Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Vercel places full legal responsibility for end user privacy compliance on its Customers, including the obligation to notify end users of data collection practices; Vercel's Notice does not cover end users whose data is processed at the Customer's direction.
This analysis describes what Vercel AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Vercel operates as a data processor for Customer-directed processing activities, with Customers bearing the controller obligations for end user personal information; organizations deploying applications on Vercel's platform must independently satisfy applicable privacy law requirements for their end users without reliance on Vercel's Notice.
The updated policy establishes a new mechanism for resolving privacy disputes related to Data Privacy Framework transfers. Users in the EU, UK, and EEA who have unresolved privacy complaints can now submit them to VeraSafe for independent review, which will be conducted free of charge. Additionally, the policy introduces an explicit Right to Restriction, permitting users to request that Vercel limit processing of their personal information or restrict further disclosures in certain instances, particularly for sensitive information. You can file a complaint with VeraSafe by submitting required information at https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.
View change record →End users of applications deployed on Vercel's platform are governed by the relevant Customer's own privacy notice and compliance framework, not by Vercel's Notice; Vercel's Notice directs such users to contact the deploying Customer directly with privacy inquiries.
Cross-platform context
See how other platforms handle Customer Responsibility for End User Compliance and similar clauses.
Compare across platforms →Monitoring
Vercel AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Customers are solely responsible for ensuring compliance with all applicable laws and regulations with respect to their End Users, including notifying their End Users of their personal information collection, use, and disclosure under their own terms of service and privacy policies. If your personal information is contained in Customer Content (defined below) and you have any questions about the specific settings and privacy practices the relevant Customer has made to share your personal information with us, please contact the relevant Customer directly or review their privacy notice.Excerpt from Vercel AI's SDK Privacy
(1) REGULATORY LANDSCAPE: This provision engages GDPR's controller-processor distinction, under which the data controller bears primary legal responsibility for lawful processing, data subject rights fulfillment, and third-party processor contracts; Customers using Vercel as a deployment platform must have a compliant Data Processing Agreement in place. Under CCPA and equivalent US state laws, a similar distinction applies between businesses and service providers. (2) GOVERNANCE EXPOSURE: High for Vercel Customers. Organizations deploying applications on Vercel bear independent obligations to their end users under GDPR, CCPA, and applicable national laws; failure to maintain adequate privacy notices and consent mechanisms for end users is not mitigated by Vercel's own Notice. (3) JURISDICTION FLAGS: EU and EEA-based Customers or those with EU end users face the greatest exposure given GDPR's stringent controller obligations and the potential for supervisory authority enforcement. California Customers with consumer-facing applications must independently satisfy CCPA and CPRA requirements for their user base. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams onboarding Vercel should confirm that an executed Data Processing Addendum is in place and covers all relevant processing activities; the Notice's explicit limitation of Vercel's controller role to its own Sites and Services means that any end-user data processing on Customer-deployed applications falls outside the scope of Vercel's privacy commitments in this Notice. (5) COMPLIANCE CONSIDERATIONS: Customers should conduct a data mapping exercise to identify all end user personal data flows through Vercel's infrastructure and confirm that their own privacy notices, consent mechanisms, and data subject rights procedures are adequate; annual reviews should confirm alignment between the Customer's DPA with Vercel and the subprocessors disclosed in Vercel's documentation.
This provision establishes that Vercel operates as a data processor for Customer-directed processing activities, with Customers bearing the controller obligations for end user personal information; organizations deploying applications on Vercel's platform must independently satisfy applicable privacy law requirements for their end users without reliance on Vercel's Notice.
End users of applications deployed on Vercel's platform are governed by the relevant Customer's own privacy notice and compliance framework, not by Vercel's Notice; Vercel's Notice directs such users to contact the deploying Customer directly with privacy inquiries.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Vercel AI.