The policy explicitly limits its own scope to personal data processed by CoreWeave as a controller and excludes Customer Data, defined as data processed on behalf of enterprise customers, from coverage; responsibility for Customer Data is attributed to the enterprise customer as data controller.
This analysis describes what Weights & Biases's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests to the enterprise customer.
Under this clause, individuals whose personal data is processed through an enterprise customer's CoreWeave deployment are not covered by this policy and must direct data access, deletion, or correction requests to the enterprise customer that controls that data, not to CoreWeave directly.
Cross-platform context
See how other platforms handle Customer Data Controller/Processor Scope Exclusion and similar clauses.
Compare across platforms →"This Privacy Policy applies to personal data that CoreWeave processes as a controller. It does not apply to the extent CoreWeave processes personal data solely as a processor or service provider on behalf of its customers. 'Customer Data' means data processed by CoreWeave on behalf of a customer in connection with that customer's use of the Services. Each customer acts as the controller of such data and is responsible for the collection, use, and disclosure of its Customer Data.Excerpt from Weights & Biases's Privacy Policy
(1) REGULATORY LANDSCAPE: The controller/processor distinction is a foundational concept under GDPR (Articles 4(7) and 4(8)) and is mirrored in CCPA/CPRA's business/service provider framework.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests …
Under this clause, individuals whose personal data is processed through an enterprise customer's CoreWeave deployment are not covered by this policy and must direct data access, deletion, or correction requests to the enterprise customer that controls that data, not to CoreWeave directly.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Weights & Biases.