The policy states that data processed by AI21 on behalf of enterprise customers is excluded from this policy's scope, and that the enterprise customer bears responsibility for consent, notices, security, and data subject requests related to that data.
This analysis describes what AI21 Labs's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that end users of AI21-powered products built by third-party businesses are not covered by this policy and must direct privacy inquiries to the deploying business. This structural allocation of responsibility means AI21's privacy commitments in this document do not extend to data processed within enterprise customer deployments.
Under this clause, individuals whose data is processed by AI21 as part of a third-party enterprise customer's product are not covered by this privacy policy. The agreement directs such individuals to contact the deploying business rather than AI21 for data subject requests and privacy inquiries.
Cross-platform context
See how other platforms handle Customer Information Exclusion from Policy Scope and similar clauses.
Compare across platforms →"For the avoidance of doubt, AI21 processes the Customer Information (defined below) on behalf of the applicable customer. Therefore, the customer is the party responsible for the security, integrity and authorized usage of Customer Information in the context of the services and for obtaining all the necessary consents and permissions and providing all notices required for the collection and usage of such Customer Information and honoring all data subject requests... Customer Information is not regulated by this Privacy Policy, and this paragraph is provided only for transparency purposes. If you have any questions related to the Customer Information, please contact the customer directly.Excerpt from AI21 Labs's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision reflects a processor-controller relationship structure under GDPR Article 28, under which AI21 acts as data processor for enterprise customers who serve as controllers.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that end users of AI21-powered products built by third-party businesses are not covered by this policy and must direct privacy inquiries to the deploying business. This structural allocation of responsibility means AI21's privacy commitments in this document do not extend to data processed within enterprise customer deployments.
Under this clause, individuals whose data is processed by AI21 as part of a third-party enterprise customer's product are not covered by this privacy policy. The agreement directs such individuals to contact the deploying business rather than AI21 for data subject requests and privacy inquiries.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AI21 Labs.