Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes disclosure of user personal information to third parties in connection with or in anticipation of an asset sale, merger, bankruptcy, or other business transaction, under a legitimate interest basis.
This analysis describes what Ideogram's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal data may be transferred to third parties in the context of corporate transactions, including in anticipation of such transactions, which may occur prior to any formal change in ownership or control.
The updated policy now provides explicit disclosure of which categories of personal information are collected and which parties receive each category. Previously, the policy required readers to consult other sections to identify this information. The updated table format discloses that identifiers such as name and email address, visual information including uploaded images, and geolocation data may be shared with other users, vendors, service providers, login integration partners, social media widgets, and affiliates. This change provides clearer visibility into data sharing practices without altering what data is collected or shared, but rather how that information is disclosed.
View change record →The updated policy no longer provides a single consolidated view of which specific categories of recipients receive which types of personal data. Previously, users could see in one table that identifiers, commercial information, geolocation data, images, account credentials, and precise location were shared with specific recipient categories such as vendors, service providers, other users, login partners, social media widgets, and tracking technology providers. The revised policy instead directs users to review other sections of the document to find this information. The specificity and accessibility of this disclosure has been reduced, though the underlying data-sharing practices may remain unchanged.
View change record →Under this provision, personal information held by Ideogram may be disclosed to prospective or actual acquirers, merger partners, or other parties in connection with a business transaction, including during due diligence phases that precede any completed transaction.
Cross-platform context
See how other platforms handle Disclosure to Third Parties in Business Transactions and similar clauses.
Compare across platforms →Monitoring
Ideogram has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To third parties in connection with or anticipation of an asset sale, merger, bankruptcy, or other business transaction, as a matter of our legitimate interests to run a successful and efficient business.Excerpt from Ideogram's Privacy Policy
1) REGULATORY LANDSCAPE: Business transaction data transfers implicate GDPR Article 6 (lawful basis) and CCPA disclosure requirements. GDPR does not recognize business transaction necessity as a standalone legal basis; transfers in this context would need to satisfy legitimate interest, including a balancing test. CCPA requires that recipients of personal information in business transactions comply with applicable privacy obligations. 2) GOVERNANCE EXPOSURE: Low to medium. Business transaction carve-outs are common in commercial privacy policies. The inclusion of anticipatory disclosures (prior to a completed transaction) is notable and means personal data may be shared with potential acquirers during due diligence, which should be evaluated for GDPR adequacy. 3) JURISDICTION FLAGS: EU and UK users face heightened exposure given GDPR's requirements for a documented legal basis and data subject transparency regarding transfers in this context. California users are subject to CCPA requirements for successor business compliance. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should assess whether a change of control at Ideogram would affect the data processing terms applicable to their user data, and whether their vendor agreements with Ideogram include change-of-control notification obligations. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether Ideogram's legitimate interest basis for anticipatory business transaction disclosures is documented in a legitimate interests assessment, and whether EU and UK users would receive adequate transparency and control in the event of a material corporate transaction.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that personal data may be transferred to third parties in the context of corporate transactions, including in anticipation of such transactions, which may occur prior to any formal change in ownership or control.
Under this provision, personal information held by Ideogram may be disclosed to prospective or actual acquirers, merger partners, or other parties in connection with a business transaction, including during due diligence phases that precede any completed transaction.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ideogram.