-
RunPod
· RunPod Terms of Service
RunPod may access and disable public access to files or data in user-controlled storage upon receipt of a DMCA notice or upon becoming aware of potential infringement. Users are required to immediately disable or remove access to content identified in a DMCA notice forwarded by RunPod....
Why it matters: This provision requires users to immediately act on DMCA notices forwarded by RunPod, creating an affirmative obligation to remove or disable access to identified content. RunPod also reserves the right to access user storage to disable content in its discretion, including based on its own awareness of potential infringement without a formal notice....
-
AWS Bedrock
· AWS Service Terms
EC2 Reserved Instances, Savings Plans, EC2 Dedicated Host Reservations, and EC2 Capacity Blocks are non-cancellable and non-refundable for the committed term, with charges continuing even if the customer terminates the broader AWS agreement, subject to limited pro rata refund rights if AWS terminates the program....
Why it matters: This provision requires customers to remain financially obligated for the full committed term of Reserved Instances, Savings Plans, Dedicated Hosts, and Capacity Blocks regardless of changes in operational requirements or agreement termination, creating a long-term financial exposure that procurement and finance teams must account for at the point of purchase....
-
AWS Bedrock
· AWS Service Terms
For generative AI services powered by Amazon Bedrock, AWS may process customer content in AWS regions other than the customer's primary region to optimize inference performance, with the specific regions determined by AWS....
Why it matters: This provision authorizes processing of customer content outside the customer's selected AWS region for AI inference workloads, which may engage GDPR Chapter V international transfer restrictions, UK GDPR transfer requirements, and sector-specific data residency obligations depending on the nature of the content and the customer's regulatory environment....
-
AWS Bedrock
· AWS Service Terms
Customers who conduct or publish benchmarks of AWS services must disclose sufficient methodology to replicate the benchmark and, by doing so, grant AWS the right to conduct and publicly disclose comparative benchmarks of the customer's own products, regardless of any restrictions in the customer's own terms of service....
Why it matters: This provision creates a contractual authorization for AWS to benchmark and publish comparative performance results on customer products upon the customer's disclosure of any AWS benchmark, which may override benchmark restriction clauses in the customer's own licensing agreements or terms of service....
-
AWS Bedrock
· AWS Service Terms
The agreement places full legal responsibility on the customer for providing privacy notices and obtaining consents required by applicable law when processing end user personal data through AWS services, and the customer represents to AWS that these obligations have been met....
Why it matters: This provision establishes that AWS's contractual liability for privacy notice and consent compliance is limited and that the customer assumes responsibility for lawful basis requirements under GDPR, CCPA, and other applicable privacy frameworks when using AWS services to process personal data....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
AWS Bedrock
· AWS Service Terms
AWS may notify customers of content it reasonably believes is prohibited and allow 2 business days to remove it before AWS acts; for illegal content, content threatening service integrity, or content subject to legal orders, AWS may act without prior notice....
Why it matters: This provision establishes AWS's content enforcement mechanism, including the conditions under which services may be suspended, and creates a 2-business-day cure period for most prohibited content while reserving the right to act immediately for illegal content or service-threatening material....
-
AWS Bedrock
· AWS Service Terms
Upon suspension or termination of beta service access, customer content stored in beta services may be deleted or become inaccessible, and the terms do not guarantee migration of that content to generally available service versions....
Why it matters: This provision establishes that customer content in beta services is at risk of permanent loss upon termination of beta access, with no contractual obligation for AWS to migrate or preserve that content, creating a material data retention and business continuity risk for customers using beta services in production contexts....
-
AWS Bedrock
· AWS Service Terms
AWS reserves the right to use customer interaction and usage data to improve its services, without specifying the categories of interaction data collected or the scope of improvement activities....
Why it matters: This provision authorizes AWS to use customer usage and interaction data for service improvement, which may engage data minimization and purpose limitation principles under GDPR where the customer is processing personal data through their AWS interactions....
-
AWS Bedrock
· AWS Service Terms
The terms incorporate the AWS DPA, the EU SCCs under Commission Implementing Decision 2021/914, the UK GDPR Addendum, the Swiss Addendum, and the CCPA Terms by reference, with each framework applying conditionally based on whether the relevant data protection regulation governs the customer's use of AWS services....
Why it matters: The conditional incorporation of multiple international data protection frameworks by reference means that the applicable contractual obligations for personal data processing depend on the customer's jurisdiction and the nature of data processed, requiring customers to assess which addenda apply to their specific use cases....
-
AWS Bedrock
· AWS Service Terms
AWS processes all RI Marketplace transaction payments on behalf of sellers, and the terms authorize AWS to withhold, deduct, or set off amounts owed by the seller to AWS or its affiliates against transaction proceeds owed to the seller....
Why it matters: The setoff provision authorizes AWS to apply amounts the seller owes to AWS against RI Marketplace transaction proceeds before remitting payment, which may reduce or eliminate proceeds available to the seller without a separate collection action....
-
AWS Bedrock
· AWS Service Terms
The terms prohibit customers and their end users from using any AWS service for cryptocurrency mining....
Why it matters: This provision establishes a categorical prohibition on cryptocurrency mining across all AWS services, applicable to both direct customer use and use facilitated through customer platforms, which may be an enforceable use restriction under the Acceptable Use Policy and the agreement's content enforcement mechanisms....
-
Zendesk
· Zendesk Privacy Policy
This notice applies only to data where Zendesk controls the purpose of processing; data processed within Zendesk's products on behalf of business customers (Subscribers) is excluded, and affected individuals are directed to contact those Subscribers directly....
Why it matters: This provision defines the scope of Zendesk's privacy obligations under this notice, excluding data processed on behalf of Subscribers and disclaiming responsibility for Subscriber data practices. Compliance teams engaging Zendesk as a vendor must assess Subscriber obligations separately, including reviewing the Zendesk Data Processing Agreement to understand the allocation of data controller and processor responsibilities....
-
Zendesk
· Zendesk Privacy Policy
California residents must complete two separate steps to fully opt out of the sale or sharing of their personal data: submit a webform request and disable advertising cookies via the website footer link on each browser and device used....
Why it matters: This provision requires California residents to take two distinct actions to exercise their CCPA opt-out right, and states that cookie blocking or clearing will negate the opt-out for automatically collected device data. The operational complexity of this mechanism may affect whether residents can effectively exercise their statutory opt-out right, particularly across multiple devices and browsers....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that it does not honor Do Not Track signals sent by web browsers, meaning users who enable DNT in their browser settings will not have that preference recognized by Zendesk's tracking technologies....
Why it matters: This provision discloses that browser-level DNT signals are not acted upon by Zendesk, which is relevant to users who rely on browser privacy settings as a primary opt-out mechanism. Whether this practice creates regulatory exposure depends on applicable state or national law requirements regarding DNT signal recognition....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that it may retain personal data after a business relationship ends for purposes including fulfilling surviving contract provisions, evidencing business practices, marketing its products and services, and meeting legal or tax requirements; data stored in backup archives may be retained until deletion is technically feasible....
Why it matters: This provision authorizes post-relationship retention for a range of purposes, including continued marketing communications, which may require evaluation under GDPR storage limitation principles and applicable national laws. The backup archive exception permits retention beyond standard deletion timelines in cases where technical deletion is not immediately feasible....
-
Zendesk
· Zendesk Privacy Policy
Zendesk acknowledges that its routine data sharing with advertising and cookie technology partners on its digital properties may qualify as a 'sale' or 'sharing' under California law, though no monetary exchange for data is described....
Why it matters: This provision constitutes Zendesk's acknowledgment that its advertising and tracking technology practices trigger CCPA and CPRA sale and sharing obligations, establishing the legal basis for California residents' opt-out rights and the associated compliance mechanisms described elsewhere in the notice....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that cross-border data transfers are conducted using EU Standard Contractual Clauses, UK Addendum, Binding Corporate Rules, and DPF certification; Zendesk asserts ongoing liability for onward transfers to third-party agents under DPF Principles....
Why it matters: This provision establishes the legal mechanisms Zendesk relies upon for international data transfers and asserts accountability for onward transfers to agents under the DPF framework. Compliance teams should assess the continued adequacy of DPF certification as a transfer mechanism given the historical legal challenges to EU-U.S. data transfer frameworks....
-
Zendesk
· Zendesk Privacy Policy
Zendesk collects sensitive personal data such as proof of vaccination and race and ethnicity on an optional basis where permitted by law, and may disclose this data to Zendesk Group affiliates, service providers, and entities involved in corporate transactions....
Why it matters: This provision discloses the collection and disclosure of special category data under GDPR terminology, including health-related data and racial or ethnic origin, which are subject to heightened protection requirements under GDPR Article 9 and equivalent national laws. The document states collection is optional and consent-based where required, but the disclosure scope includes corporate transaction parties....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that its digital properties are not directed to children under 16 and that it does not knowingly collect personal data from children, setting its age threshold at 16 rather than the COPPA threshold of 13....
Why it matters: The notice sets its children's privacy threshold at 16, which exceeds the minimum 13-year COPPA threshold and aligns with GDPR Article 8's default age of digital consent in many EU member states. This threshold applies to Zendesk's Controller-capacity data collection on its digital properties....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that automated decision-making as defined under GDPR Article 22 does not currently apply to personal data processed under this notice, but commits to notifying affected individuals and providing human intervention rights if that practice changes....
Why it matters: This provision constitutes a disclosure about the current absence of Article 22 automated decision-making and a forward-looking commitment to notification and rights provision if such processing is introduced. Given that Zendesk describes itself as an 'AI-first service platform,' this disclosure is operationally significant for monitoring as Zendesk's AI capabilities develop....
-
McDonald's
· McDonald's Privacy Policy
The policy states that McDonald's uses customer personal information to train algorithms and AI models, and employs profiling technology, with a stated carve-out that such profiling will not include automated decisions with legal or similarly significant effects unless separately disclosed....
Why it matters: This provision establishes a broad authorization to use customer data for AI and algorithm training across McDonald's products and services, with the carve-out for automated individual decisions referencing GDPR Article 22 language but not specifying which data categories are used in training or whether third-party AI vendors are involved in this processing....
-
McDonald's
· McDonald's Privacy Policy
The global section states McDonald's does not sell personal information for monetary consideration, while acknowledging that US state law definitions of 'sale' may encompass sharing with advertising networks and analytics companies for valuable consideration, directing US users to the country-specific addendum....
Why it matters: This provision discloses a structurally significant tension between the policy's assertion of no monetary sale and the acknowledgment that sharing arrangements with advertising and analytics partners may qualify as sales under California and other US state privacy statutes, triggering opt-out rights and disclosure obligations under those frameworks....
-
McDonald's
· McDonald's Privacy Policy
The US addendum provides a CCPA-required financial incentive notice disclosing that participation in MyMcDonald's Rewards involves collection of identifiers, payment details, purchase records, app interaction data, geolocation, and behavioral inferences, with McDonald's stating it does not assign an independent monetary value to this data....
Why it matters: This provision establishes the data collection scope for the loyalty program and satisfies the California law requirement to disclose the material terms of financial incentive programs that involve personal information, including the categories of data collected and an estimate of its value relative to program benefits....
-
McDonald's
· McDonald's Privacy Policy
The policy explicitly excludes franchisee-operated restaurants and any digital properties they operate from the scope of this Privacy Statement, directing customers to consult each franchisee's own privacy practices separately....
Why it matters: This provision establishes that the privacy protections, rights, and disclosures in this document do not extend to customer interactions with franchisee-operated restaurants or their digital properties, creating a fragmented governance structure across the McDonald's network where customer rights and data practices may vary by location....
-
McDonald's
· McDonald's Privacy Policy
For EU, EEA, UK, and Switzerland-based processing, McDonald's states it transfers personal information only to countries with an adequate level of protection or under Standard Contractual Clauses based on Commission Implementing Decision (EU) 2021/914, with those mechanisms available upon request....
Why it matters: This provision establishes the legal mechanism McDonald's relies upon for international data transfers from the EU, EEA, UK, and Switzerland, referencing SCCs and adequacy decisions as the primary transfer tools and noting that transfer documentation is available upon request....
-
McDonald's
· McDonald's Privacy Policy
The policy discloses that targeting cookies set by McDonald's or its advertising partners may be used to build interest profiles and deliver advertising on third-party sites, and that these cookies may interact with other third-party cookies in the user's browser, with tracking occurring over time and across multiple websites and devices....
Why it matters: This provision authorizes cross-site and cross-device behavioral tracking for advertising purposes by McDonald's and third-party advertising networks, with the additional disclosure that targeting cookies may view, edit, or set other third-party cookies in the user's browser....
-
McDonald's
· McDonald's Privacy Policy
The US addendum states that McDonald's does not knowingly collect personal information from children under 13 through its online services, and that any future decision to do so would be conducted in compliance with applicable law including required parental consent mechanisms....
Why it matters: This provision establishes McDonald's stated COPPA compliance posture and the conditional commitment to parental consent if children's data collection is introduced in the future, while acknowledging that certain child-accessible features currently operate without personal information collection....
-
McDonald's
· McDonald's Privacy Policy
Under the Data Privacy Framework, EU, UK, and Swiss individuals whose privacy concerns cannot be resolved by McDonald's or JAMS may invoke binding arbitration as a final recourse mechanism, at no charge to the individual, subject to specified conditions....
Why it matters: This provision establishes a tiered dispute resolution mechanism for DPF-covered personal data disputes: direct contact with McDonald's, then JAMS mediation at no cost, and finally binding arbitration, with the FTC retaining investigatory and enforcement authority over McDonald's DPF compliance....
-
McDonald's
· McDonald's Privacy Policy
McDonald's states it retains personal information for the duration necessary to fulfill stated purposes, comply with legal obligations, resolve disputes, and enforce agreements, without specifying defined retention periods for particular data categories....
Why it matters: This provision establishes a purpose-based retention standard without specifying retention periods for individual data categories, which may present compliance considerations under GDPR's storage limitation principle and US state privacy laws that require defined retention schedules....
-
McDonald's
· McDonald's Privacy Policy
The policy discloses automated collection of precise geolocation data, advertising identifiers, UDIDs, device serial numbers, IP addresses, and video recordings of restaurant visits through in-restaurant digital technology....
Why it matters: This provision discloses a broad range of automated data collection spanning online, mobile, and physical restaurant environments, including persistent device identifiers and in-restaurant video, which collectively enable cross-context tracking of individual customers....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of precise vehicle location data (defined as within a 1,850-foot radius) while a vehicle is in use and upon specified events, with a stated retention period of up to 3 years, and discloses that geolocation collection may continue even after OnStar disconnection under certain emergency or battery-safety conditions....
Why it matters: This provision establishes a data collection practice tied to vehicle operation that persists under specified conditions even after a user takes affirmative steps to disconnect from OnStar or disable location services, creating a documented carve-out that compliance teams should assess against state-level precise geolocation consent requirements....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of AI assistant interaction data including full transcripts, navigation destinations, contacts, call history, and discussion topics from both in-vehicle AI assistants and GM mobile apps, with disclosure limited to service providers acting on GM's behalf and law enforcement under warrant or court order....
Why it matters: This provision establishes a data collection category encompassing conversation transcripts and personal contact data generated through AI assistant use, creating a detailed behavioral and relational data record tied to vehicle and app operation that is subject to government access requests under the policy's stated warrant-or-court-order standard....
-
General Motors
· GM Privacy Statement
The policy discloses that certain data transfers, including identifiers, digital activity information, VIN, and commercial information shared with advertising networks, dealers, and financial institutions, may qualify as 'sales' under applicable state privacy laws, and that consumers may have opt-out rights for these transfers....
Why it matters: This provision identifies specific categories of personal information, including vehicle identification numbers and digital activity data, as potentially sold to third-party advertising and financial partners, triggering opt-out rights under CCPA, CPRA, and analogous state statutes that compliance teams must ensure are operationally satisfied....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of driver behavior data including vehicle speed, braking and acceleration patterns, seatbelt status, and trip duration, and states that this data may be disclosed to General Motors Insurance for usage-based insurance purposes with affirmative consent....
Why it matters: This provision establishes that granular driving behavior metrics may be used to inform insurance rate determinations when the user provides affirmative consent, creating a direct link between vehicle operation data and financial product pricing that has implications for insurance regulatory compliance and consumer disclosure requirements....
-
General Motors
· GM Privacy Statement
The policy authorizes collection of exterior vehicle camera and sensor images and video with consent or upon detection of a safety event, and separately authorizes collection of road information from exterior cameras at all times, with the acknowledgment that camera images may capture third parties in the surrounding environment....
Why it matters: This provision establishes two distinct collection triggers, consent-based and safety-event-based, for exterior camera media, and a continuous collection basis for road data derived from exterior cameras, with the acknowledged implication that third parties present in the vehicle's environment may be incidentally captured....
-
General Motors
· GM Privacy Statement
The policy states that for connected vehicle personal information categories including driver behavior, precise geolocation, exterior camera data, and AI assistant interaction data, GM will require government data requests to take the form of a warrant or court order, except in exigent circumstances or where applicable statutory authority provides otherwise....
Why it matters: This provision establishes a documented procedural standard requiring judicial process for government access to connected vehicle personal information categories, which represents a specific operational commitment that legal and compliance teams can reference when assessing government data access risk for vehicle-generated data....
-
General Motors
· GM Privacy Statement
The policy establishes that precise geolocation and driver behavior information are subject to a specific retention schedule of up to 3 years from collection, with extensions permitted for legal or regulatory obligations, and that data is de-identified or disposed of when no longer needed for stated purposes....
Why it matters: This provision establishes a documented retention baseline of up to 3 years for sensitive connected vehicle data categories, with an open-ended extension clause for legal or regulatory obligations that may result in retention beyond the stated period in circumstances not further specified in the excerpted text....
-
General Motors
· GM Privacy Statement
The policy establishes universal access, correction, and deletion rights for all covered consumers, with additional rights including targeted advertising opt-out, data sale opt-out, and automated processing opt-out available depending on the consumer's state of residence, and a stated processing time of up to 45 days....
Why it matters: This provision establishes the operational framework for consumer privacy right requests, including a 45-day processing window and a verification requirement, with jurisdiction-dependent rights that require consumers to know their state's applicable framework to determine their full entitlement....
-
General Motors
· GM Privacy Statement
The policy authorizes use and disclosure of de-identified data for purposes not described in the privacy statement, states that reasonable re-identification prevention measures are applied and required of third parties, but does not specify what technical standards constitute adequate de-identification....
Why it matters: This provision establishes that de-identified data falls outside the policy's stated use and disclosure limitations, and may be shared with third parties for unstated purposes, subject to a reasonable safeguard standard whose specific technical parameters are not defined in the document....
-
General Motors
· GM Privacy Statement
The policy discloses that personal information stored in a vehicle, including contacts, address searches, and preferences, may remain accessible to future vehicle users if not deleted prior to sale or transfer, and encourages but does not require the owner to delete this data before transfer....
Why it matters: This provision establishes that data deletion before vehicle sale or transfer is the responsibility of the current owner rather than a system-enforced process, and that failure to delete may result in personal information being accessible to subsequent vehicle users....
-
Ford
· Ford Privacy Policy
The policy states that Ford collects vehicle identification, status, and service history data along with driving behavior data including routes taken, speed, and usage patterns from connected vehicle services....
Why it matters: This provision establishes a continuous data collection relationship between Ford and connected vehicle owners that extends beyond web-based interactions to include real-time operational and behavioral data. Compliance teams should assess whether the scope of this collection and its downstream sharing is adequately disclosed and consented to under applicable state privacy frameworks....
-
Ford
· Ford Privacy Policy
The policy states that Ford collects precise geolocation data through apps, websites, and connected vehicle services, and may share this data with dealers, service providers, and other third parties....
Why it matters: Precise geolocation is classified as sensitive personal information under the CPRA, triggering heightened disclosure, opt-out, and use-limitation obligations for California residents. The authorization to share this data with dealers and unspecified third parties creates a broad distribution pathway for location information....
-
Ford
· Ford Privacy Policy
The policy states that Ford shares personal information with dealers, who operate as independent businesses with their own privacy policies and may use the data for their own marketing purposes outside of Ford's control....
Why it matters: This provision establishes that dealers are independent data controllers, meaning Ford's privacy policy obligations and consumer rights requests do not automatically bind dealer handling of shared data. Consumers exercising deletion or opt-out rights with Ford may not have those rights automatically honored by dealers who have already received their data....
-
Ford
· Ford Privacy Policy
The policy states that California residents may opt out of the sale or sharing of their personal information by using a designated link on Ford's website or submitting a request through Ford's privacy request portal, and Ford commits to process these requests within legally required timeframes....
Why it matters: This provision operationalizes the CCPA/CPRA opt-out right for California residents. The mechanism covers both 'sale' and 'sharing' of personal information, which under CPRA includes cross-context behavioral advertising data flows that may not involve monetary consideration....
-
Ford
· Ford Privacy Policy
The policy states that Ford shares personal information with advertising partners, analytics providers, and social media companies for targeted advertising, campaign measurement, and digital service analysis, using cookies, pixel tags, and similar tracking technologies....
Why it matters: This provision authorizes data sharing with advertising and analytics third parties through tracking technologies, which constitutes 'sharing' under CPRA and may require opt-out mechanisms for cross-context behavioral advertising. The involvement of social media platforms as data recipients creates additional data flow pathways beyond Ford's direct control....
-
Ford
· Ford Privacy Policy
The policy states that consumers may submit requests for deletion of their personal information, subject to exceptions, and that Ford will verify identity and respond within legally required timeframes....
Why it matters: This provision operationalizes deletion rights under CCPA/CPRA and analogous state frameworks. The reference to 'certain exceptions' is significant because CPRA permits retention of data for a range of business purposes that may limit the practical scope of deletion requests, particularly for vehicle service and warranty records....
-
Ford
· Ford Privacy Policy
The policy states that Ford may create consumer profiles by drawing inferences from collected personal information, and that these profiles may be used for marketing, personalization, and business purposes....
Why it matters: Inferences and consumer profiles are recognized as a distinct category of personal information under CPRA and several analogous state statutes, triggering specific disclosure, access, and deletion rights. The use of inferences drawn from vehicle telematics and driving behavior for marketing purposes is operationally significant given the sensitivity of the underlying data....
-
Ford
· Ford Privacy Policy
The policy states that Ford's digital services are not directed to children under 13, that Ford does not knowingly collect personal information from this group, and that Ford will delete such information if discovered....
Why it matters: This provision establishes COPPA compliance posture for Ford's digital properties. The standard 'not directed to children' and 'do not knowingly collect' formulation is common in US privacy policies and reflects minimum COPPA compliance requirements enforced by the FTC....
-
Duolingo
· Duolingo Privacy Policy
This provision authorizes Duolingo to record and store audio and text submitted through AI-powered features including Video Call, and to use those recordings and transcripts for product improvement and AI model training. The text and audio may also be shared with vendors including OpenAI and Google, subject to contractual restrictions on those vendors' independent use of the data....
Why it matters: This provision authorizes Duolingo to retain AI interaction content and use it for AI model training purposes, and to share that content with named third-party AI vendors. The adequacy of the vendor contractual restrictions on secondary use may warrant independent compliance review, particularly under GDPR data minimization and purpose limitation principles....
-
Duolingo
· Duolingo Privacy Policy
This provision discloses that Duolingo's website places targeting cookies from Google, Meta, Amazon, and unspecified other companies, which those companies may use to track user activity across multiple websites for personalized advertising purposes....
Why it matters: This provision establishes that cross-site behavioral tracking occurs through third-party cookies placed by named advertising platforms, and that users in the EU and UK are opted out of personalized advertising by default while users in other jurisdictions must actively opt out....