Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that individuals may access, correct, update, delete, object to, restrict, or request portability of their Personal Data, subject to legal exceptions. Users may also opt out of marketing emails and complain to a supervisory authority. These rights are exercised by contacting privacy@harvey.ai.
This analysis describes what Harvey AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the available data subject rights mechanisms and confirms access to regulatory complaint channels including EU DPAs and the UK ICO. The rights are subject to exceptions and exemptions, and the scope of available rights varies by jurisdiction as described in the Jurisdiction Specific Provisions section.
Under these terms, users can submit access, correction, deletion, restriction, portability, and objection requests to Harvey at privacy@harvey.ai. The agreement states Harvey responds to all requests in accordance with applicable data protection laws. Marketing email opt-out is available via the unsubscribe link in each email, and supervisory authority complaints are available for EU and UK residents.
Cross-platform context
See how other platforms handle Data Subject Rights and Supervisory Authority Complaint Rights and similar clauses.
Compare across platforms →Monitoring
Harvey AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Subject to certain exceptions and exemptions provided by law and where applicable, you may: Access, correct, update, or request deletion of your Personal Data. Object to processing of your personal data, ask us to restrict processing of your Personal Data. Request portability of your personal data, (i.e. your data to be transferred in a readable and standardised format). Opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the "unsubscribe" or "opt-out" link in the marketing emails we send you. Have the right to complain to a supervisory authority. For more information, please contact your local supervisory authority. Contact details for supervisory authorities in the EU are available here and for the UK here.Excerpt from Harvey AI's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision reflects data subject rights under GDPR Articles 15 through 22, UK GDPR equivalents, CCPA access and deletion rights, and Canadian provincial privacy law access and correction rights. The right to lodge a complaint with a supervisory authority is established under GDPR Article 77. The FTC holds enforcement jurisdiction over DPF-related complaints as noted elsewhere in the policy. (2) GOVERNANCE EXPOSURE: Low. The disclosure of data subject rights and supervisory authority complaint pathways is a standard requirement under GDPR, UK GDPR, and comparable frameworks. The policy's statement that rights are subject to exceptions and exemptions is standard and consistent with applicable law. The operational concern is whether Harvey's response processes are adequately resourced and timely for GDPR's one-month response requirement. (3) JURISDICTION FLAGS: EU and UK data subjects have enforceable rights under GDPR and UK GDPR with supervisory authority oversight. California residents have CCPA rights with enforcement by the CPPA and California AG. Quebec residents have additional rights under Law 25 including portability and cessation-of-dissemination rights as described in the Canada section. Canadian residents generally have access and correction rights subject to provincial law. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees use Harvey as end users should confirm their Customer Agreements address how Harvey as Data Processor assists the Customer as Data Controller in responding to data subject requests for Customer Data, consistent with GDPR Article 28(3)(e). (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the privacy@harvey.ai intake process is operationally capable of meeting GDPR's one-month response deadline and of routing requests related to Customer Data to the appropriate Customer organization. Identity verification procedures for data subject requests should be documented to avoid both unauthorized disclosure and unnecessary barriers to rights exercise.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the available data subject rights mechanisms and confirms access to regulatory complaint channels including EU DPAs and the UK ICO. The rights are subject to exceptions and exemptions, and the scope of available rights varies by jurisdiction as described in the Jurisdiction Specific Provisions section.
Under these terms, users can submit access, correction, deletion, restriction, portability, and objection requests to Harvey at privacy@harvey.ai. The agreement states Harvey responds to all requests in accordance with applicable data protection laws. Marketing email opt-out is available via the unsubscribe link in each email, and supervisory authority complaints are available for EU and UK residents.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Harvey AI.