-
Samsung
· Samsung Privacy Policy
The policy states that personal information will be transferred to and processed in the Republic of Korea, and acknowledges that data protection laws in recipient countries may not be as comprehensive as those in the user's country of residence. For EEA, UK, and Swiss residents, the policy states it relies on standard contractual clauses and adequacy determinations for transfers to the Republic of Korea....
Why it matters: The explicit identification of the Republic of Korea as a primary destination for personal information transfers is a specific and material disclosure for users in jurisdictions with transfer restrictions, including EEA and UK residents subject to GDPR and UK GDPR. The policy's reliance on adequacy determinations for the Republic of Korea reflects the EU-Korea adequacy decision but may require ongoing monitoring given the evolving regulatory landscape for international transfers....
-
Samsung
· Samsung Privacy Policy
The US Supplement provides US residents with opt-out rights covering sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, voice recognition data collection, and further materially different processing triggered by material policy changes. These rights are stated to be subject to applicable law....
Why it matters: This provision enumerates six distinct opt-out rights for US residents, several of which correspond to specific rights under the CCPA and CPRA and analogous state statutes. The inclusion of an opt-out right for materially different processing following policy changes is notable because it establishes a mechanism for users to limit prospective use of previously collected data when Samsung materially amends its policies....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung's services are not directed to children under 13, that Samsung does not knowingly collect personal information from children under 13 without parental consent, and that if such collection is discovered, Samsung will seek parental consent or delete the information. A reporting mechanism is provided for concerned parties....
Why it matters: This provision describes Samsung's stated compliance posture under the Children's Online Privacy Protection Act (COPPA), which governs collection of personal information from children under 13. The policy's general audience designation and knowledge-based standard for collection align with standard COPPA compliance language, though COPPA enforcement focuses on operator knowledge and the design of services....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung uses Google Analytics, Firebase Analytics, and Adobe Analytics to collect personal information about user online activities across websites, devices, and apps over time, and that information may be disclosed to or collected directly by these analytics providers. The policy directs users to the Google Analytics privacy policy for further information....
Why it matters: The named use of Google Analytics, Firebase Analytics, and Adobe Analytics establishes that cross-site and cross-device behavioral data is shared with or directly collected by third-party analytics providers operating under their own privacy frameworks. The collection of data across third-party websites and devices over time is a practice that may engage state law definitions of targeted advertising and sale of personal information....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung collects payment card numbers, expiration dates, and security codes for order processing, and that users may optionally save payment information for future transactions. The policy also discloses that social security numbers are collected when users apply for credit or financing through Samsung....
Why it matters: The collection of payment card data including security codes and social security numbers for credit applications represents categories of highly sensitive financial data. The optional storage of payment information for future transactions creates a persistent data retention relationship that users should be aware of when evaluating account data management....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Calendly
· Calendly Privacy Notice
When a Calendly customer uses the platform to schedule or record a meeting with you, Calendly asserts it acts only as a data processor under that customer's instruction, and directs any data subject rights requests regarding that data to the originating customer rather than to Calendly....
Why it matters: This provision establishes that individuals whose data is collected by a Calendly customer during scheduling or meeting recording must direct rights requests to the customer entity, not to Calendly, which has direct implications for how data subject access, deletion, and correction rights are fulfilled in practice. Organizations deploying Calendly bear controller obligations under GDPR, CCPA, and comparable frameworks for data collected through Calendly's Services on their behalf....
-
Calendly
· Calendly Privacy Notice
The policy discloses that Calendly's use of cookies and tracking technologies for targeted advertising and analytics may constitute a sale or sharing of Personal Data under the CCPA, and identifies identifiers and internet or similar network activity as the categories sold or shared in the preceding 12 months....
Why it matters: This provision creates a formal CCPA disclosure obligation and establishes that California residents have the right to opt out of cookie-based data sales and sharing via the cookie management module or GPC signal. Organizations reviewing Calendly's compliance posture should confirm that the opt-out mechanism is operationally functional and that the data categories disclosed align with actual third-party data flows....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly uses session replay and session recording tools provided by third-party service providers to record user interactions with its website, including mouse movements and webform engagement....
Why it matters: This provision discloses that detailed behavioral interaction data, including webform engagement, is captured and potentially shared with third-party service providers operating session recording tools. Depending on jurisdiction, session recording of webform interactions may implicate wiretapping or electronic communications statutes, and the adequacy of the cookie consent mechanism as a legal basis for this collection warrants review....
-
Calendly
· Calendly Privacy Notice
The policy discloses that Calendly acquires name, email address, phone number, job title, employer, employment seniority, social media usernames and avatars, and social media activity details from third-party lead-generation and marketing companies, and uses this data for sales and marketing purposes....
Why it matters: This provision establishes that Calendly may hold detailed professional and social profile data about individuals who have not directly interacted with Calendly, sourced from third-party data brokers and lead-generation companies. This data flow may implicate CCPA and GDPR notice and transparency obligations, particularly regarding the requirement to inform data subjects about data obtained from third-party sources....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly has certified to the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. DPF, and that in any conflict between the privacy notice and DPF Principles, the Principles govern; it also establishes that Calendly bears liability for onward transfers to third-party agents who process data inconsistently with the DPF Principles unless Calendly proves it is not responsible....
Why it matters: This provision establishes DPF certification as the primary legal mechanism for EU, UK, and Swiss data transfers to the United States, with DPF Principles taking precedence over the privacy notice in cases of conflict. The onward transfer liability provision is a materially significant commitment: Calendly accepts liability for its agents' DPF-inconsistent processing unless it can demonstrate it is not responsible....
-
Calendly
· Calendly Privacy Notice
The policy states that Personal Data of individuals located in the EEA, UK, Canada, and other non-U.S. jurisdictions will be processed and stored in the United States or in countries where Calendly's service providers operate, and that those jurisdictions may not offer equivalent privacy protections....
Why it matters: This provision discloses that Personal Data from EEA, UK, and Canadian individuals is transferred to and stored in the United States, a jurisdiction that has historically been subject to adequacy assessments by European and UK data protection authorities. The policy states that transfer mechanisms including the DPF, Standard Contractual Clauses, and UK Addendum are relied upon to legitimize these transfers....
-
Calendly
· Calendly Privacy Notice
The policy states that in the event of a sale, merger, asset transfer, or other corporate reorganization, Calendly may transfer Personal Data to the parties involved, and users are stated to acknowledge that such transfers are permitted....
Why it matters: This provision authorizes transfer of Personal Data to acquiring or successor entities in a corporate reorganization without requiring additional individual consent at the time of transfer. Under GDPR and CCPA, such transfers may require assessment of whether the successor entity's data practices are consistent with the purposes for which data was originally collected....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly may share Personal Data with government entities and in legal proceedings in a range of circumstances including legal process responses, safety protection, fraud prevention, and litigation, subject to Calendly's belief that such disclosure is reasonably necessary....
Why it matters: This provision authorizes disclosure to government entities and in legal proceedings across multiple broadly stated circumstances, including where Calendly 'believes' disclosure is reasonably necessary, without specifying a requirement for formal legal process in all cases. The DPF notice separately states that Calendly may be required to disclose Personal Data in response to lawful requests by public authorities including for national security or law enforcement requirements....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly does not direct its services to individuals under 18, does not knowingly collect Personal Data from children under 18, and commits to promptly deleting such data if discovered; it also references a separate FERPA and COPPA Privacy Policy and Notice for educational service providers....
Why it matters: This provision establishes an age threshold of 18 for Calendly's stated COPPA compliance, which exceeds the statutory threshold of 13 under COPPA. The reference to a separate FERPA and COPPA policy for educational institutions indicates that Calendly has specific compliance obligations in educational contexts that are addressed outside this notice....
-
Calendly
· Calendly Privacy Notice
The policy states that users may exercise data rights including access, correction, deletion, portability, and opt-out rights by submitting a request through the Calendly Privacy Center, subject to identity verification before processing....
Why it matters: This provision establishes the Privacy Center as the centralized mechanism for exercising data subject rights under CCPA, GDPR, and applicable state privacy laws, and conditions fulfillment on identity verification that may require additional information from non-account holders. The right to appeal denials is acknowledged for applicable jurisdictions....
-
Grammarly
· Grammarly Privacy Policy
The policy states that Superhuman uses collected information including user content to train its AI models, and provides individual users an opt-out mechanism accessible through account settings....
Why it matters: This provision establishes a user-facing control for AI training data use, with the default state of that control not explicitly specified in the policy text; users who have not actively reviewed account settings may not know whether their content is currently included in AI training data....
-
Grammarly
· Grammarly Privacy Policy
The policy states it does not apply to content uploaded to or output from products used under organizational account management; such content is processed under the data processing agreement between Superhuman and the managing organization, not under this policy....
Why it matters: This provision establishes that individual employees or institutional users who access Superhuman products through employer or institution-managed accounts cannot exercise data rights under this policy for their work-related content; those rights must be directed to the managing organization....
-
Grammarly
· Grammarly Privacy Policy
The policy discloses that cookie IDs, device identifiers, browsing activity on Superhuman marketing websites, and unique identifiers derived from email addresses or phone numbers are shared with advertising and social network partners for targeted advertising, and acknowledges these activities may constitute sale or sharing under applicable state privacy laws....
Why it matters: This provision operationalizes the targeted advertising disclosure requirements under CCPA/CPRA and equivalent state privacy laws by identifying the specific categories of personal information disclosed (cookie IDs, email-derived unique identifiers, browsing activity) and the recipient categories (advertising networks, social networks), and provides opt-out mechanisms for users in covered jurisdictions....
-
Grammarly
· Grammarly Privacy Policy
The policy states that user content such as emails, documents, and drafts is not used for marketing or advertising purposes, while other data categories including email address, purchase history, usage data, and inferences may be used for marketing and advertising subject to user settings....
Why it matters: This provision establishes a categorical exclusion of user content from advertising data flows, operationally distinguishing between content-level data and account or behavioral data for marketing purposes....
-
Grammarly
· Grammarly Privacy Policy
The policy states that Superhuman is certified under the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, and commits to resolving cross-border data transfer complaints first directly, then through VeraSafe as an alternative dispute resolution provider, with binding arbitration available as a final recourse under the Framework....
Why it matters: This provision establishes the operational dispute resolution pathway for EEA, UK, and Swiss individuals whose personal data is transferred to the United States, including a binding arbitration option before a Data Privacy Framework Panel as a last resort mechanism, with FTC jurisdiction over overall Framework compliance....
-
Grammarly
· Grammarly Privacy Policy
The policy states that when users activate the Notetaker or transcription features, Superhuman collects audio recordings of communications, including recordings of non-user participants in those communications, to generate transcriptions....
Why it matters: This provision discloses that audio recordings of third parties who are not Superhuman users may be captured when a user activates transcription features, raising consent and notice obligations that may vary by jurisdiction....
-
Grammarly
· Grammarly Privacy Policy
The policy states that personal data may be transferred and processed outside the user's country of residence, and that the company applies the protections described in the policy and complies with applicable legal transfer frameworks including standard contractual clauses for non-DPF transfers....
Why it matters: This provision establishes the legal transfer mechanisms Superhuman relies upon for international data flows, including the Data Privacy Frameworks for EEA, UK, and Swiss transfers and standard contractual clauses for transfers to other third countries....
-
Grammarly
· Grammarly Privacy Policy
The policy states that when users integrate or use third-party marketplace offerings, Superhuman may disclose user information to those third parties and their associated API providers according to the user's settings, and disclaims ownership or control over third-party data practices....
Why it matters: This provision establishes that data disclosed to third-party marketplace participants is governed by those third parties' own policies rather than this privacy policy, and that users are responsible for reviewing third-party terms before integration....
-
Grammarly
· Grammarly Privacy Policy
The policy asserts legitimate interests under GDPR Article 6(1)(f) as the legal basis for using all categories of collected data, including user content, to develop and improve AI models....
Why it matters: This provision establishes legitimate interests as the sole GDPR legal basis for AI development processing across all data categories, including user content such as emails and documents; users in the EEA and UK have the right to object to processing on this basis under GDPR Article 21....
-
HubSpot
· HubSpot Privacy Policy
The policy states that personal data collected through use of HubSpot products and services may be processed to train HubSpot's AI models and develop AI-related features and products....
Why it matters: This provision authorizes a secondary processing purpose beyond product delivery: personal data from product and service usage may be applied to AI model training. The provision does not specify which categories of personal data are used for training, which AI models or features are involved, or whether this processing is limited to aggregated or anonymized data versus identified personal data....
-
HubSpot
· HubSpot Privacy Policy
The policy states that HubSpot collects professional personal data including business contact information from public sources, third-party providers, and its own customers, and distributes this data to other HubSpot customers for sales and marketing use through enrichment product features....
Why it matters: This provision establishes HubSpot's role as a controller of a commercial dataset of professional personal data that is collected from individuals who are not direct HubSpot users and made available to paying customers. The policy relies on legitimate interests as the legal basis for this processing, asserting that people would expect their work-related data to be shared in this way....
-
HubSpot
· HubSpot Privacy Policy
The policy states that when HubSpot customers install the HubSpot Tracking Code on their own websites, HubSpot collects IP addresses and online identifiers from those website visitors and processes this data as a controller for HubSpot's own purposes, including improvement of its commercial dataset....
Why it matters: This provision establishes that HubSpot assumes an independent controller role over data collected from visitors to customer-operated websites via the tracking code, distinct from its processor role under customer instructions. This means visitors to third-party websites using HubSpot infrastructure may have their data processed by HubSpot for HubSpot's own commercial purposes without direct notice from HubSpot....
-
HubSpot
· HubSpot Privacy Policy
The policy states that HubSpot shares personal data including email addresses with advertising partners to enable delivery of personalized HubSpot advertisements on third-party websites and mobile applications, and that users can opt out via a form linked in the policy....
Why it matters: This provision authorizes disclosure of email addresses to third-party advertising networks for cross-site ad targeting. An opt-out mechanism is described, but the default position is that email addresses are shared with advertising partners unless users affirmatively opt out....
-
HubSpot
· HubSpot Privacy Policy
The policy states that U.S. users who connect bank accounts for payment purposes have their banking credentials transmitted to Plaid, a third-party financial data service, and that Plaid processes their personal and financial data under Plaid's own privacy policy....
Why it matters: This provision discloses that banking credentials entered during checkout are transmitted to a third party (Plaid) and processed under a separate privacy policy, meaning HubSpot's privacy protections do not govern this data once transmitted. Users must review Plaid's Privacy Policy separately to understand how their financial data is handled....
-
HubSpot
· HubSpot Privacy Policy
The policy states that HubSpot has certified under the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. DPF, and that in the event of conflict between the Privacy Policy and DPF Principles, the DPF Principles govern. The U.S. FTC is identified as the enforcement authority for DPF compliance....
Why it matters: This provision establishes HubSpot's primary cross-border transfer mechanism for EEA, UK, and Swiss personal data, identifies the FTC as the enforcement authority for DPF compliance, and commits HubSpot to a 45-day complaint resolution timeline with escalation paths through EU data protection authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner, including binding arbitration as a last resort....
-
HubSpot
· HubSpot Privacy Policy
The policy states that where applicable law does not require consent, HubSpot conducts marketing and advertising activities on the basis of legitimate business interests, and may combine data from third-party providers with other collected information for personalized communications and event promotion....
Why it matters: This provision establishes legitimate interests as the default legal basis for marketing activities targeting individuals who have not provided explicit consent, and authorizes combination of third-party sourced data with HubSpot-collected data for personalized outreach. The provision is conditioned on legal requirements in applicable jurisdictions, acknowledging that consent will be obtained where law requires it....
-
HubSpot
· HubSpot Privacy Policy
The policy states that in the event of a merger, acquisition, or bankruptcy, all personal data collected by HubSpot would transfer to the acquiring entity, with notification provided to users via email or website notice....
Why it matters: This provision authorizes the transfer of all collected personal data to a successor entity in a corporate transaction, and commits to notifying users of any resulting changes in data ownership and use. The provision does not specify a timeline for notification or describe what choices would be available to users following a transfer....
-
Asana
· Asana Privacy Statement
Asana AI features that rely on AI Partners process metadata, personal information, and user-generated content such as task titles and task descriptions, in contrast to Asana's own AI features which are limited to metadata only....
Why it matters: This provision distinguishes two categories of AI processing with materially different data scope: features powered by AI Partners access user-generated content and personal information, which may implicate subprocessor obligations, data minimization requirements, and consent mechanisms under GDPR and CCPA....
-
Asana
· Asana Privacy Statement
Asana's Data Processing Addendum is automatically incorporated into the Subscriber Terms without requiring a separately executed agreement, and applies globally to all customers....
Why it matters: This provision establishes that the DPA's data protection commitments, including processing limitations, audit rights, subprocessor obligations, and cross-border transfer mechanisms, are operative for all customers as part of the standard subscription agreement....
-
Asana
· Asana Privacy Statement
Asana uses Data Privacy Frameworks (EU-US, UK Extension, Swiss-US) as the primary mechanism for cross-border data transfers, with Standard Contractual Clauses serving as a contractual fallback if any applicable framework is invalidated....
Why it matters: This provision establishes the transfer mechanism hierarchy for international data flows from the EU, UK, and Switzerland to the US, with SCCs automatically operative as a fallback, which is relevant given prior EU Court of Justice rulings invalidating predecessor frameworks....
-
Asana
· Asana Privacy Statement
HIPAA-covered entities and business associates must execute a separate Business Associate Addendum with Asana to establish HIPAA-compliant use of the platform; the standard DPA alone does not provide HIPAA coverage....
Why it matters: This provision establishes that HIPAA compliance requires a separately executed BAA, which is an operationally distinct step from the DPA incorporation by reference, creating an affirmative obligation for healthcare-regulated customers to independently execute this agreement....
-
Asana
· Asana Privacy Statement
Asana explicitly advises customers not to store financial account numbers, social security numbers, or similar sensitive personal data within the platform, in the context of GLBA compliance....
Why it matters: This provision places an affirmative advisory obligation on customers regarding data types that should not be stored in Asana, which has implications for acceptable use compliance, liability allocation, and regulated industry customers operating under GLBA or similar frameworks....
-
Asana
· Asana Privacy Statement
Asana's privacy team reviews each law enforcement or government access request for legal validity and proportionality before responding, and the company publishes an annual Law Enforcement Transparency Report disclosing the number of requests received and responded to....
Why it matters: This provision describes the procedural framework Asana applies to government data access requests, including a proportionality review and commitment to adhere to established legal process, with transparency reporting available annually....
-
Asana
· Asana Privacy Statement
Asana offers customers a choice of data residency in Europe, Australia, Japan, or the US, and provides an Enterprise Key Management feature allowing customers to use their own encryption keys for Asana data....
Why it matters: These provisions establish specific technical and operational controls that may be material for customers subject to data localization requirements or sector-specific encryption mandates, including GDPR-aligned data residency obligations and regulated industry encryption standards....
-
Asana
· Asana Privacy Statement
Asana characterizes itself as a CCPA service provider for business customers and commits to processing personal information only for contractually specified purposes and to cooperating with customer obligations to fulfill consumer deletion and access requests....
Why it matters: This provision establishes the CCPA service provider relationship and the associated processing limitation, which is material for California-based businesses that rely on Asana to fulfill consumer data rights requests under CCPA and CPRA....
-
Monday.com
· Monday.com Privacy Policy
Account Admins employed by the Customer organization retain access to content submitted to boards designated as private, including the ability to copy and process that content, regardless of the board's privacy settings for other users....
Why it matters: This provision establishes that privacy designations applied to boards within the platform do not restrict access by Account Admins acting on behalf of the Customer organization, meaning personal data and content submitted to private boards remains accessible to organizational administrators....
-
Monday.com
· Monday.com Privacy Policy
The policy discloses that phone calls, video conferences, screen recordings, screenshots, and written correspondence may be automatically recorded, tracked, transcribed, and analyzed by monday.com and its Service Providers for analytics, quality control, training, and record-keeping....
Why it matters: This provision establishes that interactions with monday.com personnel including customer experience and product consultants may be subject to automatic recording and transcription, and that session or activity recording services and call recording and transcription services are listed as authorized Service Provider categories with access to personal data....
-
Monday.com
· Monday.com Privacy Policy
The policy discloses that contact and profile information for Prospects is collected not only directly but also from named third-party data enrichment and professional data providers including LinkedIn, ZoomInfo, Clearbit, Cognism, and Lusha....
Why it matters: This provision establishes that monday.com sources personal data about prospective customers from commercial data brokers and professional networking platforms, meaning individuals may have profile data held by monday.com without having directly interacted with the company....
-
Monday.com
· Monday.com Privacy Policy
In jurisdictions where consent is the required legal basis for processing, the policy asserts that acceptance of the Terms of Service and Privacy Policy constitutes consent to all processing described in the policy, unless local law requires a different consent form....
Why it matters: This provision asserts that a single act of accepting the terms of service operates as consent to all data processing purposes described in the policy for users in consent-required jurisdictions. Whether this mechanism satisfies specific and granular consent requirements under applicable local law is a question that depends on the regulatory framework in each jurisdiction....
-
Monday.com
· Monday.com Privacy Policy
The policy asserts that continued use of the Services after publication of an amended policy constitutes acceptance of the amended terms, with material changes accompanied by notice via prominent in-service display or email....
Why it matters: This provision establishes that policy amendments take effect upon publication and that continued use of the platform constitutes acceptance, with the adequacy of notice (prominent in-service display or email) varying depending on circumstances as determined by monday.com....
-
Monday.com
· Monday.com Privacy Policy
The policy places sole responsibility on Customer organizations (as data controllers) for providing adequate notice and consent to individuals whose data is submitted to the platform, and for handling all data subject rights requests from users and other individuals whose data Customers process through the platform....
Why it matters: This provision establishes a contractual allocation of data controller responsibilities to Customers for all personal data submitted to the platform as Customer Data, requiring Customers to independently satisfy applicable legal obligations for notice, consent, and data subject rights management without reliance on monday.com to fulfill those obligations....
-
Monday.com
· Monday.com Privacy Policy
The policy states that personal data may be retained for as long as reasonably needed for service delivery, legal and contractual compliance, and dispute protection, with retention periods determined at monday.com's reasonable discretion and in accordance with an internal data retention policy....
Why it matters: This provision does not specify fixed retention periods for any category of personal data, instead reserving retention duration determinations to monday.com's reasonable discretion and an internal policy document not reproduced in the Privacy Policy....
-
Monday.com
· Monday.com Privacy Policy
The policy authorizes disclosure of contact, business, and usage details to business partners, resellers, and distributors for purposes including sales engagement and local market development, and states that engagements with those partners beyond the scope of monday.com-directed activities are governed by the partner's own terms....
Why it matters: This provision establishes that contact, business, and usage data may be shared with an unspecified set of business partners and resellers, and that once a user engages with a partner independently, that engagement is governed by the partner's own privacy terms rather than monday.com's....
-
Monday.com
· Monday.com Privacy Policy
The policy states that monday.com Inc. is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, and relies primarily on this certification for EEA, UK, and Switzerland to US data transfers, with Standard Contractual Clauses used for transfers to other non-adequate countries. DPF Principles govern in case of conflict with policy terms....
Why it matters: This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability to Service Providers under that framework. The DPF is subject to ongoing legal and political scrutiny, and its continued validity as a transfer mechanism depends on factors external to monday.com's own policy....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that Customer Content may be used to train Figma's AI models when the 'Content Training' setting is enabled by an administrator, with de-identification and aggregation steps applied to the data used for training....
Why it matters: This provision establishes that the use of Customer Content for AI model training is governed by an administrative setting, meaning the decision rests with organizational administrators rather than individual end users in enterprise contexts. The policy does not disclose the default state of this toggle in its text, which is a material operational detail for compliance teams assessing data processing scope....