The policy states that when Quest uses third-party cloud hosting providers, it relies on those providers' publicly available policies for the data protections applied to Personal Data hosted in those environments, rather than specifying bespoke contractual data protection obligations.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision may require evaluation under GDPR Article 28, which requires that controllers engage processors only under a binding contract specifying specific data protection obligations. Reliance on a provider's public policies alone may not satisfy the Article 28 written contract requirement depending on how those public terms are structured.
Interpretive note: Whether reliance on cloud providers' public policies satisfies GDPR Article 28 depends on the specific structure of those public terms and whether formal Data Processing Agreements have been separately executed; the document does not clarify this.
The updated policy discloses that OneLogin may record calls with consent and use AI to analyze call transcripts, chat conversations, and sales emails for multiple purposes including follow-up task identification, call summarization, sales analytics, communication effectiveness analysis, and forecast modeling. Under the revised terms, recorded call audio and video may be reviewed for employee training, monitoring, and coaching purposes. The policy also states that OneLogin will save chat and call conversation data to inform future interactions. These practices apply when you communicate with OneLogin via phone calls, chat, email, text, or other teleconference solutions. You should review the updated disclosure to understand how your communication data will be processed and retained.
View change record →The updated policy removes explicit language describing how OneLogin uses AI to analyze customer communications. Previously, the policy stated that call audio and video would be recorded with consent and analyzed using AI to identify follow-up tasks, summarize calls, and conduct sales analytics; that chatbot conversations would be analyzed and saved; and that sales emails would be analyzed to determine communication efficacy and forecast next steps. These specific AI analysis practices are no longer described in the updated policy. The revised language also narrows one stated data use purpose, changing 'answers or services you have asked or licensed' to 'services you have purchased.' No consumer opt-out mechanisms or alternative disclosures are provided in the change text.
View change record →Under this clause, the specific data protection measures applied to Personal Data stored with cloud hosting providers are determined by those providers' public policies rather than Quest-specific contractual requirements. The Security Guide for each product is referenced as the source for further detail.
Cross-platform context
See how other platforms handle Reliance on Cloud Provider Public Policies for Data Protection and similar clauses.
Compare across platforms →"When we do engage third party providers for various services, including cloud hosting services for certain aspects of our offerings, we rely on the public policies and protections of those globally available services for the protections we apply to your Personal Data. For a breakdown of the policies of our primary cloud hosting service providers, please visit the Security Guide(s) for the products you are purchasing or using.Excerpt from OneLogin's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision may require evaluation under GDPR Article 28, which requires that controllers engage processors only under a binding contract specifying specific data protection obligations. Reliance on a provider's public policies alone may not satisfy the Article 28 written contract requirement depending on how those public terms are structured.
Under this clause, the specific data protection measures applied to Personal Data stored with cloud hosting providers are determined by those providers' public policies rather than Quest-specific contractual requirements. The Security Guide for each product is referenced as the source for further detail.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.