This analysis describes what Salesforce's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause delineates the scope of Salesforce's privacy obligations by excluding processor relationships from the Privacy Statement's coverage. When Salesforce operates as a processor rather than a controller, different data protection obligations and contractual frameworks typically apply under separate data processing agreements, which affects how personal data handling is governed and what privacy disclosures apply.
Users whose data is processed through Salesforce platforms where customers act as data controllers (such as through customer-created applications or communications) are not covered by this Privacy Statement. Instead, the applicable privacy terms are established through separate processor agreements between Salesforce and the customer organization rather than through this public-facing statement.
How other platforms handle this
Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...
"This Privacy Statement does not apply to the extent we process Personal Data as a processor or service provider on behalf of our customers, including where we offer to our customers various services through which our customers (or their affiliates): (i) create their own websites and applications running on our platforms; (ii) sell or offer their own products and services; (iii) send electronic communications to others.Excerpt from Salesforce's Privacy Statement
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause delineates the scope of Salesforce's privacy obligations by excluding processor relationships from the Privacy Statement's coverage. When Salesforce operates as a processor rather than a controller, different data protection obligations and contractual frameworks typically apply under separate data processing agreements, which affects how personal data handling is governed and what privacy disclosures apply.
Users whose data is processed through Salesforce platforms where customers act as data controllers (such as through customer-created applications or communications) are not covered by this Privacy Statement. Instead, the applicable privacy terms are established through separate processor agreements between Salesforce and the customer organization rather than through this public-facing statement.
ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce.