Resultsdirect logo

Resultsdirect

resultsdirect.com
Moderate Risk
Updated September 23, 2026

Results Direct provides websites, mobile apps and AI solutions to associations, acting primarily as a service provider processing personal information on behalf of its clients. The single available document is a privacy policy that claims GDPR/UK DPA compliance, participation in the EU-U.S. Data Privacy Framework, and use of Standard Contractual Clauses — but it is silent on core commercial concerns: input/output data ownership, whether user data or AI prompts are used to train models, retention schedules beyond a one-month backup window, security controls, and human review. No terms of service, DPA, or enterprise agreement was accessible. The product markets AI Solutions prominently, yet the policy never addresses AI/ML processing or third-party model providers, creating a meaningful policy-product coverage gap. Businesses handling sensitive or proprietary data should obtain contractual protections (a DPA and no-training commitment) before relying on the AI features.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The policy frames Results Direct as processing personal information on behalf of its clients and their users, implying the client retains ownership, but it never expressly states who owns submitted data, prompts, or files. Absent a terms of service or DPA, input data ownership is undefined.

Confidence
30%

Output Data Ownership

Moderate Risk

The document is entirely silent on ownership of AI-generated content or outputs, despite the product marketing AI Solutions. No terms of service was accessible to establish output ownership.

Confidence
20%

Training Data Usage

Moderate Risk

The policy states product-collected information is used only in association with client services, which weighs against training use, but it never explicitly addresses whether user inputs or AI prompts are used to train or improve models. Given the product ships AI Solutions, this silence is a material gap.

Confidence
35%

Data Retention & Deletion

Moderate Risk

The policy grants erasure rights and states backups are retained about one month after removal, but it provides no primary-data retention schedule, no deletion SLA, and no security-related retention obligations. Deletion appears to be handled via a contact request rather than a self-service mechanism.

Confidence
55%

Third-Party Data Sharing

Moderate Risk

Website/event data is shared with an email marketing provider and with publicly disclosed event sponsors, and data may be shared with authorities under lawful-request conditions. The disclosures are reasonably clear and tied to stated purposes, but there is no sub-processor list and no explicit statement that data is never sold.

Confidence
55%

Opt-Out Rights

Moderate Risk

The policy references product features that respect user choice about sharing personal information and grants rights to object to or restrict processing, but these are exercised via contact request rather than clear self-service controls, and no explicit opt-out of marketing or training is described. Rights language derives largely from GDPR framing.

Confidence
45%

Compliance & Certifications

Moderate Risk

The policy claims GDPR and UK DPA compliance, uses EU Standard Contractual Clauses, and asserts participation in the EU-U.S. Data Privacy Framework and UK Extension, referencing a certification on the DPF website. However, no SOC 2, ISO 27001/27018, or other independent audit attestations are named, and the DPF participation is asserted rather than evidenced with a certificate reference in the text.

Confidence
55%

Model Explainability & Auditability

High Risk

The document provides no information on model behavior transparency, explainability, or enterprise auditing capabilities, despite the product marketing AI Solutions. This is a complete silence on a topic relevant to an AI product.

Confidence
30%

Security Practices & Breach History

Moderate Risk

The policy makes a general commitment to information security and references a separate privacy-and-security contact page, but discloses no specific controls (encryption, access controls, penetration testing, bug bounty, incident response) and no breach history. The referenced security page was inaccessible, so no detail could be verified.

Confidence
35%

Enterprise vs. Consumer Risk Delta

Moderate Risk

Results Direct operates a B2B model serving associations rather than distinct free/paid consumer tiers, and no enterprise agreement was accessible. The single policy does not differentiate data handling by tier, so any material differences between client contracts and this public policy cannot be assessed.

Confidence
25%

Human Review of User Inputs

Moderate Risk

The policy does not state whether staff may read or access user prompts or outputs. It permits access and disclosure for fraud/security/technical purposes and lawful requests, which implies some personnel access, but there is no explicit human-review clause.

Confidence
30%

Regulatory & Litigation Exposure

Moderate Risk

The policy addresses cooperation with public authorities and law enforcement and acknowledges it is subject to FTC enforcement and DPA/ICO complaint processes. It discloses no active litigation. The lawful-disclosure language is broad but standard.

Confidence
55%

PII & SPI Data Inventory

Moderate Risk

The policy identifies limited PII collected directly (name, email, and via forms phone, company, country) plus product-related data such as push-notification identifiers. It does not enumerate a full data inventory and does not appear to collect SPI, but the categories collected through products are described only generally.

Confidence
45%

Policy–Product Currency

Moderate Risk

No explicit effective or last-updated date appears in the policy text, though asset URLs referencing 2026 suggest recent maintenance. The product prominently markets AI Solutions and an 'AI Advisor,' yet the policy never addresses AI/ML processing, model training, or third-party model providers — a partial-coverage gap. Rating is capped by the absence of a discoverable date and the AI coverage gap.

Confidence
45%

Cross-Document Consistency

Moderate Risk

Three copies of the same privacy policy were supplied at different URLs; they are substantively identical, so no cross-document conflict of legal terms exists among distinct document types. No terms of service, DPA, or security page was accessible for a genuine cross-document comparison, limiting this assessment.

Confidence
25%

You've read all 15 risk ratings for Resultsdirect. Create a free account to see the exact policy wording behind each rating.