PlanetScale · PlanetScale Privacy Policy · View original document ↗

Enterprise Customer Data Processor Carve-Out

High severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for PlanetScale Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you are an enterprise customer and PlanetScale processes data on your behalf, that data is not covered by this privacy policy and is governed by a separate agreement.

This analysis describes what PlanetScale's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Enterprise customers cannot rely on this policy for any assurances about how their end-user data is handled; they need to review their separate data processing agreement with PlanetScale.

Consumer impact (what this means for users)

End users whose data resides in databases hosted on PlanetScale by enterprise customers have no rights or protections under this policy; their recourse lies with the enterprise customer who controls that data, not PlanetScale directly.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

Strava Medium

We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal info...

See all platforms with this clause type →

Monitoring

PlanetScale has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This Privacy Policy does not apply to our handling of personal information that we process on behalf of our enterprise customers as a service provider or processor.

— Excerpt from PlanetScale's PlanetScale Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This carve-out engages GDPR Articles 4(8), 28, and 29, which govern the controller-processor relationship and require a written data processing agreement specifying the subject matter, nature, purpose, and duration of processing. Under CCPA/CPRA, a parallel concept exists through the 'service provider' designation, which also requires a written contract limiting the service provider's use of personal information. The FTC may also have jurisdiction over representations made to enterprise customers regarding data handling scope. (2) GOVERNANCE EXPOSURE: High. The absence of this policy's coverage for enterprise customer data means that the data processing agreement (DPA) between PlanetScale and each enterprise customer becomes the sole governing instrument for GDPR and CCPA compliance in that relationship. If no DPA exists or is outdated, the enterprise customer faces direct regulatory exposure, particularly under GDPR which mandates a compliant DPA as a prerequisite for lawful processor engagement. (3) JURISDICTION FLAGS: EU and EEA enterprise customers face the highest exposure, as GDPR Article 28 requires specific contractual provisions; failure to have a compliant DPA is itself a violation subject to supervisory authority enforcement. California-based enterprise customers face similar exposure under CPRA's service provider contract requirements. UK enterprise customers must additionally consider UK GDPR requirements. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams onboarding PlanetScale must ensure a current, GDPR-compliant DPA is in place before processing any personal data through the platform. The carve-out language effectively shifts all compliance responsibility for end-user data to the enterprise customer as controller. Teams should confirm whether PlanetScale's standard DPA covers sub-processor obligations, audit rights, and breach notification timelines consistent with GDPR Article 33 and contractual commitments. (5) COMPLIANCE CONSIDERATIONS: Legal teams should request and review PlanetScale's standard DPA, assess whether it meets applicable jurisdictional requirements, and ensure it is executed prior to any live data processing. Data mapping exercises should clearly distinguish data flowing through the platform as a processor engagement versus data collected directly by PlanetScale as a controller under this policy.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    PlanetScale is subject to FTC investigatory and enforcement powers, including over representations made to enterprise customers about the scope of privacy protections
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
PlanetScale Privacy Policy
Entity
PlanetScale
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 10, 2026
Record ID
CA-P-008467
Document ID
CA-D-00684
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b315065acb8a4282c6e54c56681b20e824edab57d1106f1ca3a23a4a553b776d
Analysis generated
May 7, 2026 19:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: PlanetScale
Document: PlanetScale Privacy Policy
Record ID: CA-P-008467
Captured: 2026-05-07 19:37:22 UTC
SHA-256: b315065acb8a4282…
URL: https://conductatlas.com/platform/planetscale/planetscale-privacy-policy/enterprise-customer-data-processor-carve-out/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does PlanetScale's Enterprise Customer Data Processor Carve-Out clause do?

Enterprise customers cannot rely on this policy for any assurances about how their end-user data is handled; they need to review their separate data processing agreement with PlanetScale.

How does this clause affect you?

End users whose data resides in databases hosted on PlanetScale by enterprise customers have no rights or protections under this policy; their recourse lies with the enterprise customer who controls that data, not PlanetScale directly.

Is ConductAtlas affiliated with PlanetScale?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by PlanetScale.