The statement establishes that it applies only to Salesforce's processing of Personal Data as a controller and expressly excludes processing conducted as a processor on behalf of customers; individuals whose data is processed within customer-controlled Salesforce deployments must direct privacy inquiries to the relevant customer, not to Salesforce.
This analysis describes what Salesforce's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a material scoping boundary that determines which individuals may rely on the rights and disclosures in this statement; individuals interacting with a business that uses Salesforce CRM or other Salesforce products are not covered by this Privacy Statement and must seek recourse through that business's own privacy policies and practices.
Under this provision, individuals whose Personal Data appears in a Salesforce customer's CRM, marketing automation, or other Salesforce-powered system are not covered by this Privacy Statement. The agreement states such individuals should contact the Salesforce customer directly for privacy information.
Cross-platform context
See how other platforms handle Controller Versus Processor Scope Exclusion and similar clauses.
Compare across platforms →"This Privacy Statement does not apply to the extent we process Personal Data as a processor or service provider on behalf of our customers, including where we offer to our customers various services through which our customers (or their affiliates): (i) create their own websites and applications running on our platforms; (ii) sell or offer their own products and services; (iii) send electronic communications to others; or (iv) otherwise collect, use, share or process Personal Data via our services. For detailed privacy information related to a Salesforce customer or a customer affiliate who uses Salesforce services as the controller, please contact our customer directly. We are not responsible for the privacy or data security practices of our customers, which may differ from those explained in this Privacy Statement.Excerpt from Salesforce's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 4(7) and 4(8) controller and processor definitions, CCPA/CPRA service provider distinctions, and comparable processor carve-outs under UK GDPR and other national laws.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a material scoping boundary that determines which individuals may rely on the rights and disclosures in this statement; individuals interacting with a business that uses Salesforce CRM or other Salesforce products are not covered by this Privacy Statement and must seek recourse through that business's own privacy policies and practices.
Under this provision, individuals whose Personal Data appears in a Salesforce customer's CRM, marketing automation, or other Salesforce-powered system are not covered by this Privacy Statement. The agreement states such individuals should contact the Salesforce customer directly for privacy information.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce.