Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Privacy Statement explicitly excludes Glean's enterprise products and services (Solutions) from its scope, applying only to website interactions and general business operations.
This analysis describes what Glean's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that users and organizations accessing Glean's enterprise AI search products are governed by separate agreements, not this statement, requiring procurement and compliance teams to identify and evaluate those separate data processing agreements to understand applicable data governance obligations.
Under this clause, individuals whose employers have deployed Glean Solutions are not covered by this Privacy Statement; the applicable data controller in those contexts is the customer organization, and data subject rights must be directed accordingly.
Cross-platform context
See how other platforms handle Scope Exclusion: Solutions Products and similar clauses.
Compare across platforms →Monitoring
Glean has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"This Privacy Statement does not apply to your use of our products and services (collectively, 'Solutions'). This Privacy Statement applies to all Glean websites and Business Operations that link to or reference it.Excerpt from Glean's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 28, which requires data processing agreements between controllers and processors, and CCPA's service provider framework. Where Glean acts as a processor for enterprise customers, the statement confirms the customer organization is the data controller, meaning GDPR and CCPA obligations for those data flows rest with the customer entity, not Glean directly. 2) GOVERNANCE EXPOSURE: Medium. The explicit scope exclusion is operationally clear, but it creates a documentation gap for enterprise customers who may not have separately located and reviewed applicable DPAs or service agreements governing Solutions data flows. 3) JURISDICTION FLAGS: EU and UK customers are subject to GDPR Article 28 processor agreement requirements; California enterprise customers should assess whether Glean's separate Solutions agreements include required CCPA service provider terms. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams onboarding Glean should confirm that a separate data processing agreement or equivalent instrument governs Solutions data, and that it addresses controller-processor obligations, subprocessor disclosure, and audit rights consistent with applicable law. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should map all Glean data flows across both the website/business operations context (governed by this statement) and the Solutions context (governed by separate agreements) to ensure complete data inventory and accurate privacy notice coverage.
This provision establishes that users and organizations accessing Glean's enterprise AI search products are governed by separate agreements, not this statement, requiring procurement and compliance teams to identify and evaluate those separate data processing agreements to understand applicable data governance obligations.
Under this clause, individuals whose employers have deployed Glean Solutions are not covered by this Privacy Statement; the applicable data controller in those contexts is the customer organization, and data subject rights must be directed accordingly.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Glean.