Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
PlanetScale revised how its Privacy Policy applies to enterprise customer data. Previously, the policy stated it does not govern data processed on behalf of enterprise customers. The updated language now specifies that such processing is governed by a Data Processing Addendum or Business Associate Agreement between the parties, and clarifies that the Privacy Policy continues to govern PlanetScale's processing of personal information it controls.
The updated terms clarify that PlanetScale's Privacy Policy continues to govern personal information it processes as a controller. For enterprise customers, data processing is explicitly governed by separate Data Processing Addendum or Business Associate Agreements rather than this Privacy Policy. This is a clarification of existing practice rather than a material operational change.
The updated language clarifies the governance structure for enterprise customer data, explicitly confirming that such processing is governed by separate Data Processing Addendums or Business Associate Agreements rather than the Privacy Policy alone. This formalization helps enterprise customers and their data protection officers understand which agreement governs their data and aligns with standard GDPR and data protection practices that separate controller and processor obligations.
Explicitly distinguishes between data governed by Privacy Policy (data PlanetScale controls) and data governed by DPAs/BAAs (enterprise customer data processed as service provider or processor).
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
PlanetScale clarified the scope of its Privacy Policy to explicitly reference Data Processing Addendums (DPAs) and Business Associate Agreements (BAAs) for enterprise customer data processing. The change establishes that such processing falls outside the Privacy Policy and is instead governed by separate data processing agreements. This is a structural clarification that aligns with standard GDPR and data protection practice, where processor responsibilities are typically documented in DPAs separate from privacy notices. For organizations using PlanetScale as a vendor, this change confirms existing governance structure but formalizes the distinction between controller and processor roles.
ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003964.