The policy states that Quest may aggregate or de-identify Personal Data and share the resulting data with third parties, treating de-identified data as no longer subject to personal data protections.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes de-identification of Personal Data and its unrestricted sharing with third parties. The adequacy of de-identification techniques is not specified in the document; GDPR and CCPA contain specific standards for de-identification or anonymization that determine whether data retains protected status, and regulators have increasingly scrutinized de-identification claims.
Interpretive note: The adequacy of Quest's de-identification practices cannot be assessed from the document alone; applicability of GDPR anonymization or CCPA de-identification standards depends on the specific methodology employed.
The updated policy discloses that OneLogin may record calls with consent and use AI to analyze call transcripts, chat conversations, and sales emails for multiple purposes including follow-up task identification, call summarization, sales analytics, communication effectiveness analysis, and forecast modeling. Under the revised terms, recorded call audio and video may be reviewed for employee training, monitoring, and coaching purposes. The policy also states that OneLogin will save chat and call conversation data to inform future interactions. These practices apply when you communicate with OneLogin via phone calls, chat, email, text, or other teleconference solutions. You should review the updated disclosure to understand how your communication data will be processed and retained.
View change record →The updated policy removes explicit language describing how OneLogin uses AI to analyze customer communications. Previously, the policy stated that call audio and video would be recorded with consent and analyzed using AI to identify follow-up tasks, summarize calls, and conduct sales analytics; that chatbot conversations would be analyzed and saved; and that sales emails would be analyzed to determine communication efficacy and forecast next steps. These specific AI analysis practices are no longer described in the updated policy. The revised language also narrows one stated data use purpose, changing 'answers or services you have asked or licensed' to 'services you have purchased.' No consumer opt-out mechanisms or alternative disclosures are provided in the change text.
View change record →Under this clause, Quest may de-identify Personal Data including identifiers and usage data and share it with third parties without the restrictions applicable to Personal Data. The specific de-identification standards or techniques used are not described in the policy.
Cross-platform context
See how other platforms handle De-identification and Aggregation for Third-Party Sharing and similar clauses.
Compare across platforms →"We may aggregate or de-identify information (including Personal Data) so that it does not identify you and then share that de-identified (and therefore no longer personal) data with third parties, either on its own or with other non-personal data.Excerpt from OneLogin's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes de-identification of Personal Data and its unrestricted sharing with third parties. The adequacy of de-identification techniques is not specified in the document; GDPR and CCPA contain specific standards for de-identification or anonymization that determine whether data retains protected status, and regulators have increasingly scrutinized de-identification claims.
Under this clause, Quest may de-identify Personal Data including identifiers and usage data and share it with third parties without the restrictions applicable to Personal Data. The specific de-identification standards or techniques used are not described in the policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.