Resultsdirect
resultsdirect.comResults Direct provides websites, mobile apps and AI solutions to associations, acting primarily as a service provider processing personal information on behalf of its clients. The single available document is a privacy policy that claims GDPR/UK DPA compliance, participation in the EU-U.S. Data Privacy Framework, and use of Standard Contractual Clauses — but it is silent on core commercial concerns: input/output data ownership, whether user data or AI prompts are used to train models, retention schedules beyond a one-month backup window, security controls, and human review. No terms of service, DPA, or enterprise agreement was accessible. The product markets AI Solutions prominently, yet the policy never addresses AI/ML processing or third-party model providers, creating a meaningful policy-product coverage gap. Businesses handling sensitive or proprietary data should obtain contractual protections (a DPA and no-training commitment) before relying on the AI features.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The policy frames Results Direct as processing personal information on behalf of its clients and their users, implying the client retains ownership, but it never expressly states who owns submitted data, prompts, or files. Absent a terms of service or DPA, input data ownership is undefined.
Output Data Ownership
The document is entirely silent on ownership of AI-generated content or outputs, despite the product marketing AI Solutions. No terms of service was accessible to establish output ownership.
Training Data Usage
The policy states product-collected information is used only in association with client services, which weighs against training use, but it never explicitly addresses whether user inputs or AI prompts are used to train or improve models. Given the product ships AI Solutions, this silence is a material gap.
Data Retention & Deletion
The policy grants erasure rights and states backups are retained about one month after removal, but it provides no primary-data retention schedule, no deletion SLA, and no security-related retention obligations. Deletion appears to be handled via a contact request rather than a self-service mechanism.
Third-Party Data Sharing
Website/event data is shared with an email marketing provider and with publicly disclosed event sponsors, and data may be shared with authorities under lawful-request conditions. The disclosures are reasonably clear and tied to stated purposes, but there is no sub-processor list and no explicit statement that data is never sold.
Opt-Out Rights
The policy references product features that respect user choice about sharing personal information and grants rights to object to or restrict processing, but these are exercised via contact request rather than clear self-service controls, and no explicit opt-out of marketing or training is described. Rights language derives largely from GDPR framing.
Compliance & Certifications
The policy claims GDPR and UK DPA compliance, uses EU Standard Contractual Clauses, and asserts participation in the EU-U.S. Data Privacy Framework and UK Extension, referencing a certification on the DPF website. However, no SOC 2, ISO 27001/27018, or other independent audit attestations are named, and the DPF participation is asserted rather than evidenced with a certificate reference in the text.
Model Explainability & Auditability
The document provides no information on model behavior transparency, explainability, or enterprise auditing capabilities, despite the product marketing AI Solutions. This is a complete silence on a topic relevant to an AI product.
Security Practices & Breach History
The policy makes a general commitment to information security and references a separate privacy-and-security contact page, but discloses no specific controls (encryption, access controls, penetration testing, bug bounty, incident response) and no breach history. The referenced security page was inaccessible, so no detail could be verified.
Enterprise vs. Consumer Risk Delta
Results Direct operates a B2B model serving associations rather than distinct free/paid consumer tiers, and no enterprise agreement was accessible. The single policy does not differentiate data handling by tier, so any material differences between client contracts and this public policy cannot be assessed.
Human Review of User Inputs
The policy does not state whether staff may read or access user prompts or outputs. It permits access and disclosure for fraud/security/technical purposes and lawful requests, which implies some personnel access, but there is no explicit human-review clause.
Regulatory & Litigation Exposure
The policy addresses cooperation with public authorities and law enforcement and acknowledges it is subject to FTC enforcement and DPA/ICO complaint processes. It discloses no active litigation. The lawful-disclosure language is broad but standard.
PII & SPI Data Inventory
The policy identifies limited PII collected directly (name, email, and via forms phone, company, country) plus product-related data such as push-notification identifiers. It does not enumerate a full data inventory and does not appear to collect SPI, but the categories collected through products are described only generally.
Policy–Product Currency
No explicit effective or last-updated date appears in the policy text, though asset URLs referencing 2026 suggest recent maintenance. The product prominently markets AI Solutions and an 'AI Advisor,' yet the policy never addresses AI/ML processing, model training, or third-party model providers — a partial-coverage gap. Rating is capped by the absence of a discoverable date and the AI coverage gap.
Cross-Document Consistency
Three copies of the same privacy policy were supplied at different URLs; they are substantively identical, so no cross-document conflict of legal terms exists among distinct document types. No terms of service, DPA, or security page was accessible for a genuine cross-document comparison, limiting this assessment.
You've read all 15 risk ratings for Resultsdirect. Create a free account to see the exact policy wording behind each rating.