Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Privacy Policy applies to all users of any Sourcegraph product or service and governs personal data that Sourcegraph collects and uses in its capacity as a Data Controller.
This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Sourcegraph acts as a Data Controller for personal data collected through its products, which under GDPR imposes direct legal obligations on Sourcegraph regarding lawful basis for processing, data subject rights, and accountability independent of the agreement's own terms.
Interpretive note: The specific categories of personal data collected, purposes of processing, and data subject rights mechanisms are contained in the Privacy Policy document itself, which is not reproduced here; the full scope of Data Controller obligations cannot be assessed from this summary document alone.
This clause establishes that the Privacy Policy governs personal data Sourcegraph collects and uses as a Data Controller for all users of any Sourcegraph product or service. Under GDPR and analogous frameworks, data subjects have rights against Sourcegraph as a Data Controller, including access, correction, deletion, and portability rights depending on applicable law.
Cross-platform context
See how other platforms handle Privacy Policy Scope and Data Controller Status and similar clauses.
Compare across platforms →Monitoring
Sourcegraph Cody has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"You use any Sourcegraph product or service. The Privacy Policy covers your personal data that we collect and use as a Data ControllerExcerpt from Sourcegraph Cody's Sourcegraph Terms of Service
1. REGULATORY LANDSCAPE: Sourcegraph's self-identification as a Data Controller directly engages GDPR and UK GDPR, which impose obligations including lawful basis for processing, transparency requirements, data subject rights fulfillment, data protection impact assessments for high-risk processing, and data breach notification. CCPA also imposes obligations on businesses that collect and control personal data from California residents, including disclosure requirements and opt-out rights for data sales or sharing for cross-context behavioral advertising. 2. GOVERNANCE EXPOSURE: Medium. Enterprise customers should note that Sourcegraph's Data Controller status means it has independent data processing obligations and rights over personal data collected through its products, distinct from the controller-processor relationship established by the DPA. This dual role (controller for some data, processor for customer personal data) may require separate legal analysis. 3. JURISDICTION FLAGS: EU and UK users have the strongest data subject rights against Sourcegraph as a Data Controller. California residents have CCPA rights including the right to know, delete, and opt out of data sale or sharing. Organizations deploying Sourcegraph in regulated sectors (healthcare, financial services) should assess whether Sourcegraph's Data Controller activities engage sector-specific privacy requirements. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should review the Privacy Policy to understand what personal data Sourcegraph collects as a Data Controller from their employees who use the platform, as this may create independent privacy obligations for the employer organization depending on applicable employment privacy law. 5. COMPLIANCE CONSIDERATIONS: Legal teams should review the Privacy Policy for specific data categories collected, purposes of processing, retention periods, and third-party sharing practices. Data Protection Officers should assess whether Sourcegraph's Data Controller activities require a Record of Processing Activities entry. Users in jurisdictions with data subject rights should be informed of how to exercise those rights against Sourcegraph directly.
This provision establishes that Sourcegraph acts as a Data Controller for personal data collected through its products, which under GDPR imposes direct legal obligations on Sourcegraph regarding lawful basis for processing, data subject rights, and accountability independent of the agreement's own terms.
This clause establishes that the Privacy Policy governs personal data Sourcegraph collects and uses as a Data Controller for all users of any Sourcegraph product or service. Under GDPR and analogous frameworks, data subjects have rights against Sourcegraph as a Data Controller, including access, correction, deletion, and portability rights depending on applicable law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.