Data that enterprise or business customers submit through Sourcegraph's business products is governed by separate contracts with those customers, not by this public privacy policy.
This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that the consumer-facing privacy protections in this policy do not apply to data processed under enterprise agreements, meaning individual users in organizational deployments may have different and separately negotiated data protections.
Individual users whose organizations have deployed Sourcegraph under a business agreement should review their employer's data processing agreement with Sourcegraph rather than this policy to understand how their data is handled, as this policy explicitly excludes Customer Personal Data from its scope.
How other platforms handle this
You can contact us in order to (1) update or correct your personally identifiable information, (2) change your preferences with respect to communications and other information you receive from us, or (3) delete the personally identifiable information maintained about you...
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
to request that your data be transferred to a third party (data portability)
"This Privacy Policy does not apply to Customer Personal Data, which we process on behalf of customers to our business offerings. Our use of that data is instead governed by our customer agreements.Excerpt from Sourcegraph Cody's Sourcegraph Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR controller-processor distinctions, under which Sourcegraph acts as a data processor for business customers who are controllers of Customer Personal Data.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that the consumer-facing privacy protections in this policy do not apply to data processed under enterprise agreements, meaning individual users in organizational deployments may have different and separately negotiated data protections.
Individual users whose organizations have deployed Sourcegraph under a business agreement should review their employer's data processing agreement with Sourcegraph rather than this policy to understand how their data is handled, as this policy explicitly excludes Customer Personal Data from its scope.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.