9 Total
0 High severity
5 Medium severity
4 Low severity
Stay ahead of the changes
Track OneLogin and get the diff the day its terms change.
Summary

This is the privacy policy of Quest Software Inc. and One Identity, covering both companies' websites, SaaS products, portals, and any properties bearing their logos. The policy authorizes collection of identifiers, device data, IP addresses, call recordings, and AI-analyzed transcripts of phone calls, chatbot conversations, and sales emails, and discloses sharing of this data with approximately 30 named advertising, analytics, and marketing technology partners including Google, LinkedIn, LiveRamp, AppNexus, and theTradeDesk. The policy also states that Quest uses job applicant data including Social Security Numbers and government identifiers, and that when Quest engages third-party cloud hosting providers, it relies on those providers' public policies for data protections applied to Personal Data stored in those environments.

Analysis

This Privacy Policy governs Quest Software Inc. and One Identity's collection, use, processing, transfer, and storage of Personal Data across their websites, SaaS products, and associated services, effective May 1, 2026, with stated legal bases including consent, contractual necessity, legitimate interests, and compliance obligations. The agreement states that Quest collects identifiers, device information, IP addresses, browsing and clickstream data, billing information, call recordings, AI-analyzed communications transcripts, and job applicant data including Social Security Numbers; the terms authorize sharing this data with affiliated companies, Business Partners, advertising vendors (including AdRoll, Google DoubleClick, LiveRamp, and approximately 30 named third parties), payment processors, and cloud hosting providers, and permit de-identification and aggregation of Personal Data for sharing with third parties. The document discloses AI-powered analysis of call transcripts, chatbot interactions, and sales emails for analytics, coaching, and forecasting purposes, and explicitly states that the system does not respond to browser Do Not Track signals; the policy also states that Quest relies on public policies of third-party cloud hosting providers for data protections applied to Personal Data processed in those environments, which may warrant review against applicable data protection standards. The policy asserts compliance with GDPR (via EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework), CCPA and CPRA (California residents), and the UK and Swiss extensions to the Data Privacy Framework; regulatory exposure exists under GDPR Article 13/14 disclosure obligations, CCPA/CPRA Sensitive Personal Information provisions, and FTC Act Section 5 given the breadth of advertising technology partners and AI processing disclosures.

What this means for you

The agreement establishes that Quest collects identifiers, device data, call recordings, AI-analyzed communication transcripts, and job applicant data including Social Security Numbers, and authorizes sharing with approximately 30 named advertising and analytics partners. Under these terms, browser Do Not Track signals are not honored, though the Cookie Preference Center and Global Privacy Control signals are acknowledged. You can submit data subject requests including access, deletion, rectification, and opt-out of marketing at https://oneidentity.com/legal/preferences.aspx, by email at privacy@quest.com, or by calling 1-888-820-4606.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: May 2026

May 6, 2026

medium
What changed OneLogin updated its privacy policy on May 6, 2026 to disclose new data collection and processing practices around recorded communications. The policy now states that calls may be recorded with consent to optimize interactions and improve processes, and that OneLogin uses AI to analyze call transcripts, chat conversations, and sales emails to extract follow-up tasks, summarize interactions, perform sales analytics, and forecast next steps. The updated language also clarifies that recorded call data will be saved and used in future interactions, and it specifies new communication channels (email, text, telephone, chat) as points where personal data collection occurs.
Why this matters The updated policy discloses that OneLogin may record calls with consent and use AI to analyze call transcripts, chat conversations, and sales emails for multiple purposes including follow-up task identification, call summarization, sales analytics, communication effectiveness analysis, and forecast modeling. Under the revised terms, recorded call audio and video may be reviewed for employee training, monitoring, and coaching purposes. The policy also states that OneLogin will save chat and call conversation data to inform future interactions. These practices apply when you communicate with OneLogin via phone calls, chat, email, text, or other teleconference solutions. You should review the updated disclosure to understand how your communication data will be processed and retained.
View full change record →
What changed OneLogin removed detailed disclosures about AI-powered analysis of customer communications, including call recording practices, chatbot interactions, and email analysis. The updated policy no longer explicitly describes how AI is used to analyze call transcripts, identify follow-up tasks, summarize conversations, or analyze sales emails. Additionally, the policy modified language about how collected data will be used, narrowing one stated purpose from 'answers or services you have asked or licensed' to 'services you have purchased,' and updated the security contact email from webmaster@oneidentity.com to webmaster@quest.com.
Why this matters The updated policy removes explicit language describing how OneLogin uses AI to analyze customer communications. Previously, the policy stated that call audio and video would be recorded with consent and analyzed using AI to identify follow-up tasks, summarize calls, and conduct sales analytics; that chatbot conversations would be analyzed and saved; and that sales emails would be analyzed to determine communication efficacy and forecast next steps. These specific AI analysis practices are no longer described in the updated policy. The revised language also narrows one stated data use purpose, changing 'answers or services you have asked or licensed' to 'services you have purchased.' No consumer opt-out mechanisms or alternative disclosures are provided in the change text.
View full change record →

Featured, Medium severity
Featured, Low severity
Stay ahead of the changes

Monitoring

OneLogin has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle AI Analysis of Call Recordings, Chatbot, and Sales Email Transcripts and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured May 29, 2026 01:10 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000694
Version ID CA-V-003122
SHA-256 b593402ebbdddc867529297970d325beaad7960734090f9addcb1a7619aea2f3
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans