Sourcegraph Cody · Sourcegraph Terms of Service · View original document ↗

Privacy Policy Scope and Data Controller Status

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Sourcegraph Cody changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Sourcegraph Cody Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The Privacy Policy applies to all users of any Sourcegraph product or service and governs personal data that Sourcegraph collects and uses in its capacity as a Data Controller.

This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Sourcegraph acts as a Data Controller for personal data collected through its products, which under GDPR imposes direct legal obligations on Sourcegraph regarding lawful basis for processing, data subject rights, and accountability independent of the agreement's own terms.

Interpretive note: The specific categories of personal data collected, purposes of processing, and data subject rights mechanisms are contained in the Privacy Policy document itself, which is not reproduced here; the full scope of Data Controller obligations cannot be assessed from this summary document alone.

Consumer impact (what this means for users)

This clause establishes that the Privacy Policy governs personal data Sourcegraph collects and uses as a Data Controller for all users of any Sourcegraph product or service. Under GDPR and analogous frameworks, data subjects have rights against Sourcegraph as a Data Controller, including access, correction, deletion, and portability rights depending on applicable law.

Cross-platform context

See how other platforms handle Privacy Policy Scope and Data Controller Status and similar clauses.

Compare across platforms →

Monitoring

Sourcegraph Cody has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You use any Sourcegraph product or service. The Privacy Policy covers your personal data that we collect and use as a Data Controller

Excerpt from Sourcegraph Cody's Sourcegraph Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: Sourcegraph's self-identification as a Data Controller directly engages GDPR and UK GDPR, which impose obligations including lawful basis for processing, transparency requirements, data subject rights fulfillment, data protection impact assessments for high-risk processing, and data breach notification. CCPA also imposes obligations on businesses that collect and control personal data from California residents, including disclosure requirements and opt-out rights for data sales or sharing for cross-context behavioral advertising. 2. GOVERNANCE EXPOSURE: Medium. Enterprise customers should note that Sourcegraph's Data Controller status means it has independent data processing obligations and rights over personal data collected through its products, distinct from the controller-processor relationship established by the DPA. This dual role (controller for some data, processor for customer personal data) may require separate legal analysis. 3. JURISDICTION FLAGS: EU and UK users have the strongest data subject rights against Sourcegraph as a Data Controller. California residents have CCPA rights including the right to know, delete, and opt out of data sale or sharing. Organizations deploying Sourcegraph in regulated sectors (healthcare, financial services) should assess whether Sourcegraph's Data Controller activities engage sector-specific privacy requirements. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should review the Privacy Policy to understand what personal data Sourcegraph collects as a Data Controller from their employees who use the platform, as this may create independent privacy obligations for the employer organization depending on applicable employment privacy law. 5. COMPLIANCE CONSIDERATIONS: Legal teams should review the Privacy Policy for specific data categories collected, purposes of processing, retention periods, and third-party sharing practices. Data Protection Officers should assess whether Sourcegraph's Data Controller activities require a Record of Processing Activities entry. Users in jurisdictions with data subject rights should be informed of how to exercise those rights against Sourcegraph directly.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over privacy representations and data handling practices of technology companies operating in the U.S. market.
    File a complaint →
  • State AG
    State Attorneys General in California and other states with comprehensive privacy laws have enforcement authority over Data Controller obligations and consumer data rights.
    File a complaint →

Provision details

Document information
Document
Sourcegraph Terms of Service
Entity
Sourcegraph Cody
Document last updated
May 12, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016481
Document ID
CA-D-00798
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dad75d49ec42e4dcb95115df4cffd9c23f9fd8521852c37fb825a6c4e1c61312
Analysis generated
July 9, 2026 14:41 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Sourcegraph Cody
Document: Sourcegraph Terms of Service
Record ID: CA-P-016481
Captured: 2026-07-09 14:41:59 UTC
SHA-256: dad75d49ec42e4dc…
URL: https://conductatlas.com/platform/sourcegraph-cody/sourcegraph-terms-of-service/provision/CA-P-016481/privacy-policy-scope-and-data-controller-status/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Sourcegraph Cody's Privacy Policy Scope and Data Controller Status clause do?

This provision establishes that Sourcegraph acts as a Data Controller for personal data collected through its products, which under GDPR imposes direct legal obligations on Sourcegraph regarding lawful basis for processing, data subject rights, and accountability independent of the agreement's own terms.

How does this clause affect you?

This clause establishes that the Privacy Policy governs personal data Sourcegraph collects and uses as a Data Controller for all users of any Sourcegraph product or service. Under GDPR and analogous frameworks, data subjects have rights against Sourcegraph as a Data Controller, including access, correction, deletion, and portability rights depending on applicable law.

Is ConductAtlas affiliated with Sourcegraph Cody?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.