63 Total
22 High severity
35 Medium severity
6 Low severity

Key Facts

How are claims brought by Authorized Affiliates treated?
Pinecone requires that all claims brought by Authorized Affiliates be treated as claims made by the Customer and be subject to the Agreement's liability restrictions, including any aggregate limitation of liability.
What must the Customer confirm?
Pinecone requires the Customer to confirm that it has provided notice and obtained all consents and rights necessary under Data Protection Laws for Pinecone to process Customer Personal Data and provide Services pursuant to the Agreement.
Has the Customer provided notice and obtained all consents necessary for Pinecone to process Customer Personal Data?
Pinecone requires the Customer to confirm that it has provided notice and obtained all consents and rights necessary under Data Protection Laws for Pinecone to process Customer Personal Data and provide Services pursuant to the Agreement.
What is the Customer prohibited from including in Customer Data?
Pinecone prohibits the Customer from including special categories of personal data (GDPR Article 9), personal data relating to criminal convictions and offenses (GDPR Article 10), or similarly sensitive personal data in any Customer Data.
Does Pinecone prohibit the Customer from including special categories of personal data in Customer Data?
Pinecone prohibits the Customer from including special categories of personal data (GDPR Article 9), personal data relating to criminal convictions and offenses (GDPR Article 10), or similarly sensitive personal data in any Customer Data.
What does Pinecone require regarding regulatory penalties Pinecone incurs from Customer's failure to comply with its DPA obligations?
Pinecone requires that any regulatory penalties Pinecone incurs arising from the Customer's failure to comply with its DPA obligations reduce Pinecone's liability under the Agreement.
What liability remains subject to the limitation of liability provisions of the Agreement?
Pinecone establishes that each party's and all of its Affiliates' liability arising out of or related to the DPA, the SCCs, or any data protection agreements remains subject to the limitation of liability provisions of the Agreement.
When will Pinecone delete Customer Personal Data?
Pinecone will delete Customer Personal Data in accordance with the Documentation and Agreement upon termination, unless prohibited by Applicable Law.
What does Pinecone do with Customer Personal Data upon termination?
Pinecone will delete Customer Personal Data in accordance with the Documentation and Agreement upon termination, unless prohibited by Applicable Law.
Can Pinecone modify the DPA?
Pinecone may modify the DPA at any time by posting a revised version, provided that the modifications do not materially diminish the overall security of Services and do not change the scope of Pinecone's processing.
Stay ahead of the changes
Track Pinecone and get the diff the day its terms change.
Summary

This addendum sets the rules for how Pinecone handles personal data submitted by customers. Customers are responsible for ensuring they have the right to submit data to Pinecone—including obtaining all necessary consents—and must never submit highly sensitive categories of personal data such as health information or criminal records. If a dispute arises about a third-party data processor Pinecone uses and it is not resolved within 14 days, the customer's only remedy is to cancel the relevant service subscriptions.

Analysis

This Data Processing Addendum establishes the terms under which Pinecone processes Customer Personal Data in connection with its Services. Pinecone's processing is limited strictly to what is necessary to perform its Agreement obligations and to the Customer's documented instructions, with a corresponding prohibition on the Customer submitting GDPR special-category, criminal-conviction, or similarly sensitive personal data. The Customer bears the obligation to confirm that all required notices have been given and consents obtained under applicable Data Protection Laws before Pinecone processes any data. Liability for data-protection claims—including those arising under SCCs—is capped by the Agreement's liability limits for both parties and their Affiliates, and any regulatory penalties Pinecone incurs due to the Customer's DPA non-compliance reduce Pinecone's liability under the Agreement. Pinecone retains unilateral authority to modify the DPA by posting a revised version, subject only to the constraints that modifications may not materially diminish service security or change the scope of Pinecone's processing.

What this means for you

As a customer, you are contractually required to confirm that all necessary notices have been provided and consents obtained under applicable Data Protection Laws before Pinecone processes your data, and you must not submit GDPR special-category data, criminal-conviction data, or similarly sensitive personal data. Pinecone will process your personal data only to the extent needed to perform the Agreement and according to your documented instructions, and will notify you in writing without undue delay—and within any legally required deadline—after becoming aware of a Security Incident. If you object to a Subprocessor and the objection is not resolved within 14 days of your Objection Notice, the one action available to you is to terminate the relevant Service subscriptions.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

63 provisions
12 featured
17 clause types
22 high severity
Stay ahead of the changes

Monitoring

Pinecone has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Affiliate Claims must be brought by Customer and subject to liability cap and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 12, 2026 06:14 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000819
Version ID CA-V-002505
SHA-256 ac0a1b73ed18f662bb647bf50a385d7bcf353b92672e783a4327527886a34249
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans