If you use Cohere's API to process personal data, a separate Data Processing Addendum applies that sets out additional privacy and data protection obligations.
This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The DPA structure is the primary mechanism through which GDPR, CCPA, and other data protection obligations are operationalized in the agreement; enterprise customers processing personal data through the API must ensure the DPA is executed and that its terms are consistent with their privacy compliance obligations.
Interpretive note: The full terms of the DPA are not reproduced in this document; the adequacy of DPA protections for specific jurisdictional requirements depends on the DPA's current content at cohere.com/dpa.
The agreement states that a Data Processing Addendum applies when personal data is processed through the API; enterprise customers handling personal data of employees, customers, or other individuals must execute the DPA and ensure its terms satisfy applicable data protection law in their jurisdiction.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"To the extent that Customer's use of the Services involves the processing of personal data, the parties agree to enter into Cohere's Data Processing Addendum (DPA), which is available at cohere.com/dpa and incorporated into this Agreement by reference upon execution.Excerpt from Cohere's SaaS Agreement
(1) REGULATORY LANDSCAPE: The DPA structure directly engages GDPR Articles 28 (processor requirements) and 46 (transfer mechanisms), CCPA's service provider contractual requirements, and equivalent data protection frameworks in other jurisdictions.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The DPA structure is the primary mechanism through which GDPR, CCPA, and other data protection obligations are operationalized in the agreement; enterprise customers processing personal data through the API must ensure the DPA is executed and that its terms are consistent with their privacy compliance obligations.
The agreement states that a Data Processing Addendum applies when personal data is processed through the API; enterprise customers handling personal data of employees, customers, or other individuals must execute the DPA and ensure its terms satisfy applicable data protection law in their jurisdiction.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.