Harvey AI · Harvey AI Terms of Service · View original document ↗

Confidentiality Obligations

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Harvey AI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Harvey AI Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement establishes mutual confidentiality obligations requiring each party to protect the other's Confidential Information with at least reasonable care, restrict its use to purposes within the scope of the Terms, and limit access to employees and contractors with need-to-know who are bound by equivalent confidentiality obligations. Customer Content and Customer Data are defined as the customer's Confidential Information.

This analysis describes what Harvey AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision defines the contractual confidentiality standard governing Harvey's handling of Customer Content and Customer Data as the customer's Confidential Information. The provision that Harvey cannot unilaterally update terms in a way that detracts from its confidentiality obligations reinforces the enforceability of this standard.

Consumer impact (what this means for users)

Under this clause, Harvey is contractually obligated to protect Customer Content and Customer Data as the customer's Confidential Information, restrict their use to the scope of the Terms, and limit access to personnel with a need-to-know bound by equivalent confidentiality protections. The agreement states that the disclosing party is entitled to seek equitable relief for any disclosure breach.

Cross-platform context

See how other platforms handle Confidentiality Obligations and similar clauses.

Compare across platforms →

Monitoring

Harvey AI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Each party (as the "Receiving Party") will use the same degree of care that it uses to protect the confidentiality of its own confidential information of like kind (but not less than reasonable care) to: (i) not use any Confidential Information of the other party (the "Disclosing Party") for any purpose outside the scope of these Terms; and (ii) except as otherwise authorized by the Disclosing Party in writing, limit access to Confidential Information of the Disclosing Party to those of its and its Affiliates' employees and contractors who need that access for purposes consistent with these Terms and who are bound by confidentiality obligations to the Receiving Party containing protections not materially less protective than this section.

Excerpt from Harvey AI's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The confidentiality provision operates alongside GDPR Article 28 processor obligations, HIPAA confidentiality requirements where a BAA is in effect, and applicable trade secret protections under the Defend Trade Secrets Act and state law. For legal sector customers, attorney-client privilege and professional responsibility rules independently govern the confidentiality of client materials submitted as Customer Data. (2) GOVERNANCE EXPOSURE: Low. The confidentiality standard of reasonable care with access restrictions to need-to-know personnel is consistent with standard commercial practice. The equitable relief provision is a standard mechanism for breaches where monetary damages may be insufficient. (3) JURISDICTION FLAGS: EEA and UK customers benefit from GDPR and UK GDPR obligations that independently require Harvey to implement appropriate technical and organizational measures, operating in parallel with the contractual confidentiality standard. The Data Breach Cap applies to confidentiality breach claims, limiting aggregate monetary recovery to $500,000 or twice annual fees, which may be material context for customers with high-value confidential information. (4) CONTRACT AND VENDOR IMPLICATIONS: The requirement that Subprocessors with access to Customer Data be bound by the DPA ensures that downstream confidentiality obligations extend to Harvey's supply chain. The DPA Subprocessor management provisions should be reviewed to confirm how Harvey monitors and enforces Subprocessor confidentiality compliance. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the confidentiality standard in this Agreement is consistent with applicable professional responsibility rules and any client-specific data handling agreements. The mandatory equitable relief language supports the practical enforceability of confidentiality obligations but does not guarantee specific judicial outcomes.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over data security practices and may evaluate whether Harvey's confidentiality and security measures meet reasonable commercial standards.
    File a complaint →

Provision details

Document information
Document
Harvey AI Terms of Service
Entity
Harvey AI
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074250
Document ID
CA-D-00504
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1d9e48d455ac5024238a11813bc22d4a0522b870f0b746468ac0b9955c0526b3
Analysis generated
July 12, 2026 14:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Harvey AI
Document: Harvey AI Terms of Service
Record ID: CA-P-074250
Captured: 2026-07-12 14:53:43 UTC
SHA-256: 1d9e48d455ac5024…
URL: https://conductatlas.com/platform/harvey-ai/harvey-ai-terms-of-service/provision/CA-P-074250/confidentiality-obligations/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Harvey AI's Confidentiality Obligations clause do?

This provision defines the contractual confidentiality standard governing Harvey's handling of Customer Content and Customer Data as the customer's Confidential Information. The provision that Harvey cannot unilaterally update terms in a way that detracts from its confidentiality obligations reinforces the enforceability of this standard.

How does this clause affect you?

Under this clause, Harvey is contractually obligated to protect Customer Content and Customer Data as the customer's Confidential Information, restrict their use to the scope of the Terms, and limit access to personnel with a need-to-know bound by equivalent confidentiality protections. The agreement states that the disclosing party is entitled to seek equitable relief for any disclosure breach.

Is ConductAtlas affiliated with Harvey AI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Harvey AI.