-
Synthesia
· Synthesia Privacy Policy
The policy states that personal data including contact information, financial data, usage data, technical data, and potentially biometric data may be transferred to third parties in the event of a merger, acquisition, asset sale, bankruptcy, or insolvency, including during pre-transaction due diligence....
Why it matters: This provision reserves the right to transfer personal data including biometric data to acquiring entities or parties involved in due diligence prior to any transaction closing, which may occur before users are notified of the transfer. The inclusion of biometric data in potentially transferable assets creates heightened compliance considerations under BIPA and GDPR Article 9....
-
Synthesia
· Synthesia Privacy Policy
The policy states that Synthesia's services are not directed at users under age 16, and that Synthesia does not knowingly collect information from or permit use by minors. The age threshold of 16 exceeds the US COPPA threshold of 13 and aligns with GDPR Article 8's default age of digital consent in many EU member states....
Why it matters: The policy sets a minimum age of 16, which aligns with GDPR Article 8 digital consent thresholds applicable in several EU member states and exceeds the US COPPA threshold of 13. Given that the platform collects biometric data, the application of this age restriction to biometric processing workflows is particularly material....
-
Writer
· Writer Privacy Policy
The policy states that Writer will not use data provided by users during service use, including AI prompt inputs and generated outputs, to train its models under any circumstances....
Why it matters: This provision directly addresses a primary data use concern for AI platform users by establishing an explicit contractual prohibition on using user-provided content for model training. The scope covers all inputs and outputs provided during service use in the controller context governed by this policy....
-
Writer
· Writer Privacy Policy
The policy authorizes Writer to aggregate or de-identify collected user data and share that de-identified data with any third party, including advertisers, partners, and sponsors, for any purpose including research and marketing....
Why it matters: This provision establishes that once data is de-identified as defined by Writer, it may be disclosed to an unrestricted set of third parties for unrestricted purposes. The policy does not specify the technical standard used to achieve de-identification, and the definition relies on data no longer being linkable to a user or device rather than a codified regulatory standard....
-
Writer
· Writer Privacy Policy
The policy authorizes third-party advertising partners, including Google, to place cookies and tracking technologies on users' devices to collect behavioral data and serve targeted advertising across other websites and applications....
Why it matters: This provision establishes that third-party advertising networks, operating under their own privacy policies, collect user data through Writer's platform for cross-site behavioral advertising. This creates data flows governed by third-party terms outside Writer's direct control....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Writer
· Writer Privacy Policy
Writer certifies compliance with the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework for personal data transferred from the EEA, UK, and Switzerland, and is subject to FTC enforcement authority for DPF compliance failures....
Why it matters: This provision establishes the legal transfer mechanism Writer relies upon for personal data flows from the EEA, UK, and Switzerland to the United States, and designates JAMS as the dispute resolution provider with binding DPF arbitration available as a final recourse mechanism for unresolved complaints....
-
Writer
· Writer Privacy Policy
The policy states that collected user data may be transferred to and stored in the United States and other countries, and that continued use of the services constitutes acknowledgment that such transfers will occur....
Why it matters: This provision relies on continued use of the services as acknowledgment of international data transfers. Under GDPR, transfer mechanisms must meet specific legal standards, and acknowledgment-by-use may require evaluation as a valid GDPR Chapter V transfer basis depending on the jurisdiction and regulatory interpretation....
-
Writer
· Writer Privacy Policy
The policy establishes a CCPA opt-out right for California residents to opt out of the disclosure of personal information for cross-context behavioral advertising, exercisable via a 'Your privacy choices' link or Global Privacy Control signal....
Why it matters: This provision establishes the operative opt-out mechanism for California residents under the CCPA and confirms that Writer honors Global Privacy Control browser signals, which satisfies a specific California regulatory requirement under the CCPA regulations....
-
Writer
· Writer Privacy Policy
The policy states that Writer's services are not directed to users under 16, that the company does not knowingly collect personal information from persons under 16, and that it will delete such information if discovered....
Why it matters: The policy sets a minimum age of 16 rather than 13, which exceeds the minimum threshold under the U.S. Children's Online Privacy Protection Act (COPPA) and aligns with the minimum age threshold established under GDPR Article 8 for information society services in jurisdictions that have not lowered the default age....
-
Writer
· Writer Privacy Policy
The policy authorizes disclosure of user personal information to third parties during or in contemplation of corporate transactions including mergers, asset sales, reorganizations, financing events, or changes of control....
Why it matters: This provision establishes that personal data may be shared with potential acquirers or transaction counterparties during due diligence, prior to any completed transaction, and without a separate user notification mechanism described in this clause....
-
Writer
· Writer Privacy Policy
The policy states that Writer may update the Privacy Policy at any time by posting a revised version on its website, and that continued use of the services constitutes confirmation that the user has read and understood the updated policy....
Why it matters: This provision treats continued service use as affirmative acknowledgment of any updated policy terms. Users are not guaranteed active notification of changes beyond the posting of an updated version on the website, except where applicable law requires another form of notice....
-
Jasper AI
· Jasper Privacy Policy
The policy governs data processing associated with user-submitted content inputs across Jasper's AI tools including Jasper Chat, AI Studio, Image Pipelines, and the API layer. The scope of this processing encompasses content generated, submitted, or processed through these systems....
Why it matters: This provision establishes the operational scope of data processing for AI-generated and user-submitted content across Jasper's product surface. Enterprise and API customers should evaluate what data handling obligations apply to content inputs submitted through these systems, particularly where inputs may contain personal or proprietary information....
-
Jasper AI
· Jasper Privacy Policy
The policy addresses sharing of user data with third-party service providers, analytics partners, and integration partners across Jasper's product ecosystem. The specific categories of third parties and the scope of data shared are disclosed within the policy's data sharing provisions....
Why it matters: This provision establishes the conditions under which user data is disclosed to third parties including analytics vendors, infrastructure providers, and integration partners. The breadth of Jasper's product surface including browser extensions, APIs, and third-party integrations means the third-party data sharing perimeter may extend across multiple systems....
-
Jasper AI
· Jasper Privacy Policy
The policy includes provisions addressing the privacy rights of California residents under applicable state law, including rights associated with data access, deletion, and opt-out of certain data sharing practices. These provisions are referenced in the policy's legal information section....
Why it matters: This provision establishes the rights available to California residents under CCPA/CPRA, including access, deletion, correction, and opt-out rights. The operational availability and mechanism for exercising these rights is a material compliance consideration for Jasper's California-based user base....
-
Jasper AI
· Jasper Privacy Policy
The policy addresses data rights and processing obligations for EU, EEA, and UK users under applicable international data protection frameworks. The scope of these provisions and the designated lawful bases for processing are referenced in the policy's international user sections....
Why it matters: This provision establishes the terms under which EU, EEA, and UK user data is processed, including the lawful basis assertions and data subject rights available under GDPR. Enterprise customers with EU-based employees or customers should evaluate whether the policy's international provisions are sufficient for their compliance obligations....
-
Jasper AI
· Jasper Privacy Policy
The policy governs data collected through Jasper's browser extensions and third-party integrations, which extend the platform's data collection scope beyond the core web application. Data collected through these channels is subject to the policy's general data handling terms....
Why it matters: Browser extensions and integrations operate within users' broader browsing and application environments, potentially collecting data beyond the scope of core platform interactions. The policy's application to these channels establishes the data handling terms for an expanded collection surface....
-
Jasper AI
· Jasper Privacy Policy
The policy addresses data processing applicable to enterprise customers and API users of Jasper's platform, covering data submitted through the Jasper APIs, Jasper MCP, and Image APIs. Enterprise customers and developers accessing Jasper via API are subject to the policy's data handling provisions....
Why it matters: API-based data processing creates distinct data flow structures where enterprise customer data and end-user personal data may be transmitted to and processed by Jasper's systems. The policy's application to API users establishes the baseline data handling terms for these technical integrations, though enterprise Data Processing Agreements may supplement or modify these terms....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that GPT-5.5 underwent OpenAI's full pre-deployment safety evaluation suite, including the Preparedness Framework, with targeted red-teaming specifically covering advanced cybersecurity and biology capabilities, supplemented by structured feedback from approximately 200 early-access partners....
Why it matters: This provision establishes the evidentiary basis for OpenAI's safety claims at deployment and identifies cybersecurity and biology as the primary dual-use capability risk domains subjected to structured adversarial testing. Organizations and regulators evaluating compliance with AI safety obligations may reference this disclosure when assessing whether the pre-deployment process meets applicable standards....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that GPT-5.5 Pro safety evaluations are generally based on GPT-5.5 evaluation results used as proxies, with separate evaluation conducted only where OpenAI judges that the parallel test-time compute setting could materially affect risk or safeguard posture....
Why it matters: This provision establishes that GPT-5.5 Pro, a distinct product configuration, relies primarily on safety evaluations conducted for a different operational setting. Compliance teams assessing AI model governance should evaluate whether this proxy methodology meets the independent evaluation expectations of applicable frameworks, particularly for higher-compute configurations that may exhibit different capability profiles....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document asserts that GPT-5.5 is being released with OpenAI's most robust safeguard set across its model releases to date, characterized as designed to reduce misuse while maintaining access for legitimate use cases....
Why it matters: This provision constitutes a comparative safety claim that may be assessed against prior OpenAI model releases and evaluated under consumer protection and advertising standards frameworks. The document does not define the specific safeguards or metrics underlying this assertion....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that the system card was amended after initial publication on April 24, 2026 to add disclosures specific to the deployment of GPT-5.5 and GPT-5.5 Pro through the API....
Why it matters: This provision establishes that material API safeguard information was added to the system card after the model's initial release, which is operationally significant for API users who may have assessed deployment risks based on the original document. Compliance teams should confirm they are reviewing the April 24, 2026 version of the system card....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document describes GPT-5.5 as an agentic model designed to execute multi-step, multi-tool workflows autonomously, including online research, code writing, document creation, and cross-tool task execution, with reduced reliance on user guidance compared to prior models....
Why it matters: The description of GPT-5.5 as an agentic system capable of operating across tools with reduced human guidance is operationally significant for deployers assessing automation risk, human oversight obligations, and accountability frameworks under emerging AI governance requirements. The agentic capability profile described directly informs risk classification under frameworks such as the EU AI Act....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that safety evaluation results described across system cards were conducted in an offline setting unless specifically noted otherwise, meaning they do not reflect live or production deployment conditions....
Why it matters: This disclosure establishes that the safety evaluation results described in the system card are based on offline testing rather than production deployment conditions, which is a material methodological limitation for compliance teams assessing the real-world applicability of the stated safety posture....
-
Palantir
· Palantir Privacy Statement
The statement authorizes Palantir to generate inferred data by combining internally collected data with third-party partner and publicly available data, and to use this inferred data along with other collected categories to place targeted advertisements on third-party platforms including LinkedIn and Twitter....
Why it matters: This provision establishes that inferred data, derived from combining multiple internally collected categories with external third-party data, is used as an input for behavioral advertising on external social media and search platforms. The provision relies on legitimate interests as the legal basis for this processing in the EEA, UK, and Switzerland context, which may require evaluation under applicable regulatory guidance on behavioral advertising....
-
Palantir
· Palantir Privacy Statement
The statement authorizes Palantir to disclose an individual's training participation, progress data, quiz results, and certification outcomes to the individual's employer or to the organization that provided the certification exam code....
Why it matters: This provision establishes that training and certification data generated by individual employees using employer-provided exam codes will be disclosed to the employer or issuing organization, creating a data flow from individual to employer that the individual may not separately consent to beyond the initial registration for training....
-
Palantir
· Palantir Privacy Statement
The statement designates Stripe as an independent data controller for payment and contact data collected during transactions on Palantir websites, and directs users to Stripe's own privacy policy for information on how that data is processed....
Why it matters: This provision establishes that Palantir does not control the processing of payment data once it is submitted via Stripe's payment interface on Palantir platforms. Individuals seeking to exercise data rights over payment data or understand how it is used must engage directly with Stripe under Stripe's own terms and privacy policy....
-
Palantir
· Palantir Privacy Statement
The statement discloses that personal data transferred out of the EEA, UK, or Switzerland to non-adequate countries is protected using Standard Contractual Clauses approved by the European Commission, UK Secretary of State, or UK ICO....
Why it matters: This provision establishes the legal mechanism Palantir relies upon for cross-border data transfers from the EEA, UK, and Switzerland to the United States and other third countries. Individuals may request additional information about applicable transfer safeguards by exercising their data access rights....
-
Palantir
· Palantir Privacy Statement
The statement discloses that Palantir collects photographs, images, audio recordings, and video recordings through security and monitoring systems in its offices and during Palantir or Palantir-affiliated events and seminars....
Why it matters: This provision establishes that audiovisual data, including security footage and event recordings, is collected from individuals who visit Palantir offices or attend affiliated events. The legal basis cited for this processing in EEA/UK/Switzerland contexts is Palantir's legitimate interests in safety and security of employees, visitors, and confidential information....
-
Palantir
· Palantir Privacy Statement
The statement enumerates data subject rights available to individuals in the UK, EEA, and Switzerland, including access, correction, erasure, restriction, objection, portability, consent withdrawal, and the right to lodge a supervisory authority complaint....
Why it matters: This provision establishes the specific rights Palantir acknowledges for EEA, UK, and Swiss residents and the mechanism for exercising them, including direct contact with Palantir's Data Protection Officer. The statement notes these rights are not absolute and may be balanced against other considerations....
-
Palantir
· Palantir Privacy Statement
The statement authorizes processing and transfer of personal data in connection with a broad range of corporate transactions, including mergers, acquisitions, divestitures, bankruptcy, restructuring, receivership, reorganization, dissolution, and asset sales, where personal data forms part of the assets involved....
Why it matters: This provision establishes that personal data collected under this statement may be transferred to a buyer or other transaction party across a wide range of corporate restructuring scenarios. The provision applies to proposed transactions as well as completed ones, which means personal data may be disclosed during due diligence processes prior to transaction completion....
-
Palantir
· Palantir Privacy Statement
The statement discloses that Palantir's websites are not intended for children under 16 and that Palantir does not knowingly collect personal information from children under 16 as defined by COPPA....
Why it matters: This provision establishes Palantir's stated age threshold of 16 years for website use, which exceeds COPPA's 13-year statutory threshold, and provides a deletion mechanism for parental notification of inadvertent collection....
-
Palantir
· Palantir Privacy Statement
The statement establishes that Palantir may send marketing communications and conduct personalization profiling on the basis of legitimate interests in jurisdictions where consent has not been separately sought, in addition to consent-based marketing where consent is obtained....
Why it matters: This provision establishes a dual legal basis structure for marketing communications and personalization profiling: consent where obtained, and legitimate interests where consent has not been separately sought. This means Palantir may send marketing communications without prior consent in contexts where legitimate interests is asserted as the applicable basis, subject to the right to object....
-
Meta
· Meta Frontier AI Framework
The document states that Meta's Frontier AI Framework is scoped to cybersecurity threats and chemical and biological weapons risks, and that these are designated as the primary areas for risk assessment in frontier AI model development....
Why it matters: This provision defines the operational boundaries of Meta's disclosed risk evaluation framework, establishing that the framework does not purport to address the full range of AI risk categories identified in regulatory frameworks such as the EU AI Act, which encompasses broader harm categories including fundamental rights, discrimination, and societal impact....
-
Meta
· Meta Frontier AI Framework
The document states that Meta conducts threat modeling exercises, including work with external experts, to anticipate misuse scenarios by different actors and to identify catastrophic outcomes related to cyber, chemical, and biological risks associated with frontier AI models....
Why it matters: This provision describes the primary procedural mechanism Meta states it uses to assess model risk before release; however, the document does not disclose the identity of external experts, the frequency or methodology of exercises, or how outcomes of these exercises affect release decisions....
-
Meta
· Meta Frontier AI Framework
The document states that Meta defines risk thresholds based on how much a model facilitates identified threat scenarios, and that the company applies mitigations to keep risks within what it characterizes as acceptable levels....
Why it matters: This provision describes the decision criteria Meta states it applies to model releases, but the specific thresholds, the definition of acceptable levels, and the mitigation mechanisms are not disclosed, limiting external assessment of the framework's operational rigor....
-
Meta
· Meta Frontier AI Framework
The document asserts that Meta's open-source model release approach contributes to risk mitigation by enabling external community assessments of model capabilities, which the document characterizes as improving model efficacy, trustworthiness, and field-level risk evaluation....
Why it matters: This provision frames open-source release as a component of Meta's risk management strategy, a characterization that may be relevant to regulatory discussions about whether open-source AI releases require additional oversight mechanisms compared to closed-model deployments....
-
Meta
· Meta Frontier AI Framework
The document states that the Frontier AI Framework is published in fulfillment of a commitment Meta made at the 2024 Seoul AI Summit, a multilateral governmental AI governance forum....
Why it matters: This provision contextualizes the framework as a voluntary commitment made in a multilateral governmental forum rather than a regulatory obligation, which is relevant to assessing the enforceability and scope of the framework's stated practices....
-
Meta
· Meta Frontier AI Framework
The document asserts that open-source AI development is essential to U.S. technological leadership, economic growth, and national security, framing open-source release as a policy imperative rather than solely a commercial or technical decision....
Why it matters: This provision articulates a public policy position on open-source AI that may be relevant to regulatory and legislative discussions about AI release modalities, export controls, and national security review processes for AI technologies....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave may collect biometric information and video surveillance recordings from individuals who visit its offices or data centers, alongside standard visitor identification data such as name, company affiliation, badge credentials, and access times....
Why it matters: This provision authorizes collection of biometric information at physical locations under a legitimate interests basis (GDPR Article 6(1)(f)), without specifying a separate consent mechanism. State biometric privacy statutes in Illinois, Texas, and other jurisdictions impose independent written consent requirements that may not be satisfied by a legitimate interest basis alone, creating potential compliance exposure for CoreWeave and for enterprise customers whose employees or contractors visit CoreWeave facilities....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy authorizes sharing personal data with current and future CoreWeave parent companies, subsidiaries, and affiliates, including for the purpose of cross-context behavioral advertising, defined as targeted advertising based on user activity across different websites, applications, or services over time....
Why it matters: This provision authorizes cross-context behavioral advertising data sharing with affiliated entities, which under CPRA constitutes 'sharing' subject to opt-out rights. The policy provides opt-out mechanisms via the website footer link, GPC signals, and cookie preference tools, satisfying CPRA's opt-out disclosure requirements, though the operational scope of affiliate sharing across current and future affiliates warrants monitoring as CoreWeave's corporate structure evolves....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy explicitly limits its own scope to personal data processed by CoreWeave as a controller and excludes Customer Data, defined as data processed on behalf of enterprise customers, from coverage; responsibility for Customer Data is attributed to the enterprise customer as data controller....
Why it matters: This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests to the enterprise customer....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave collects the inputs and outputs of service tools and offerings submitted by customers through the Services, in addition to messages, support communications, and Slack interactions, for purposes including analyzing usage, operating the Services, debugging, evaluation, and product improvement....
Why it matters: This provision authorizes collection and use of the content customers submit to CoreWeave's service tools, including model inputs and outputs, for product improvement and analytics purposes under a legitimate interests basis. Customers using AI or ML tools through CoreWeave's platform should assess whether their submissions may include personal data or confidential information subject to their own data governance obligations....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave may apply AI and ML technologies to user data for service operation, maintenance, improvement, security, and customer experience purposes, with the policy stating that notice or consent will be obtained where required by applicable law....
Why it matters: This provision authorizes AI and ML processing of user data under a conditional consent framework tied to applicable law requirements, which means the level of notice or consent provided may vary by jurisdiction. The policy separately states that CoreWeave does not perform automated decision-making or profiling producing legal or similarly significant effects, which limits the scope of this provision's most significant potential impacts....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy states that CoreWeave recognizes and honors GPC signals as opt-out requests for sale or sharing of personal information where applicable law requires, processes the GPC signal as a restriction on non-essential tracking technologies on the specific device and browser, and does not respond to Do Not Track browser signals....
Why it matters: This provision operationalizes CPRA's requirement that businesses recognize GPC signals as opt-out requests, while clarifying that the effect of the GPC signal is limited to the specific device and browser from which it is sent and is processed through CoreWeave's consent management platform. The explicit non-response to DNT signals is a standard disclosure under California's Online Privacy Protection Act....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy states that personal data is retained only as long as necessary for the described purposes or as required by law, and that upon expiration of that necessity, data will be deleted, anonymized, or securely isolated, with a carve-out for data that cannot be immediately deleted from backup systems....
Why it matters: This provision does not specify fixed retention periods for any category of personal data, instead applying a purpose-necessity standard with a backup system carve-out. The absence of specific retention schedules may complicate enterprise customers' data mapping and audit obligations under GDPR and CPRA, which encourage or require specific retention period documentation....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave may transfer personal data internationally, including to countries without equivalent data protection standards, and states that Standard Contractual Clauses are used as a transfer mechanism where required....
Why it matters: This provision discloses cross-border data transfer practices and identifies Standard Contractual Clauses as the primary safeguard mechanism, consistent with GDPR Chapter V requirements. The policy does not specify which country-to-country transfer routes are covered or identify whether transfer impact assessments have been conducted, which are additional requirements under GDPR for SCCs....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy authorizes disclosure or transfer of personal data to potential or actual acquirers, successors, or assignees in connection with mergers, acquisitions, debt financing, asset sales, or insolvency proceedings, where personal data is treated as a business asset....
Why it matters: This provision is a standard business transfer clause that authorizes sharing personal data with potential acquirers during due diligence and transferring it to successors upon completion of a transaction. Users have no advance notice or opt-out mechanism specified for this transfer scenario under the policy's terms....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement grants W&B a right to use Customer Data, including machine learning models, datasets, and generated reports, not only to deliver contracted services but also to develop new products and improve AI features....
Why it matters: This provision establishes a secondary use right over Customer Data that extends beyond service delivery to product development and AI feature improvement, which procurement and legal teams should evaluate against the organization's own data protection obligations and applicable regulatory frameworks including GDPR purpose limitation requirements....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement explicitly authorizes W&B to use Customer Data submitted by free-tier and academic-license users for W&B's internal testing and development purposes, as a condition of free access....
Why it matters: This provision establishes that customers accessing W&B under free or academic licenses, including students and employees of accredited educational institutions, grant W&B rights to use their submitted data for testing and development, which is a condition disclosed in the terms but may not be prominently surfaced at the point of free account creation....
-
Weights & Biases
· Weights & Biases Terms of Service
Based on the document structure and standard MSA provisions referenced, the agreement references arbitration provisions; however, the document text provided was truncated before the full arbitration clause text was reproduced. The agreement is structured to include dispute resolution provisions in Section 14 (Miscellaneous)....
Why it matters: Arbitration clauses in B2B SaaS agreements require disputes to be resolved through private arbitration rather than court proceedings, and commonly include class action waivers that prevent consolidated claims. Legal teams should locate and review the full arbitration provision in the untruncated agreement....