Skip to main content
Policy

Compliance Overview

How Roundtable AI approaches privacy law, AI-provider governance, data protection, and vendor transparency.

Last updated August 16, 2026

Roundtable is a product and brand owned and operated by Webb Technologies LLC (“Webb Technologies,” “we,” “us,” or “our”). We keep our compliance posture honest: this page distinguishes practices in operation from mandatory controls for services that have not launched. It is not a certification or a substitute for your own legal review. For procurement or legal questions, email compliance@round-table.ai.

Our Role Depends on the Service

Webb Technologies may act as a business/controller for account, purchase, eligibility, security, and direct-customer administration information. When an organizational customer submits personal information for processing through the Roundtable platform, Webb Technologies may instead act as that customer's service provider/processor for that content. The actual role depends on the information, purpose, contract, and applicable law.

We provide an appropriate Data Processing Addendum when required and supported for the service. Where a covered transfer of personal data leaves the EEA or UK, the applicable vendor and customer agreements use a recognized transfer mechanism, such as the Standard Contractual Clauses, where required.

Data Handling and Access

  • Webb Technologies uses contracted cloud infrastructure, including Amazon Web Services, for Roundtable application hosting and storage.
  • Access to production data is limited by role, and privileged access is logged.
  • We encrypt application data in transit and at rest and manage service credentials separately from application content.
  • We minimize information before sending it to an AI provider and prohibit regulated, privileged, credential, and highly sensitive content from the Second Opinion.
  • We publish collection purposes, recipient categories, retention, and no-account rights in the Privacy Policy.

Privacy Regulations and Choices

  • GDPR / UK GDPR: applicable rights requests and processor obligations are handled according to Webb Technologies' role for the relevant processing. Covered transfers use the contractual safeguard described above.
  • CCPA / CPRA and similar U.S. state laws: we do not sell personal information for money. Some analytics or advertising disclosures may constitute “sharing” or targeted advertising. Use “Your Privacy Choices” or Global Privacy Control (GPC) to opt out where applicable; GPC also suppresses applicable Second Opinion advertising signals.
  • Other regional laws: access, correction, deletion, portability, objection, and appeal requests are handled through the privacy inbox according to the law that applies.

The Second Opinion is initially limited to U.S.-based businesses with adult participants physically located in the United States. That limit is a launch control; it does not change rights that apply to information Webb Technologies already holds through another Roundtable service.

To exercise a right, including for a no-account Second Opinion purchase, email privacy@round-table.ai. We verify the request using the account or purchase email and respond within the period required by applicable law.

Second Opinion AI-Provider Controls

The Second Opinion intentionally compares results from four commercial AI-provider categories. It is not fulfilled through a facilitator's personal or free consumer chat accounts. The service will not launch until the organization-owned accounts, contracts, settings, and technical checks below are verified.

Provider categoryRequired launch configurationRetention and feature limitation to understand
Anthropic Claude commercial APIOrganization-owned commercial API workspace; training/feedback use disabled; approved zero-data-retention configuration where contractedOrdinary commercial API inputs and outputs are generally deleted within 30 days; safety-flagged content, feedback, files, caching, batch, beta, and search features can follow different rules
OpenAI APIPaid organization/project; training, feedback, evaluation, and data-sharing opt-ins disabled; stateless calls with storage disabled; approved zero-data-retention or modified abuse-monitoring terms where requiredAPI business data is not used for training by default, but abuse-monitoring logs can retain content for up to 30 days; stored responses, files, threads, tools, background work, and external connectors have separate retention
Google paid Gemini API or contracted enterprise serviceActive billing on the exact production project; product-improvement use disabled by paid-service terms; approved zero-data-retention configuration where requiredGoogle's published abuse-monitoring period for covered paid Gemini API content can be up to 55 days absent approved zero-data retention; files, caches, grounding, interactions, and session-resumption features have separate rules
X.AI LLC commercial API providing GrokOrganization-owned enterprise/API account; personal data submitted only through the zero-data-retention (ZDR) API as required by the current enterprise terms; successful x-zero-data-retention response indication verifiedZDR limits stateful responses, stored files/collections, batch or deferred work, and stored media; the best-evidenced current contracting entity is X.AI LLC (Nevada), which uses the SpaceXAI trade name; published data-processing documentation must be checked for matching entity coverage before use

For the initial service, only minimized, stateless text is permitted. Customers and facilitators may not use files, provider-side conversation state, stored responses, caches, batch/deferred or background processing, deep research, web/search grounding, external tools/connectors, or feedback submission with Second Opinion content unless that exact feature is separately approved, configured, contracted, and disclosed in writing. The applicable provider end-user terms and acceptable-use policies also apply; Webb Technologies will not use the service to bypass them. We review the provider register at least quarterly and when a provider changes its entity, contract, model, feature, retention, or subprocessor terms.

AI systems can be inaccurate, biased, incomplete, or outdated. Provider agreement is not independent corroboration. Provider names on this page factually identify intended recipients and services; they do not state sponsorship, endorsement, partnership, or approval. X.AI LLC's current enterprise terms require advance written approval for name, logo, or mark use. Counsel must reconcile required privacy-recipient identification with those terms, and Webb Technologies must obtain any required vendor permission before using a provider's name or marks in promotional copy, logos, co-branding, “powered by” claims, or endorsement implications.

Meeting and Recording Control

The launch service does not record or transcribe the human meeting and does not enable automated meeting notes, speaker identification, voiceprints, face templates, emotion analysis, or attention analysis. “AI Interaction Transcript” means only the prompts and responses exchanged with the AI systems.

If a recording or transcription feature is ever proposed, Webb Technologies will first complete a separate legal/privacy review, name the vendor, disclose purpose/access/retention, provide a no-record alternative, and obtain affirmative consent from every participant before capture. Participants are asked not to introduce their own recorder or note-taking bot without everyone's express agreement.

Security Practices

We do not claim formal certifications we do not hold. Current safeguards are summarized in our Security Overview. They include established infrastructure providers, encryption in transit and at rest, infrastructure-as-code, peer review, access control, backups, and incident investigation.

Customers remain responsible for minimizing inputs, limiting authorized recipients, reviewing AI output, and reporting suspected unauthorized disclosure promptly.

Vendors, Subprocessors, and Other Recipients

The table identifies providers used across the platform and the planned Second Opinion flow. “Conditional” means the provider must be named and this list updated before customer information is sent; it does not mean every vendor receives every customer's information. Legal roles differ by activity and jurisdiction.

Vendor or categoryPurpose and information categoryTypical processing location/status
Amazon Web ServicesHosting, networking, encrypted application storage, backups, and security logsGlobal infrastructure; configured service locations
AnthropicClaude commercial AI inference; minimized prompts and generated responsesProvider locations and subprocessors under commercial terms
OpenAIAPI AI inference; minimized prompts and generated responsesProvider locations and subprocessors under commercial terms
GoogleGemini paid/enterprise AI inference; minimized prompts and generated responsesProvider locations and subprocessors under commercial terms
X.AI LLC / Grok APIGrok AI inference through ZDR; minimized prompts and generated responsesCurrent enterprise contracting entity; matching DPA coverage, subprocessors, locations, end-user terms/AUP flow-down, and required name/mark permission must be confirmed before Second Opinion launch
StripeOne-time payments, refunds, subscription billing for other products, fraud prevention, tax/payment recordsUnited States and other Stripe locations
Customer.ioAccount and marketing communications; Second Opinion receipt, eligibility, booking, delivery, and refund emailUnited States/EU according to configured workspace and vendor terms; Second Opinion transactional engagement tracking disabled
CalendlySecond Opinion scheduling, invitee contact details, appointment time, time zone, and booking statusConditional on the configured booking workflow; vendor locations/subprocessors
Remote meeting providerConnection, invitation, and attendance metadata; no launch recording or transcriptionConditional; exact provider must appear here and in the invitation before use
Plausible AnalyticsCookie-free website audience measurement without persistent visitor identifiersEU hosting (Germany)
Google Analytics 4Consent/permission-controlled website analytics and conversion measurementUnited States/EU and other Google locations

Advertising platforms such as Meta and Google may receive bounded conversion identifiers where the Privacy Policy, your choices, and applicable law permit. We do not intentionally send screener answers, business URLs, AI interactions, meeting content, notes, or briefs to advertising or analytics platforms.

We update this page before enabling a new material provider or changing a provider's purpose. Customers that require advance subprocessor notice should arrange it in a written customer agreement.

Current Provider Documents

These links are provided for transparency and change control. They were reviewed for this draft on August 15, 2026; the provider's current online version controls unless Webb Technologies has a negotiated agreement. Counsel and the service owner must recheck them before launch and after a provider notice.

Retention and Deletion

The Privacy Policy contains the controlling category-by-category schedule. The Second Opinion launch targets are 30 days for abandoned screeners, 90 days for session content and deliverables, 24 months for limited fulfillment/eligibility metadata, up to 12 months for security logs, and seven years or the legally required period for contract, payment, refund, and tax records. Narrow preservation holds may apply to disputes, incidents, government requests, or legal claims.

Release Governance

Before accepting Second Opinion payment, Webb Technologies requires:

  • attorney review of the actual landing page, Service Terms, Refund Policy, Privacy notice, checkout assent, target states, and facilitator script;
  • verified organization-owned AI accounts, DPAs/settings, and a provider configuration record;
  • a point-of-collection safe-data notice before the first free-text field;
  • a no-recording meeting configuration and host checklist;
  • immutable evidence of the offer, quote, legal-document versions, and assent;
  • tested eligibility, delivery, reschedule, no-show, refund, no-account privacy-rights, retention, and deletion workflows; and
  • a claim register tying price, inventory, delivery, and refund statements to an operating system and owner.

This release checklist is a control specification, not a statement that every gate has already passed. The durable implementation plan is maintained in the product repository and must be signed off by accountable product, engineering, operations, privacy, and legal owners.

Questions, DPA requests, or vendor due-diligence requests may be sent to compliance@round-table.ai.