-
Grammarly
· Grammarly Privacy Policy
The policy states that Superhuman uses collected information including user content to train its AI models, and provides individual users an opt-out mechanism accessible through account settings....
Why it matters: This provision establishes a user-facing control for AI training data use, with the default state of that control not explicitly specified in the policy text; users who have not actively reviewed account settings may not know whether their content is currently included in AI training data....
-
Grammarly
· Grammarly Privacy Policy
The policy states it does not apply to content uploaded to or output from products used under organizational account management; such content is processed under the data processing agreement between Superhuman and the managing organization, not under this policy....
Why it matters: This provision establishes that individual employees or institutional users who access Superhuman products through employer or institution-managed accounts cannot exercise data rights under this policy for their work-related content; those rights must be directed to the managing organization....
-
Grammarly
· Grammarly Privacy Policy
The policy discloses that cookie IDs, device identifiers, browsing activity on Superhuman marketing websites, and unique identifiers derived from email addresses or phone numbers are shared with advertising and social network partners for targeted advertising, and acknowledges these activities may constitute sale or sharing under applicable state privacy laws....
Why it matters: This provision operationalizes the targeted advertising disclosure requirements under CCPA/CPRA and equivalent state privacy laws by identifying the specific categories of personal information disclosed (cookie IDs, email-derived unique identifiers, browsing activity) and the recipient categories (advertising networks, social networks), and provides opt-out mechanisms for users in covered jurisdictions....
-
Grammarly
· Grammarly Privacy Policy
The policy states that Superhuman is certified under the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, and commits to resolving cross-border data transfer complaints first directly, then through VeraSafe as an alternative dispute resolution provider, with binding arbitration available as a final recourse under the Framework....
Why it matters: This provision establishes the operational dispute resolution pathway for EEA, UK, and Swiss individuals whose personal data is transferred to the United States, including a binding arbitration option before a Data Privacy Framework Panel as a last resort mechanism, with FTC jurisdiction over overall Framework compliance....
-
Grammarly
· Grammarly Privacy Policy
The policy states that personal data may be transferred and processed outside the user's country of residence, and that the company applies the protections described in the policy and complies with applicable legal transfer frameworks including standard contractual clauses for non-DPF transfers....
Why it matters: This provision establishes the legal transfer mechanisms Superhuman relies upon for international data flows, including the Data Privacy Frameworks for EEA, UK, and Swiss transfers and standard contractual clauses for transfers to other third countries....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Grammarly
· Grammarly Privacy Policy
The policy states that when users integrate or use third-party marketplace offerings, Superhuman may disclose user information to those third parties and their associated API providers according to the user's settings, and disclaims ownership or control over third-party data practices....
Why it matters: This provision establishes that data disclosed to third-party marketplace participants is governed by those third parties' own policies rather than this privacy policy, and that users are responsible for reviewing third-party terms before integration....
-
Grammarly
· Grammarly Privacy Policy
The policy asserts legitimate interests under GDPR Article 6(1)(f) as the legal basis for using all categories of collected data, including user content, to develop and improve AI models....
Why it matters: This provision establishes legitimate interests as the sole GDPR legal basis for AI development processing across all data categories, including user content such as emails and documents; users in the EEA and UK have the right to object to processing on this basis under GDPR Article 21....
-
HubSpot
· HubSpot Privacy Policy
The policy states that personal data collected through use of HubSpot products and services may be processed to train HubSpot's AI models and develop AI-related features and products....
Why it matters: This provision authorizes a secondary processing purpose beyond product delivery: personal data from product and service usage may be applied to AI model training. The provision does not specify which categories of personal data are used for training, which AI models or features are involved, or whether this processing is limited to aggregated or anonymized data versus identified personal data....
-
HubSpot
· HubSpot Privacy Policy
The policy states that when HubSpot customers install the HubSpot Tracking Code on their own websites, HubSpot collects IP addresses and online identifiers from those website visitors and processes this data as a controller for HubSpot's own purposes, including improvement of its commercial dataset....
Why it matters: This provision establishes that HubSpot assumes an independent controller role over data collected from visitors to customer-operated websites via the tracking code, distinct from its processor role under customer instructions. This means visitors to third-party websites using HubSpot infrastructure may have their data processed by HubSpot for HubSpot's own commercial purposes without direct notice from HubSpot....
-
HubSpot
· HubSpot Privacy Policy
The policy states that HubSpot shares personal data including email addresses with advertising partners to enable delivery of personalized HubSpot advertisements on third-party websites and mobile applications, and that users can opt out via a form linked in the policy....
Why it matters: This provision authorizes disclosure of email addresses to third-party advertising networks for cross-site ad targeting. An opt-out mechanism is described, but the default position is that email addresses are shared with advertising partners unless users affirmatively opt out....
-
HubSpot
· HubSpot Privacy Policy
The policy states that U.S. users who connect bank accounts for payment purposes have their banking credentials transmitted to Plaid, a third-party financial data service, and that Plaid processes their personal and financial data under Plaid's own privacy policy....
Why it matters: This provision discloses that banking credentials entered during checkout are transmitted to a third party (Plaid) and processed under a separate privacy policy, meaning HubSpot's privacy protections do not govern this data once transmitted. Users must review Plaid's Privacy Policy separately to understand how their financial data is handled....
-
Asana
· Asana Privacy Statement
Asana's Data Processing Addendum is automatically incorporated into the Subscriber Terms without requiring a separately executed agreement, and applies globally to all customers....
Why it matters: This provision establishes that the DPA's data protection commitments, including processing limitations, audit rights, subprocessor obligations, and cross-border transfer mechanisms, are operative for all customers as part of the standard subscription agreement....
-
Asana
· Asana Privacy Statement
Asana uses Data Privacy Frameworks (EU-US, UK Extension, Swiss-US) as the primary mechanism for cross-border data transfers, with Standard Contractual Clauses serving as a contractual fallback if any applicable framework is invalidated....
Why it matters: This provision establishes the transfer mechanism hierarchy for international data flows from the EU, UK, and Switzerland to the US, with SCCs automatically operative as a fallback, which is relevant given prior EU Court of Justice rulings invalidating predecessor frameworks....
-
Asana
· Asana Privacy Statement
Asana explicitly advises customers not to store financial account numbers, social security numbers, or similar sensitive personal data within the platform, in the context of GLBA compliance....
Why it matters: This provision places an affirmative advisory obligation on customers regarding data types that should not be stored in Asana, which has implications for acceptable use compliance, liability allocation, and regulated industry customers operating under GLBA or similar frameworks....
-
Asana
· Asana Privacy Statement
Asana offers customers a choice of data residency in Europe, Australia, Japan, or the US, and provides an Enterprise Key Management feature allowing customers to use their own encryption keys for Asana data....
Why it matters: These provisions establish specific technical and operational controls that may be material for customers subject to data localization requirements or sector-specific encryption mandates, including GDPR-aligned data residency obligations and regulated industry encryption standards....
-
Asana
· Asana Privacy Statement
Asana characterizes itself as a CCPA service provider for business customers and commits to processing personal information only for contractually specified purposes and to cooperating with customer obligations to fulfill consumer deletion and access requests....
Why it matters: This provision establishes the CCPA service provider relationship and the associated processing limitation, which is material for California-based businesses that rely on Asana to fulfill consumer data rights requests under CCPA and CPRA....
-
Monday.com
· Monday.com Privacy Policy
Account Admins employed by the Customer organization retain access to content submitted to boards designated as private, including the ability to copy and process that content, regardless of the board's privacy settings for other users....
Why it matters: This provision establishes that privacy designations applied to boards within the platform do not restrict access by Account Admins acting on behalf of the Customer organization, meaning personal data and content submitted to private boards remains accessible to organizational administrators....
-
Monday.com
· Monday.com Privacy Policy
The policy discloses that phone calls, video conferences, screen recordings, screenshots, and written correspondence may be automatically recorded, tracked, transcribed, and analyzed by monday.com and its Service Providers for analytics, quality control, training, and record-keeping....
Why it matters: This provision establishes that interactions with monday.com personnel including customer experience and product consultants may be subject to automatic recording and transcription, and that session or activity recording services and call recording and transcription services are listed as authorized Service Provider categories with access to personal data....
-
Monday.com
· Monday.com Privacy Policy
The policy discloses that contact and profile information for Prospects is collected not only directly but also from named third-party data enrichment and professional data providers including LinkedIn, ZoomInfo, Clearbit, Cognism, and Lusha....
Why it matters: This provision establishes that monday.com sources personal data about prospective customers from commercial data brokers and professional networking platforms, meaning individuals may have profile data held by monday.com without having directly interacted with the company....
-
Monday.com
· Monday.com Privacy Policy
In jurisdictions where consent is the required legal basis for processing, the policy asserts that acceptance of the Terms of Service and Privacy Policy constitutes consent to all processing described in the policy, unless local law requires a different consent form....
Why it matters: This provision asserts that a single act of accepting the terms of service operates as consent to all data processing purposes described in the policy for users in consent-required jurisdictions. Whether this mechanism satisfies specific and granular consent requirements under applicable local law is a question that depends on the regulatory framework in each jurisdiction....
-
Monday.com
· Monday.com Privacy Policy
The policy places sole responsibility on Customer organizations (as data controllers) for providing adequate notice and consent to individuals whose data is submitted to the platform, and for handling all data subject rights requests from users and other individuals whose data Customers process through the platform....
Why it matters: This provision establishes a contractual allocation of data controller responsibilities to Customers for all personal data submitted to the platform as Customer Data, requiring Customers to independently satisfy applicable legal obligations for notice, consent, and data subject rights management without reliance on monday.com to fulfill those obligations....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that Customer Content may be used to train Figma's AI models when the 'Content Training' setting is enabled by an administrator, with de-identification and aggregation steps applied to the data used for training....
Why it matters: This provision establishes that the use of Customer Content for AI model training is governed by an administrative setting, meaning the decision rests with organizational administrators rather than individual end users in enterprise contexts. The policy does not disclose the default state of this toggle in its text, which is a material operational detail for compliance teams assessing data processing scope....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that when a user interacts with or views a file, their IP address, specific in-file actions, and viewing timestamps may be disclosed to the file's administrator and, in some cases, to other file viewers....
Why it matters: This provision establishes that file administrators operating within enterprise or team deployments receive access to identifiable interaction data including IP addresses and specific user actions, which may create secondary data controller obligations for organizational customers subject to GDPR or CCPA....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that domain capture is enabled by default for K-12 Enterprise education accounts, resulting in automatic disclosure of names, email addresses, and profile pictures to all users sharing the same organizational email domain....
Why it matters: This provision establishes a default-on data sharing configuration for education accounts that discloses student or staff identifying information across an organization without requiring affirmative action to enable the feature, which may engage FERPA and state student privacy obligations for U.S. educational institutions....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that third-party advertising partners are permitted to deploy tracking technologies on Figma's services to collect IP addresses, cookie identifiers, page visit data, location, and time-of-day data for use in interest-based advertising on third-party services....
Why it matters: This provision authorizes third-party advertising partners to independently collect identifiable behavioral data from Figma users across the service, and that data is then used for cross-site targeted advertising, engaging CCPA sale and sharing provisions and GDPR consent requirements for EU users....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that when a user accesses Figma through an organizational account or has their account paid for by another party, Figma will disclose that user's information to the organization or paying party upon request and grant the organization certain control rights over the user's account information....
Why it matters: This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that personal information is retained for the duration of service use or as necessary for listed business and legal purposes, and that requesting deletion of personal information requires the user to delete their Figma account entirely....
Why it matters: This provision conditions personal data deletion on full account deletion, meaning users cannot request removal of specific personal data categories while retaining their Figma account, which may interact with GDPR and CCPA data minimization and deletion rights depending on the specific data category and processing purpose involved....
-
Airtable
· Airtable Privacy Policy
The policy authorizes Airtable to disclose user information to the employer, organization, or workspace owner associated with the user's account, including where the employer created the account on the user's behalf or is associated with the user's email domain....
Why it matters: This provision establishes that employees or organizational members using an Airtable account created or administered by their employer may have their account activity and personal information disclosed to that employer or workspace owner, creating an operational dependency for enterprise HR, legal, and compliance functions....
-
Airtable
· Airtable Privacy Policy
The policy discloses that Airtable collects inferences derived from usage data, including predictions about user preferences, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes....
Why it matters: This provision discloses the collection of a broad range of inferred personal data categories, including psychological and attitudinal inferences, which under CCPA are classified as a distinct category of personal information and may engage specific rights and restrictions....
-
Airtable
· Airtable Privacy Policy
The policy states that deleted Content, including personal information contained within it, may be retained in archived or backup copies to support features such as revision history and base snapshots, and that permanent deletion requires a manual request to Airtable....
Why it matters: This provision establishes that standard in-product deletion does not result in permanent removal of Content, and that permanent deletion requires a separate manual contact process, which may affect data minimization and erasure obligations under GDPR and U.S. state privacy laws....
-
Airtable
· Airtable Privacy Policy
The policy requires users to complete two separate steps to opt out of targeted advertising: first, toggling cookies off in the Cookie Preference Center or enabling Global Privacy Control, and second, submitting a separate opt-out form or email to privacy@airtable.com....
Why it matters: This provision establishes a two-step opt-out process for targeted advertising that requires both a technical cookie setting action and a separate affirmative request submission, which may require evaluation under state privacy laws that specify the permissible mechanics of opt-out mechanisms....
-
Airtable
· Airtable Privacy Policy
The policy states that Airtable reserves the right to access, retain, take possession of, delete, or deny user access to Content when it determines in its sole discretion that such action is necessary for security, rights protection, or enforcement of the Terms of Service....
Why it matters: This provision reserves broad unilateral authority for Airtable to access and take action on user Content, including denial of access, based on internal determinations made at sole discretion, which creates operational risk for enterprise customers relying on Airtable for business-critical data storage....
-
Klarna
· Klarna Privacy Policy
The document states that Klarna collects app interaction data, linked bank transaction data, purchase history, preferred items, contact and identification information, financial details, device data, and interaction records for purposes including personalization, fraud prevention, and marketing....
Why it matters: This provision establishes a broad set of data categories collected by Klarna, including linked bank transaction data and behavioral and device identifiers, which collectively span financial, identity, and behavioral data types relevant to GLBA, CCPA, and GDPR compliance obligations....
-
Klarna
· Klarna Privacy Policy
The document provides a GLBA-based opt-out mechanism allowing users to limit Klarna's sharing of non-public personal information with unaffiliated third parties, accessible through the Klarna app or at app.klarna.com under Settings then Privacy....
Why it matters: This provision operationalizes Klarna's GLBA opt-out obligation as a financial institution, allowing US consumers to limit sharing of NPI with unaffiliated third parties through in-app or web-based settings without requiring physical mail or phone contact....
-
Klarna
· Klarna Privacy Policy
The document states that requesting data deletion will result in termination of all agreements with Klarna and loss of access to order history and account, while Klarna retains certain data for legal compliance and fraud prevention purposes even after a deletion request....
Why it matters: This provision links the exercise of a data deletion right to termination of all Klarna agreements and account access, which is an operational consequence that consumers should be aware of before initiating a deletion request; the breadth of this linkage may warrant evaluation under GDPR's right to erasure framework, which does not generally condition erasure on agreement termination....
-
Klarna
· Klarna Privacy Policy
The document states that Klarna performs internal and third-party credit checks and receives personal data including name, date of birth, place of birth, financial information, and behavioral data from credit and fraud prevention agencies, stores, and public databases to assess product eligibility....
Why it matters: This provision establishes that Klarna receives personal data from external credit and fraud agencies, stores, and public databases in addition to data provided directly by the consumer, which is relevant to FCRA applicability in the US context and to GDPR transparency obligations regarding data obtained from third-party sources....
-
Klarna
· Klarna Privacy Policy
The document states that Klarna retains purchase history, interaction records, device details, linked bank transaction data, and preferred item data to send marketing communications, offers, product recommendations, and personalized in-app features....
Why it matters: This provision establishes that financial and behavioral data, including linked bank transactions, is used for marketing and personalization purposes, which engages GLBA restrictions on use of NPI for marketing, CCPA rights regarding use of personal information for targeted advertising, and GDPR requirements for a lawful basis for direct marketing....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel may share de-identified AI product information, including chat prompts, uploaded images, and design or text generations, from Hobby and Pro plan users with external AI business partners for model training and product development purposes, subject to opt-out through team settings....
Why it matters: This provision authorizes disclosure of de-identified AI product inputs to third-party AI business partners, creating a data flow that extends beyond Vercel's internal operations; compliance teams should evaluate whether the de-identification standard applied satisfies applicable law thresholds, particularly under GDPR and US state privacy laws where re-identification risk standards vary....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel discloses that it has shared identifiers, commercial information, and internet activity data with third-party advertising networks in the preceding 12 months in a manner that may qualify as 'selling' or 'sharing' personal information under applicable US state privacy laws....
Why it matters: This provision constitutes a disclosure of advertising-related data sharing practices that trigger opt-out rights under CCPA, CPRA, and equivalent state laws; the document states that Vercel honors GPC signals and provides a linked opt-out form, which are operationally relevant compliance mechanisms for California and other state law compliance....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel has self-certified under the EU-US DPF, UK Extension, and Swiss-US DPF programs, establishing a legal transfer mechanism for personal data from the EU, UK, and Switzerland to the US; in case of conflict, the DPF Principles take precedence over the Notice's own terms....
Why it matters: This provision establishes Vercel's stated legal basis for cross-border personal data transfers from the EU, UK, and Switzerland, with FTC enforcement jurisdiction over compliance; the DPF Principles supremacy clause creates an operative hierarchy that affects how this Notice is interpreted for EU, UK, and Swiss data subjects....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel places full legal responsibility for end user privacy compliance on its Customers, including the obligation to notify end users of data collection practices; Vercel's Notice does not cover end users whose data is processed at the Customer's direction....
Why it matters: This provision establishes that Vercel operates as a data processor for Customer-directed processing activities, with Customers bearing the controller obligations for end user personal information; organizations deploying applications on Vercel's platform must independently satisfy applicable privacy law requirements for their end users without reliance on Vercel's Notice....
-
Mercury
· Mercury Privacy Policy
The policy states that Mercury does not sell Personal Information for money but acknowledges that advertising-related cookie and tracking technologies may qualify as a 'sale' or 'sharing' under applicable U.S. state privacy laws, and that this does not apply to users under 16....
Why it matters: This provision establishes that Mercury's advertising tracking practices may trigger opt-out rights under CCPA and similar U.S. state privacy laws, and requires Mercury to honor opt-out signals including the Global Privacy Control; the policy states that GPC is recognized and a 'Your Privacy Choices' opt-out link is provided....
-
Mercury
· Mercury Privacy Policy
The policy states that Mercury uses AI and machine learning for fraud detection, credit application evaluation, document verification, and transaction categorization, and that decisions with legal consequences, financial implications, or material effects on service access always include human oversight rather than being made by AI alone....
Why it matters: This provision establishes Mercury's stated operational safeguard against fully automated consequential decision-making, which is relevant to GDPR Article 22 requirements for EEA users and to emerging U.S. state automated decision-making regulations; the policy does not specify the mechanism or documentation standard for human oversight....
-
Mercury
· Mercury Privacy Policy
The policy states that privacy rights requests including deletion and access may be denied in part when the Personal Information is subject to federal financial laws that are exempt from U.S. state privacy law requirements, and directs personal account users to a separate Consumer Financial Privacy Notice....
Why it matters: This provision establishes that GLBA-regulated data held for personal banking accounts may fall outside the scope of CCPA and similar state privacy law rights requests, which means users seeking deletion or access to federally regulated financial data may receive partial or denied responses....
-
Mercury
· Mercury Privacy Policy
The policy states that Personal Information may be stored and processed in any country where Mercury or its affiliates and service providers operate, and that EEA and UK transfers are protected by Standard Contractual Clauses and additional technical safeguards....
Why it matters: This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted....
-
Mercury
· Mercury Privacy Policy
The policy authorizes disclosure of contact identifiers, internet activity data, and geolocation data to social and advertising networks and analytics providers for the purpose of placing advertisements on third-party websites and conducting performance analytics....
Why it matters: This provision authorizes sharing of contact information, internet activity, and geolocation data with social advertising networks including Facebook Ads, Bing Ads, Google Ads, and LinkedIn Ads as identified in the cookie table, which may constitute 'sharing' under CCPA and trigger opt-out rights for California residents....
-
Mercury
· Mercury Privacy Policy
The policy authorizes collection of audio and video recordings during sales, support, research, and customer feedback calls or meetings, subject to opt-out or consent withholding, and permits disclosure of these recordings to affiliates, service providers, business partners, and regulators....
Why it matters: This provision authorizes recording of calls and meetings with opt-out or consent mechanisms, and the data disclosure table indicates these recordings may be shared with affiliates, service providers, business partners, and regulators; applicable wiretapping and call recording laws vary significantly by jurisdiction and may impose additional consent requirements beyond what this policy describes....
-
Mercury
· Mercury Privacy Policy
The policy states that Personal Information is retained based on operational, legal, tax, fraud prevention, dispute resolution, and legal defense factors, without specifying fixed retention periods for any data category, and notes that financial regulatory requirements may require extended retention....
Why it matters: The policy does not specify fixed retention timelines for any category of Personal Information, including biometric data, financial records, or audio and video recordings; this approach requires users and compliance teams to rely on Mercury's internal retention schedules rather than disclosed timeframes....
-
Synthesia
· Synthesia Privacy Policy
The policy establishes that enterprise customers (employers or other purchasing entities) act as data controllers for Customer Data submitted to the platform, while Synthesia acts as data controller for Other Information it independently collects. Synthesia processes Customer Data only on customer instructions....
Why it matters: This provision allocates primary compliance responsibility for Customer Data governance to enterprise customers, establishing that those customers determine the purposes and conditions of processing for user-submitted content including avatar samples, scripts, and videos. Authorized users with questions about Customer Data handling are directed to their employer or the relevant enterprise customer rather than Synthesia....
-
Synthesia
· Synthesia Privacy Policy
The policy states that Synthesia may retain Other Information including contact data, usage data, technical data, and financial data after a user deletes their account, for purposes including legitimate business interests, audits, legal compliance, dispute resolution, and agreement enforcement. No specific maximum retention period is stated for post-deletion retention....
Why it matters: This provision reserves the right to retain user data beyond account deletion without specifying a defined post-deletion retention period, which may require evaluation under GDPR's data minimization and storage limitation principles. The absence of a stated maximum retention duration creates ambiguity for data subjects seeking to exercise erasure rights....