Provision record
Cursor · Cursor Privacy Policy · View original document ↗

Enterprise Data Processor Carve-Out

High severity High confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

If your employer or another organization set up your Cursor account, this privacy policy may not apply to you. Instead, how your data is handled is governed by the contract between Anysphere and that organization.

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Employees or users whose accounts are provisioned by an organization may not have the same rights or protections described in this policy; their data rights depend entirely on the terms of the agreement between their employer and Anysphere.

Consumer impact (what this means for users)

The policy states it does not govern data processing for employer-provisioned accounts; those users' data rights depend on the employer's customer agreement with Anysphere, which the employee may not have direct access to.

How other platforms handle this

ZipRecruiter Medium

Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.

Square Medium

to request that your data be transferred to a third party (data portability)

Google Cloud Medium

Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Please note that this Privacy Policy does not apply where Anysphere acts as a data processor and processes personal data on behalf of commercial customers using our commercial services, for example, if your employer has provisioned a Cursor account for you to use at work. Our use of that data is governed by our customer agreements covering access to and use of those offerings.

Excerpt from Cursor's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 28 (processor obligations) for EEA users, as commercial customer agreements must include Data Processing Agreement terms meeting GDPR requirements.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Cursor Privacy Policy
Entity
Cursor
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 12, 2026
Record ID
CA-P-011600
Document ID
CA-D-00452
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1e5849a4a5fbaa739f760d04f8a003ee1ec366c9f4216cb1cb0ea9b8cf9d01f3
Analysis generated
May 7, 2026 17:01 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cursor
Document: Cursor Privacy Policy
Record ID: CA-P-011600
Captured: 2026-05-07 17:01:07 UTC
SHA-256: 1e5849a4a5fbaa73…
URL: https://conductatlas.com/platform/cursor/cursor-privacy-policy/provision/CA-P-011600/enterprise-data-processor-carve-out/
Accessed: Sept. 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Cursor's Enterprise Data Processor Carve-Out clause do?

Employees or users whose accounts are provisioned by an organization may not have the same rights or protections described in this policy; their data rights depend entirely on the terms of the agreement between their employer and Anysphere.

How does this clause affect you?

The policy states it does not govern data processing for employer-provisioned accounts; those users' data rights depend on the employer's customer agreement with Anysphere, which the employee may not have direct access to.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.