, threads, tools, background work, and external connectors have separate retention |
| Google paid Gemini API or contracted enterprise service | Active billing on the exact production project; product-improvement use disabled by paid-service terms; approved zero-data-retention configuration where required | Google's published abuse-monitoring period for covered paid Gemini API content can be up to 55 days absent approved zero-data retention; files, caches, grounding, interactions, and session-resumption features have separate rules |
| X.AI LLC commercial API providing Grok | Organization-owned enterprise/API account; personal data submitted only through the zero-data-retention (ZDR) API as required by the current enterprise terms; successful x-zero-data-retention response indication verified | ZDR limits stateful responses, stored files/collections, batch or deferred work, and stored media; the best-evidenced current contracting entity is X.AI LLC (Nevada), which uses the SpaceXAI trade name; published data-processing documentation must be checked for matching entity coverage before use |
For the initial service, only minimized, stateless text is permitted. Customers and facilitators may not use files, provider-side conversation state, stored responses, caches, batch/deferred or background processing, deep research, web/search grounding, external tools/connectors, or feedback submission with Second Opinion content unless that exact feature is separately approved, configured, contracted, and disclosed in writing. The applicable provider end-user terms and acceptable-use policies also apply; Webb Technologies will not use the service to bypass them. We review the provider register at least quarterly and when a provider changes its entity, contract, model, feature, retention, or subprocessor terms.
AI systems can be inaccurate, biased, incomplete, or outdated. Provider agreement is not independent corroboration. Provider names on this page factually identify intended recipients and services; they do not state sponsorship, endorsement, partnership, or approval. X.AI LLC's current enterprise terms require advance written approval for name, logo, or mark use. Counsel must reconcile required privacy-recipient identification with those terms, and Webb Technologies must obtain any required vendor permission before using a provider's name or marks in promotional copy, logos, co-branding, “powered by” claims, or endorsement implications.
Meeting and Recording Control
The launch service does not record or transcribe the human meeting and does not enable automated meeting notes, speaker identification, voiceprints, face templates, emotion analysis, or attention analysis. “AI Interaction Transcript” means only the prompts and responses exchanged with the AI systems.
If a recording or transcription feature is ever proposed, Webb Technologies will first complete a separate legal/privacy review, name the vendor, disclose purpose/access/retention, provide a no-record alternative, and obtain affirmative consent from every participant before capture. Participants are asked not to introduce their own recorder or note-taking bot without everyone's express agreement.
Security Practices
We do not claim formal certifications we do not hold. Current safeguards are summarized in our Security Overview. They include established infrastructure providers, encryption in transit and at rest, infrastructure-as-code, peer review, access control, backups, and incident investigation.
Customers remain responsible for minimizing inputs, limiting authorized recipients, reviewing AI output, and reporting suspected unauthorized disclosure promptly.
Vendors, Subprocessors, and Other Recipients
The table identifies providers used across the platform and the planned Second Opinion flow. “Conditional” means the provider must be named and this list updated before customer information is sent; it does not mean every vendor receives every customer's information. Legal roles differ by activity and jurisdiction.
| Vendor or category | Purpose and information category | Typical processing location/status |
|---|---|---|
| Amazon Web Services | Hosting, networking, encrypted application storage, backups, and security logs | Global infrastructure; configured service locations |
| Anthropic | Claude commercial AI inference; minimized prompts and generated responses | Provider locations and subprocessors under commercial terms |
| OpenAI | API AI inference; minimized prompts and generated responses | Provider locations and subprocessors under commercial terms |
| Gemini paid/enterprise AI inference; minimized prompts and generated responses | Provider locations and subprocessors under commercial terms | |
| X.AI LLC / Grok API | Grok AI inference through ZDR; minimized prompts and generated responses | Current enterprise contracting entity; matching DPA coverage, subprocessors, locations, end-user terms/AUP flow-down, and required name/mark permission must be confirmed before Second Opinion launch |
| Stripe | One-time payments, refunds, subscription billing for other products, fraud prevention, tax/payment records | United States and other Stripe locations |
| Customer.io | Account and marketing communications; Second Opinion receipt, eligibility, booking, delivery, and refund email | United States/EU according to configured workspace and vendor terms; Second Opinion transactional engagement tracking disabled |
| Calendly | Second Opinion scheduling, invitee contact details, appointment time, time zone, and booking status | Conditional on the configured booking workflow; vendor locations/subprocessors |
| Remote meeting provider | Connection, invitation, and attendance metadata; no launch recording or transcription | Conditional; exact provider must appear here and in the invitation before use |
| Plausible Analytics | Cookie-free website audience measurement without persistent visitor identifiers | EU hosting (Germany) |
| Google Analytics 4 | Consent/permission-controlled website analytics and conversion measurement | United States/EU and other Google locations |
Advertising platforms such as Meta and Google may receive bounded conversion identifiers where the Privacy Policy, your choices, and applicable law permit. We do not intentionally send screener answers, business URLs, AI interactions, meeting content, notes, or briefs to advertising or analytics platforms.
We update this page before enabling a new material provider or changing a provider's purpose. Customers that require advance subprocessor notice should arrange it in a written customer agreement.
Current Provider Documents
These links are provided for transparency and change control. They were reviewed for this draft on August 15, 2026; the provider's current online version controls unless Webb Technologies has a negotiated agreement. Counsel and the service owner must recheck them before launch and after a provider notice.
- Anthropic: Commercial Terms, Acceptable Use Policy, Data Processing Addendum, and commercial retention explanation
- OpenAI: Services Agreement, Usage Policies, Data Processing Addendum, and API data controls
- Google Gemini: API Additional Terms, usage and abuse-monitoring policy, zero-data-retention guidance, and processor terms
- X.AI/Grok: Enterprise Terms, Acceptable Use Policy, Data Processing Addendum, and security/ZDR FAQ
Retention and Deletion
The Privacy Policy contains the controlling category-by-category schedule. The Second Opinion launch targets are 30 days for abandoned screeners, 90 days for session content and deliverables, 24 months for limited fulfillment/eligibility metadata, up to 12 months for security logs, and seven years or the legally required period for contract, payment, refund, and tax records. Narrow preservation holds may apply to disputes, incidents, government requests, or legal claims.
Release Governance
Before accepting Second Opinion payment, Webb Technologies requires:
- attorney review of the actual landing page, Service Terms, Refund Policy, Privacy notice, checkout assent, target states, and facilitator script;
- verified organization-owned AI accounts, DPAs/settings, and a provider configuration record;
- a point-of-collection safe-data notice before the first free-text field;
- a no-recording meeting configuration and host checklist;
- immutable evidence of the offer, quote, legal-document versions, and assent;
- tested eligibility, delivery, reschedule, no-show, refund, no-account privacy-rights, retention, and deletion workflows; and
- a claim register tying price, inventory, delivery, and refund statements to an operating system and owner.
This release checklist is a control specification, not a statement that every gate has already passed. The durable implementation plan is maintained in the product repository and must be signed off by accountable product, engineering, operations, privacy, and legal owners.
Questions, DPA requests, or vendor due-diligence requests may be sent to compliance@round-table.ai.