Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy explicitly limits its own scope to personal data processed by CoreWeave as a controller and excludes Customer Data, defined as data processed on behalf of enterprise customers, from coverage; responsibility for Customer Data is attributed to the enterprise customer as data controller.
This analysis describes what Weights & Biases's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests to the enterprise customer.
Under this clause, individuals whose personal data is processed through an enterprise customer's CoreWeave deployment are not covered by this policy and must direct data access, deletion, or correction requests to the enterprise customer that controls that data, not to CoreWeave directly.
Cross-platform context
See how other platforms handle Customer Data Controller/Processor Scope Exclusion and similar clauses.
Compare across platforms →Monitoring
Weights & Biases has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"This Privacy Policy applies to personal data that CoreWeave processes as a controller. It does not apply to the extent CoreWeave processes personal data solely as a processor or service provider on behalf of its customers. 'Customer Data' means data processed by CoreWeave on behalf of a customer in connection with that customer's use of the Services. Each customer acts as the controller of such data and is responsible for the collection, use, and disclosure of its Customer Data.Excerpt from Weights & Biases's Privacy Policy
(1) REGULATORY LANDSCAPE: The controller/processor distinction is a foundational concept under GDPR (Articles 4(7) and 4(8)) and is mirrored in CCPA/CPRA's business/service provider framework. This provision aligns the policy's scope with standard cloud infrastructure practice. However, regulators including the European Data Protection Board have noted that processor agreements must be in place and must meet minimum content requirements; the existence of such agreements between CoreWeave and enterprise customers is not addressed in this policy. (2) GOVERNANCE EXPOSURE: Medium. Enterprise customers deploying workloads on CoreWeave's infrastructure must ensure that appropriate data processing agreements are in place with CoreWeave, covering the categories of personal data processed, processing purposes, subprocessor obligations, and security measures. The policy's exclusion of Customer Data from its scope does not relieve CoreWeave of processor obligations under applicable law, but it does place responsibility on enterprise customers to operationalize those obligations contractually. (3) JURISDICTION FLAGS: GDPR Article 28 requires a written data processing agreement between controller and processor; enterprise customers in the EEA or processing EEA resident data must verify that such agreements exist with CoreWeave. CCPA/CPRA requires a written service provider agreement limiting CoreWeave's use of Customer Data to specified business purposes. Healthcare enterprise customers may face HIPAA Business Associate Agreement requirements. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams at enterprise customers should confirm that CoreWeave's standard customer agreements include compliant data processing addenda (DPAs) for GDPR purposes and service provider agreements for CCPA purposes. The policy's explicit exclusion of Customer Data from its own scope makes the DPA the primary governance instrument for Customer Data, which should be reviewed for adequacy against applicable regulatory requirements. (5) COMPLIANCE CONSIDERATIONS: Enterprise customers should conduct data mapping to identify what categories of personal data flow through CoreWeave's infrastructure, confirm that DPAs cover those categories and processing purposes, and assess whether CoreWeave's subprocessor disclosures (not addressed in this policy) are adequate. Healthcare and financial services customers face heightened obligations and should assess HIPAA BAA and GLBA applicability respectively.
This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests …
Under this clause, individuals whose personal data is processed through an enterprise customer's CoreWeave deployment are not covered by this policy and must direct data access, deletion, or correction requests to the enterprise customer that controls that data, not to CoreWeave directly.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Weights & Biases.