Weights & Biases · Weights & Biases Privacy Policy · View original document ↗

Customer Data Controller/Processor Scope Exclusion

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Weights & Biases changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Weights & Biases recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Weights & Biases Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy explicitly limits its own scope to personal data processed by CoreWeave as a controller and excludes Customer Data, defined as data processed on behalf of enterprise customers, from coverage; responsibility for Customer Data is attributed to the enterprise customer as data controller.

This analysis describes what Weights & Biases's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests to the enterprise customer.

Consumer impact (what this means for users)

Under this clause, individuals whose personal data is processed through an enterprise customer's CoreWeave deployment are not covered by this policy and must direct data access, deletion, or correction requests to the enterprise customer that controls that data, not to CoreWeave directly.

Cross-platform context

See how other platforms handle Customer Data Controller/Processor Scope Exclusion and similar clauses.

Compare across platforms →

Monitoring

Weights & Biases has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This Privacy Policy applies to personal data that CoreWeave processes as a controller. It does not apply to the extent CoreWeave processes personal data solely as a processor or service provider on behalf of its customers. 'Customer Data' means data processed by CoreWeave on behalf of a customer in connection with that customer's use of the Services. Each customer acts as the controller of such data and is responsible for the collection, use, and disclosure of its Customer Data.

Excerpt from Weights & Biases's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The controller/processor distinction is a foundational concept under GDPR (Articles 4(7) and 4(8)) and is mirrored in CCPA/CPRA's business/service provider framework. This provision aligns the policy's scope with standard cloud infrastructure practice. However, regulators including the European Data Protection Board have noted that processor agreements must be in place and must meet minimum content requirements; the existence of such agreements between CoreWeave and enterprise customers is not addressed in this policy. (2) GOVERNANCE EXPOSURE: Medium. Enterprise customers deploying workloads on CoreWeave's infrastructure must ensure that appropriate data processing agreements are in place with CoreWeave, covering the categories of personal data processed, processing purposes, subprocessor obligations, and security measures. The policy's exclusion of Customer Data from its scope does not relieve CoreWeave of processor obligations under applicable law, but it does place responsibility on enterprise customers to operationalize those obligations contractually. (3) JURISDICTION FLAGS: GDPR Article 28 requires a written data processing agreement between controller and processor; enterprise customers in the EEA or processing EEA resident data must verify that such agreements exist with CoreWeave. CCPA/CPRA requires a written service provider agreement limiting CoreWeave's use of Customer Data to specified business purposes. Healthcare enterprise customers may face HIPAA Business Associate Agreement requirements. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams at enterprise customers should confirm that CoreWeave's standard customer agreements include compliant data processing addenda (DPAs) for GDPR purposes and service provider agreements for CCPA purposes. The policy's explicit exclusion of Customer Data from its own scope makes the DPA the primary governance instrument for Customer Data, which should be reviewed for adequacy against applicable regulatory requirements. (5) COMPLIANCE CONSIDERATIONS: Enterprise customers should conduct data mapping to identify what categories of personal data flow through CoreWeave's infrastructure, confirm that DPAs cover those categories and processing purposes, and assess whether CoreWeave's subprocessor disclosures (not addressed in this policy) are adequate. Healthcare and financial services customers face heightened obligations and should assess HIPAA BAA and GLBA applicability respectively.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC holds authority over inadequate data processing disclosures and service provider agreement practices under Section 5 of the FTC Act and CPRA's service provider framework.
    File a complaint →

Provision details

Document information
Document
Weights & Biases Privacy Policy
Entity
Weights & Biases
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015601
Document ID
CA-D-00494
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a8c89feb5b1802818671d040094f75bc0483f6a07350286b7481194aa7e1140
Analysis generated
July 9, 2026 08:22 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Weights & Biases
Document: Weights & Biases Privacy Policy
Record ID: CA-P-015601
Captured: 2026-07-09 08:22:27 UTC
SHA-256: 0a8c89feb5b18028…
URL: https://conductatlas.com/platform/weights-biases/weights-biases-privacy-policy/provision/CA-P-015601/customer-data-controllerprocessor-scope-exclusion/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Weights & Biases's Customer Data Controller/Processor Scope Exclusion clause do?

This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests …

How does this clause affect you?

Under this clause, individuals whose personal data is processed through an enterprise customer's CoreWeave deployment are not covered by this policy and must direct data access, deletion, or correction requests to the enterprise customer that controls that data, not to CoreWeave directly.

Is ConductAtlas affiliated with Weights & Biases?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Weights & Biases.