This analysis describes what Smartsheet's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision allocates responsibility for personal data governance by designating the customer as the entity responsible for establishing privacy policies and responding to data subject inquiries. The bifurcation clarifies that Smartsheet's primary obligation is to the customer organization, not to individual end-users whose data is processed through the platform.
The updated privacy policy states that only Smartsheet's U.S.-based affiliates participate in the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework. Previously, the policy referenced participation by Smartsheet and its affiliates without geographic qualification. This narrowed scope may affect the data transfer mechanisms available for processing personal data from EU, UK, and Swiss users if non-U.S. affiliates are involved in data handling. The policy does not explicitly describe alternative transfer mechanisms for non-U.S. affiliates.
View change record →Users whose data is collected through a customer's Smartsheet deployment operate under the customer organization's privacy policy rather than Smartsheet's policy directly. This provision establishes that data inquiries and privacy governance questions should be addressed to the customer organization, not to Smartsheet.
How other platforms handle this
When our business customers use certain Services, we generally process and store limited personal information on their behalf as a data processor. For certain products such as Docusign's Contract Lifecycle Management (CLM) and Identity products, we may act as a processor and as a controller in certa...
Mixpanel acts as a data processor on behalf of its customers (the controllers) when processing end user data through the Mixpanel analytics platform, and as a data controller with respect to data it collects about its own website visitors and account holders.
This Privacy Policy does not apply where Anthropic acts as a data processor and processes personal data on behalf of commercial customers using Anthropic's Commercial Services – for example, your employer has provisioned you a Claude for Work account, or you're using an app that is powered on the ba...
Monitoring
Smartsheet has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When Smartsheet collects personal data on behalf of our customers (such as when a customer's employee or end-user uses the Smartsheet services), Smartsheet acts as a data processor and our customer acts as a data controller. In these cases, our customer's privacy policy governs the use of your personal data, and you should contact that customer if you have questions about how your personal data is used.— Excerpt from Smartsheet's Smartsheet Privacy Policy
We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and liability.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision allocates responsibility for personal data governance by designating the customer as the entity responsible for establishing privacy policies and responding to data subject inquiries. The bifurcation clarifies that Smartsheet's primary obligation is to the customer organization, not to individual end-users whose data is processed through the platform.
Users whose data is collected through a customer's Smartsheet deployment operate under the customer organization's privacy policy rather than Smartsheet's policy directly. This provision establishes that data inquiries and privacy governance questions should be addressed to the customer organization, not to Smartsheet.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Smartsheet.