Vannus / Catalog / Google Workspace

Google Workspace

Vannus has not established which model this vendor runs, and does not infer one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracting entity depends on your region or order form — read the clause — under US corporate control on either track, and therefore within reach of US legal process through that control.
Controlled by Alphabet Inc. (United States), per the LEI register, partially corroborated [2026-09-12].
workspace.google.com · read 2026-08-01
read from terms of service

Google's cloud productivity and collaboration suite (Gmail, Drive, Docs, Sheets, Meet, Chat, Calendar) with Gemini generative-AI features bundled as core services across most business editions.

productivity, email, collaboration
What the vendor's own documentation says
Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction.
workspace.google.com ↗ Vendor-sourcedQuote re-checked 14 Sep 2026
Who controls it
US corporate controlRegion-dependent — a US entity contracts in some regions, another elsewhere · clause re-checked 17 Sep 2026
Contracting entityGoogle LLC (United States, and any location not otherwise covered); Google Cloud EMEA Limited for EMEA except France, Italy and Poland
Governing lawCalifornia law, litigated exclusively in the federal or state courts of Santa Clara County, California, for every customer that is not a US government entity; regional modifications carve out APAC, India, MENA, Latin America, Brazil and Mexico, but NOT the EEA
Trains on your dataNo — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Origin
United States

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

Compliance the vendor states
SOC2GDPRISO 27001HIPAA

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit Google Workspace ↗ Grade your whole stack →