Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that CoreWeave may collect biometric information and video surveillance recordings from individuals who visit its offices or data centers, alongside standard visitor identification data such as name, company affiliation, badge credentials, and access times.
This analysis describes what Weights & Biases's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes collection of biometric information at physical locations under a legitimate interests basis (GDPR Article 6(1)(f)), without specifying a separate consent mechanism. State biometric privacy statutes in Illinois, Texas, and other jurisdictions impose independent written consent requirements that may not be satisfied by a legitimate interest basis alone, creating potential compliance exposure for CoreWeave and for enterprise customers whose employees or contractors visit CoreWeave facilities.
Interpretive note: Whether the legitimate interests legal basis cited is sufficient to satisfy applicable biometric statutes in specific jurisdictions depends on those statutes' independent consent and disclosure requirements, which vary by state.
Under this clause, individuals visiting CoreWeave offices or data centers may have biometric information and video surveillance data collected and retained for physical security purposes. The agreement cites legitimate interests as the legal basis for this processing without specifying a separate consent mechanism or a defined retention period for biometric data.
Cross-platform context
See how other platforms handle Biometric and Surveillance Data Collection at Physical Locations and similar clauses.
Compare across platforms →Monitoring
Weights & Biases has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When you visit our offices or data centers, we may collect identification and access-related information, such as your name, contact details, company affiliation, visitor logs, badge or credential information, access times, and, where applicable, biometric information and video surveillance.Excerpt from Weights & Biases's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision may require evaluation under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and the Washington My Health MY Data Act, each of which imposes notice, written consent, and data retention and destruction schedule requirements that operate independently of GDPR legitimate interest bases. The FTC and relevant state attorneys general hold enforcement authority. BIPA in particular authorizes private rights of action with statutory damages. (2) GOVERNANCE EXPOSURE: High. The provision discloses biometric data collection but does not specify a written consent mechanism, a biometric data retention schedule, or a destruction timeline. BIPA requires informed written consent before collection and a publicly available written policy establishing a retention schedule. The absence of these disclosures in the policy creates potential exposure for CoreWeave and for enterprise customers whose personnel visit CoreWeave facilities. (3) JURISDICTION FLAGS: Illinois creates the highest exposure given BIPA's private right of action and its application to any entity collecting biometric identifiers in Illinois. Texas and Washington impose state-level obligations. EU and UK visitors to US facilities may also raise questions about whether GDPR Article 6(1)(f) legitimate interest balancing adequately covers biometric processing without a separate DPIA. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees or contractors regularly access CoreWeave data centers should assess whether CoreWeave's biometric collection practices are disclosed in their vendor agreements and whether those agreements address compliance with applicable biometric statutes. Procurement teams may want to request a copy of CoreWeave's biometric data retention and destruction policy before authorizing facility visits. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether CoreWeave maintains a publicly available biometric data retention schedule as required by BIPA and whether written consent is obtained from Illinois residents prior to biometric collection. A data protection impact assessment may be warranted for EU/UK contexts. Enterprise customers should document facility visit procedures to determine whether their own BIPA or CUBI compliance obligations are triggered by employee visits to CoreWeave locations.
This provision authorizes collection of biometric information at physical locations under a legitimate interests basis (GDPR Article 6(1)(f)), without specifying a separate consent mechanism. State biometric privacy statutes in Illinois, Texas, and other jurisdictions impose independent written consent requirements that may not be satisfied by a legitimate interest basis alone, creating potential compliance exposure for CoreWeave and for enterprise customers …
Under this clause, individuals visiting CoreWeave offices or data centers may have biometric information and video surveillance data collected and retained for physical security purposes. The agreement cites legitimate interests as the legal basis for this processing without specifying a separate consent mechanism or a defined retention period for biometric data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Weights & Biases.