Found in 61 of 352 platforms tracked (17% adoption) · 633 provisions
This provision discloses a specific per-violation financial penalty figure associated with SMS non-compliance, placing customers on notice of the financial exposure associated with CTIA guideline vio…
This clause establishes that account termination can occur immediately upon complaint, without a documented cure period or internal dispute process, and that prepaid service fees are forfeited under …
This clause establishes the operational scope of American Airlines' performance obligations and liability exposure for service disruptions attributable to external events rather than carrier operatio…
This provision operationalizes federal regulatory requirements for oversale compensation, establishing a standardized framework that defines American Airlines' financial obligations when involuntary …
This provision discloses a structural trust limitation in multi-agent architectures that is operationally significant for enterprises building complex AI pipelines, as it means Claude will not automa…
This provision establishes that a production model deployed in agentic contexts has disclosed prompt injection vulnerabilities relative to its predecessor, with risk mitigation relying on applied saf…
This provision establishes that a deployed production model has been assessed as capable of materially assisting biological weapons-relevant tasks, with risk management delegated to runtime detection…
This provision is operationally significant because evaluation awareness behavior, if it develops further, could affect the reliability of safety and capability assessments conducted under standard e…
This provision establishes that CBRN-related AI capabilities are subject to a defined threshold that triggers mandatory safeguard requirements, reflecting a specific operational constraint on model d…
This provision establishes the behavioral safety standard Anthropic applies to agentic deployments, which is operationally significant for enterprises using Claude in automated workflows, API integra…
This clause creates a carve-out from the general privacy policy framework, establishing that customer-specific data processing obligations are defined through individual service agreements rather tha…
This provision reserves the bank's right to alter transaction processing and posting sequences without notice, and the agreement itself acknowledges that these sequencing decisions can affect the num…
This provision establishes that overdraft authorization is entirely discretionary, that past overdraft accommodation does not create an obligation to extend future accommodation, and that the bank ma…
This provision requires personal account disputes to proceed through individual arbitration rather than litigation or class proceedings. The Resolving Claims section governs the specific procedures, …
This provision authorizes the bank to embed undisclosed profit and variable mark-up into foreign currency exchange rates applied to customer transactions, with the rate and mark-up level determined s…
This provision establishes a financial ceiling on Customer's recoverable damages against Baseten that is limited to historical fees paid, and categorically excludes recovery for categories of harm th…
This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full c…
This provision asserts broad set-off rights across all accounts, including joint accounts and deposited federal benefit payments. Federal law, including 31 C.F.R. Part 212, restricts financial instit…
This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are ope…
This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be juri…
This provision establishes that Kit may terminate account access and withhold both payment refunds and subscriber data export without prior notification, creating material operational exposure for bu…
This provision establishes a permanent platform ban as a consequence of policy-based termination, with no stated appeal or reinstatement process, creating an irreversible operational consequence for …
This provision requires users to bear defense costs and indemnify Anker across a broad set of triggering circumstances, including the user's general relationship with Anker and provision of data, whi…
This provision extends the release and assumption of risk to bodily injury, wrongful death, and loss of privacy claims, and purports to bind not only the user but also their heirs and personal repres…
This provision routes all contractual disputes to SIAC arbitration seated in Singapore, a forum that may be practically inaccessible or legally unenforceable for consumer claimants in the EU, UK, Aus…
This provision establishes that Experian's data broker subsidiaries have sold or disclosed sensitive personal information categories, some of which are subject to heightened protections or opt-in con…
This provision contractually shortens the limitations period for all causes of action related to the Web site. The default statutory limitations period for many claim types in New York and other stat…
This provision places full contractual responsibility for third-party tag compliance on the user and establishes a user-side guarantee of rights to uploaded tags. Google's right to screen tags is per…
This provision contractually obligates GTM users to comply with the EU user consent policy, which operationalizes consent requirements under the ePrivacy Directive and GDPR for EU/EEA user data. The …
This provision establishes a direct contractual obligation on GTM users to configure tags and data layer implementations so that no personally identifiable or reasonably linkable data is transmitted …
This provision places the full burden of regulatory compliance on Customers, including compliance with the EU AI Act, which imposes obligations that vary by AI system risk classification and operatio…
This provision establishes a contractual liability allocation under which Groq bears no responsibility for harms arising from Customer reliance on AI-generated outputs, including inaccurate outputs, …
This provision requires enterprise customers deploying Groq AI in any of the named high-risk domains to establish and maintain human oversight mechanisms as a contractual condition of service use, an…
This provision establishes a prerequisite BAA execution for any use of PHI with the Service, consistent with HIPAA requirements for covered entities and business associates. The explicit PCI non-comp…
This provision places the technical and operational responsibility for data minimization on the Customer rather than Contentsquare, covering keystroke data, prefilled form data, HTML-displayed data, …
This provision extends the waiver to claims arising from Instacart's own negligence and from sensitive health information disclosure, including information relating to mental health, HIV status, and …
This provision requires U.S. residents to submit covered claims to binding arbitration on an individual basis, with the arbitrator holding exclusive authority to decide questions of arbitrability und…
This provision extends the liability exclusion to cover physical injuries, bodily injury, and death arising from Third-Party Provider services, which may interact with state consumer protection and p…
This provision establishes a $100 USD aggregate damages cap as Provider's maximum financial exposure to any individual user. The clause excludes direct, indirect, incidental, punitive, and consequent…
This provision restricts use cases that would trigger obligations under the Fair Credit Reporting Act, which governs the use of consumer reports for eligibility determinations. The prohibition places…
This provision establishes a unilateral option mechanism by which Provider may acquire full intellectual property ownership of patentable user submissions at a predetermined, fixed consideration. The…
This provision requires users to grant broad intellectual property rights in submitted content as a condition of participation in Interactive Areas. The license is irrevocable and perpetual, meaning …
This provision establishes that material billing terms and data processing obligations for AI features are located in a document external to this Agreement, meaning the full contractual scope of AI S…
This provision establishes a combined damages exclusion and aggregate liability cap that limits LlamaIndex's financial exposure to $100 or amounts paid, whichever is greater, regardless of the nature…
This provision requires disputes to proceed through individual JAMS arbitration rather than federal or state court, and the agreement assigns to the arbitrator exclusive authority to resolve question…
This provision authorizes deployment of third-party session-recording tools that may capture text inputs in real time, including content entered into LLM-related chat or communication features, which…
This provision establishes the financial ceiling on Atlassian's liability for data security failures, with the Special Claims cap creating a specific recovery ceiling for unauthorized Customer Data d…
This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibil…
This provision establishes that KYC service outputs cannot be used as a basis for FCRA adverse action decisions, which means Customer cannot use identity verification results to deny credit, employme…
This provision requires Customer to pay remaining term fees even in circumstances where termination is triggered by external regulatory or network events outside Customer's control, such as Issuer wi…
This provision establishes a contractual liability ceiling tied to Marqeta's revenue rather than Customer's potential losses, and imposes a one-year contractual limitations period on all breach claim…
This provision authorizes Marqeta to apply funds from Customer's Custodial Account against outstanding Customer liabilities on a continuous basis without requiring a separate triggering event or cour…
This provision requires Customer to absorb financial and legal exposure arising not only from its own conduct but also from the acts or omissions of its customers, Retail Partners, and Lending Bank i…
This provision establishes that Meta's AI systems are authorized to perform actions on behalf of users and to process content and messages exchanged with AI features, with that interaction data used …
This provision establishes that the safety assurances described in the model card apply to the base model as released by Meta, and that deploying organizations must independently conduct safety evalu…
This provision establishes that ad personalization using off-platform behavioral data applies to individuals regardless of whether they have a Meta account or are logged in at the time of data collec…
This provision establishes that special category data as defined under GDPR and analogous frameworks may be processed for product personalization and analytics where users choose to provide it or giv…
This provision establishes that user-generated public content is within scope for AI model training and development, including for third parties beyond Meta's own products. The operational scope of t…
This provision establishes that data collected on one Meta platform, such as Facebook or Instagram, may be combined with data from other Meta Companies such as WhatsApp, for personalization, advertis…
This provision establishes Microsoft's procedural obligations regarding AI system design and evaluation. It creates an operational framework requiring bias identification and mitigation activities du…
This provision establishes an operational requirement that human review and decision authority remain embedded in AI system workflows for high-risk applications. The commitment creates a structural c…
This provision establishes a broad authorization for AI training as a secondary use of personal data collected across Microsoft's consumer product portfolio, which may require evaluation under GDPR l…
This provision establishes Microsoft's authorization to collect and process biometric identifiers, a category of sensitive personal data subject to heightened regulatory requirements including Illino…
This provision establishes that user data collected across Microsoft's product ecosystem is shared with multiple named external advertising entities, and the breadth of this sharing may require evalu…
The provision establishes a dual consent framework for Memory feature operation: general service personalization proceeds under legitimate interest, while storage of sensitive health information requ…
This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational …
This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining th…
This provision establishes a categorical prohibition on weapons-related use cases across all OpenAI products and services. The explicit inclusion of CBRNE weapons alongside conventional weapons refle…
This provision establishes a categorical prohibition on using OpenAI services for weapons-related purposes including CBRNE, which is operationally significant for defense contractors, research instit…
This routing mechanism creates a bifurcated terms structure, with EU-jurisdiction users operating under distinct contractual provisions designed to address regional legal requirements. The provision …
This provision discloses OpenAI's active reporting practice to NCMEC, which is consistent with obligations established under US federal law for electronic service providers that obtain apparent CSAM.…
This provision prohibits emotion inference in workplace and educational contexts and criminal risk prediction based on personal traits, both of which are among the prohibited AI practices enumerated …
This provision establishes a categorical prohibition on a class of AI applications that regulatory frameworks including the EU AI Act designate as prohibited practices, creating a policy-level alignm…
This provision discloses an active reporting practice: OpenAI states it reports apparent CSAM and child endangerment to NCMEC, which is consistent with obligations under federal law for electronic se…
This provision imposes a human-in-the-loop requirement for a broad set of consequential decision domains, which is operationally significant for enterprise and API customers building automated decisi…
This provision requires that any deployment of OpenAI services involving automated decisions in the named sensitive domains include human review as a condition of permitted use. Organizations integra…
This provision creates opt-out obligations under CCPA, the California Privacy Rights Act, and analogous statutes in the approximately eighteen additional states named in the policy, and the explicit …
This provision places responsibility for verifying AI-generated outputs on users and discloses the risk of hallucinations and inaccuracies in AI content. In a health insurance context where AI featur…
This provision requires disputes to proceed through individual arbitration administered by JAMS in New York, New York, and includes an explicit waiver of jury trial and class action participation. Th…
This provision asserts that Oscar owns derivative AI assets, specifically vectorized data and model relationship information, developed from User Submissions. This assertion of ownership over AI-deri…
This provision establishes a $100 ceiling on all financial claims against Oura that survive the broader damages exclusion, covering a health-monitoring wearable that collects physiological and biomet…
This provision requires that disputes proceed through individual arbitration rather than court litigation, and prohibits class or representative actions. The provision includes a self-referential cla…
This provision requires customers to prospectively waive all IP-related claims arising from AI-generated output, including direct and indirect infringement claims. For organizations deploying AI outp…
This provision grants PlanetScale unilateral suspension authority triggered by subjective determinations including 'may subject PlanetScale to third party liability' and 'suspected unauthorized acces…
This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categor…
These provisions impose use-case specific restrictions that go beyond Replicate's own acceptable use policy, including prohibitions on competitive product development using model outputs, surveillanc…
This provision requires disputes to proceed through individual arbitration before a sole arbitrator whose decision is final subject to limited FAA review, and prohibits users from participating in cl…
This provision requires customers to assume defense costs and liability for a broad range of claims arising from their use of the platform, including claims arising from AI-generated outputs and thir…
This provision establishes that the act of publishing a community model on the platform creates a permanent, non-revocable license running to all platform users, which the publisher cannot subsequent…
This provision sets an exceptionally low monetary ceiling on recoverable damages from Replicate, including for claims involving data loss, security breach, service interruption, and breach of contrac…
This provision asserts contractual limitations on customers' ability to dispute charges through external mechanisms including card network chargebacks, and places the burden of proof on the customer …
This clause authorizes re-hypothecation for amounts potentially exceeding the customer's debit balance, which means third parties may hold customer securities as collateral in amounts beyond the cust…
This provision grants Robinhood discretion to liquidate account assets without prior notice across a broad set of triggering circumstances, including margin deficiency, ACH reversal, bankruptcy filin…
This provision discloses that API product use authorizes disclosure of account credentials, financial information, and trade data to third-party API licensees, with an explicit acknowledgment that th…
This clause establishes that the security interest applies broadly across all present and future accounts, including accounts in which the customer has an interest, not solely the margin account gene…
This clause establishes that disputes arising from margin account activities are subject to mandatory predispute arbitration as set out in the incorporated Customer Agreement, requiring customers to …
This provision allocates full financial responsibility for AI agent-generated orders to the customer, including orders resulting from agent malfunctions or unintended outputs, and establishes that Ro…
This provision establishes a broad contractual right of offset that extends beyond the Robinhood brokerage account to external bank accounts and accounts held with Robinhood affiliates, exercisable w…
This clause establishes that Robinhood's discretionary liquidation authority applies across all customer accounts without a preceding notice or demand requirement, and that the customer has contractu…
This provision requires customers to acknowledge the existence of a predispute arbitration clause at the time of account opening, which under applicable FINRA and SEC frameworks governs the forum and…
This provision establishes the legal basis under which Roblox asserts that users cannot claim monetary compensation or legal title to virtual items or Robux, including in the event of account suspens…
This provision requires that unresolved disputes between U.S. users and Roblox proceed through individual arbitration administered under AAA Consumer Arbitration Rules, rather than through state or f…
This provision addresses the use of AI generation tools to produce NCII, an area of active state and federal legislative development in the United States and under the EU AI Act framework; the prohib…
This provision engages right-of-publicity law, GDPR Article 9 (where biometric data is implicated), and state biometric privacy statutes (including Illinois BIPA) by prohibiting the input or generati…
This provision establishes a mandatory reporting and indefinite suspension mechanism that engages U.S. federal CSAM reporting obligations applicable to electronic service providers; it also operates …
This provision discloses that third-party social media cookies embedded in Spotify's web properties are capable of cross-site browser tracking and interest profiling, with downstream effects on conte…
This provision creates a two-tier dispute resolution framework: users who have executed the Advisory Agreement are subject to mandatory arbitration as defined in that separate document, while users w…
This provision restricts a specific category of potentially harmful synthetic media use involving the attribution of sensitive personal characteristics including medical conditions, disabilities, and…
This provision restricts a category of high-risk synthetic media deployment involving political, journalistic, and public interest content, and establishes a consent-gated framework that differentiat…
This provision conditions the applicability of the DPA's processor obligations and protections on formal execution, meaning organizations that have not completed this step may not have a compliant Ar…
This provision establishes that account termination for code of conduct violations may result in ticket cancellation without refund, and that Ticketmaster may take enforcement action against accounts…
This provision establishes a monetary ceiling on all claims against Ticketmaster and Live Nation, including claims arising from ticket purchases, marketplace use, and event attendance, and asserts a …
This provision authorizes cross-site behavioral tracking and targeted advertising on digital properties through which users may also access health plan information, benefit details, and medical recor…
This provision requires evaluation under the HIPAA Security Rule and Breach Notification Rule, which establish standards for the protection of electronic Protected Health Information in transmission.…
This provision establishes a unilateral change mechanism under which the data practices governing health, financial, and behavioral information may be altered without advance individual notification,…
This provision establishes a permanent, royalty-free IP assignment covering any content, ideas, or know-how submitted through the site, with no carve-out for proprietary or commercially sensitive sub…
This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreem…
This clause establishes that ActiveCampaign conducts ongoing automated monitoring of both customer-side activity and recipient-side engagement data, with unilateral authority to remove content and in…
This clause establishes that continued use of the platform following any form of notice constitutes binding acceptance of revised terms, including changes that could alter permitted use categories, r…
This provision establishes that use of purchased or rented contact lists through the platform constitutes a policy violation, which could trigger account suspension under the general enforcement prov…
This clause establishes eligibility criteria for platform access that are not defined by objective thresholds, granting ActiveCampaign unilateral authority to restrict or terminate service to custome…
This provision places affirmative opt-in verification obligations on customers, aligning with TCPA, CAN-SPAM, and CASL requirements, and establishes that failure to comply exposes customers to accoun…
This provision establishes the operational authority and standards under which the carrier may exercise passenger denial or removal authority. It codifies the carrier's discretionary gatekeeping func…
This clause operationalizes federal accessibility requirements by explicitly binding the carrier to statutory compliance standards and establishing a service obligation framework. It clarifies the re…
This provision discloses that Anthropic's adherence to its own stated RSP requirements has not been complete, with specific procedural gaps identified in evaluation timelines, methodology, and buffer…
This provision discloses the categories of training data sources and the operational practices of Anthropic's web crawler, which are relevant to copyright, data rights, and consent considerations tha…
This provision is a material disclosure of known limitations in the model's safety architecture, which is operationally significant for any operator making safety representations to their own users b…
This provision provides documented evidence that Anthropic conducted structured pre-deployment safety evaluations for catastrophic risk scenarios, which is operationally relevant to enterprise custom…
This provision discloses Anthropic's internal governance mechanism for frontier AI risk management, which is operationally relevant to enterprise customers and regulators assessing whether the model …
This provision establishes a non-negotiable safety floor across all deployment contexts, meaning operators building products on the Claude API cannot contractually or technically override these restr…
This provision establishes that the operational scope of permitted and prohibited uses of Opus 4.8 is governed by a separate Usage Policy document, meaning the system card alone does not constitute a…
This provision discloses that Anthropic conducts and publishes model welfare assessments, including evaluations of functional emotional states, task preferences, and the model's expressed attitudes t…
This provision establishes a gatekeeping mechanism for adjusted safeguard access, requiring partners to satisfy Anthropic's assessment of trustworthiness and use-case benefit before receiving modifie…
This provision establishes an internal whistleblower mechanism specific to RSP compliance, with anti-retaliation protections, providing a formal channel through which employees can raise concerns abo…
This provision establishes the core operational trigger mechanism of the RSP: internally defined capability benchmarks that create mandatory internal obligations for Anthropic to upgrade safeguards a…
The revised CB-2 threshold introduces greater operational specificity into the definition of what constitutes a threshold-crossing capability, which affects how future model assessments are conducted…
This provision describes the technical architecture through which Anthropic monitors and filters user interactions with its models at ASL-3 capability levels, establishing that both real-time and asy…
This provision establishes a structural check on Anthropic's unilateral control over its own safety audit process by vesting reviewer selection approval authority in the LTBT, an entity distinct from…
This provision defines the operational permission architecture that governs what Claude will and will not do in any given deployment, making it the primary mechanism by which operators customize mode…
This provision describes the access control architecture for model weights as a core ASL-3 security requirement, establishing procedural controls including multi-party authorization and hardware auth…
This provision allocates tax compliance responsibility to Customer and implements a gross-up mechanism to protect Anthropic's net revenue. The gross-up calculation compounds by including taxes on the…
This provision discloses a third-party data routing pathway that is activated when users enable the ChatGPT extension, with data handling for those requests governed by OpenAI's terms rather than App…
This provision establishes Apple's stated architectural data handling commitment for server-side AI processing, asserting a no-retention and no-access design for Private Cloud Compute. The operationa…
This provision establishes the formal subprocessor register that Atlassian is contractually and regulatorily required to maintain under its DPA and GDPR Article 28. Enterprise customers rely on this …
This provision establishes the operational mechanism for GDPR Article 28(2) compliance, requiring Atlassian to provide prior notice of subprocessor changes and permitting customers to object to new s…
This provision is operationally significant for EU, UK, and Australian customers because it establishes that personal data may be transferred to and processed in the United States, requiring valid tr…
This provision is operationally significant because AI-related subprocessors may process customer content data, not merely metadata, which creates additional considerations under GDPR's requirements …
This clause reserves Bank of America's right to adjust variable interest rates on deposit accounts without prior notice and without a stated limit on the size of the adjustment, which is the operativ…
This provision establishes a contractual restriction on the sources of funds that can be deposited into the SafeBalance for Family Banking account, including blocking employer direct deposits, ACH tr…
This provision authorizes reporting of detailed account default and closure information, including Social Security Number or Tax Identification Number, to specialty consumer reporting agencies whose …
This provision obtains consent to automated and prerecorded contact through the act of providing a telephone number, which is operationally significant for Telephone Consumer Protection Act complianc…
This provision restructures the fee waiver eligibility criteria for monthly maintenance fees, ATM fees, overdraft item fees, wire transfer fees, stop payment fees, international transaction fees, and…
This clause assigns full liability to the parent for all child transactions on the account and authorizes Bank of America to treat the child's actions as legally equivalent to the parent's actions, w…
This provision reserves the bank's right to adjust variable interest rates on deposit accounts without advance notice and without any stated floor or ceiling on rate changes, meaning account holders …
This provision reserves Bank of America's right to unilaterally alter the terms governing all personal deposit accounts covered by this schedule at any time; the applicable regulatory notice requirem…
This provision defines the conditions under which overdraft fees are assessed and the specific exceptions that apply, which directly governs the financial exposure of account holders who maintain acc…
The Right of Set Off provision, referenced throughout the agreement in connection with joint accounts, POD accounts, and overdrafts, authorizes the bank to apply deposit account funds to satisfy debt…
This provision obtains a standing authorization to obtain consumer reports and employment verification for a broad set of stated purposes including the open-ended category of 'any other lawful purpos…
This provision discloses that the total cost of international wire transfers includes not only the stated wire transfer fees but also an undisclosed markup embedded in the exchange rate, and that the…
This provision establishes a sixty-day advance written notice requirement to prevent automatic renewal, which creates a contract management trigger for enterprise procurement calendars managing annua…
This provision establishes a fixed twenty-day data retrieval window post-termination, after which Customer Content is destroyed, requiring Customer organizations to operationalize data extraction bef…
This provision establishes that Baseten may suspend access to production ML deployments for overdue payments, which may affect Customer's operational continuity and downstream End User services if bi…
This provision places defense and indemnification obligations on Customer for claims arising from alleged warranty breaches, including claims based on the allegation of a breach even where no actual …
This provision establishes the operational mechanism through which GDPR Article 28 sub-processor approval obligations are managed, and limits Customer's recourse upon unresolvable sub-processor objec…
This provision establishes that Customer organizations have no mechanism to withdraw or restrict Baseten's use of feedback once submitted, and that Baseten may sublicense such feedback, which may hav…
This provision establishes that Baseten holds ownership rights over a category of data derived from Customer platform activity, which may have implications for Customer data governance policies and c…
This provision establishes the operational basis for Bumble's content moderation infrastructure and investigation procedures. It clarifies that message collection and automated scanning are integral …
Contractually shortened statutes of limitations in consumer financial services agreements are subject to enforceability challenges in certain jurisdictions, particularly where state law establishes m…
This provision establishes that Chase retains unilateral discretion over the foreign exchange rate applied to international wire transfers, and that the rate includes a commission component, which is…
This provision defines the primary fee trigger and waiver mechanism for overdraft charges across eligible Chase personal checking accounts. The $50 threshold and next-business-day cure window are ope…
The collection and retention of biometric data (selfie) and government-issued identity document images during trusted device enrollment implicates state biometric privacy statutes including the Illin…
This provision establishes that early CD withdrawals result in penalties that may reduce principal if accrued interest is insufficient to cover the penalty amount, with the penalty magnitude increasi…
The unilateral closure right without prior notice is a standard term in retail banking agreements but has operational significance for customers who rely on the account for direct deposits, automated…
This provision implements the Regulation E affirmative opt-in requirement for overdraft fees on everyday debit card transactions. The default opt-out position means that without affirmative election,…
The authorization to apply Social Security and federal benefit payment deposits to overdraft repayment intersects with federal protections under 31 C.F.R. Part 212, which governs the treatment of cer…
This provision requires individual arbitration for dispute resolution and forecloses class action participation, which are standard but material terms in consumer financial services agreements. The C…
The scope of disclosure permitted under the Privacy Notice category is not defined within the agreement itself and requires reference to the separate Privacy Notice incorporated into the document. Th…
This provision creates a unilateral enrollment and cancellation right for any individual co-owner on joint accounts, which means one co-owner can modify the overdraft protection status of a shared ac…
This provision identifies the categories of third-party recipients of personal data and notably includes advertising networks and background screening companies among the service provider categories,…
This provision establishes the operative mechanism for individuals to exercise data subject rights and qualifies the scope of those rights by jurisdiction and by Checkout's legal retention obligation…
This provision establishes an operative opt-out right for California residents under CPRA for cross-context behavioral advertising, which is a distinct mechanism from a sale opt-out, and the notice s…
This provision establishes the legal transfer mechanisms Checkout relies on for cross-border data flows from the UK and EEA, and discloses that transfer impact assessments are conducted, which are op…
This provision establishes a secondary automated biometric processing mechanism, distinct from the primary identity verification function, that may impose a temporary service access block on individu…
This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has di…
This provision reserves to Kit open-ended enforcement authority over content that does not fall within enumerated prohibited categories, based on an undefined standard of 'potentially harmful or misl…
This provision establishes that accounts operating in enumerated industry categories do not have guaranteed platform eligibility and are subject to individual assessment, creating operational uncerta…
This provision establishes that list collection methodology is a condition of platform access, and that accounts using non-permission-based lists are subject to immediate termination without refund o…
This provision establishes that ongoing platform access is contingent on maintaining acceptable email performance metrics as assessed by Kit, with termination consequences and no data portability ent…
This provision establishes a platform-level permission standard that requires documented proof of consent for each subscriber, and limits purchase-based consent to a 12-month window, creating an ongo…
This provision establishes the mechanism and conditions under which the contractual relationship between Cursor and users may be altered. It allocates to Cursor the authority to change material terms…
This provision references specific remediation timeline commitments as a contractual obligation, but the actual timelines are not disclosed in this public document and must be reviewed in the Securit…
This provision discloses that Databricks' internal security monitoring operations run on the same platform sold to customers, processing security signals from systems that may include customer-adjace…
This provision discloses that employee access to customer data is subject to internal controls, but the document does not specify the mechanisms, such as role-based access control, audit logging, or …
This provision establishes that the enforceable security obligations are located in the Security Addendum of the customer agreement rather than in the public Trust Center disclosure, making the Adden…
This provision distinguishes between certifications Databricks holds as an organization and compliance frameworks for which it offers specific product configurations, a distinction that is operationa…
This provision establishes a data sharing mechanism that extends beyond Disney's own platforms to third-party advertising ecosystems, using identifiers and hashed email addresses as linkage data. Und…
This provision establishes a dual-role access structure across a portfolio of more than 40 named brands, under which each subsidiary entity may use personal information for its own independent data c…
The collection of video and still images at physical properties engages biometric privacy frameworks in jurisdictions such as Illinois (BIPA), Texas, and Washington, depending on whether collected im…
This provision discloses that personal and viewing information shared with Hulu's business partners exits the scope of this privacy policy and becomes subject to each partner's own privacy practices.…
This provision requires users to make affirmative representations regarding their sanctions status and affiliations at the point of purchase or use, and prohibits downstream re-export to embargoed re…
This provision permits Anker to assign the entire agreement, including all rights and obligations, to a third party without user notification or consent. This means users' contractual relationship co…
This provision establishes that account creation and mobile number provision each independently constitute affirmative consent to receive marketing communications across all Anker brands, with opt-ou…
This provision authorizes account termination for any reason without prior notice, which may affect access to purchased products' cloud-connected features, stored data, and active services. The autom…
This provision allocates full verification responsibility and reliance risk to the user for all AI-generated outputs across text, image, and audio modalities, and disclaims Anker's liability for any …
The irrevocable and sublicensable nature of this license means that once content is submitted, the agreement does not provide a mechanism for users to revoke Anker's right to use that content in conn…
This provision authorizes Anker to unilaterally modify device and app functionality through mandatory updates on terms defined solely by Anker, including the criteria for what constitutes a critical …
This provision establishes the scope and mechanism of consumer opt-out rights, including the specific clarification that profiling for legal or significant effects is not offered as an opt-out option…
This provision establishes that GPC-based opt-outs operate at the browser identifier level and do not automatically extend to a consumer's full Experian account or other personal information records …
This provision establishes a geographic differentiation in Experian's sensitive personal information collection practices, with consumers in seventeen named states excluded from the collection and sa…
This provision establishes a categorical exclusion of all damage categories, including those arising from negligence or tortious action, which represents the broadest possible liability shield availa…
This provision disclaims all warranties covering the accuracy and reliability of information presented on the site, which has operational significance for users who access credit-related information …
This provision establishes a unilateral modification mechanism that requires no affirmative user notification beyond a site posting and deems continued use as contractual acceptance, which has known …
This provision acknowledges the use of traffic analysis technology on experian.com but does not specify the types of data collected, the technologies used, or any retention or sharing practices at th…
This provision establishes a dual-role framework under which Experian may operate as either a data controller or a processor depending on the context, and directs consumers to the relevant business c…
This provision establishes that retention periods are not fixed and may vary by data category, product, and purpose, without specifying maximum retention durations. The absence of stated retention ti…
This provision grants GM unrestricted discretion to terminate accounts and delete content without prior notice, and imposes a permanent ban on new account creation following termination. The absence …
This provision establishes a broad license that extends beyond operating the Web site to encompass GM's general business, promotional activity, and redistribution through any media channel. The licen…
This provision requires users to bear financial responsibility for defending GM against third-party claims that arise from user conduct or content, including attorney's fees. The obligation survives …
This provision requires users in all U.S. states and internationally to pursue claims against GM in New York courts under New York law, which may create a practical barrier for users located outside …
This provision distinguishes the treatment of User Comments from User Videos: while the video license terminates within a commercially reasonable time after removal, the comment license has no termin…
This provision establishes that GM may modify material terms without prior notification and that continued site use operates as acceptance of changes. Users bear the responsibility of independently m…
This provision disclaims liability for unauthorized access to personal and financial information stored on GM's servers, as well as for personal injury and property damage arising from use of the Web…
Organizations with Copilot Business or Enterprise subscriptions renewing on or after 5 March 2026 are subject to different governing terms, requiring a contract transition review to assess whether ma…
This provision establishes that GitHub contractually allocates all responsibility for Suggestion-related outcomes to the user, including potential third-party intellectual property claims. Organizati…
This provision establishes the contractual ownership position as between GitHub and the user for AI-generated output. However, the agreement does not address ownership questions that may arise under …
This provision establishes the default data lifecycle for Prompt data and defines the conditions under which retention is triggered. Enterprise organizations with source code confidentiality requirem…
This provision incorporates three external policy documents by reference, including a Microsoft policy, creating a multi-document compliance obligation. The Required Mitigations at aka.ms/AIfilters e…
This provision establishes that a data processing agreement under the Google Ads Data Processing Terms governs applicable GTM deployments, which is operationally significant for GDPR Article 28 compl…
This provision establishes that the operative terms governing GTM use are distributed across at least three external documents, each subject to unilateral modification, meaning the full scope of user…
This provision discloses that Google collects operational and tag deployment data from GTM users, but includes a specific limitation that this data will not be shared with other Google products witho…
The provision creates a bifurcated update framework: user-configurable updates for routine content changes, and automatically-applied updates when Google determines a critical security, operability, …
The clause operationalizes a unilateral amendment mechanism whereby Google can alter the governing terms with advance notice, and automatically apply those modifications retroactively to a user's ent…
This provision establishes an explicit prohibition on autonomous lethal weapon applications, requiring human authorization or control as a precondition for any weapons-related use, which directly eng…
This provision grants Groq the contractual right to request use-case and compliance information from Customers at any time, which may require Customers to disclose operational details about their AI …
This provision extends Customer compliance obligations to third parties accessing Groq services through the Customer, creating a due diligence responsibility for API operators and platform developers…
This provision establishes that prompt engineering or other technical methods used to elicit policy-violating outputs from Groq models constitutes a policy violation, extending acceptable use obligat…
This provision establishes that Groq retains discretionary authority to investigate Customer conduct and take enforcement action based on suspected rather than confirmed violations, without specifyin…
This provision establishes a structural bifurcation of data controller and data processor responsibilities that directly determines the path for data subject rights requests. End users whose employer…
This provision establishes procedural constraints on Harvey's unilateral modification authority and creates a contractual termination right tied to adverse term changes. The absolute restriction on u…
This provision creates an operational CCPA compliance obligation requiring a functioning opt-out mechanism for targeted advertising data flows. The terms authorize disclosure of website visitor Perso…
DPF certification establishes the legal transfer mechanism for Personal Data flowing from the EU, UK, and Switzerland to Harvey's US servers, and the provision states that DPF Principles override con…
This provision authorizes disclosure of Personal Data to third-party counterparties during due diligence processes before any transaction is completed. The notification commitment is stated but does …
This provision establishes an explicit contractual prohibition on AI model training from customer inputs and outputs, and extends that restriction to Subprocessors. The carve-out for cloud storage pr…
This provision requires disputes to proceed through private arbitration under specified institutional rules, with the seat and governing rules varying by customer geography. The threshold of $250,000…
This provision establishes the maximum recoverable damages under the agreement for most claim types and sets a distinct higher threshold for data breach and confidentiality-related claims. Compliance…
This provision allocates third-party claim risk between the parties based on the source of the allegedly infringing or harmful content. The customer's indemnification obligation for claims arising fr…
This provision establishes a 30-day deadline for disputing invoices and authorizes Harvey to assess compounding interest on overdue undisputed amounts and to suspend Service access for nonpayment. Th…
This provision establishes that Harvey collects Personal Data about individuals who have not directly interacted with Harvey, sourced from third-party marketing vendors, research firms, and event org…
This provision authorizes Contentsquare to charge overage fees at its then-applicable rate when usage thresholds are exceeded, invoiced annually in arrears. Customers may accumulate significant overa…
This provision establishes a mutual 12-month fee-based liability cap and a broad exclusion of consequential and indirect damages. The carve-outs for gross negligence and willful misconduct are mutual…
Deemed execution of the DPA and SCCs at MSA signing means the parties are contractually bound by those documents without separate signature, and the DPA terms are subject to unilateral update by Cont…
This provision establishes a 90-day advance written notice requirement to prevent automatic renewal, which applies at the end of both the Initial Term and each subsequent Renewal Term. Enterprise cus…
This provision grants a data use license that is perpetual and survives contract termination, covering anonymized Customer Data and Usage Data for machine learning model training, benchmarking, produ…
This provision establishes that executed Order Forms create irrevocable payment commitments for the full term, absent specific Order Form carve-outs. The annual CPI-indexed fee adjustment mechanism m…
The indemnification obligation for the nature, origin, or content of Customer Data is broad and applies to any third-party claim connected to that data, including privacy and data protection claims a…
The refund mechanism for Customer-initiated termination for cause is conditioned on the termination being both proper and undisputed, which introduces a potential dispute resolution dependency before…
This provision explicitly includes AI prompts, feedback, and voice submissions within the content license scope, and expressly authorizes use of that content for developing and evaluating machine-lea…
This provision establishes that users bear full legal responsibility for automated systems and AI agents acting on their behalf, including sub-agents and downstream processes, and requires technical …
This provision extends the prohibition on AI training to open-source and non-commercial research purposes, which is a notably broad restriction relative to terms that limit prohibitions to commercial…
This provision authorizes Instacart to charge any active payment method on file at renewal, including updated card information provided by card issuers through card-updater services, without requirin…
This provision extends indemnification obligations to actions taken by AI agents operating on the user's behalf, to disputes with third-party retailers and delivery providers, and to the user's downs…
The provision expressly discloses that automated messages may be delivered outside quiet hours defined by federal, state, or local law, which engages the Telephone Consumer Protection Act (TCPA) and …
This provision establishes that EEA residents are subject to a distinct contractual framework, which must be evaluated separately to determine whether it satisfies GDPR and related EEA regulatory req…
This provision determines that the Global Terms of Service govern the contractual relationship for the majority of Kraken users worldwide, including US users; the substantive obligations, data handli…
This provision establishes that Canadian users are subject to a distinct contractual framework that must be reviewed separately to assess compliance with Canadian financial services, AML, and privacy…
This provision establishes that Brazilian users are subject to a distinct contractual framework that must be reviewed separately to assess compliance with the Lei Geral de Proteção de Dados and appli…
This provision establishes the contractual architecture through which Kraken assigns different operative terms, including data handling, dispute resolution, and liability provisions, to different use…
This provision establishes that users are bound by updated terms immediately upon posting, without affirmative notice or a waiting period, and that continued site use operates as consent to any modif…
This provision requires users outside Ohio to litigate any claims in Montgomery County, Ohio, which may create a practical barrier to pursuing legal claims depending on the user's location and the na…
This provision places full responsibility on users to identify and withhold HIPAA and HITECH-covered information before posting, and does not establish any technical or administrative safeguards by P…
This provision authorizes disclosure of a defined set of user data categories including IP addresses, usage history, and posted materials to law enforcement and unspecified third parties based on Pro…
This provision requires users to bear the full cost of defending Provider and its third-party information providers against any claims arising from user-submitted content or Terms of Use violations, …
This provision is operationally significant for a legal information platform because it establishes that content, including content provided by attorneys in Interactive Areas, carries no confidential…
This provision requires that all disputes be litigated in Delaware courts under Delaware law, and establishes a mutual jury trial waiver applicable to any action arising from or related to the Agreem…
This provision establishes a unilateral amendment mechanism that does not require affirmative Customer re-acceptance; continued use of the Service after the 30-day notice period constitutes acceptanc…
This provision establishes that fees paid under an active Order are non-refundable except in the specific termination-for-cause scenario described in Section 5.3, and that recurring billing proceeds …
This provision establishes Linear's unrestricted right to use Service Data once aggregated and anonymized, and asserts Linear's ownership of that data. The practical scope of this right depends on th…
This provision establishes that data deletion following termination is not automatic but is triggered by Customer request or workspace deletion, and is subject to a 30-day processing period. Customer…
This provision establishes a mutual liability cap tied to 12 months of fees paid, which may be substantially lower than the value of data or business operations at risk in the event of a service fail…
This provision grants LlamaIndex broad discretion to terminate or suspend access without notice, cause, or liability, which may affect organizational users who depend on the Service for operational w…
This provision authorizes disclosure of individual user activity data to employers without specifying what categories of usage data may be shared or what notice, if any, is provided to the individual…
The policy does not specify fixed retention periods for any personal data category, applying instead a general reasonableness standard with open-ended extensions for legal and business purposes, whic…
This provision authorizes cross-context behavioral advertising using persistent identifiers shared with third-party ad networks, enabling user tracking across nonaffiliated websites and services beyo…
This provision establishes a usage-triggered automatic billing cycle on a weekly basis, meaning charges can be incurred without a separate affirmative enrollment action each billing period once the t…
This provision operates as a present-tense IP assignment: upon submission of any feedback, all intellectual property rights in that feedback transfer to LlamaIndex. The clause covers not only direct …
This provision asserts that LlamaIndex holds exclusive ownership over Usage Data collected from user systems and software interactions, and authorizes its use for any lawful purpose including product…
This provision establishes a structural limitation on the scope of data subject rights exercisable directly against LlamaIndex, creating a dependency on enterprise customers' own privacy notices and …
This provision authorizes disclosure of personal data to prospective acquirers or creditors during deal negotiations and in insolvency proceedings, which may occur before any transaction is finalized…
This provision creates a broad user-side indemnification obligation covering not only intentional violations but also third-party use of the user's account credentials, which may include unauthorized…
This provision authorizes LlamaIndex to create derived data profiles about users beyond the information directly collected, which may be used for targeted advertising, personalization, or other purpo…
This provision establishes Atlassian's obligation to defend and indemnify the Customer for IP infringement claims arising from authorized product use, while identifying four categories of use that re…
This provision establishes that non-payment with ten days written notice is sufficient to trigger suspension of all Product access and Support, creating a direct operational risk for organizations th…
This provision authorizes recurring charges to a stored payment method across multiple billing events, including scope-of-use overages that may not be individually pre-approved by Customer, creating …
This provision determines the legal framework under which disputes are resolved and the forum in which litigation must occur, with direct implications for the cost and procedural context of any dispu…
This provision permits Atlassian to modify the Agreement, including the DPA governing Customer Data processing, mid-term for paid subscriptions where legal compliance or product changes are cited, wi…
This provision establishes an automatic renewal obligation at rates that may differ from the original Order price, creating a billing exposure if Customer fails to provide timely non-renewal notice b…
This provision grants a broad set of parties, including Marqeta's third-party designees, audit access to Customer's business practices and compliance records for the duration of the agreement and at …
This provision authorizes Marqeta to alter operational, pricing-adjacent, and service-related terms with 30 days' notice without Customer's consent, while protecting a defined set of core legal provi…
This provision establishes that Customer feedback, enhancement requests, and recommendations become Marqeta's exclusive intellectual property. Customer's license to use the system and deliverables is…
This provision permits Marqeta to commercially use and disclose pseudonymized transaction and cardholder data derived from Customer's program at a population level. While Customer's identity is prote…
The explicit reference to logging text entered during sessions is operationally distinct relative to commonly observed tracking disclosures and may encompass form field content entered before submiss…
The use of data providers and aggregators to supplement first-party data collection is a practice that may require evaluation under applicable law, particularly regarding notice and consent obligatio…
This provision establishes Alameda County, California as the exclusive litigation forum for all disputes and eliminates jury trial rights for both parties. Business customers located outside Californ…
This provision requires Marqeta to maintain a compliant CCPA opt-out mechanism for California residents and to honor Global Privacy Control signals as an opt-out preference signal, with the Californi…
This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of th…
This provision establishes that individuals whose personal data is processed through Marqeta's payment and card program infrastructure are subject to different and separately published privacy terms,…
This provision establishes that a broad range of user data, including content, messages, metadata, device identifiers, and transaction information, may be accessed and shared with law enforcement and…
This provision establishes that Meta may incorporate user identity signals including name and profile photo into commercial advertising displays without user compensation. The practical scope is limi…
This provision establishes that Meta's ad personalization infrastructure extends to third-party apps that participate in Meta Audience Network, using stored user profile and activity data to target a…
This provision establishes the operational timeline and conditions under which user content is retained after a deletion request. The retention carve-outs for legal obligations, safety, technical lim…
This provision establishes a two-tier dispute resolution framework: consumer disputes are subject to the user's local law and courts, while business and non-consumer disputes are exclusively assigned…
This provision discloses that identifiable categories of user-generated content and AI interaction logs from Meta's consumer platforms were incorporated into model pretraining. Organizations deployin…
This provision establishes the contractual framework within which commercial and research use of Llama 4 is permitted, and incorporates by reference both the Acceptable Use Policy and the Llama 4 Com…
This provision establishes that the model's safety design assumes the presence of additional system-level guardrails, meaning deployments that omit these tools operate outside the safety architecture…
This provision establishes the legal basis under which Meta processes, distributes, and modifies user-generated content across its platform and with service providers. The license is transferable and…
This provision creates a layered contractual structure in which supplemental terms are automatically incorporated based on product usage, with those terms superseding the base agreement in cases of c…
This provision establishes the foundational commercial model of the agreement: free service access in exchange for personalized advertising consent. The terms authorize use of personal data including…
This provision creates an explicit responsibility boundary: Meta's safety evaluations cover 12 languages and up to 5 input images, and any deployment extending beyond those parameters operates withou…
The governance structure operationalizes Microsoft's responsible AI commitments through defined accountability assignments, systematic review procedures, and regulatory reporting mechanisms. This est…
This provision establishes that voice data, a category that may constitute biometric information under some state laws and a sensitive personal data category under others, is collected across multipl…
This provision establishes that a persistent identifier enabling cross-app tracking is generated by default in Windows and made available to third-party developers and advertising networks, which may…
This provision establishes the legal mechanism Microsoft relies on for transfers of personal data from the EU, UK, and Switzerland to the United States, and defines Microsoft's liability posture for …
This provision establishes a hierarchy of contractual terms that is directly relevant to enterprise customers assessing their privacy and data protection posture under Microsoft contracts, and determ…
This provision establishes that users of preview and free products operate under a materially different data collection and privacy control environment compared to standard Microsoft products, which …
This provision discloses a data enrichment practice that may implicate state data broker registration laws, GDPR transparency requirements regarding data sourced from third parties, and CCPA notice o…
This scope exclusion establishes that the Privacy Policy's protections and obligations apply only to non-business use cases. For commercial users processing personal data, the data controller-process…
The clause operationalizes a specific legal mechanism under data protection frameworks that permits data processing for product improvement and feature development without requiring explicit user con…
This provision establishes a processor-to-controller breach notification timeline of 48 hours, which is shorter than the GDPR's 72-hour controller-to-supervisory-authority window, providing Customer …
The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insu…
The provision establishes that policy changes become effective immediately upon posting without advance notice, email notification, or a defined review period, which may be inconsistent with GDPR req…
This provision establishes a mutual cap on aggregate liability equal to 12 months of fees under the applicable Service Order and excludes recovery of consequential and indirect damages by either part…
This provision establishes that any suggestions, comments, or other feedback submitted by Customer to Modal are subject to a broad, perpetual, and irrevocable license that cannot be withdrawn, and th…
This provision establishes a contractual prohibition on AI model training using Customer Data as a default, requiring affirmative written consent before any such use. Because Input and Output are cla…
This provision establishes that Customer cannot block a new subprocessor appointment without exiting the service entirely, and that email notification of subprocessor changes requires Customer to aff…
This provision establishes a post-termination data retention and use right for Modal covering aggregate and anonymized usage data, which operates as an exception to the general data deletion obligati…
The provision does not identify the third parties receiving personal data, does not describe the contractual mechanism through which the stated obligation is enforced, and does not specify which cate…
This provision establishes that Customers are financially obligated for the full committed service term and amount regardless of whether they use the Service, creating a fixed cost exposure that does…
This provision establishes that Customer bears the full defense and indemnification burden for any third-party claims arising from Customer Data, including claims that Customer Data infringes third-p…
This provision establishes the legal basis for cross-border personal data transfers by Modal, incorporating EU SCCs (Modules 1-3), UK IDTA, and Swiss law provisions by reference into the DPA. The adv…
IP addresses are classified as personal data under GDPR in the EU, and the inclusion of 'other statistics' creates an open-ended category of automatically collected data that is not bounded by the pr…
The provision uses an open-ended 'including but not limited to' formulation that does not limit collection to the listed categories, which means actual data collection could extend beyond name, phone…
The provision does not identify the specific cookies used, distinguish between functional and tracking cookies, or describe what information is collected through cookies, which may be insufficient un…
This provision establishes a contractual allocation of data controller responsibilities to Customers for all personal data submitted to the platform as Customer Data, requiring Customers to independe…
This provision asserts that a single act of accepting the terms of service operates as consent to all data processing purposes described in the policy for users in consent-required jurisdictions. Whe…
This provision establishes that monday.com sources personal data about prospective customers from commercial data brokers and professional networking platforms, meaning individuals may have profile d…
This provision establishes that interactions with monday.com personnel including customer experience and product consultants may be subject to automatic recording and transcription, and that session …
This provision establishes that privacy designations applied to boards within the platform do not restrict access by Account Admins acting on behalf of the Customer organization, meaning personal dat…
This provision may require evaluation under GDPR Article 28, which requires that controllers engage processors only under a binding contract specifying specific data protection obligations. Reliance …
This provision discloses a substantial advertising technology ecosystem operating on Quest's website, with data flowing to approximately 30 named third parties for targeted advertising, analytics, an…
Collection of Social Security Numbers and government identifiers from job applicants constitutes Sensitive Personal Information under CCPA/CPRA, triggering specific use limitation and opt-out rights.…
This provision authorizes AI-powered processing of communication content across three channels (calls, chatbot, email) for operational and commercial analytics purposes. The scope of AI processing ap…
This provision establishes the transfer mechanisms Quest asserts for cross-border Personal Data flows, including the EU-U.S. DPF, UK Extension, Swiss-U.S. DPF, and EU SCCs. DPF certification is subje…
This clause establishes that users bear the full financial obligation for the billing period regardless of usage or cancellation timing, and that non-payment triggers a monthly compounding late fee, …
This clause establishes that users are contractually bound by updated terms upon continued use, without requiring affirmative notification or re-consent, which means material changes to rights, oblig…
This clause establishes that account access and continuity are not contractually guaranteed and that termination does not require cause, notice, or a cure period, which is operationally significant f…
This clause establishes a broad user-side indemnification obligation that includes attorneys' fees and any claims of any kind arising from use of the Service, which creates financial exposure for use…
This provision aligns with prohibitions established under the EU AI Act for real-time remote biometric identification systems in publicly accessible spaces, and its inclusion signals that OpenAI's co…
This provision establishes the legal basis under which user-submitted content may become training data for OpenAI's AI models. The opt-out mechanism places the affirmative action on the user, meaning…
This provision establishes a distinct data collection and sharing regime for users on the Free and Go tiers, including collection of advertising engagement data and sharing with external marketing pa…
This clause establishes the procedural mechanism by which contractual obligations may be unilaterally modified by the service provider, requiring users to either accept changes through continued use …
This clause establishes an external policy document as a binding component of the service agreement, creating enforceable requirements that govern how users may distribute or publicize service output…
This provision establishes an internal governance gate that defines the conditions under which a frontier model may be released, creating a documented procedural commitment that downstream API operat…
This provision establishes a technical enforcement mechanism restricting voice output to a defined set of pre-approved voices, directly addressing fraud, impersonation, and voice cloning risks identi…
This provision establishes a post-training behavioral restriction targeting voice-based biometric identification, addressing privacy and surveillance risks associated with audio input processing in a…
This provision establishes a behavioral distinction between prohibited ungrounded inference and permitted hedged sensitive trait attribution, addressing allocative and representational harms identifi…
This provision establishes a disclosed data minimization practice and an operational opt-out mechanism for image training data that the document states was applied to the GPT-4o series, creating a do…
This provision establishes that employer-level administrators have access to employee content submitted through ChatGPT Enterprise or business accounts, and that registration with a work email addres…
This provision establishes the conditions under which OpenAI will not fulfill a deletion request within the standard 30-day window, including a broadly stated 'fraud and abuse' carve-out applicable t…
This provision authorizes collection and retention of personal data from individuals who have not agreed to OpenAI's terms or privacy policy, as the data subjects are third parties whose information …
This provision establishes that government and defense sector entities seeking to use OpenAI services for national security or intelligence functions must obtain prior approval from OpenAI. The absen…
These prohibitions mirror prohibited AI practices enumerated in the EU AI Act, including social scoring by public authorities, emotion recognition in the workplace and educational settings, and crimi…
This provision establishes OpenAI's unilateral authority to revoke access based on a reasonableness standard, without specifying procedural requirements, timelines, or defined criteria beyond the rea…
This provision establishes OpenAI's enforcement authority, including access termination, and discloses the existence of an appeals mechanism, though the policy does not specify timelines, standards, …
This clause creates a binding compliance obligation tied to external policy documents, meaning the substantive conduct rules users must follow are defined in policies separate from the main agreement…
This provision creates a bifurcated terms structure based on user location, ensuring compliance with EU and UK regulatory frameworks that may impose requirements distinct from those in the primary te…
This provision establishes the documented basis for GPT-4o's medium overall risk classification under the Preparedness Framework and discloses the methodology and findings of a structured persuasion …
This disclosure establishes that GPT-4o's safety mitigations may not perform consistently across all real-world audio conditions, which is operationally relevant for API operators deploying voice-ena…
This provision reserves broad authority to disclose personal data to government authorities and third parties beyond mandatory legal compliance, including through a self-assessed 'sole discretion' de…
This provision establishes a prohibition on use of OpenAI services for election-related influence operations, including domestic political campaigning and demobilization, which is operationally signi…
This provision sets a damages cap of $100.00 or three months of fees paid, whichever is greater, for direct damages, and excludes all indirect and consequential damages. In the context of a health in…
This provision establishes that any content a user posts or submits through the Services is subject to a perpetual and irrevocable license granted to Oscar, including the right to sublicense. The irr…
This provision operationalizes state consumer privacy rights for residents of approximately nineteen states and establishes a two-step appeal process, first to Oscar and then to the state Attorney Ge…
This provision establishes that cross-site behavioral tracking and sharing of online activity with advertising partners occurs through Oscar's Sites; the policy provides an opt-out mechanism via the …
This provision requires users to bear the cost of defending Oscar against claims arising from third-party use of the user's account identity, in addition to their own misuse. The indemnification obli…
This provision establishes that Oscar can unilaterally modify the Terms and that continued use of the Services after modification constitutes binding acceptance of the new terms. Users who disagree w…
This provision asserts a waiver of California Civil Code Section 1542 for California residents, which, if enforceable, would mean that any release of claims against Oscar in connection with these Ter…
This provision authorizes a use of personal information, including de-identification and third-party disclosure for AI development, that is operationally distinct from standard service delivery purpo…
This provision operationally limits the scope of state consumer privacy rights, including CCPA access, correction, and deletion rights, for personal information that qualifies as Protected Health Inf…
This provision authorizes pre-transaction disclosure of personal information to potential acquirers or transaction counterparties before any transaction is completed, which means personal data may be…
This provision extends the indemnification obligation to cover claims arising from use of the user's account by any third party, not only the user themselves. The provision covers attorneys' fees and…
This provision establishes that research participants may have restricted access to their own biometric data during study periods, that the governing agreement and data rights framework shifts to the…
This provision establishes that subscription charges are assessed at the beginning of each term, cancellations do not yield prorated refunds, and the agreement's general refund policy is limited to l…
This provision shortens the limitations period for claims against Oura to one year for non-EU users, which is shorter than the default statutes of limitations in most US states for contract and tort …
This provision asserts a non-medical-device characterization and disclaims all liability for health record information, which may warrant evaluation under FDA guidance on mobile medical applications …
This provision establishes that the agreement is subject to unilateral modification by Oura at any time, with continued service use constituting acceptance of modified terms, and that Oura bears no l…
This provision bundles consent to marketing communications, including automated dialing and pre-recorded messages, into the general agreement acceptance flow. The agreement states that consent to mar…
This provision establishes that customers bear the full financial obligation for fees incurred regardless of service outcome, and that PlanetScale retains the right to accrue interest charges and sus…
This provision establishes that customer data stored on PlanetScale may be deleted upon account termination, including termination for inactivity, with PlanetScale bearing no retention obligation pos…
This indemnification obligation places defense and indemnification costs on the customer for third-party claims arising from Customer Content and any AUP or agreement breach, including breaches by en…
This provision grants PlanetScale an irrevocable and perpetual intellectual property license over a broadly defined category of customer-provided materials, including proposals and documents, without…
The exclusive venue clause requires all disputes to be litigated in San Francisco, California federal or state courts, which may create practical barriers for non-California customers. The agreement …
This provision authorizes physical and records-based audits of customer infrastructure, which may extend to sensitive business systems and data beyond the scope of PlanetScale's database service. The…
This provision establishes a liability ceiling tied to recent fee payments, which for low-spend or new customers may represent a materially limited recovery amount relative to potential data loss or …
This provision establishes that Progressive bears no liability for credential-based unauthorized access except in cases of its own gross negligence, and that Progressive may suspend account access wi…
This provision limits Progressive's financial exposure for website-related harms including unauthorized data access, with a carve-out only for gross negligence or intentional misconduct, which means …
This indemnification obligation shifts legal defense costs and liability to the user for TCPA-related claims that may arise if the user provides an incorrect or third-party phone number, which is ope…
This provision requires all website-related disputes to proceed in a specific Ohio county venue, which may present practical barriers for users located outside Ohio, and the enforceability of this fo…
This provision places the burden on users to monitor the terms page for changes and treats continued site use as binding acceptance of modifications, without requiring affirmative notice or consent f…
This provision grants Progressive an unlimited license over submitted materials without time restriction, geographic limitation, or compensation obligation, covering a broad range of content categori…
This provision establishes that prepaid balances are subject to automatic expiration and forfeiture after 12 months, and that customers have no property right or refund entitlement in unused balances…
This provision permits Replicate to alter or discontinue paid service features without notice and without liability, while fee changes require reasonable prior notice before the next renewal period. …
This provision authorizes Replicate to use aggregated and anonymized customer usage data for any legal purpose in perpetuity, including after the agreement ends. The scope of the resultant data licen…
This clause defines Revolut's data monetization boundaries by restricting a specific category of data transfer—the sale of personal data—while other forms of data sharing (such as with service provid…
The provision operationalizes a data protection contact channel, enabling users to initiate communication with the Data Protection Officer regarding data handling practices. This establishes a proced…
The clause establishes the operational basis for aggregating financial data across multiple accounts held by the user at other institutions, enabling Revolut to perform financial analysis, creditwort…
Legitimate interests is a legal basis under data protection frameworks that permits processing without explicit user consent when the organization's interests are balanced against individual rights. …
This provision creates a broad indemnification obligation requiring customers to defend and compensate Robinhood and its affiliates against losses arising from third-party claims related to the custo…
This provision establishes that posting revised terms to the Robinhood website satisfies the notice requirement for material agreement changes, and that continued account use constitutes binding acce…
The force majeure clause includes unusually heavy trading in securities as an event beyond Robinhood's reasonable control, which may be relevant in high-volatility market conditions. This formulation…
This clause establishes that each joint account holder is independently liable for the full margin obligations of the account, and that instructions from any single co-owner, including margin-related…
This clause authorizes credit report pulls without specifying the permissible purpose required under the Fair Credit Reporting Act, which limits the circumstances under which consumer reports may be …
This clause establishes a one-directional fee-shifting obligation under which the customer bears Robinhood's legal and collection costs but does not establish any reciprocal obligation for Robinhood …
This provision establishes that the borrow rate is variable, changes daily, and is set at Robinhood's discretion based on competitive necessities, without specifying a cap or advance notice requireme…
This provision obtains consent for automated telemarketing calls and text messages under the Telephone Consumer Protection Act, and authorizes sharing of the customer's phone number with third-party …
This provision assigns personal financial liability to the custodian for reversed or fraudulent third-party gifts to a minor's custodial account through the optional gifting feature, with recovery by…
Because the Creator Terms are incorporated by reference into the User Terms and apply to all users who access the Services, all users, including those who do not self-identify as creators, are subjec…
The regional appendices establish that users in major regulatory jurisdictions operate under modified terms designed to address local legal requirements, including GDPR for EU users, UK GDPR for UK u…
The provision delegates to Roblox the determination of what constitutes a material versus non-material change, and what qualifies as a modification made for legal reasons, both of which affect whethe…
This provision establishes the contractual basis under which Roblox asserts that virtual currency and content purchases are non-refundable, which has particular operational significance for minor use…
The program establishes the sole mechanism through which creators can convert Robux earnings into real currency, and Roblox reserves the right to set and modify the exchange rate, eligibility require…
This provision assigns contractual liability to parents and guardians for all minor account activity, including financial transactions, which has direct implications for purchase disputes, unauthoriz…
This provision grants Runway broad discretionary authority to suspend accounts without specifying procedural standards, notice periods, or timelines for the appeal process, which may affect enterpris…
This provision addresses an area of active copyright and right-of-publicity litigation in the context of AI-generated content; the restriction applies to living artists only and does not extend to hi…
This provision directly engages the FTC Act's Section 5 prohibition on unfair or deceptive practices and may also implicate the Computer Fraud and Abuse Act, wire fraud statutes, and state consumer p…
These product-specific prohibitions engage COPPA's restrictions on content and data collection directed at children under 13, and extend further to cover all minors under 18 in the context of likenes…
This provision establishes that customer AI use is subject to the terms of the Acceptable Use Policy, which governs permitted and restricted uses of Salesforce AI capabilities and may include enforce…
This provision establishes a data retention and use restriction applicable to third-party LLM interactions within the Salesforce platform, which is a material term for enterprise customers assessing …
This provision describes a technical de-identification mechanism that operates on data in transit to third-party LLMs, which is directly relevant to compliance obligations under GDPR, CCPA, and HIPAA…
This provision establishes a stated data ownership principle that has direct implications for data portability, deletion, and secondary use rights under GDPR, CCPA, and applicable contractual data pr…
This provision establishes temporary cross-regional data routing affecting customers in the UAE, Israel, Lebanon, Bahrain, Oman, Jordan, Qatar, Kuwait, and Egypt, creating a situation where Customer …
The document establishes that generative AI processing by OpenAI and Microsoft Azure is integrated across a broad range of covered services, meaning Customer Data from financial services, education, …
This provision establishes that a category of data, specifically identifying information about customer instances and users, may be processed across Salesforce's global infrastructure regardless of t…
This provision creates a direct operational link between feature configuration decisions and sub-processor inventory: enabling Einstein NLP, generative AI, speech, or analytics features introduces ad…
This provision establishes that Cloudflare, Akamai Technologies, and Amazon CloudFront, each designated as Global CDN providers for multiple covered services including B2C Commerce, Commerce Cloud Ei…
Under GDPR Article 28, controllers are entitled to object to changes in sub-processor arrangements. This provision establishes the operational mechanism through which Salesforce delivers advance sub-…
This provision establishes a conditional cross-regional data routing mechanism that activates automatically during failover events without requiring a separate customer election. For customers with c…
This provision establishes the legal basis and operational scope for Spotify's cross-platform advertising data sharing, authorizing disclosure of browser- and device-associated personal data to third…
This provision establishes a bifurcated consent architecture in which browser-level and account-level personal data are governed by separate opt-out mechanisms. Compliance teams should evaluate wheth…
This provision discloses that targeting cookies enable cross-site tracking and interest profiling shared with third-party advertisers. Under GDPR and the ePrivacy Directive, processing of this nature…
This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected …
This provision disclaims all warranties applicable to the platform and its content, including warranties of accuracy and security. For a financial services platform where users rely on market data, i…
This provision extends indemnification obligations to claims arising from use of the user's account by any person, including unauthorized users, which may create financial exposure for users in the e…
This provision caps aggregate financial liability at twelve months of fees paid, which for users on lower-tier subscription plans may represent a minimal dollar amount relative to potential investmen…
This provision establishes blanket recording consent as a condition of platform use, covering communications with Stash representatives and agents. The scope of permitted use extends to any use in th…
This provision reserves broad termination authority for Stash, including the ability to delete account data without advance notice. For users holding financial accounts through the platform, this ter…
This provision grants Stash and its successors and assigns the right to derive commercial revenue from user-submitted content for the full term of any applicable intellectual property rights, without…
This provision establishes that any amendment to the Terms of Use becomes binding upon the user through continued platform use, provided notification was delivered through any of the listed channels.…
This provision establishes the legal framework under which Synthesia processes Customer Data, positioning the business customer as the data controller and Synthesia as the data processor. This design…
This provision bars a specific category of data extraction activity that has become a contested area in AI development and intellectual property law, placing contractual restrictions on users who may…
This provision establishes that the DPA operates alongside the Customer Terms of Service, which means terms in both documents apply to the processing relationship. Compliance teams should assess both…
This provision establishes a contractual obligation to preserve AI content provenance mechanisms, which aligns with emerging regulatory requirements under the EU AI Act and voluntary industry framewo…
This provision establishes the enforcement mechanism for the AUP, granting Synthesia discretionary authority to suspend or terminate access based on its assessment of violation severity and intent, w…
This provision establishes a consent-gated permission structure for commercial advertising use of avatar content, requiring affirmative written authorization from Synthesia for Stock Avatars and indi…
This provision establishes an explicit contractual prohibition mirroring obligations under US, UK, and EU counterterrorism laws, and reflects the multi-jurisdictional compliance framework applicable …
Version updates to a DPA may alter sub-processor lists, transfer mechanisms, security obligations, or data subject rights procedures. Organizations that executed a prior version should review the Jan…
These restrictions establish specific commercial and revenue-based thresholds for permissible stock audio use, with the billion-dollar revenue threshold creating a differentiated permission structure…
This provision restricts deceptive identity representation in AI-generated content, with the scope of the prohibition differentiated by service plan tier; the explicit non-enterprise qualifier create…
The scope of data covered by the DPA determines which processing activities are subject to its protections and obligations. Without the full addendum text, it is not possible to confirm whether all p…
This provision establishes a mandatory procedural prerequisite to arbitration that requires personal participation in a teleconference or videoconference meet-and-confer, with a 60-day window, before…
The provision includes an authorization for wireless carriers to disclose user account and device information to Ticketmaster, which is a disclosure mechanism distinct from Ticketmaster's own data co…
This provision establishes a distinct procedural track for coordinated consumer claims that meet the 75-demand threshold, which may affect the pace and structure of resolution for large-scale consume…
This provision extends the user's indemnification obligation to cover event organizers, suppliers, advertisers, and sponsors in addition to Ticketmaster itself, and grants Ticketmaster the right to a…
This provision permits users as young as 13 to hold accounts with parental authorization, and places responsibility for minors' conduct and use of the Marketplace on parents or legal guardians who ac…
This provision establishes an enforcement basis for removal of election-related misinformation, which intersects with political speech considerations, AI-generated content provisions, and regulatory …
This provision establishes a platform-level disclosure requirement for all promotional content that operates alongside and intersects with FTC endorsement and disclosure guidance. Failure to use the …
The youth safety provisions establish multiple overlapping prohibition categories for minor-related content, and the age-restriction mechanism creates an operational content filtering obligation for …
This provision establishes an enforcement basis for action against accounts purchasing or selling engagement-boosting services, which is relevant to creator accounts, brand accounts, and third-party …
This provision establishes an affirmative user obligation to label AI-generated or edited realistic depictions, creating an enforcement basis for removing unlabeled synthetic media. The prohibition o…
The FYF ineligibility tier functions as an algorithmic distribution restriction that operates independently from removal, meaning content may remain on the platform and be accessible directly while r…
The verified seller exception creates a tiered access system for regulated goods marketing on TikTok, establishing that verification status and compliance with unspecified requirements are conditions…
The explicit non-sale affirmation is a material CCPA compliance disclosure; the commitment to provide notice and opt-out rights before any future sale establishes a procedural obligation that would a…
This provision authorizes Personal Data to be transferred to a successor entity in a corporate transaction without requiring individual user consent for that specific transfer, which is a standard bu…
The consent-as-transfer-mechanism framing for general users may require evaluation under GDPR, where valid cross-border transfer requires specific legal mechanisms under Chapter V rather than general…
This provision creates a technical and contractual limitation on the company's ability to fulfill data subject rights requests for data processed under ZDR, which may require evaluation under GDPR Ar…
This provision establishes a consent-based restriction on a core commercial use of user-submitted data in AI development contexts. The opt-in framing represents a specific commitment that may require…
This provision establishes the operational rights framework for GDPR-covered users and identifies the contact mechanism for exercising rights not available through account settings; the consent withd…
This provision asserts a broad, perpetual, and sublicensable license over user-submitted content with no compensation obligation and no expiration tied to account termination or service discontinuati…
This provision discloses the company's non-compliance with browser-level Do Not Track signals in the context of a platform that collects health, financial, and behavioral data. Several US state priva…
This provision establishes a minimum age of 13 and a parental consent requirement for minor users, engaging COPPA's applicability threshold and state-specific age of majority requirements. The agreem…
This provision addresses California's Shine the Light statute obligations but does not address California Consumer Privacy Act rights such as the right to know, right to delete, or right to opt out o…
This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collecte…
This provision authorizes data aggregation across online behavioral data, health and medical information, financial data, and offline records from vendors, which may produce enriched data profiles ex…
This provision requires users outside Minnesota to litigate disputes in Minnesota courts under Minnesota law, which may present practical barriers to pursuing claims for users in other states. The en…
This provision establishes an automatic login mechanism for accounts that may contain health plan information, medical records, and financial data, and states that users who do not affirmatively log …
This provision asserts that the Privacy Policy does not establish enforceable rights or contractual obligations, which may be cited by the company in response to user claims arising from data handlin…
This provision establishes a contractual limitations period shorter than the default statutory limitations period applicable to many claim types under Minnesota law and the laws of many other states.…
This provision makes continued platform use the mechanism for consent to modified terms, with no requirement for affirmative acknowledgment, separate notification to users, or advance notice period b…
This provision grants the company unilateral termination authority without procedural prerequisites or advance notice requirements. For members who rely on the Online Services to access plan document…
This provision asserts a broad limitation of liability covering all legal theories and all losses arising from platform use or company acts. The document itself acknowledges that state law may limit …
This provision requires users to cover the company's legal defense costs, including attorneys' fees for counsel selected by the company rather than the user, arising from third-party claims connected…
This provision asserts that unsolicited submissions transfer automatically to company ownership with no compensation or confidentiality obligation, and explicitly permits the company to develop compe…
This clause covers the full scope of damage categories and extends the disclaimer to all parties involved in creating or delivering the site, not only Visa itself. The qualification 'to the maximum e…
This provision establishes that personal information handling is governed by site-specific privacy policies rather than a unified global framework, and that terms may vary materially across regional …
This provision asserts that the website terms of use take precedence over separately negotiated agreements with Visa in the event of any conflict, which may affect the terms of commercial, financial,…
This provision establishes that Visa may update the website terms of use at any time without advance notice, and that users are bound by revisions upon posting. There is no stated mechanism for notif…
This provision establishes that any use of site content beyond personal, non-commercial downloading requires Visa's written consent, and explicitly identifies patent coverage of site features. The no…
This provision expressly disclaims implied warranties including merchantability and fitness for a particular purpose, and also states that Visa does not warrant that site content is free from third-p…
This provision authorizes account suspension and termination without notice at Zelle's sole discretion, including during an ongoing investigation. The absence of a required pre-suspension notice or a…
This provision establishes Delaware as the governing law for site-level terms and designates the FAA as the governing framework for Section 10, which by reference indicates an arbitration clause. The…
This provision establishes that the legal terms governing site use can change without direct user notification, placing the obligation to monitor for changes on users. The characterization of continu…
This provision establishes a $100.00 ceiling on the Zelle Network's financial liability in states where broader damage exclusions cannot be fully enforced, which applies to claims arising from site u…
This provision asserts an automatic IP assignment from the submitter to Zelle for any unsolicited material, with no compensation obligation and no confidentiality requirement. Under this clause, Zell…
This provision establishes that Zelle may disclose user identity to law enforcement based on suspected violations of these Terms, and that users waive claims arising from those disclosures or any res…
This provision requires users to waive, irrevocably and in advance, all claims against Zelle arising from third-party site interactions, including those involving credit card and personal data exposu…
This clause creates a binding renewal obligation at potentially updated pricing unless the Customer takes affirmative action within the specified notice window. The combination of auto-renewal at the…
This provision authorizes Service Data sharing with third-party providers as a consequence of enabling integrations, without requiring a separate disclosure or consent step at the time of each integr…
This provision places the legal responsibility for obtaining all consents and providing all notices necessary for lawful processing of Service Data on the Customer rather than Zendesk. This allocatio…
This provision authorizes Zendesk to modify agreement terms and incorporated policies on a rolling basis. For the core agreement, continued use after the notice period constitutes consent. For URL-in…
This provision establishes that customers are financially committed for the full subscription term regardless of reduced usage, business changes, or service dissatisfaction, with limited exceptions e…
The fifth suspension ground, which permits suspension based on Zendesk's reasonable determination that it is necessary to avoid material harm to Zendesk, its affiliates, or customers, is a broad disc…
This provision establishes a financial ceiling on liability claims under the agreement. The Excluded Claims definition carves out several categories, including payment obligations, indemnification ob…
This provision authorizes Zendesk to use Service Data for product improvement purposes, which may extend beyond the scope of processing strictly necessary to deliver contracted services. Depending on…
This clause establishes a specific operational limitation on the permitted use of ActiveCampaign's messaging infrastructure, which is operationally significant for any organization that manages emerg…
This provision changes the internal transparency posture for unredacted safety risk information, reducing the employee population with guaranteed access to unredacted Risk Reports from all regular-cl…
The clause establishes Anthropic's right to use Customer identity for marketing and business development purposes while creating an opt-out mechanism. It further obligates the Customer to consider in…
This provision discloses that crowd worker welfare obligations are contractually delegated to platform intermediaries, which determines the mechanism and enforceability of these standards. The docume…
The Frontier Safety Roadmap provision establishes a public disclosure mechanism for Anthropic's AI safety objectives and their completion status, creating a trackable record of stated safety commitme…
This provision establishes the consent basis and opt-out mechanism for Apple's use of Apple Intelligence content data for product improvement, applying only to users who have previously opted into De…
This provision establishes a user-accessible transparency mechanism that documents server-side data routing for Apple Intelligence requests, providing an auditable log of off-device processing. The a…
This provision establishes that on-device processing is the default architectural approach for Apple Intelligence, with server-side routing to Private Cloud Compute occurring only when the task requi…
This provision defines the scope of data Apple asserts it collects in connection with server-side AI processing, establishing the boundary between content data (not collected) and operational metadat…
This provision establishes that payment-related personal data is processed by third-party subprocessors, which is relevant for customers' PCI DSS compliance assessments and for understanding the data…
This provision establishes that customer-facing interaction data and platform usage analytics are processed by third parties, which is operationally significant for customers whose support communicat…
This provision establishes a transaction fee that applies specifically when an IRA holder exercises the right to transfer retirement assets to another custodian, which is a standard account portabili…
This provision establishes the bank's own ATM surcharge structure for out-of-network ATM use, and discloses that ATM operator fees are assessed separately and in addition to the bank's own fee, resul…
This provision establishes that CD holders are subject to an early withdrawal penalty and that Bank of America may alter CD features at renewal by disclosing changes in the maturity notice, which def…
This provision establishes Delaware as the exclusive legal and procedural forum for claims brought by Baseten against Customer, while the venue consent is unilaterally directed at Customer, which may…
This provision reserves Chase's right to override customer routing or transfer system instructions and to charge wire transfer fees on transactions completed as internal transfers, which may affect t…
The agreement explicitly states that rate changes require no advance notice, which means account holders may not receive advance disclosure before a rate reduction takes effect on their savings or in…
The early withdrawal penalty structure for personal CDs caps penalties at the total interest earned during the current term, which limits but does not eliminate potential principal reduction in low-i…
This provision establishes consent to automated dialing and prerecorded voice messages upon providing a mobile number, which implicates the Telephone Consumer Protection Act (TCPA). The agreement sta…
The waiver conditions for monthly service fees establish the specific operational requirements account holders must meet each statement period to avoid recurring charges, with thresholds varying sign…
This provision reserves Chase's right to alter the interest rate and APY on interest-bearing accounts without restriction on frequency or magnitude and without advance notice, which is an operational…
This provision extends account termination authority to conduct in customer communications, not only to content or list management practices, and applies the same no-refund and discretionary data exp…
This provision defines the operational scope of Craigslist's data monetization and sharing practices by explicitly restricting several common data commercialization mechanisms. The clause establishes…
This provision discloses the existence of an ongoing public vulnerability disclosure channel, which is operationally relevant for security researchers and for customers evaluating the scope of indepe…
This provision establishes a specific, measurable penetration testing cadence with a mandatory remediation gate for material findings, and discloses that the third-party test report is available to c…
This provision establishes the legal transfer mechanisms Disney intends to rely upon for cross-border personal information flows, specifically naming standard contractual clauses (SCCs) and consent a…
This provision establishes that notice of material policy changes may be delivered to the email address last provided by the user, making the accuracy of contact information on file operationally sig…
This provision consolidates US state privacy rights into a single notice, covering rights established under CCPA (California), and analogous frameworks in states including Virginia, Colorado, Connect…
This provision reflects a mandatory disclosure obligation under the Texas Data Privacy and Security Act and Texas data broker registration requirements. The registration creates a public compliance r…
This provision constitutes a mandatory CCPA compliance disclosure and provides a quantitative record of Experian's rights request processing performance for the 2025 calendar year. The disclosure of …
This provision establishes a categorical prohibition on data collection and sale for minors under 16, which aligns with the CCPA's prohibition on selling personal information of minors under 16 witho…
This provision establishes that Experian accepts no liability for third-party sites accessed through links on experian.com, which is operationally relevant where the site links to partner, affiliate,…
This provision establishes that any reproduction or redistribution of experian.com content or use of Experian trademarks requires affirmative written authorization, which applies to media organizatio…
This provision establishes the mechanism through which copyright holders can request removal of infringing content from gm.com and through which GM may assert safe harbor protection under the Digital…
This provision permits GM to transfer the terms and associated content licenses to a successor entity, acquirer, or third party without user consent or notice. In the context of a corporate transacti…
This provision establishes that users who opt into experimental Copilot features are subject to different and separately published terms, which may contain different data handling, liability, or acce…
This provision establishes that the applicable governing terms for GitHub Copilot depend on the procurement channel and plan type, creating three parallel governance tracks. Organizations should conf…
This provision establishes that rate limit and parameter compliance is a contractual obligation enforced across the account and organizational level, not just at the individual API request level, and…
This provision establishes that policy flexibility is available only through individual exception requests approved at Groq's discretion, and that approved exceptions create no binding precedent for …
This provision authorizes ongoing collection and use of behavioral and interaction data for platform development purposes. The definition of Usage Data explicitly excludes Customer Data and Content, …
This provision defines the scope of Harvey's processing rights over Customer Data and Input. The license is limited in purpose to service provision, technical problem resolution, and legal compliance…
This provision establishes the available data subject rights mechanisms and confirms access to regulatory complaint channels including EU DPAs and the UK ICO. The rights are subject to exceptions and…
This provision defines the contractual confidentiality standard governing Harvey's handling of Customer Content and Customer Data as the customer's Confidential Information. The provision that Harvey…
The retention period for end users whose employers hold a Customer Agreement is governed by that agreement rather than solely by this policy, creating a dependency on enterprise contract terms for de…
The Feedback license is irrevocable, perpetual, sublicensable, and transferable, meaning Customer retains no control over how submitted Feedback is used or disclosed after submission. The agreement e…
This provision confirms Customer ownership of User Submissions while establishing that Linear's license to process and display them is limited to Service delivery purposes. The license is transferabl…
This provision establishes that any suggestions, comments, or feedback submitted by Customer regarding the Service are subject to an unrestricted, perpetual, irrevocable license in favor of Linear, i…
The license granted is perpetual and irrevocable in its terms, but the agreement expressly limits its scope to actions reasonably necessary to provide and maintain the Service, and provides operation…
The policy establishes an age threshold of 18, which exceeds the COPPA threshold of 13, and may interact with state-level minor protection statutes such as California's Age-Appropriate Design Code, d…
Appointment of an EU representative under GDPR Article 27 is required for controllers established outside the EU that offer goods or services to EU data subjects or monitor their behavior. This provi…
The policy explicitly identifies investors and shareholders as a distinct data subject category and describes specific financial and transactional personal data categories collected from them, includ…
This provision establishes a defined window for no-fault product return and full fee refund on initial orders, providing a concrete mechanism for Customers to exit subscriptions that do not meet thei…
This provision grants Atlassian an unrestricted license to use Customer feedback and suggestions, including for product development purposes, without creating any obligation to compensate or attribut…
The distinction between material and non-material changes determines whether users receive advance notice or consent requests before new data practices take effect. The document does not define the c…
This provision describes the technical scope and limitations of Marqeta's GPC signal recognition mechanism, which is the primary opt-out pathway for CCPA sale and sharing disclosed in Section 3 of th…
The document sets the age threshold for children's data protection at 16, which aligns with GDPR Article 8's default age of digital consent in the absence of member state modification, and exceeds th…
The policy does not publish specific retention periods for individual data categories in this notice, instead referencing an internal records retention policy and schedule that is not reproduced here…
Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement author…
This provision explicitly authorizes a category of use, synthetic data generation and model distillation, that has been restricted or contested in licenses for other large language models. Organizati…
This provision establishes the mechanism by which updated terms are communicated and accepted, with continued platform use constituting agreement to modified terms. The 30-day notice period is a spec…
This provision documents the scope and methodology of Meta's pre-release safety evaluation for Llama 4, providing institutional deployers with a basis for assessing the categories of risk that were f…
This provision constitutes a voluntary ESG disclosure quantifying the energy and emissions footprint of Llama 4 training. The distinction between location-based and market-based emissions figures ref…
This request cannot be evaluated because no enforceable provision text exists to describe. Responsible AI Reports document corporate practices and commitments but do not establish binding contractual…
This provision reflects a standard COPPA-aligned disclosure for services not directed at children. The policy does not provide a specific contact address for parental requests, which may create a pra…
This provision establishes that all disputes must be litigated in California courts under California law, regardless of where the Customer is located or incorporated. The forum non conveniens waiver …
This provision establishes that policy amendments take effect upon publication and that continued use of the platform constitutes acceptance, with the adequacy of notice (prominent in-service display…
This provision does not specify fixed retention periods for any category of personal data, instead reserving retention duration determinations to monday.com's reasonable discretion and an internal po…
This provision establishes that contact, business, and usage data may be shared with an unspecified set of business partners and resellers, and that once a user engages with a partner independently, …
This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability…
This provision operationalizes marketing opt-out rights and data retention terms. The 10-day opt-out processing deadline and the carve-out for transactional communications are operationally specific …
This provision authorizes de-identification of Personal Data and its unrestricted sharing with third parties. The adequacy of de-identification techniques is not specified in the document; GDPR and C…
This provision operationalizes GDPR and CCPA/CPRA data subject rights through a unified request mechanism and provides an alternative dispute resolution pathway via TrustArc in addition to supervisor…
This provision directly states that Do Not Track browser signals are not honored, meaning users relying on this browser-level control will not have their tracking preferences implemented through this…
This clause requires all dispute resolution to occur in San Francisco, California courts, which establishes a defined legal forum and governing law for contractual claims, and may affect the practica…
This clause establishes that any technical, product, or operational feedback submitted by users, including bug reports and improvement suggestions, becomes the sole property of OneLogin upon submissi…
This provision establishes the age eligibility framework for OpenAI's consumer services, including a 13-year minimum age threshold consistent with COPPA requirements and a parental permission require…
This provision discloses that personal data submitted by US users may be stored and processed in multiple international jurisdictions, and that OpenAI commits to using legally valid transfer mechanis…
This provision discloses that OpenAI conducts monitoring of service use for policy compliance and states that such monitoring is conducted with privacy safeguards, though the specific nature of those…
This provision establishes the procedural framework through which users can exercise data subject rights, with jurisdiction-dependent availability and a centralized submission pathway. The policy als…
This provision establishes an input-side moderation mechanism for audio content that blocks erotic and violent speech generation based on transcription analysis, creating a disclosed content restrict…
This provision establishes that privacy policy changes take effect through continued use without requiring affirmative consent or direct notice to users, which may be evaluated against state law requ…
The provision's statement that the Sites are not intended to subject Oscar to the jurisdiction of countries other than the United States, combined with acknowledgment of transfers to countries that m…
The age 13 to 16 protection is conditioned on Oscar having 'actual knowledge' of the individual's age, which is a standard limitation that means the protection may not apply where age is not verified…
The absence of defined retention periods for specific data categories means the policy does not establish a maximum retention timeline, and the stated standard of 'as long as we believe it is necessa…
This provision assigns to Oura the right to use any user-submitted feedback, including ideas and concepts, for any purpose without compensation or attribution. This is a standard clause in consumer t…
This provision discloses the use of IP-based geolocation for content personalization and asserts that the process does not constitute collection of personal information, though the classification of …
This provision establishes Progressive's DMCA safe harbor compliance mechanism under the Digital Millennium Copyright Act, designating a specific agent and contact information for copyright infringem…
This provision establishes Progressive's unilateral right to discontinue the Mobile Alerts service without advance notice for any reason, while providing users with two specific opt-out mechanisms; t…
This provision disclaims Progressive's responsibility for the accuracy, availability, or security of the website content to the fullest extent permitted by law, which in practice means users cannot a…
This provision operates as an automatic IP assignment clause, transferring ownership of any service-related suggestions or ideas to Replicate without requiring a separate signed agreement or compensa…
This provision creates a single authoritative text for policy interpretation and dispute resolution. It ensures consistent policy application across all users regardless of the language version they …
This provision establishes account transfer restrictions that affect creators operating as businesses, while creating a limited exception for commercial transactions involving virtual content revenue…
This provision establishes a transparency mechanism directly relevant to enterprise customers' AI governance obligations, including requirements under the EU AI Act for documentation of high-risk AI …
This provision establishes an automated content moderation mechanism within the Einstein Trust Layer that operates on all AI-generated outputs, with direct implications for enterprise customers in re…
This provision establishes that AI outputs within the Salesforce platform are grounded in customer-approved data sources and that existing data access controls are maintained during AI processing, wh…
This provision establishes that the sub-processor table may disclose processing relationships and locations for products that are not yet commercially available, meaning the listed sub-processors and…
This provision establishes that regional data hosting is not uniformly available as a self-service configuration and that region selection for one service may produce downstream region assignments fo…
This provision establishes that NLP-processed data from Einstein Bots is stored in a location determined by the customer's primary org region rather than by a separate regional election, and that APA…
The designation of functional cookies as 'always active' alongside strictly necessary cookies may require evaluation under GDPR and ePrivacy Directive guidance, which generally permits exemption from…
This provision establishes the minimum age requirement for service enrollment. As a financial services platform offering investment and banking products, this age restriction aligns with legal requir…
This provision establishes that content posted on the platform, described as limited in the clause header but irrevocable and sublicensable in its operative terms, can be redistributed by Stash to th…
This provision establishes a contractual restriction on competitive use of platform access, a common clause in SaaS agreements that may interact with competition law principles in certain jurisdictio…
The provision states that updated Terms bind users only upon their affirmative agreement, which is a consumer-favorable mechanism relative to terms that take effect automatically upon continued use; …
This provision establishes a harm-predicated standard for personal information sharing, covering doxing and related practices, and creates an enforcement basis for removal of content disclosing perso…
This provision establishes COPPA-aligned age restriction and data removal commitments; the absence of a defined response timeline for parental notification or removal requests may warrant operational…
The notification mechanism is conditional on legal obligation rather than a proactive commitment to direct user notice, meaning users bear responsibility for monitoring the policy page for changes ab…
This provision establishes a transparency commitment regarding government data requests that is operationally distinct from policies that provide no such notification; the practical scope of this com…
This provision governs electronic delivery of regulated communications, including explanation of benefits and privacy notices, which are subject to federal and state insurance requirements. The provi…
This provision establishes COPPA compliance intent for Online Services that may be accessed by minors in the context of family health plan management or dependent benefit access. The qualifier 'inten…
This provision establishes a comprehensive disclaimer of all warranties for site functionality, content accuracy, and security, to the fullest extent permitted by applicable law. As a site-level disc…
The exclusive venue requirement means that customers outside California who pursue litigation must do so in San Francisco County, California courts, which may affect the practical accessibility of di…
Monitor emails you the same day a platform you choose changes these clauses.
A unknown / unclassified clause is a provision in a platform's terms of service or privacy policy governing unknown / unclassified-related rights, obligations, or restrictions.
ConductAtlas tracks 61 platforms with unknown / unclassified clauses - roughly 17% of platforms in the archive. 117 are classified as high severity.
Severity reflects the magnitude of rights waived, availability of opt-out, breadth of users affected, financial or legal exposure created, and the degree of discretion retained by the platform.