-
Datadog
· Datadog Sub-Processors
The subprocessor list identifies the country or region of operation for each listed entity, disclosing that some subprocessors are located in the United States and potentially other third countries outside the EEA or UK, which are subject to cross-border transfer restrictions under GDPR and UK GDPR....
Why it matters: This provision creates a compliance dependency for EU and UK data controller customers, who must verify the applicable transfer mechanism for each third-country subprocessor as part of their transfer impact assessment obligations under GDPR Chapter V and post-Schrems II guidance....
-
Twilio
· Twilio Sub-Processors
The document states that while Regional Twilio allows customers to select Ireland or Australia for Customer Content storage and processing, all other account and service usage data continues to be processed in the United States, with additional exceptions for fraud and abuse investigations that may apply even to regionally stored Customer Content....
Why it matters: This provision discloses a material limitation on Regional Twilio's data residency scope: non-content account and usage data remains subject to US processing regardless of the region selected, creating a residual cross-border transfer exposure that customers relying on regional data residency for GDPR compliance should evaluate against their transfer mechanism and accountability obligations....
-
Twilio
· Twilio Sub-Processors
The document lists Anthropic, Amazon Bedrock, OpenAI, and Microsoft Azure as sub-processors for AI Products, each processing personal data contained in customer-defined workflows or communications, with primary processing in the USA and, for Microsoft Azure, also in the EU....
Why it matters: The engagement of multiple AI vendors as sub-processors for personal data in customer-defined workflows creates layered processing chains in which the nature and extent of personal data processed by each AI vendor depends on the content of customer-configured workflows, and may require separate evaluation under GDPR, the EU AI Act, and applicable AI governance frameworks....
-
Google Gemini
· Gemini 3.1 Pro Model Card
The model card discloses that Gemini 3.1 Pro has reached the cyber alert threshold under Google's Frontier Safety Framework, indicating elevated cyber capabilities relative to its predecessor, while stating the Critical Capability Level has not been reached and that mitigations remain active....
Why it matters: This provision discloses a material frontier safety finding that enterprise deployers, regulated sector customers, and AI governance compliance teams may need to evaluate as part of vendor risk assessments and internal AI risk classification processes. The ongoing deployment of mitigations in the cyber domain, as stated in the document, is an operationally relevant disclosure for organizations assessing supply chain risk from AI model providers....
-
Google Gemini
· Gemini 3.1 Pro Model Card
The document discloses that Gemini 3.1 Pro can provide accurate and actionable CBRN-relevant information but does not meet the Critical Capability Level threshold because it fails to provide sufficiently complete instructions for critical stages required to enhance the capabilities of low to medium resourced threat actors, and that ongoing mitigations are deployed....
Why it matters: This provision discloses a material CBRN risk finding and the deployment of active mitigations, which is operationally significant for regulated sector deployers, government customers, and compliance teams evaluating the model's risk profile under biosecurity, export control, and AI governance frameworks. The characterization of actionable CBRN information capability, qualified by the stated failure to reach critical stage completeness, is a nuanced safety finding requiring careful reading....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
OpenAI
· OpenAI GPT-5.5 System Card
The document discloses that GPT-5.5 can provide assistance that meaningfully advances user capability in cybersecurity tasks and persuasive content generation, with these capabilities rated at medium risk and subject to policy-based rather than technical hard-block mitigations in most deployment contexts....
Why it matters: This provision discloses that GPT-5.5 possesses dual-use capabilities in cybersecurity and persuasion domains that are managed primarily through usage policy enforcement rather than absolute technical restrictions. Operators and regulators should note that the effectiveness of policy-based mitigations depends on enforcement mechanisms that the document does not fully specify....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document discloses that GPT-5.5 was assessed for its potential to provide assistance in biological and chemical weapons-relevant domains, received a medium risk rating, and is subject to usage policy restrictions on such content as the primary mitigation mechanism....
Why it matters: The disclosure that GPT-5.5 was evaluated and rated at medium risk in biological and chemical threat domains is operationally significant for regulatory compliance purposes, as these domains are subject to specific legal restrictions in most jurisdictions. The primary mitigation described is usage policy enforcement rather than absolute technical restriction....
-
Meta
· Llama 4 Model Card
The card places primary responsibility for safety testing and application-specific risk mitigation on developers who deploy Llama 4, rather than providing technical enforcement at the model level....
Why it matters: This provision establishes that the safety assurances described in the model card apply to the base model as released by Meta, and that deploying organizations must independently conduct safety evaluation for their specific use cases. Enterprise legal and compliance teams should assess whether this responsibility allocation aligns with their internal AI governance frameworks and any applicable regulatory requirements....
-
Anthropic
· Claude Sonnet 5 System Card
The document states that Claude is designed to request only necessary permissions, avoid storing sensitive information beyond immediate needs, prefer reversible actions, and err on the side of pausing and confirming with users when uncertain about intended scope in autonomous task execution....
Why it matters: This provision establishes the behavioral safety standard Anthropic applies to agentic deployments, which is operationally significant for enterprises using Claude in automated workflows, API integrations, and multi-step task pipelines where the model may take real-world actions with limited human review....
-
Anthropic
· Claude Sonnet 5 System Card
The document discloses that in multi-agent deployments where Claude acts as a subagent receiving instructions from an orchestrating system, it cannot verify the identity or integrity of the orchestrator and must apply its safety standards regardless, and that Claude should be vigilant about prompt injection attacks from external content....
Why it matters: This provision discloses a structural trust limitation in multi-agent architectures that is operationally significant for enterprises building complex AI pipelines, as it means Claude will not automatically trust instructions received through automated orchestration channels and may refuse or pause tasks based on its own safety assessment....
-
Greenhouse
· Greenhouse Terms of Service
Greenhouse's Talent Matching feature automatically sorts candidate pipelines by risk and relevance categories, with a stated requirement that every product release pass a third-party bias audit conducted by Warden AI before deployment, and monthly public publication of audit results....
Why it matters: This provision discloses an automated candidate-sorting mechanism that categorizes candidates by risk and relevance, a function that may constitute automated processing with employment-related effects, triggering evaluation under GDPR automated decision-making provisions, the EU AI Act's high-risk AI classification for employment tools, and jurisdiction-specific automated hiring laws such as New York City Local Law 144....
-
Faire
· Faire Terms of Service
The terms require all disputes between users and Faire to be resolved through binding individual arbitration administered under JAMS rules, rather than through litigation in court, with limited exceptions for small claims matters. The clause applies to claims arising from the Terms or the Services and is governed by the Federal Arbitration Act....
Why it matters: This provision requires disputes to proceed through individual JAMS arbitration rather than court litigation, and the associated class action waiver means users may not aggregate claims with other users. The terms include a thirty-day opt-out window from the date of first acceptance, which is a procedurally significant deadline for users who wish to preserve access to court-based dispute resolution....
-
Faire
· Faire Terms of Service
The terms prohibit users from bringing or participating in class action lawsuits or representative proceedings against Faire, and require all claims to be pursued on an individual basis only. The arbitrator is also prohibited from consolidating multiple users' claims absent mutual agreement....
Why it matters: This provision, combined with the mandatory arbitration clause and the $100 liability cap, means that users may only pursue individual claims through JAMS arbitration, and the arbitrator cannot consolidate claims from multiple affected users. This mechanism is operationally significant for situations involving platform-wide issues affecting large numbers of retailers or brands simultaneously....
-
Faire
· Faire Terms of Service
The terms exclude Faire's liability for indirect, consequential, punitive, and certain other categories of damages, and cap total aggregate liability to any user at the greater of fees paid to Faire in the prior twelve months or one hundred dollars. This cap applies to all claims regardless of their legal basis....
Why it matters: This provision establishes a financial ceiling on Faire's aggregate liability that may be substantially lower than the actual losses a retailer or brand could experience from platform errors, data incidents, or service failures. The provision includes a qualifier acknowledging applicable law may limit its scope, which is relevant for EU and California users where liability caps may be constrained by statute or regulation....
-
Faire
· Faire Terms of Service
The terms require users to defend, indemnify, and hold harmless Faire and its affiliates against all claims, liabilities, damages, costs, and attorneys' fees arising from the user's violation of the Terms, use of the Services, submitted content, or products. This obligation is not subject to a financial cap stated in the indemnification clause itself....
Why it matters: This provision creates an open-ended indemnification obligation running from the user to Faire, covering product liability claims, IP infringement claims, and other third-party actions arising from user conduct or content. The absence of a stated financial ceiling on this obligation is operationally significant for brands whose products are sold through the platform and who may be required to defend and fund Faire's legal costs in related litigation....
-
Reverb
· Reverb Terms of Service
The terms require all disputes between users and Reverb to be resolved through individual binding arbitration administered by JAMS, with both parties waiving the right to participate in class actions or representative proceedings. Users may opt out of this clause by notifying Reverb in writing within 30 days of first accepting the Terms....
Why it matters: This provision requires disputes to proceed through individual arbitration under JAMS rules rather than court litigation, and prohibits class or representative proceedings. The opt-out window is limited to 30 days from first acceptance, and the provision includes a carve-out permitting either party to seek injunctive or equitable relief in court for intellectual property matters....
-
Reverb
· Reverb Terms of Service
The terms authorize Reverb to suspend or terminate any user account and remove any content at any time and for any reason, with or without prior notice, at Reverb's sole discretion....
Why it matters: This provision grants Reverb broad discretionary authority to terminate accounts and remove content without prior notice, which may affect active listings, pending transactions, and seller access to funds held in the platform....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement requires that nearly all disputes between users and Hims & Hers be resolved through binding individual arbitration administered by JAMS rather than through court litigation, with limited exceptions for small claims court....
Why it matters: This provision requires users to resolve disputes individually through JAMS arbitration, which governs the procedural mechanism available for claims including those related to billing, service delivery, and health data practices....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement states that users and Hims & Hers may only bring claims against each other individually and waive the right to participate as a plaintiff or class member in any class or representative proceeding....
Why it matters: This provision requires that any claim against Hims & Hers proceed on an individual basis only, and prohibits the arbitrator from consolidating multiple users' claims or presiding over representative proceedings, absent mutual agreement....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement requires that any legal claim arising from use of Hims & Hers services be filed within one year of the claim accruing, after which the claim is stated to be permanently barred....
Why it matters: This provision contractually shortens the period within which users may bring claims against Hims & Hers to one year, which is shorter than the default statute of limitations for many contract and consumer protection claims under applicable state law....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement states that Hims & Hers and its affiliates will not be liable for indirect, incidental, special, consequential, or punitive damages arising from use of or inability to use the services, including loss of data, profits, or other intangible losses....
Why it matters: This provision asserts that Hims & Hers liability for service-related harm is limited to direct damages and excludes consequential, punitive, and incidental damages, which is significant given that the platform delivers telehealth and prescription services where service failures could have health implications....