-
Slack
· Slack Sub-Processors (Salesforce)
This provision states that the sub-processor list may include services or features that have not yet been released to general availability, included for the purpose of advance disclosure, and that such inclusion does not create an obligation for Salesforce to deliver those services or features....
Why it matters: This provision establishes that the sub-processor table may disclose processing relationships and locations for products that are not yet commercially available, meaning the listed sub-processors and locations for certain services may not reflect current operational processing but rather anticipated future configurations, which organizations should account for when using this document to map active processing activities....
-
Zoom
· Zoom Sub-Processors
Cloud recordings, in-meeting chat transcripts, and file attachments submitted to Zoom support agents are conditionally shared with four subprocessors: MaestroQA for quality assurance, SendSafely for encrypted file transfer, ServiceNow for customer service platform functions, and TaskUS for support operations, with processing locations spanning Ireland, the United States, Germany, and the Philippines....
Why it matters: This provision establishes that Customer Content including recordings and chat transcripts submitted through support interactions may be shared with vendors in the Philippines and multiple EU and US jurisdictions; TaskUS is located in the Philippines and Croatia, jurisdictions lacking EU adequacy status, with SCCs as the stated transfer mechanism....
-
Zoom
· Zoom Sub-Processors
Twilio is authorized to process name, email address, phone number, meeting or webinar subject, meeting ID, start date and time, and meeting summaries for the purpose of delivering Zoom service notifications including phone authentication, meeting invites, and AI feature requests, with processing in the United States and European Union under SCCs....
Why it matters: Meeting summaries and meeting subjects are among the data categories Twilio may process for notification delivery; these categories may contain substantive business or sensitive information, and their inclusion in notification infrastructure creates a disclosure pathway beyond the core meeting experience....
-
Zoom
· Zoom Sub-Processors
OneTrust is authorized to process name, email address, account type, country, IP address, DSAR reports, and user cookie preferences for the purpose of managing data subject access requests and cookie preference selections, with processing in the United States under SCCs....
Why it matters: DSAR reports processed by OneTrust may contain aggregated personal data about the requesting individual compiled in response to data subject access requests under GDPR or CCPA; the processing of these reports by a US-based subprocessor under SCCs is a material consideration for data controllers assessing whether their data subject rights fulfillment process involves adequate transfer safeguards....
-
Zoom
· Zoom Sub-Processors
Sendbird is authorized to process user name, Workvivo ID, and Customer Content submitted via the Workvivo chat feature, when that feature is optionally enabled, with processing in the European Union and United States under Standard Contractual Clauses....
Why it matters: This provision was added in November 2025 following the removal of Zendesk; organizations using Workvivo should assess whether their data protection documentation reflects Sendbird as a new subprocessor for chat content and whether their employees have been notified of this processing arrangement....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Stripe
· Stripe Service Providers (Sub-Processors)
Stripe is converting its primary US entity from Stripe, Inc. to Stripe, LLC, effective January 3, 2026. The document lists both entity names with a transition date....
Why it matters: This provision requires Business Users who have executed agreements referencing Stripe, Inc. as the contracting or processing entity to assess whether their existing contracts, DPAs, or Standard Contractual Clauses require amendment to reflect the new legal entity name effective January 3, 2026....
-
Stripe
· Stripe Service Providers (Sub-Processors)
The document states that Stripe India Private Limited stores certain personal data related to Indian payment transactions on servers located in India to comply with Indian regulatory data localization requirements. This disclosure appears in both the sub-processor list and the affiliate list....
Why it matters: This provision confirms that personal data associated with Indian payment transactions is subject to data localization obligations under Indian regulation, which affects how Business Users and their technical teams configure data flows for Indian payment processing. Business Users operating in India or processing Indian payment transactions should confirm that their own data handling and disclosure documentation reflects this localization requirement....
-
Stripe
· Stripe Service Providers (Sub-Processors)
The document states that Stripe performs due diligence including a vendor security assessment before engaging any service provider or sub-processor, and that all service providers are subject to contractual terms limiting data processing to service provision purposes consistent with Stripe's commitments and applicable data protection law....
Why it matters: This provision discloses Stripe's stated sub-processor vetting and contractual control framework, which is directly relevant to Business Users' own GDPR Article 28 obligations to ensure that processors they engage provide sufficient guarantees regarding sub-processor management. Business Users may rely on this disclosure as part of their own vendor due diligence documentation....
-
Stripe
· Stripe Service Providers (Sub-Processors)
The document states that Khoros, LLC has been removed as a sub-processor and replaced by Sprinklr, Inc. for managing incoming queries via social media. Sprinklr, Inc. is a US-based entity....
Why it matters: This sub-processor substitution affects the entity processing personal data included in social media queries directed to Stripe. Business Users who have documented Khoros, LLC in their own sub-processor lists or data processing records should update those records to reflect Sprinklr, Inc. as the replacement entity....
-
Stripe
· Stripe Service Providers (Sub-Processors)
The document states that Business Users may subscribe to email notifications to receive alerts when the sub-processor list is updated. This mechanism is relevant to preserving the 30-day objection window under the DPA....
Why it matters: The subscription mechanism is operationally significant because the 30-day deemed-acceptance window begins upon page update rather than upon individual notice; Business Users who do not subscribe may not be aware of changes within the objection period. Subscribing to email notifications is the primary operational control available to Business Users for timely awareness of sub-processor changes....
-
Stripe
· Stripe Service Providers (Sub-Processors)
The document lists Microsoft Corporation as a sub-processor for AI technology used to process information contained in user support queries, for the stated purpose of improving the quality of Stripe's user support operations. Microsoft is a US-based entity....
Why it matters: The use of AI technology to process support query data, which may include personal data submitted by Business Users and their End Customers, introduces an additional sub-processor relationship that Business Users should account for in their data processing documentation. The document does not specify which Microsoft AI products or services are used, which limits assessment of the specific processing activities involved....
-
OpenAI
· OpenAI Sub-Processor List
The document states that customer support sub-processors (Intercom, Salesforce, TaskUs, Accenture, Pylon Labs) only process Customer Data to the extent the customer explicitly elects to share it during a support interaction. Processing is not automatic and is conditioned on customer-initiated disclosure....
Why it matters: This provision establishes that customer support data processing is conditional on customer action, limiting the default exposure of Customer Data to support sub-processors. Enterprise customers should communicate this condition to internal teams managing support interactions to avoid inadvertent disclosure of sensitive data....
-
OpenAI
· OpenAI Sub-Processor List
The document states that WorkOS (cross-domain identity management) and Merge API (infrastructure management via Connectors) are engaged only when the customer elects to use those features. Pylon Labs is engaged only when the customer elects premium support. These sub-processors do not process Customer Data by default....
Why it matters: This provision establishes that three sub-processors are conditionally engaged based on feature or support tier elections, meaning the applicable sub-processor set varies by customer configuration. Compliance teams should document which optional features are enabled to maintain accurate sub-processor records....
-
OpenAI
· OpenAI Sub-Processor List
The document offers a subscription mechanism for customers to receive notifications when new third-party sub-processors are added. Customers can sign up via a linked form, and questions or concerns can be directed to privacy@openai.com....
Why it matters: This provision establishes a voluntary notification mechanism for sub-processor changes, which is relevant to enterprise customers who need to track sub-processor additions for GDPR Article 28 compliance or contractual DPA obligations that may require advance notice of sub-processor changes....
-
Anthropic
· Anthropic Sub-Processors
Stripe, based in the United States, is listed as the billing subprocessor for Claude Pro/Max, Claude Developer Platform, and Claude for Work, meaning payment and billing-related data for these products is processed by Stripe in the US....
Why it matters: This provision discloses that payment and billing data for paid and enterprise Anthropic products is processed by a US-based third party, which is relevant to organizations assessing financial data handling and cross-border transfer implications for EU or UK users making payments....
-
Anthropic
· Anthropic Sub-Processors
WorkOS, located in the United States, is listed as the subprocessor responsible for security and single sign-on (SSO) functionality for Claude for Work and the Claude Developer Platform, meaning authentication and identity data for enterprise and developer users is processed by WorkOS....
Why it matters: This provision discloses that authentication credentials and identity data for enterprise (Claude for Work) and developer platform users are processed by a US-based third party, which is relevant to organizations with identity governance, access management, and cross-border data transfer compliance obligations....
-
Anthropic
· Anthropic Sub-Processors
Cloudflare is listed as the content delivery network and traffic routing subprocessor for all Anthropic products, with a processing location described as worldwide but local to the customer, indicating that traffic may be routed through Cloudflare infrastructure nearest to the user's geographic location....
Why it matters: This provision discloses that all network traffic for all Anthropic products passes through Cloudflare's global CDN infrastructure, meaning request and response data is handled by Cloudflare nodes that may be located in the user's region, with implications for data flow mapping and network-level security assessments....
-
Mistral AI
· Mistral Medium 3.5 Model Card
The document discloses that API access to Mistral Medium 3.5 is priced at $1.50 per million input tokens and $7.50 per million output tokens....
Why it matters: This provision establishes the commercial rate structure applicable to API consumption of Mistral Medium 3.5; organizations with high-volume or production API usage should account for these rates in vendor contract and budget planning....
-
Mistral AI
· Mistral Medium 3.5 Model Card
The document discloses that Mistral Medium 3.5 supports a context window of 256,000 tokens per API call....
Why it matters: The 256k context window specification is an operationally significant technical parameter that determines the maximum input size per request, directly affecting how the model may be used for long-document processing, multi-turn conversation, and agentic workflows....
-
OpenAI
· OpenAI GPT-5 System Card
OpenAI states that all GPT-5 model variants incorporate a safety training approach called safe-completions, which the document describes as designed to prevent disallowed content from being produced....
Why it matters: This provision establishes a uniform safety training layer applied across all GPT-5 model variants, including those accessed via the API, which may affect the range of outputs available to developers and enterprise users building applications on the platform....
-
OpenAI
· OpenAI GPT-5 System Card
The document states that when a user reaches usage limits, remaining queries are handled by a mini model variant rather than the primary model, affecting response quality and capability for those queries....
Why it matters: This provision establishes an automatic model degradation mechanism tied to usage limits, which may affect the capability level and output quality available to users and developers who exceed defined thresholds, with potential implications for enterprise service level expectations....
-
OpenAI
· OpenAI GPT-5 System Card
The document states that API access provides developers with direct access to gpt-5-thinking, gpt-5-thinking-mini, and gpt-5-thinking-nano, with the nano variant described as specifically designed for developer use cases....
Why it matters: This provision defines the model variants available to API developers, which determines the capability ceiling for applications built on the GPT-5 platform and establishes that the High capability bio/chem classification and safe-completions restrictions apply to the thinking model variants accessible via the API....
-
Meta
· Llama 4 Model Card
The card discloses that Llama 4 model training consumed 7.38 million GPU hours and generated an estimated 1,999 tons of CO2 equivalent on a location-based basis, with Meta asserting a market-based emissions figure of 0 tons based on renewable energy matching and open-source release....
Why it matters: This provision constitutes a voluntary ESG disclosure quantifying the energy and emissions footprint of Llama 4 training. The distinction between location-based and market-based emissions figures reflects recognized greenhouse gas accounting methodologies and may be relevant to institutional investors and ESG compliance teams assessing Meta's climate disclosures....
-
Meta
· Llama 4 Model Card
The card discloses that Meta conducted recurring red teaming exercises and targeted evaluations across three critical risk categories, CBRNE, child safety, and cyber attack enablement, and describes the methodology and scope of those evaluations....
Why it matters: This provision documents the scope and methodology of Meta's pre-release safety evaluation for Llama 4, providing institutional deployers with a basis for assessing the categories of risk that were formally evaluated prior to release and those that were not....
-
Meta
· Llama 4 Model Card
The card states that the Llama 4 Community License explicitly permits using Llama 4 model outputs to generate synthetic training data and to perform knowledge distillation for improving other AI models....
Why it matters: This provision explicitly authorizes a category of use, synthetic data generation and model distillation, that has been restricted or contested in licenses for other large language models. Organizations developing AI models may rely on this authorization when designing training pipelines that incorporate Llama 4 outputs....
-
Google DeepMind
· Google DeepMind Frontier Safety Framework
The document establishes that security mitigations are applied to prevent unauthorized exfiltration of model weights, noting that weight access enables removal of most safeguards. The framework introduces tiered security levels mapped to CCLs to identify where strongest mitigations are required....
Why it matters: This provision identifies model weight exfiltration as a primary security risk and establishes that tiered mitigations are applied based on CCL classification. The document states that the social value of any single actor's security mitigations is significantly reduced if not broadly applied across the field, framing this as a collective-action problem requiring industry-wide standards....
-
Google DeepMind
· Google DeepMind Frontier Safety Framework
The document asserts that frontier AI security is a collective responsibility requiring industry-wide standards, stating that the value of any single actor's security mitigations is reduced if not broadly applied. DeepMind calls for accelerated efforts toward common industry standards among all frontier AI developers....
Why it matters: This provision frames DeepMind's security recommendations as intended for field-wide adoption rather than as company-specific commitments, and references the Seoul Frontier AI Safety Commitments as a step toward collective governance. The provision's call for common industry standards is relevant to regulatory and standard-setting processes underway in the EU, UK, and US....
-
Greenhouse
· Greenhouse Privacy Policy
Greenhouse holds certifications under the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, and states that DPF Principles supersede conflicting policy language; FTC enforcement jurisdiction applies to DPF compliance....
Why it matters: This provision establishes that DPF Principles take precedence over any conflicting policy language and that FTC enforcement jurisdiction applies to Greenhouse's cross-border data transfer compliance, providing EU, UK, and Swiss individuals a formal complaint pathway to their respective data protection authorities....
-
Greenhouse
· Greenhouse Privacy Policy
The policy states that Greenhouse requires affirmative express consent before disclosing or repurposing sensitive categories of personal information, including health conditions, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and sexual life data....
Why it matters: This provision establishes an opt-in consent requirement for sensitive personal information that applies regardless of geographic jurisdiction, providing a baseline protection for sensitive data categories that aligns with GDPR Article 9 requirements and extends a similar protection to non-EEA users....
-
Greenhouse
· Greenhouse Privacy Policy
The policy discloses that Personal Information may be transferred to and processed in countries with different or less protective data protection laws, and states that Greenhouse will use lawful transfer mechanisms and contractual restrictions to maintain protections....
Why it matters: This provision establishes Greenhouse's general commitment to lawful transfer mechanisms for international data flows, which in practice is supplemented by the DPF certification described elsewhere in the policy; the provision does not enumerate specific transfer mechanisms beyond the DPF program, leaving the operational implementation to be confirmed through the Data Processing Addendum....
-
Greenhouse
· Greenhouse Privacy Policy
Greenhouse retains Personal Information as long as a legitimate business need exists, after which it will delete or anonymize the data; if deletion is not immediately possible due to backup storage, the data will be isolated from further processing until deletion is feasible....
Why it matters: This provision establishes an indefinite retention period tied to the existence of a legitimate business need, without specifying fixed retention durations for particular data categories, which may require evaluation under GDPR storage limitation principles....
-
Faire
· Faire Privacy Policy
The policy states that personal information is retained for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, reporting, legal claim, and fraud prevention purposes, without specifying fixed retention periods for most data categories....
Why it matters: This provision establishes Faire's retention standard as purpose-based rather than time-bounded for most data categories; under GDPR, a purpose-based retention standard without specific retention periods or criteria may require additional disclosure to satisfy Article 13 and Article 14 transparency obligations....
-
Faire
· Faire Privacy Policy
The policy authorizes Faire to disclose all categories of personal information it holds to a buyer or successor entity in the event of a merger, acquisition, asset sale, bankruptcy, or similar transaction, treating user personal data as a transferable asset....
Why it matters: This provision reserves the right to transfer personal information of all users to an acquiring or successor entity without requiring individual consent at the time of transfer; under GDPR, such transfers may require assessment of the legal basis and whether the successor entity's processing purposes remain compatible with the original collection purposes....
-
Faire
· Faire Terms of Service
The terms prohibit users from uploading or transmitting content that infringes third-party IP rights, violates applicable law, is fraudulent or misleading, is defamatory or obscene, promotes discrimination or violence, or promotes illegal activities. These prohibitions apply to all User Content submitted through the platform....
Why it matters: This provision establishes the content standards that govern what users may post or upload to the platform, and violation of these standards is a basis for account suspension or termination under the Terms. The IP infringement prohibition is particularly relevant for brands uploading product images or descriptions that may incorporate third-party licensed materials....
-
Reverb
· Reverb Privacy Policy
The document's embedded configuration discloses a thirdPartyAnalyticsStorageAllowed flag, indicating that Reverb authorizes storage of analytics-related data by third-party analytics providers when this consent state is active. This flag is separate from advertising-related consent flags....
Why it matters: This provision authorizes third-party analytics storage as a distinct consent category, which may include behavioral data, session data, and event tracking data stored by analytics providers such as those identified elsewhere in the page metadata. Under this clause, analytics data flows to third parties are governed by the thirdPartyAnalyticsStorageAllowed consent state....
-
Reverb
· Reverb Terms of Service
The terms restrict platform use to users aged 18 and older and require users to represent their age as a condition of access....
Why it matters: This provision establishes a minimum age requirement for marketplace participation and places responsibility on users to self-certify their age. The document does not describe technical age verification mechanisms, which may be relevant to COPPA compliance obligations for US-based operators and DSA age assurance requirements for EU/EEA operations....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement states that Delaware law governs the Terms, with exclusive venue for non-arbitrated claims in federal or state courts in San Francisco, California....
Why it matters: This provision establishes Delaware law as the governing substantive law while designating San Francisco, California as the exclusive venue for any litigation that proceeds outside arbitration, which determines which state's consumer protection and contract law applies to disputes....
-
Meta
· Meta Frontier AI Framework
The document states that Meta's Frontier AI Framework limits its primary risk focus to cybersecurity threats and chemical and biological weapons risks, explicitly scoping out other risk categories from the framework's core prioritization....
Why it matters: This provision establishes the defined scope of Meta's risk governance framework for frontier AI models, which determines which threat categories receive structured evaluation prior to model release and which fall outside the framework's stated prioritization....
-
Meta
· Meta Frontier AI Framework
The document states that Meta's framework includes a process for identifying specific catastrophic outcomes in cyber, chemical, and biological domains and evaluating whether AI model capabilities enable those outcomes, with mitigation identification as a follow-on step....
Why it matters: This provision describes the first procedural pillar of Meta's pre-release risk evaluation process, establishing that outcome-level identification precedes capability evaluation and mitigation planning in the framework's stated workflow....
-
Meta
· Meta Frontier AI Framework
The document states that Meta conducts threat modeling exercises, including engagement with external experts as needed, to anticipate misuse of frontier AI models leading to catastrophic outcomes....
Why it matters: This provision discloses that Meta's pre-release risk process includes structured threat modeling and conditional external expert engagement, though the document does not specify the criteria triggering external expert involvement, the independence of those experts, or the scope of their mandate....
-
Meta
· Meta Frontier AI Framework
The document states that Meta defines risk thresholds based on model facilitation of threat scenarios and maintains processes to keep risks within acceptable levels through the application of mitigations....
Why it matters: This provision discloses that Meta uses internally defined risk thresholds and mitigation processes as gates in the model release workflow, but does not specify the threshold levels, the criteria for determining acceptability, or the nature of the mitigations applied....
-
Meta
· Meta Frontier AI Framework
The document states that Meta's open source AI model release approach contributes to risk mitigation by enabling independent community assessment of model capabilities, which Meta characterizes as improving model efficacy, trustworthiness, and field-level risk evaluation....
Why it matters: This provision presents Meta's open source strategy as a component of its risk governance framework, asserting that broad public access to model weights enables community-level safety evaluation; this framing is relevant to regulatory and policy debates about whether open weight model releases reduce or increase frontier AI risk....
-
Meta
· Meta Frontier AI Framework
The document states that the Frontier AI Framework incorporates consideration of technology benefits alongside catastrophic risk evaluation, and characterizes societal benefit as the primary stated motivation for developing frontier AI technologies....
Why it matters: This provision discloses that Meta's risk framework includes a benefits analysis component alongside risk evaluation, which is relevant to how the framework balances restriction against release in model deployment decisions; however, the document does not describe the methodology or weighting applied to benefits in that analysis....