-
Segment
· Segment Privacy Policy
The notice states that Twilio uses advertising cookies, pixels, and web beacons for targeted advertising and acknowledges that under some U.S. state laws this constitutes sharing or targeted advertising, with opt-out available through the Cookie Preferences tool, browser settings, or Global Privacy Control....
Why it matters: This provision discloses that Twilio's advertising tracking technologies engage U.S. state privacy law definitions of sharing and targeted advertising, which trigger opt-out rights under frameworks including CCPA as amended by CPRA. The notice provides multiple opt-out mechanisms and explicitly names Global Privacy Control as a recognized opt-out signal....
-
Segment
· Segment Privacy Policy
The notice states that data subjects may have rights to access, correct, delete, port, object to, restrict, and withdraw consent for processing of their personal data, subject to limitations where Twilio has a legal requirement or legitimate interest, with deletion requests potentially affecting service availability....
Why it matters: This provision establishes that data subject rights are available under applicable law but subject to stated limitations based on legal requirements or legitimate interests, and that account deletion may result in loss of access to some or all services. The notice directs individuals whose data is processed by Twilio as a data processor to contact the relevant customer rather than Twilio directly....
-
Snowflake
· Snowflake Privacy Notice
The page footer includes a 'Do Not Share My Personal Information' link, which the California Consumer Privacy Act and California Privacy Rights Act require covered businesses to make available to California residents as a mechanism to opt out of the sale or sharing of personal information for cross-context behavioral advertising....
Why it matters: This provision establishes that Snowflake maintains a CCPA/CPRA opt-out mechanism accessible via the page footer. The presence of this link indicates that Snowflake's activities may include sharing personal information in ways that trigger California opt-out obligations under the CPRA....
-
Snowflake
· Snowflake Privacy Notice
Snowflake's legal framework consists of a base Terms of Service supplemented by multiple addenda and product-specific terms, including separate documents for AI Features, Marketplace, Data Clean Rooms, Crunchy Bridge, U.S. Government use, and technical services, each of which may impose distinct obligations on customers....
Why it matters: This layered structure establishes that the operative terms governing any specific customer's use of Snowflake may span multiple documents. Compliance teams must identify which addenda apply to their specific product deployments, as obligations under data processing, security, acceptable use, and AI governance may differ materially across the document set....
-
Snowflake
· Snowflake Privacy Notice
Snowflake publishes a Data Processing Addendum, a Transfer Mechanism document, and a DPIA Fact Sheet as part of its legal framework, indicating that cross-border personal data transfers and GDPR-compliant processing obligations are addressed through separate operative documents....
Why it matters: This provision establishes that Snowflake's GDPR-related data processing obligations, including the legal basis for cross-border data transfers, are governed by a separate Data Processing Addendum and Transfer Mechanism document. EU and UK customers must obtain and review these documents to confirm that their use of Snowflake satisfies GDPR Chapter V transfer requirements....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Snowflake
· Snowflake Privacy Notice
Snowflake designates a separate legal page with distinct terms for U.S. Government entities, defined as federal agencies and state government agencies, meaning standard commercial terms do not govern these entities' use of Snowflake services....
Why it matters: This provision establishes that U.S. Government customers, including federal and state agencies, are subject to a separate and distinct set of terms rather than the standard commercial Terms of Service. Organizations identifying as U.S. Government entities must obtain and review the Government-specific terms, as material differences in data processing, security, liability, and acceptable use obligations may exist....
-
Snowflake
· Snowflake Privacy Notice
Snowflake discloses that its AI features are governed by separate Snowflake AI Terms and Snowflake Model and Service Pass-Through Terms, establishing a distinct legal framework for AI product use that operates in addition to the base Terms of Service....
Why it matters: This provision establishes that customers using Snowflake AI features are subject to additional operative terms beyond the base Terms of Service. The existence of Model and Service Pass-Through Terms indicates that third-party model providers may have pass-through contractual obligations that affect customers' rights and obligations when using AI-powered features....
-
Snowflake
· Snowflake Privacy Notice
Snowflake publishes a Law Enforcement Requests Policy and Transparency Reports, disclosing that a formal policy exists governing how Snowflake responds to law enforcement requests for customer data....
Why it matters: This provision discloses the existence of a formal law enforcement data disclosure framework. Customers whose data is processed through Snowflake should review this policy to understand the conditions under which Snowflake may disclose customer data to law enforcement authorities and what notice, if any, Snowflake provides to affected customers....
-
Snowflake
· Snowflake Privacy Notice
Snowflake maintains and publishes a list of sub-processors and affiliates, indicating that customer data may be processed by third-party sub-processors in addition to Snowflake itself....
Why it matters: The Sub-Processors and Affiliates list is a material GDPR Article 28 compliance element, as it discloses the third-party entities to whom Snowflake may transfer or provide access to customer personal data in the course of service delivery. Under standard DPA terms, customers may have rights to object to new sub-processor additions....
-
Checkout.com
· Checkout.com Privacy
The notice states that personal data may be transferred internationally to Checkout group companies or third-party service providers, with EU SCC and UK Addendum mechanisms and transfer impact assessments used for transfers from the UK or EEA to countries without an adequacy decision....
Why it matters: This provision establishes the legal transfer mechanisms Checkout relies on for cross-border data flows from the UK and EEA, and discloses that transfer impact assessments are conducted, which are operationally significant for GDPR and UK GDPR compliance purposes....
-
Checkout.com
· Checkout.com Privacy
The notice discloses that California residents may opt out of the sharing of personal information for cross-context behavioral advertising by submitting a request via a link in the California section of the notice or by emailing dpo@checkout.com, and states that Checkout does not sell personal information....
Why it matters: This provision establishes an operative opt-out right for California residents under CPRA for cross-context behavioral advertising, which is a distinct mechanism from a sale opt-out, and the notice separately asserts that no personal information is sold....
-
Checkout.com
· Checkout.com Privacy
The notice establishes a set of data subject rights including access, correction, erasure, processing restriction, objection, consent withdrawal, and objection to automated decision-making, all exercisable by contacting dpo@checkout.com, with the notice qualifying that availability of these rights depends on jurisdiction and that erasure may be declined where legal retention obligations apply....
Why it matters: This provision establishes the operative mechanism for individuals to exercise data subject rights and qualifies the scope of those rights by jurisdiction and by Checkout's legal retention obligations, which are relevant parameters for compliance teams assessing the practical scope of data subject access and erasure requests....
-
Checkout.com
· Checkout.com Privacy
The notice discloses that personal data may be shared with Checkout group affiliates, third-party service providers covering a range of functions including advertising networks and background screening, and payment ecosystem partners including banks, card schemes, alternative payment method providers, and issuers....
Why it matters: This provision identifies the categories of third-party recipients of personal data and notably includes advertising networks and background screening companies among the service provider categories, which are operationally distinct from the core payment processing function and may engage additional regulatory considerations....
-
Checkout.com
· Checkout.com Privacy
The notice discloses that when an identity document is flagged for verification or a facial image is used multiple times in a short period, a hashed version of the facial image may be stored for up to 96 hours to detect repeated use of the same image with different documents, with temporary service access blocks possible during that period, all blocks subject to human operator review....
Why it matters: This provision establishes a secondary automated biometric processing mechanism, distinct from the primary identity verification function, that may impose a temporary service access block on individuals whose facial image triggers the fraud detection heuristic, with human review stated as the backstop for all such blocks....
-
Checkout.com
· Checkout.com Privacy
The notice establishes that Checkout acts as a data controller for its own processing activities but may act as a data processor for Merchant Customer data when processing on a Merchant's behalf, directing affected individuals to the Merchant's own privacy notice in processor contexts....
Why it matters: This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has direct implications for where affected individuals must direct data rights requests and complaints....
-
RunPod
· RunPod Privacy Policy
The policy authorizes RunPod and its advertising partners to collect device data, online activity data, and other interaction data via cookies and similar technologies to serve interest-based ads, and discloses that this practice may qualify as a 'sale' or 'sharing' of personal information under CCPA and similar state laws. Users can opt out via the Cookie Notice or by emailing dsar@runpod.io....
Why it matters: This provision requires RunPod to maintain an operational opt-out mechanism for targeted advertising data sharing under CCPA and applicable state laws, and compliance teams should verify that opt-out requests submitted via Cookie Notice or email result in documented cessation of the relevant data flows to advertising partners....
-
RunPod
· RunPod Privacy Policy
The policy states that RunPod may modify the Privacy Policy at any time, and that notification consists of updating the date and posting the revised version on the Service. Continued use of the Service after the effective date of any modification constitutes acknowledgment that the updated policy applies....
Why it matters: This provision establishes that the primary notification mechanism for material privacy policy changes is a date update and website posting, and that continued platform use is treated as acceptance of modified terms. Under GDPR, this mechanism may not satisfy consent requirements for processing that requires explicit consent, and European-facing compliance teams should evaluate whether additional consent collection is required for modified processing purposes....
-
RunPod
· RunPod Privacy Policy
The policy authorizes disclosure of personal information to prospective and actual acquirers, investors, and their advisors in the context of corporate transactions including mergers, acquisitions, financings, public offerings, insolvencies, or bankruptcies....
Why it matters: This provision establishes that personal information may be transferred to third-party counterparties and advisors during due diligence or transaction processes, including in insolvency or bankruptcy scenarios where personal information is treated as a business asset. The scope covers prospective transactions, meaning disclosure may occur before any transaction is completed....
-
RunPod
· RunPod Privacy Policy
The policy identifies legitimate interests as the primary legal basis for direct marketing and service improvement and analytics processing under GDPR, with consent as a secondary basis where required by applicable law for marketing communications....
Why it matters: Reliance on legitimate interests as the legal basis for direct marketing and analytics processing requires documented legitimate interests assessments (LIAs) balancing RunPod's interests against data subject rights, and EU and UK users retain the right to object to processing on legitimate interests grounds under GDPR Article 21....
-
RunPod
· RunPod Privacy Policy
The policy states that users covered by applicable state privacy laws may opt out of automated processing or profiling used to evaluate or predict personal characteristics including economic situation, health, preferences, interests, reliability, behavior, and location....
Why it matters: This provision establishes an opt-out right for profiling and automated decision-making under applicable state privacy laws, covering a broad set of personal characteristics. Compliance teams should confirm that RunPod's data processing systems can operationally honor these opt-out requests....
-
RunPod
· RunPod Privacy Policy
The policy discloses that personal information may be transferred to the United States or other countries where privacy protections may differ from those in the user's location, and directs European users to the European-specific section for additional information on transfer safeguards....
Why it matters: This provision discloses cross-border personal information transfers to jurisdictions that may have less protective privacy laws, which under GDPR requires the use of appropriate transfer mechanisms such as standard contractual clauses or adequacy decisions. The policy does not enumerate specific transfer mechanisms in the general section, though the European section addresses this separately....
-
RunPod
· RunPod Privacy Policy
The policy asks users not to submit sensitive personal information such as government identification numbers, health information, or financial information through the Service, while also acknowledging that sensitive personal information may be incidentally collected and stating that users may request limitation of its processing to specified purposes....
Why it matters: This provision creates a contractual restriction on user submission of sensitive data, while simultaneously acknowledging the possibility of incidental collection and providing a statutory limitation right under applicable state privacy laws. The coexistence of a user-facing prohibition and a processing limitation right indicates that the policy contemplates the possibility of sensitive data entering the system despite the restriction....
-
RunPod
· RunPod Terms of Service
Users assign all intellectual property rights in Feedback, ratings, ideas, and know-how submitted to RunPod without compensation or attribution. RunPod may use this Feedback for any commercial purpose including developing and selling products, and users waive all moral rights to such Feedback....
Why it matters: This provision asserts a full IP assignment of user-submitted Feedback and ratings to RunPod, including patentable concepts and know-how, without any compensation obligation. The moral rights waiver may have limited effect in jurisdictions where moral rights are not waivable by contract, such as certain EU member states....
-
RunPod
· RunPod Terms of Service
Users retain ownership of Marketplace reviews but grant RunPod an irrevocable, perpetual, worldwide, sublicensable, royalty-free license to use, modify, reproduce, distribute, and incorporate reviews into other works in any medium. This license cannot be revoked once a review is submitted....
Why it matters: This provision grants RunPod a perpetual and irrevocable license to Marketplace reviews that survives any account deletion or termination. The sublicensable-through-multiple-tiers structure permits RunPod to extend these rights to third parties without further consent from the reviewer....
-
RunPod
· RunPod Terms of Service
Subscriptions automatically renew for successive periods matching the initial term duration at RunPod's then-current fee unless the user opts out or declines renewal in accordance with the Purchases and Payment section....
Why it matters: This provision establishes automatic renewal at RunPod's then-current pricing, meaning renewal fees may differ from the original subscription rate. Users must affirmatively opt out before the renewal date to avoid being billed for subsequent terms....
-
RunPod
· RunPod Terms of Service
Users grant RunPod a worldwide, royalty-free license to access and use uploaded content to operate the Service, and to use that content in aggregated and anonymized form to improve RunPod's products and services....
Why it matters: This provision authorizes RunPod to use aggregated and anonymized versions of user content for product improvement purposes. The scope of this license is limited on its face to aggregated and anonymized form for improvement purposes, distinguishing it from the broader Feedback assignment clause....
-
RunPod
· RunPod Terms of Service
Users must represent that they are not on OFAC sanctions lists, are not located in or controlled by entities in embargoed countries (Cuba, Iran, North Korea, Syria, Crimea, DNR, LNR), and are not acting on behalf of the Venezuelan government. Breach of this representation is grounds for account suspension and termination....
Why it matters: This provision requires affirmative representations regarding OFAC and export control compliance at the time of account creation and on an ongoing basis. Providing false representations exposes the user to account termination and may create legal exposure under U.S. sanctions law independently of the Terms....
-
RunPod
· RunPod Terms of Service
RunPod provides no uptime warranty, availability guarantee, or support for Community Cloud services, and is not a party to transactions between Hosts and compute consumers. Users access Community Cloud at their own risk with no warranty that services will meet their requirements....
Why it matters: This provision establishes that Community Cloud services operate without any service level agreement, uptime commitment, or RunPod support obligation. Users selecting Community Cloud over paid Compute Services have no contractual recourse against RunPod for service failures or Host misconduct....
-
RunPod
· RunPod Terms of Service
RunPod may access and disable public access to files or data in user-controlled storage upon receipt of a DMCA notice or upon becoming aware of potential infringement. Users are required to immediately disable or remove access to content identified in a DMCA notice forwarded by RunPod....
Why it matters: This provision requires users to immediately act on DMCA notices forwarded by RunPod, creating an affirmative obligation to remove or disable access to identified content. RunPod also reserves the right to access user storage to disable content in its discretion, including based on its own awareness of potential infringement without a formal notice....
-
AWS Bedrock
· AWS Service Terms
Customers who conduct or publish benchmarks of AWS services must disclose sufficient methodology to replicate the benchmark and, by doing so, grant AWS the right to conduct and publicly disclose comparative benchmarks of the customer's own products, regardless of any restrictions in the customer's own terms of service....
Why it matters: This provision creates a contractual authorization for AWS to benchmark and publish comparative performance results on customer products upon the customer's disclosure of any AWS benchmark, which may override benchmark restriction clauses in the customer's own licensing agreements or terms of service....
-
AWS Bedrock
· AWS Service Terms
AWS may notify customers of content it reasonably believes is prohibited and allow 2 business days to remove it before AWS acts; for illegal content, content threatening service integrity, or content subject to legal orders, AWS may act without prior notice....
Why it matters: This provision establishes AWS's content enforcement mechanism, including the conditions under which services may be suspended, and creates a 2-business-day cure period for most prohibited content while reserving the right to act immediately for illegal content or service-threatening material....
-
AWS Bedrock
· AWS Service Terms
Upon suspension or termination of beta service access, customer content stored in beta services may be deleted or become inaccessible, and the terms do not guarantee migration of that content to generally available service versions....
Why it matters: This provision establishes that customer content in beta services is at risk of permanent loss upon termination of beta access, with no contractual obligation for AWS to migrate or preserve that content, creating a material data retention and business continuity risk for customers using beta services in production contexts....
-
AWS Bedrock
· AWS Service Terms
The terms incorporate the AWS DPA, the EU SCCs under Commission Implementing Decision 2021/914, the UK GDPR Addendum, the Swiss Addendum, and the CCPA Terms by reference, with each framework applying conditionally based on whether the relevant data protection regulation governs the customer's use of AWS services....
Why it matters: The conditional incorporation of multiple international data protection frameworks by reference means that the applicable contractual obligations for personal data processing depend on the customer's jurisdiction and the nature of data processed, requiring customers to assess which addenda apply to their specific use cases....
-
AWS Bedrock
· AWS Service Terms
AWS processes all RI Marketplace transaction payments on behalf of sellers, and the terms authorize AWS to withhold, deduct, or set off amounts owed by the seller to AWS or its affiliates against transaction proceeds owed to the seller....
Why it matters: The setoff provision authorizes AWS to apply amounts the seller owes to AWS against RI Marketplace transaction proceeds before remitting payment, which may reduce or eliminate proceeds available to the seller without a separate collection action....
-
Zendesk
· Zendesk Privacy Policy
This notice applies only to data where Zendesk controls the purpose of processing; data processed within Zendesk's products on behalf of business customers (Subscribers) is excluded, and affected individuals are directed to contact those Subscribers directly....
Why it matters: This provision defines the scope of Zendesk's privacy obligations under this notice, excluding data processed on behalf of Subscribers and disclaiming responsibility for Subscriber data practices. Compliance teams engaging Zendesk as a vendor must assess Subscriber obligations separately, including reviewing the Zendesk Data Processing Agreement to understand the allocation of data controller and processor responsibilities....
-
Zendesk
· Zendesk Privacy Policy
California residents must complete two separate steps to fully opt out of the sale or sharing of their personal data: submit a webform request and disable advertising cookies via the website footer link on each browser and device used....
Why it matters: This provision requires California residents to take two distinct actions to exercise their CCPA opt-out right, and states that cookie blocking or clearing will negate the opt-out for automatically collected device data. The operational complexity of this mechanism may affect whether residents can effectively exercise their statutory opt-out right, particularly across multiple devices and browsers....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that it may retain personal data after a business relationship ends for purposes including fulfilling surviving contract provisions, evidencing business practices, marketing its products and services, and meeting legal or tax requirements; data stored in backup archives may be retained until deletion is technically feasible....
Why it matters: This provision authorizes post-relationship retention for a range of purposes, including continued marketing communications, which may require evaluation under GDPR storage limitation principles and applicable national laws. The backup archive exception permits retention beyond standard deletion timelines in cases where technical deletion is not immediately feasible....
-
Zendesk
· Zendesk Privacy Policy
Zendesk acknowledges that its routine data sharing with advertising and cookie technology partners on its digital properties may qualify as a 'sale' or 'sharing' under California law, though no monetary exchange for data is described....
Why it matters: This provision constitutes Zendesk's acknowledgment that its advertising and tracking technology practices trigger CCPA and CPRA sale and sharing obligations, establishing the legal basis for California residents' opt-out rights and the associated compliance mechanisms described elsewhere in the notice....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that cross-border data transfers are conducted using EU Standard Contractual Clauses, UK Addendum, Binding Corporate Rules, and DPF certification; Zendesk asserts ongoing liability for onward transfers to third-party agents under DPF Principles....
Why it matters: This provision establishes the legal mechanisms Zendesk relies upon for international data transfers and asserts accountability for onward transfers to agents under the DPF framework. Compliance teams should assess the continued adequacy of DPF certification as a transfer mechanism given the historical legal challenges to EU-U.S. data transfer frameworks....
-
Zendesk
· Zendesk Privacy Policy
Zendesk collects sensitive personal data such as proof of vaccination and race and ethnicity on an optional basis where permitted by law, and may disclose this data to Zendesk Group affiliates, service providers, and entities involved in corporate transactions....
Why it matters: This provision discloses the collection and disclosure of special category data under GDPR terminology, including health-related data and racial or ethnic origin, which are subject to heightened protection requirements under GDPR Article 9 and equivalent national laws. The document states collection is optional and consent-based where required, but the disclosure scope includes corporate transaction parties....
-
McDonald's
· McDonald's Privacy Policy
The policy states that McDonald's uses customer personal information to train algorithms and AI models, and employs profiling technology, with a stated carve-out that such profiling will not include automated decisions with legal or similarly significant effects unless separately disclosed....
Why it matters: This provision establishes a broad authorization to use customer data for AI and algorithm training across McDonald's products and services, with the carve-out for automated individual decisions referencing GDPR Article 22 language but not specifying which data categories are used in training or whether third-party AI vendors are involved in this processing....
-
McDonald's
· McDonald's Privacy Policy
The global section states McDonald's does not sell personal information for monetary consideration, while acknowledging that US state law definitions of 'sale' may encompass sharing with advertising networks and analytics companies for valuable consideration, directing US users to the country-specific addendum....
Why it matters: This provision discloses a structurally significant tension between the policy's assertion of no monetary sale and the acknowledgment that sharing arrangements with advertising and analytics partners may qualify as sales under California and other US state privacy statutes, triggering opt-out rights and disclosure obligations under those frameworks....
-
McDonald's
· McDonald's Privacy Policy
The US addendum provides a CCPA-required financial incentive notice disclosing that participation in MyMcDonald's Rewards involves collection of identifiers, payment details, purchase records, app interaction data, geolocation, and behavioral inferences, with McDonald's stating it does not assign an independent monetary value to this data....
Why it matters: This provision establishes the data collection scope for the loyalty program and satisfies the California law requirement to disclose the material terms of financial incentive programs that involve personal information, including the categories of data collected and an estimate of its value relative to program benefits....
-
McDonald's
· McDonald's Privacy Policy
The policy explicitly excludes franchisee-operated restaurants and any digital properties they operate from the scope of this Privacy Statement, directing customers to consult each franchisee's own privacy practices separately....
Why it matters: This provision establishes that the privacy protections, rights, and disclosures in this document do not extend to customer interactions with franchisee-operated restaurants or their digital properties, creating a fragmented governance structure across the McDonald's network where customer rights and data practices may vary by location....
-
McDonald's
· McDonald's Privacy Policy
The policy discloses that targeting cookies set by McDonald's or its advertising partners may be used to build interest profiles and deliver advertising on third-party sites, and that these cookies may interact with other third-party cookies in the user's browser, with tracking occurring over time and across multiple websites and devices....
Why it matters: This provision authorizes cross-site and cross-device behavioral tracking for advertising purposes by McDonald's and third-party advertising networks, with the additional disclosure that targeting cookies may view, edit, or set other third-party cookies in the user's browser....
-
McDonald's
· McDonald's Privacy Policy
The policy discloses automated collection of precise geolocation data, advertising identifiers, UDIDs, device serial numbers, IP addresses, and video recordings of restaurant visits through in-restaurant digital technology....
Why it matters: This provision discloses a broad range of automated data collection spanning online, mobile, and physical restaurant environments, including persistent device identifiers and in-restaurant video, which collectively enable cross-context tracking of individual customers....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of exterior vehicle camera and sensor images and video with consent or upon detection of a safety event, and separately authorizes collection of road information from exterior cameras at all times, with the acknowledgment that camera images may capture third parties in the surrounding environment....
Why it matters: This provision establishes two distinct collection triggers, consent-based and safety-event-based, for exterior camera media, and a continuous collection basis for road data derived from exterior cameras, with the acknowledged implication that third parties present in the vehicle's environment may be incidentally captured....
-
General Motors
· GM Privacy Statement
The policy states that for connected vehicle personal information categories including driver behavior, precise geolocation, exterior camera data, and AI assistant interaction data, GM will require government data requests to take the form of a warrant or court order, except in exigent circumstances or where applicable statutory authority provides otherwise....
Why it matters: This provision establishes a documented procedural standard requiring judicial process for government access to connected vehicle personal information categories, which represents a specific operational commitment that legal and compliance teams can reference when assessing government data access risk for vehicle-generated data....
-
General Motors
· GM Privacy Statement
The policy establishes that precise geolocation and driver behavior information are subject to a specific retention schedule of up to 3 years from collection, with extensions permitted for legal or regulatory obligations, and that data is de-identified or disposed of when no longer needed for stated purposes....
Why it matters: This provision establishes a documented retention baseline of up to 3 years for sensitive connected vehicle data categories, with an open-ended extension clause for legal or regulatory obligations that may result in retention beyond the stated period in circumstances not further specified in the excerpted text....
-
General Motors
· GM Privacy Statement
The policy establishes universal access, correction, and deletion rights for all covered consumers, with additional rights including targeted advertising opt-out, data sale opt-out, and automated processing opt-out available depending on the consumer's state of residence, and a stated processing time of up to 45 days....
Why it matters: This provision establishes the operational framework for consumer privacy right requests, including a 45-day processing window and a verification requirement, with jurisdiction-dependent rights that require consumers to know their state's applicable framework to determine their full entitlement....