TestFit
testfit.ioTestFit shows good data protection practices with GDPR compliance and standard security measures, but lacks transparency around AI model training usage of user inputs and has limited user control options. The service appears designed for architectural/planning professionals with reasonable enterprise protections, though some key policies around AI training and data retention could be clearer.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Customer retains ownership of all data submitted to the platform. The terms clearly state that Customer Data remains with the customer, and TestFit only receives necessary rights to process the data for service delivery.
Output Data Ownership
Output ownership is not explicitly addressed in the terms. While customer data ownership is preserved, there's no clear statement about who owns the AI-generated outputs or results produced by the service.
Training Data Usage
The policy does not explicitly address whether user inputs are used for AI model training. While Usage Data is assigned to TestFit, there's no clear opt-out mechanism or transparency about model training practices.
Data Retention & Deletion
Data retention policies are limited. The DPA mentions deletion upon termination, but lacks specific retention schedules or user-initiated deletion rights during active service. TestFit may retain data in backups indefinitely.
Third-Party Data Sharing
The service uses subprocessors for data processing, which is appropriately disclosed in the DPA. TestFit provides notification of subprocessor changes and maintains appropriate contracts with subprocessors to protect customer data.
Opt-Out Rights
Limited opt-out rights are provided. Customers can object to new subprocessors with reasonable grounds, but there are no explicit opt-out mechanisms for data collection or AI model training usage.
Compliance & Certifications
TestFit demonstrates strong compliance with GDPR through their comprehensive Data Processing Addendum, including Standard Contractual Clauses and UK Addendum. They reference an Information Security Policy and appear to follow European data protection standards.
Model Explainability & Auditability
Limited transparency is provided about model behavior. The DPA includes audit rights for data processing compliance, but there's no specific mention of AI model explainability or algorithmic transparency features.
Security Practices & Breach History
TestFit references comprehensive security measures in their Information Security Policy and commits to prompt breach notification. They implement appropriate technical and organizational measures for data protection.
Enterprise vs. Consumer Risk Delta
The service offers differentiated tiers including free trial, educational, and paid enterprise versions. Paid customers receive additional features and service level agreements, with appropriate protections for enterprise users.
Human Review of User Inputs
The policy does not explicitly address human review of user inputs. While confidentiality obligations exist for personnel, there's no clear statement about when or if human staff may access customer prompts or outputs.
Regulatory & Litigation Exposure
TestFit acknowledges standard obligations to comply with government data requests and law enforcement cooperation as required by law, with appropriate notification to customers where legally permissible.
PII & SPI Data Inventory
TestFit collects minimal PII including name, email address, job title/role, employer, and usage data. No sensitive personal information is mentioned as being collected, which is appropriate for their architectural planning service.
You've read all 15 risk ratings for TestFit. Create a free account to see the exact policy wording behind each rating.