Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This addendum sets the rules for how Pinecone handles personal data submitted by customers. Customers are responsible for ensuring they have the right to submit data to Pinecone—including obtaining all necessary consents—and must never submit highly sensitive categories of personal data such as health information or criminal records. If a dispute arises about a third-party data processor Pinecone uses and it is not resolved within 14 days, the customer's only remedy is to cancel the relevant service subscriptions.
This Data Processing Addendum establishes the terms under which Pinecone processes Customer Personal Data in connection with its Services. Pinecone's processing is limited strictly to what is necessary to perform its Agreement obligations and to the Customer's documented instructions, with a corresponding prohibition on the Customer submitting GDPR special-category, criminal-conviction, or similarly sensitive personal data. The Customer bears the obligation to confirm that all required notices have been given and consents obtained under applicable Data Protection Laws before Pinecone processes any data. Liability for data-protection claims—including those arising under SCCs—is capped by the Agreement's liability limits for both parties and their Affiliates, and any regulatory penalties Pinecone incurs due to the Customer's DPA non-compliance reduce Pinecone's liability under the Agreement. Pinecone retains unilateral authority to modify the DPA by posting a revised version, subject only to the constraints that modifications may not materially diminish service security or change the scope of Pinecone's processing.
As a customer, you are contractually required to confirm that all necessary notices have been provided and consents obtained under applicable Data Protection Laws before Pinecone processes your data, and you must not submit GDPR special-category data, criminal-conviction data, or similarly sensitive personal data. Pinecone will process your personal data only to the extent needed to perform the Agreement and according to your documented instructions, and will notify you in writing without undue delay—and within any legally required deadline—after becoming aware of a Security Incident. If you object to a Subprocessor and the objection is not resolved within 14 days of your Objection Notice, the one action available to you is to terminate the relevant Service subscriptions.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Pinecone has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Affiliate Claims must be brought by Customer and subject to liability cap and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.