-
General Motors
· GM Privacy Statement
The policy authorizes use and disclosure of de-identified data for purposes not described in the privacy statement, states that reasonable re-identification prevention measures are applied and required of third parties, but does not specify what technical standards constitute adequate de-identification....
Why it matters: This provision establishes that de-identified data falls outside the policy's stated use and disclosure limitations, and may be shared with third parties for unstated purposes, subject to a reasonable safeguard standard whose specific technical parameters are not defined in the document....
-
General Motors
· GM Privacy Statement
The policy discloses that personal information stored in a vehicle, including contacts, address searches, and preferences, may remain accessible to future vehicle users if not deleted prior to sale or transfer, and encourages but does not require the owner to delete this data before transfer....
Why it matters: This provision establishes that data deletion before vehicle sale or transfer is the responsibility of the current owner rather than a system-enforced process, and that failure to delete may result in personal information being accessible to subsequent vehicle users....
-
Ford
· Ford Privacy Policy
The policy states that Ford shares personal information with dealers, who operate as independent businesses with their own privacy policies and may use the data for their own marketing purposes outside of Ford's control....
Why it matters: This provision establishes that dealers are independent data controllers, meaning Ford's privacy policy obligations and consumer rights requests do not automatically bind dealer handling of shared data. Consumers exercising deletion or opt-out rights with Ford may not have those rights automatically honored by dealers who have already received their data....
-
Ford
· Ford Privacy Policy
The policy states that California residents may opt out of the sale or sharing of their personal information by using a designated link on Ford's website or submitting a request through Ford's privacy request portal, and Ford commits to process these requests within legally required timeframes....
Why it matters: This provision operationalizes the CCPA/CPRA opt-out right for California residents. The mechanism covers both 'sale' and 'sharing' of personal information, which under CPRA includes cross-context behavioral advertising data flows that may not involve monetary consideration....
-
Ford
· Ford Privacy Policy
The policy states that Ford shares personal information with advertising partners, analytics providers, and social media companies for targeted advertising, campaign measurement, and digital service analysis, using cookies, pixel tags, and similar tracking technologies....
Why it matters: This provision authorizes data sharing with advertising and analytics third parties through tracking technologies, which constitutes 'sharing' under CPRA and may require opt-out mechanisms for cross-context behavioral advertising. The involvement of social media platforms as data recipients creates additional data flow pathways beyond Ford's direct control....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Ford
· Ford Privacy Policy
The policy states that consumers may submit requests for deletion of their personal information, subject to exceptions, and that Ford will verify identity and respond within legally required timeframes....
Why it matters: This provision operationalizes deletion rights under CCPA/CPRA and analogous state frameworks. The reference to 'certain exceptions' is significant because CPRA permits retention of data for a range of business purposes that may limit the practical scope of deletion requests, particularly for vehicle service and warranty records....
-
Ford
· Ford Privacy Policy
The policy states that Ford may create consumer profiles by drawing inferences from collected personal information, and that these profiles may be used for marketing, personalization, and business purposes....
Why it matters: Inferences and consumer profiles are recognized as a distinct category of personal information under CPRA and several analogous state statutes, triggering specific disclosure, access, and deletion rights. The use of inferences drawn from vehicle telematics and driving behavior for marketing purposes is operationally significant given the sensitivity of the underlying data....
-
Duolingo
· Duolingo Privacy Policy
This provision authorizes Duolingo to record and store audio and text submitted through AI-powered features including Video Call, and to use those recordings and transcripts for product improvement and AI model training. The text and audio may also be shared with vendors including OpenAI and Google, subject to contractual restrictions on those vendors' independent use of the data....
Why it matters: This provision authorizes Duolingo to retain AI interaction content and use it for AI model training purposes, and to share that content with named third-party AI vendors. The adequacy of the vendor contractual restrictions on secondary use may warrant independent compliance review, particularly under GDPR data minimization and purpose limitation principles....
-
Duolingo
· Duolingo Privacy Policy
This provision discloses that Duolingo's website places targeting cookies from Google, Meta, Amazon, and unspecified other companies, which those companies may use to track user activity across multiple websites for personalized advertising purposes....
Why it matters: This provision establishes that cross-site behavioral tracking occurs through third-party cookies placed by named advertising platforms, and that users in the EU and UK are opted out of personalized advertising by default while users in other jurisdictions must actively opt out....
-
Duolingo
· Duolingo Privacy Policy
This provision states that Duolingo may anonymize personal information and use the resulting de-identified data for any purpose, including AI model training, asserting that such data falls outside the definition of personal information because it cannot identify individuals....
Why it matters: This provision reserves broad secondary use rights over de-identified data derived from user activity. The practical scope of this authorization depends on the robustness of the anonymization method applied, which the policy does not describe in technical detail; applicable law in some jurisdictions may impose standards for what constitutes adequate de-identification....
-
Duolingo
· Duolingo Privacy Policy
This provision discloses that FullStory and a Session Replay service log user activity including clicks, mouse movements, scrolling, typing, browser and device information, IP address, pages visited, and learning activity. Users can disable these services using the Tracking toggle in app Settings; both are disabled by default for Child Users....
Why it matters: This provision discloses that detailed behavioral session recording, including keystroke-level typing activity and video replay of user sessions, is conducted by third-party services. Users must actively opt out via the Tracking toggle rather than being enrolled on an opt-in basis, except for Child Users who are excluded by default....
-
Duolingo
· Duolingo Privacy Policy
This provision establishes that Child Users under 13 (or applicable local age of digital consent) are registered without name, email, or phone number, using only a non-identifying username. The policy asserts COPPA compliance by limiting collection to what is necessary for internal service operations and committing to delete inadvertently collected additional data....
Why it matters: This provision establishes the operational framework for COPPA compliance, including the categories of data excluded from collection for Child Users and the parental notification mechanism triggered at first logout. The policy separately states that all users under 16 receive additional protections including non-personalized advertising and disabled third-party behavioral tracking....
-
Duolingo
· Duolingo Privacy Policy
This provision states that Duolingo relies on the EU-U.S. DPF, UK Extension to the DPF, and Swiss-U.S. DPF as the legal mechanism for transferring personal data from the EU, UK, and Switzerland to the United States, and that Duolingo retains liability under DPF Principles for data transferred to third-party agents that process it inconsistently with those Principles....
Why it matters: This provision establishes the international data transfer legal basis for EU, UK, and Swiss user data processed in the United States, and affirms FTC jurisdiction over DPF compliance. Duolingo's ongoing DPF certification requires annual renewal and is subject to FTC enforcement action for material misrepresentation of compliance....
-
Duolingo
· Duolingo Privacy Policy
This provision authorizes Duolingo to share personal information with named advertising networks including Unity, Meta, LiftOff, Pangle, Moloco, and Google for personalized advertising purposes. EU and UK users are opted out by default; all other users may opt out through app Settings....
Why it matters: This provision discloses that personal information is shared with six named advertising network vendors and unspecified additional marketing analytics and website analysis providers for cross-site advertising and market research purposes. The default opt-out for EU and UK users reflects applicable regulatory requirements in those jurisdictions....
-
Walgreens
· Walgreens Privacy Policy
The policy states that information submitted through a pharmacy account login, including prescription order data, is governed by HIPAA's Notice of Privacy Practices rather than this privacy policy, creating a distinct legal framework for pharmacy interactions separate from general retail data practices....
Why it matters: This provision establishes a structural data governance boundary between HIPAA-covered pharmacy data and general retail personal information, which determines which consumer rights framework and which notice and consent mechanisms apply depending on the nature of the customer interaction....
-
Walgreens
· Walgreens Privacy Policy
The policy states that personal information collected from customers may be disclosed to potential buyers or transferred to acquiring entities in connection with mergers, acquisitions, or the sale of Walgreens stores or assets, and that customer information is treated as a transferred business asset in such transactions....
Why it matters: This provision establishes that customer personal information, including all categories described in the policy, may be disclosed during the evaluation phase of a potential transaction and transferred to a new entity following an acquisition, without requiring separate individual consent at the time of transfer....
-
Walgreens
· Walgreens Privacy Policy
The policy states that by using chatbot or managed chat features on the Walgreens website, users consent to Walgreens recording and retaining transcripts of all communications and recording or recreating website activity, with that data potentially shared with third-party service providers for analysis and storage....
Why it matters: This provision establishes that chatbot interactions and website activity may be recorded, retained, and shared with service providers, and that use of the interactive features constitutes consent to these practices. Users who discuss health or pharmacy-adjacent topics through chatbot channels should note that this data may be subject to the general retail privacy policy rather than HIPAA depending on whether the interaction occurs outside of a pharmacy account login....
-
Walgreens
· Walgreens Privacy Policy
The policy states that third-party advertising networks place cookies on users' devices to collect data and build behavioral profiles for targeted advertising on Walgreens' website and third-party websites, and that some of these networks participate in opt-out programs operated by the Digital Advertising Alliance and Network Advertising Initiative....
Why it matters: This provision authorizes third-party advertising networks to build behavioral profiles from user data collected across Walgreens and unaffiliated websites, and discloses that opting out of interest-based advertising does not stop data collection for analytics and fraud prevention purposes....
-
Walgreens
· Walgreens Privacy Policy
The policy discloses that Walgreens' myWalgreens loyalty program provides price discounts and perks in exchange for consumer participation that may generate personal information across all categories described in the policy, and includes a California-required Notice of Financial Incentive describing the basis for the data-for-benefit exchange including a qualitative description of data valuation methodology....
Why it matters: CPRA requires that businesses offering financial incentives in exchange for personal information provide a Notice of Financial Incentive including a good faith estimate of the value of the consumer's data and the material terms of the program, and this provision constitutes Walgreens' attempt to satisfy that requirement, including the statement that data value is not calculated in accounting statements....
-
Verizon
· Verizon Privacy Policy
The Custom Experience program uses browsing and app usage data to personalize communications and product recommendations. Customers are enrolled by default and must actively opt out to be excluded from the program....
Why it matters: This provision establishes an opt-out default for a program that uses mobile device browsing and app usage data for behavioral profiling and targeted marketing, meaning customers are included unless they take affirmative action to opt out....
-
Verizon
· Verizon Privacy Policy
The policy discloses that CPNI (telecommunications usage data including call records, location, and billing information) is governed by federal law and that Verizon may seek consent to use CPNI to market services beyond those a customer already has, with an opt-out available....
Why it matters: This provision establishes that CPNI is subject to federal Communications Act requirements and that customers can limit its use for marketing beyond existing services, an operationally significant right for telecommunications customers that is governed by FCC rules rather than general consumer privacy law....
-
Verizon
· Verizon Privacy Policy
The Business and Marketing Insights program uses postpaid and small business customer data including web browsing, device location, app usage, demographic information, and third-party data to generate aggregate insights that are disclosed to third parties; the policy states the disclosed insights do not individually identify customers....
Why it matters: This provision establishes that Verizon uses individual-level behavioral and location data from postpaid and small business customers as inputs to create aggregate insights that are then commercially disclosed to third parties, with the policy asserting individual identifiability is removed at the output stage....
-
Verizon
· Verizon Privacy Policy
The policy discloses that Fios TV apps and the Fios TV website include Comscore and Nielsen software that collects TV viewership data, advertising identifiers, IP addresses, and device information and transmits this data to Comscore and Nielsen for market research and audience measurement purposes....
Why it matters: This provision establishes that Fios TV viewing data, advertising identifiers, and device information are disclosed to Comscore and Nielsen through embedded software, creating a third-party data collection arrangement within a video service subject to the Cable Communications Policy Act's subscriber data protection requirements....
-
Verizon
· Verizon Privacy Policy
The policy authorizes Verizon to use automated processing including artificial intelligence and machine learning to train algorithmic models using customer data for network management, marketing personalization, and service prediction. The policy includes a specific statement that customer personal information is not collected, used, or sold to train large language models....
Why it matters: This provision establishes that customer data is used to train machine learning models for marketing and service prediction purposes, and includes an explicit carve-out stating that personal information is not used for large language model training, a disclosure that addresses a specific area of consumer and regulatory concern regarding generative AI....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states that personal data collected across all categories described in the notice may be used to train artificial intelligence models, with examples including network improvement and customer service enhancement....
Why it matters: This provision establishes AI model training as a stated purpose for personal data use across all collected data categories, without specifying which categories are excluded from AI training or what separate consent conditions, if any, apply to this use beyond those governing the underlying collection purpose....
-
T-Mobile
· T-Mobile Privacy Policy
T-Mobile's Relevant Ads program operates as a default, collecting app usage data, mobile advertising IDs, and purchased demographic data to build interest models and deliver targeted third-party advertising through advertising partners....
Why it matters: This provision establishes that targeted advertising using app usage data, mobile advertising IDs, and purchased demographic data operates by default, requiring consumers to actively opt out through the Privacy Dashboard rather than opt in to participate....
-
T-Mobile
· T-Mobile Privacy Policy
T-Mobile compiles fraud indicators from account status, SIM change history, call and text history, URL interaction data, and risk scores, and shares these indicators with third-party companies where a consumer holds accounts, with an opt-out available through the Privacy Dashboard....
Why it matters: This provision establishes that SIM change history, call and text history, and risk scores derived from network behavior may be shared with external companies outside T-Mobile for fraud prevention purposes, creating a third-party data sharing relationship that consumers can opt out of through the Privacy Dashboard....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states that T-Mobile collects personal data from social media companies, financial institutions, credit reporting agencies, and data resellers, supplementing data collected directly from consumers and automatically through network interactions....
Why it matters: This provision establishes that consumer profiles at T-Mobile are built in part from externally purchased or obtained data sourced from data resellers, social media companies, and credit reporting agencies, which are then combined with internally collected network, usage, and account data for uses described throughout the notice....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement provides a data sale and sharing opt-out mechanism through the Privacy Dashboard and a site-level link, recognizes the Global Privacy Control signal as a valid opt-out, and states that separate consent withdrawal through the Privacy Dashboard may be required for consumers enrolled in specific advertising programs....
Why it matters: This provision establishes that T-Mobile engages in the sale and sharing of personal data for targeted advertising as defined under applicable state privacy law, that opt-out is available but requires multiple steps for consumers enrolled in program-specific advertising, and that GPC signal recognition satisfies California's CCPA opt-out signal requirement....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement provides an opt-out mechanism through the Privacy Dashboard for profiling activities that produce legal or similarly significant effects, defining profiling as automated processing to evaluate or predict aspects including economic situation, health, reliability, behavior, and location....
Why it matters: This provision establishes a consumer opt-out right for profiling that produces legal or similarly significant effects, consistent with emerging state privacy law requirements for automated decision-making, and signals that T-Mobile engages in or anticipates engaging in such profiling activities....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states that device usage, app behavior, demographic, and ad interaction data is aggregated and that resulting aggregate reports may be sold to third-party companies, with an opt-out available through the Privacy Dashboard....
Why it matters: This provision establishes that aggregate behavioral and demographic reports derived from consumer device and network usage data may be commercially sold to external companies, representing an outbound commercial data product derived from subscriber activity....
-
Roblox
· Roblox Privacy Policy
The policy states that third-party experience creators automatically receive users' usernames, display names, user IDs, game metrics, UGC transaction details, and regional location derived from IP addresses, without any opt-out mechanism described for this sharing....
Why it matters: This provision establishes automatic data sharing with third-party creators as an inherent condition of using any Roblox experience, creating downstream data controller or processor relationships that may require contractual documentation under GDPR Article 28 and equivalent frameworks in other jurisdictions....
-
Roblox
· Roblox Privacy Policy
The policy states that user-posted content, including chat and audio, may be used for AI training and content filtering improvement purposes where law permits. This applies to content posted in chats, forums, group walls, personal posts, and other features....
Why it matters: This provision reserves the right to use user-generated content, including communications content, for AI training purposes subject to applicable law, which may require evaluation under GDPR's lawful basis and purpose limitation principles, as well as emerging AI training data regulations in the EU and other jurisdictions....
-
Roblox
· Roblox Privacy Policy
The policy states that for users under 13, persistent identifiers such as IP addresses and device identifiers are collected and used only for the six enumerated internal operations purposes, and that Roblox implements technical and contractual measures to enforce this restriction....
Why it matters: This provision establishes COPPA-compliant limitations on persistent identifier use for users under 13, with the policy asserting that technical and contractual safeguards are in place to prevent use beyond the enumerated purposes, including a restriction to contextual advertising only (no personalized advertising) for this age group....
-
Roblox
· Roblox Privacy Policy
The policy establishes that users under 18 receive only non-personalized advertisements, while users 18 and older may receive personalized advertisements, with consent required where applicable law mandates it. Users 18 and older can manage personalized ad preferences through account settings....
Why it matters: This provision establishes a platform-wide age gate for personalized advertising set at 18 rather than the COPPA threshold of 13, which represents a more restrictive advertising policy for the 13-17 age cohort and may interact with GDPR consent requirements for users in the EEA who are minors under applicable national law....
-
Roblox
· Roblox Privacy Policy
The policy states that users who opt into the Contact Importer feature share their mobile address book contents, including first and last names and phone numbers of all contacts, with Roblox, and that Roblox automatically accesses and syncs this data periodically. Data from non-matching contacts is not retained....
Why it matters: This provision establishes ongoing, automatic collection of third-party contact data (individuals who are not Roblox users and have not consented to data collection) from the address books of users who activate the feature, which may require evaluation under GDPR, CCPA, and other privacy frameworks with respect to the rights of non-user data subjects....
-
Roblox
· Roblox Privacy Policy
The policy states that Roblox may share Personal Information and the contents of user communications with law enforcement, regulators, courts, schools, children's services, and other public agencies under several conditions including legal process, crime prevention belief, safety threats, and legal rights protection. The policy also specifically references obligations under the EU Digital Services Act Article 18, UK Online Safety Act, and Australian Online Safety Act as bases for disclosing communication contents....
Why it matters: This provision establishes the conditions under which Roblox discloses user data and communications to governmental and public authorities, including discretionary disclosures based on Roblox's belief that disclosure may prevent a crime or protect legal rights, in addition to compelled disclosures under legal process. The explicit reference to DSA Article 18, UK Online Safety Act, and Australian Online Safety Act reflects jurisdiction-specific statutory obligations....
-
Roblox
· Roblox Privacy Policy
The policy states that participation in the Roblox Developer Exchange Program requires submission of IRS W-9 or W-8 tax forms and may require identity verification through a government-issued photo ID processed by a third-party vendor. This program is limited to users 13 and older....
Why it matters: This provision establishes that developers seeking to monetize through the Developer Exchange Program must provide tax identification information and may be required to submit government-issued identity documents to a third-party vendor, creating distinct data collection and processing obligations for this user segment including identity document handling by a named or unnamed third party....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung collects and stores voice recordings on its servers when users enable voice commands or contact customer service, and that third-party speech-to-text or call center providers may also receive and store voice commands. The policy also states that keyboard input typed when predictive text is enabled is collected and may be synchronized across Samsung mobile devices via a Samsung account....
Why it matters: Voice recordings and keyboard input represent categories of personal information with heightened sensitivity; collection of keyboard input through predictive text and synchronization across devices via Samsung account extends the scope of data collection beyond single-device interactions. Third-party receipt of voice commands via speech-to-text providers introduces additional data controllers outside Samsung's direct control....
-
Samsung
· Samsung Privacy Policy
The policy states that personal information will be transferred to and processed in the Republic of Korea, and acknowledges that data protection laws in recipient countries may not be as comprehensive as those in the user's country of residence. For EEA, UK, and Swiss residents, the policy states it relies on standard contractual clauses and adequacy determinations for transfers to the Republic of Korea....
Why it matters: The explicit identification of the Republic of Korea as a primary destination for personal information transfers is a specific and material disclosure for users in jurisdictions with transfer restrictions, including EEA and UK residents subject to GDPR and UK GDPR. The policy's reliance on adequacy determinations for the Republic of Korea reflects the EU-Korea adequacy decision but may require ongoing monitoring given the evolving regulatory landscape for international transfers....
-
Samsung
· Samsung Privacy Policy
The US Supplement provides US residents with opt-out rights covering sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, voice recognition data collection, and further materially different processing triggered by material policy changes. These rights are stated to be subject to applicable law....
Why it matters: This provision enumerates six distinct opt-out rights for US residents, several of which correspond to specific rights under the CCPA and CPRA and analogous state statutes. The inclusion of an opt-out right for materially different processing following policy changes is notable because it establishes a mechanism for users to limit prospective use of previously collected data when Samsung materially amends its policies....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung's services are not directed to children under 13, that Samsung does not knowingly collect personal information from children under 13 without parental consent, and that if such collection is discovered, Samsung will seek parental consent or delete the information. A reporting mechanism is provided for concerned parties....
Why it matters: This provision describes Samsung's stated compliance posture under the Children's Online Privacy Protection Act (COPPA), which governs collection of personal information from children under 13. The policy's general audience designation and knowledge-based standard for collection align with standard COPPA compliance language, though COPPA enforcement focuses on operator knowledge and the design of services....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung uses Google Analytics, Firebase Analytics, and Adobe Analytics to collect personal information about user online activities across websites, devices, and apps over time, and that information may be disclosed to or collected directly by these analytics providers. The policy directs users to the Google Analytics privacy policy for further information....
Why it matters: The named use of Google Analytics, Firebase Analytics, and Adobe Analytics establishes that cross-site and cross-device behavioral data is shared with or directly collected by third-party analytics providers operating under their own privacy frameworks. The collection of data across third-party websites and devices over time is a practice that may engage state law definitions of targeted advertising and sale of personal information....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung collects payment card numbers, expiration dates, and security codes for order processing, and that users may optionally save payment information for future transactions. The policy also discloses that social security numbers are collected when users apply for credit or financing through Samsung....
Why it matters: The collection of payment card data including security codes and social security numbers for credit applications represents categories of highly sensitive financial data. The optional storage of payment information for future transactions creates a persistent data retention relationship that users should be aware of when evaluating account data management....
-
Calendly
· Calendly Privacy Notice
When a Calendly customer uses the platform to schedule or record a meeting with you, Calendly asserts it acts only as a data processor under that customer's instruction, and directs any data subject rights requests regarding that data to the originating customer rather than to Calendly....
Why it matters: This provision establishes that individuals whose data is collected by a Calendly customer during scheduling or meeting recording must direct rights requests to the customer entity, not to Calendly, which has direct implications for how data subject access, deletion, and correction rights are fulfilled in practice. Organizations deploying Calendly bear controller obligations under GDPR, CCPA, and comparable frameworks for data collected through Calendly's Services on their behalf....
-
Calendly
· Calendly Privacy Notice
The policy discloses that Calendly's use of cookies and tracking technologies for targeted advertising and analytics may constitute a sale or sharing of Personal Data under the CCPA, and identifies identifiers and internet or similar network activity as the categories sold or shared in the preceding 12 months....
Why it matters: This provision creates a formal CCPA disclosure obligation and establishes that California residents have the right to opt out of cookie-based data sales and sharing via the cookie management module or GPC signal. Organizations reviewing Calendly's compliance posture should confirm that the opt-out mechanism is operationally functional and that the data categories disclosed align with actual third-party data flows....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly uses session replay and session recording tools provided by third-party service providers to record user interactions with its website, including mouse movements and webform engagement....
Why it matters: This provision discloses that detailed behavioral interaction data, including webform engagement, is captured and potentially shared with third-party service providers operating session recording tools. Depending on jurisdiction, session recording of webform interactions may implicate wiretapping or electronic communications statutes, and the adequacy of the cookie consent mechanism as a legal basis for this collection warrants review....
-
Calendly
· Calendly Privacy Notice
The policy discloses that Calendly acquires name, email address, phone number, job title, employer, employment seniority, social media usernames and avatars, and social media activity details from third-party lead-generation and marketing companies, and uses this data for sales and marketing purposes....
Why it matters: This provision establishes that Calendly may hold detailed professional and social profile data about individuals who have not directly interacted with Calendly, sourced from third-party data brokers and lead-generation companies. This data flow may implicate CCPA and GDPR notice and transparency obligations, particularly regarding the requirement to inform data subjects about data obtained from third-party sources....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly has certified to the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. DPF, and that in any conflict between the privacy notice and DPF Principles, the Principles govern; it also establishes that Calendly bears liability for onward transfers to third-party agents who process data inconsistently with the DPF Principles unless Calendly proves it is not responsible....
Why it matters: This provision establishes DPF certification as the primary legal mechanism for EU, UK, and Swiss data transfers to the United States, with DPF Principles taking precedence over the privacy notice in cases of conflict. The onward transfer liability provision is a materially significant commitment: Calendly accepts liability for its agents' DPF-inconsistent processing unless it can demonstrate it is not responsible....
-
Calendly
· Calendly Privacy Notice
The policy states that Personal Data of individuals located in the EEA, UK, Canada, and other non-U.S. jurisdictions will be processed and stored in the United States or in countries where Calendly's service providers operate, and that those jurisdictions may not offer equivalent privacy protections....
Why it matters: This provision discloses that Personal Data from EEA, UK, and Canadian individuals is transferred to and stored in the United States, a jurisdiction that has historically been subject to adequacy assessments by European and UK data protection authorities. The policy states that transfer mechanisms including the DPF, Standard Contractual Clauses, and UK Addendum are relied upon to legitimize these transfers....