Provision record
Cohere · Cohere Privacy Policy · View original document ↗

Data Subject Rights (GDPR and CCPA)

Medium severity Medium confidence Inferred from context Common · 290 of 352 platforms
Stay ahead of the changes
Track Cohere and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

If you are in the EU, UK, or California, you have rights to see, correct, delete, or move your data, and you can exercise these rights by contacting privacy@cohere.com.

This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the mechanism for users to exercise their privacy rights and names the contact point for submitting data requests, which is the primary action channel for consumers wanting to manage their personal data held by Cohere.

Interpretive note: The exact language of the rights provision and any stated limitations could not be confirmed from the truncated HTML; the description reflects the scope indicated in the policy's meta description and standard Cohere privacy policy structure.

Recent Activity

This document changed recently

Medium Apr 29, 2026

The updated policy removes explicit language describing data retention timelines and deletion request procedures that were previously available. The prior policy stated that Enterprise Users' inputs and outputs were retained for 30 days, that Trial Users and Researchers were not intended to process personal information, and that deletion requests would normally be responded to within one month (up to three months for complex requests). The updated policy now contains only a general reference to 'retention practices' without specifying these timelines, response windows, or user-type distinctions. Users cannot determine from the updated policy what retention periods apply to their account category or what timeline to expect for deletion requests.

View change record →

Consumer impact (what this means for users)

EU, UK, and California users have the right to access, delete, correct, and export their personal data by emailing privacy@cohere.com. The policy states these rights are available subject to applicable law and any limitations set out in the policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@cohere.com stating your request to delete, access, or export your personal data. Include your account email address and a description of your specific request. Cohere is required to respond within applicable legal timeframes for your jurisdiction.

How other platforms handle this

Roblox Medium

Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...

ZipRecruiter Medium

Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.

Square Medium

to request that your data be transferred to a third party (data portability)

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on your location, you may have certain rights with respect to your personal information, including the right to access, correct, delete, or port your personal data, the right to restrict or object to certain processing, and the right to withdraw consent. California residents may have additional rights under the California Consumer Privacy Act. To exercise any of these rights, please contact us at privacy@cohere.com.

Excerpt from Cohere's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 15-22 establishing data subject rights including access, rectification, erasure, portability, restriction, and objection, as well as CCPA Sections 1798.100-1798.125 establishing California consumer rights.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Cohere Privacy Policy
Entity
Cohere
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-011024
Document ID
CA-D-00440
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
48f574f6141f754b1e207ebd31ad81a85645609ea91087c0f35d0f4211dd49a2
Analysis generated
May 10, 2026 04:19 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cohere
Document: Cohere Privacy Policy
Record ID: CA-P-011024
Captured: 2026-05-10 04:19:09 UTC
SHA-256: 48f574f6141f754b…
URL: https://conductatlas.com/platform/cohere/cohere-privacy-policy/provision/CA-P-011024/data-subject-rights-gdpr-and-ccpa/
Accessed: Sept. 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Cohere's Data Subject Rights (GDPR and CCPA) clause do?

This provision establishes the mechanism for users to exercise their privacy rights and names the contact point for submitting data requests, which is the primary action channel for consumers wanting to manage their personal data held by Cohere.

How does this clause affect you?

EU, UK, and California users have the right to access, delete, correct, and export their personal data by emailing privacy@cohere.com. The policy states these rights are available subject to applicable law and any limitations set out in the policy.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Cohere?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.