Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data is retained only as long as necessary for the described purposes or as required by law, and that upon expiration of that necessity, data will be deleted, anonymized, or securely isolated, with a carve-out for data that cannot be immediately deleted from backup systems.
This analysis describes what Weights & Biases's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision does not specify fixed retention periods for any category of personal data, instead applying a purpose-necessity standard with a backup system carve-out. The absence of specific retention schedules may complicate enterprise customers' data mapping and audit obligations under GDPR and CPRA, which encourage or require specific retention period documentation.
Under this clause, CoreWeave retains personal data for purposes-based periods without specifying fixed timelines, and data held in backup systems may be retained beyond the standard deletion trigger until backup cycles allow deletion. Users may contact privacy@coreweave.com with data retention questions.
Cross-platform context
See how other platforms handle Data Retention Policy and similar clauses.
Compare across platforms →Monitoring
Weights & Biases has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer have a legitimate business need or legal obligation to process personal data, we will delete, anonymize, or securely isolate such data. If deletion is not immediately possible (for example, due to backup systems), the data will be securely stored and isolated until deletion is feasible.Excerpt from Weights & Biases's Privacy Policy
(1) REGULATORY LANDSCAPE: GDPR Article 5(1)(e) requires that personal data be kept in a form that permits identification no longer than necessary for processing purposes and recommends that controllers establish specific retention periods. CPRA similarly requires that personal data be retained only as long as reasonably necessary. The absence of category-specific retention schedules in this policy may require evaluation against GDPR's storage limitation principle requirements. (2) GOVERNANCE EXPOSURE: Low to Medium. The purposes-based retention standard is consistent with GDPR's storage limitation principle in conceptual terms, but regulators and auditors typically expect documented retention schedules by data category. Enterprise customers relying on CoreWeave as a processor should assess whether their DPAs specify retention obligations. (3) JURISDICTION FLAGS: EEA and UK regulators place the greatest emphasis on documented retention schedules. California's CPRA includes a 'reasonably necessary' retention standard that the policy's language is consistent with. The backup system carve-out is a standard operational provision but should be documented in data mapping records. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should verify that their DPAs with CoreWeave address retention periods for Customer Data, including post-termination deletion timelines and backup cycle handling, as this policy does not govern Customer Data retention. (5) COMPLIANCE CONSIDERATIONS: Legal teams should request CoreWeave's internal retention schedule to supplement this policy's general standard for any audit or regulatory inquiry purposes. Data mapping records should document the backup system carve-out and the associated deletion timeline for each data category processed.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision does not specify fixed retention periods for any category of personal data, instead applying a purpose-necessity standard with a backup system carve-out. The absence of specific retention schedules may complicate enterprise customers' data mapping and audit obligations under GDPR and CPRA, which encourage or require specific retention period documentation.
Under this clause, CoreWeave retains personal data for purposes-based periods without specifying fixed timelines, and data held in backup systems may be retained beyond the standard deletion trigger until backup cycles allow deletion. Users may contact privacy@coreweave.com with data retention questions.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Weights & Biases.