The policy states that Modal Labs uses commercially acceptable means to protect personal information but does not guarantee absolute security against data breaches or unauthorized access.
This analysis describes what Modal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insufficient to satisfy GDPR's requirement for appropriate technical and organizational security measures.
Interpretive note: The standard of 'commercially acceptable means' is undefined in the document, making assessment of actual security measures indeterminate from this provision alone.
Under this clause, Modal Labs does not guarantee the security of personal information transmitted to or stored by the service, and the security standard applied is described only as 'commercially acceptable means' without further specification.
Cross-platform context
See how other platforms handle Security Limitation Disclaimer and similar clauses.
Compare across platforms →"We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.Excerpt from Modal's Privacy Policy
(1) REGULATORY LANDSCAPE: GDPR requires that controllers implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insufficient to satisfy GDPR's requirement for appropriate technical and organizational security measures.
Under this clause, Modal Labs does not guarantee the security of personal information transmitted to or stored by the service, and the security standard applied is described only as 'commercially acceptable means' without further specification.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Modal.