A cloud-based data analytics platform that provides unified analytics for big data and machine learning, enabling organizations to process, analyze, and derive insights from large datasets. The company offers collaborative workspaces where data scientists, engineers, and analysts can work together on data projects using popular programming languages and frameworks. Their policies are relevant to consumers because they govern how user data, code, and analytical outputs are handled, stored, and potentially shared within their cloud infrastructure.
High, provisions that significantly limit your legal rights, authorize broad data collection, or create material financial exposure. Medium, provisions worth knowing about but with partial protections or limited scope. Low, standard terms with minimal consumer impact.
Higher = more protective of you, the user/customer — a deliberately user-protective lens, not a universal “good vs bad” score. Computed algorithmically from Databricks’s cited governance stances; no dimension we haven’t confidently read is ever counted against the score. Free, reproducible, and never purchasable.
The prohibition covers all metadata generated by the Services and explicitly reaches audit logs and credentials, which are operationally sensitive data types.
Strict access controls on internal employees directly limit the insider-threat surface for production systems and customer data.
The materiality threshold means that no penetration test can be closed as passing while material vulnerabilities remain unresolved, creating a mandatory remediation gate.
Explicitly prioritizing Severity-0 vulnerabilities above other rollouts means the most critical threats, including zero-day exploits, are structurally moved to the front of the remediation queue.
Requiring security scanning before production promotion creates a gatekeeping step that prevents unscanned code or images from reaching the live environment.
This document explains the security measures Databricks has committed to following to protect customer data, and those commitments are written into the customer contract — not just an informal policy. …
This policy sets out the rules for what you can and cannot do when using Databricks Services. You cannot use the platform to attack or disrupt services, build competing products, …
This document sets the rules for using Databricks' websites and content. Databricks gives you a revocable, limited license to use its Sites but can take it away at any time …
This notice explains what personal information Databricks collects about you, how long it keeps it, and who it shares it with — including advertisers, business partners, and event sponsors who …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
ConductAtlas tracks 4 Databricks documents including terms of service, privacy policy, and other governance documents. Every document is captured daily with cryptographic verification.
Databricks has made 4 policy changes in the past 12 months across the documents ConductAtlas tracks.
ConductAtlas has classified 53 provisions across Databricks's tracked documents. 3 are rated high severity, 34 medium, and 16 low.
Yes. Monitor subscribers ($4.99/month) can add Databricks to their watchlist and receive same-day email alerts whenever any tracked document changes.