Found in 60 of 352 platforms tracked (17% adoption) · 606 provisions
This clause establishes that account termination can occur immediately upon complaint, without a documented cure period or internal dispute process, and that prepaid service fees are forfeited under …
This provision discloses a specific per-violation financial penalty figure associated with SMS non-compliance, placing customers on notice of the financial exposure associated with CTIA guideline vio…
This provision operationalizes federal regulatory requirements for oversale compensation, establishing a standardized framework that defines American Airlines' financial obligations when involuntary …
This clause establishes the operational scope of American Airlines' performance obligations and liability exposure for service disruptions attributable to external events rather than carrier operatio…
This provision establishes that a production model deployed in agentic contexts has disclosed prompt injection vulnerabilities relative to its predecessor, with risk mitigation relying on applied saf…
This provision is operationally significant because evaluation awareness behavior, if it develops further, could affect the reliability of safety and capability assessments conducted under standard e…
This provision establishes that a deployed production model has been assessed as capable of materially assisting biological weapons-relevant tasks, with risk management delegated to runtime detection…
This provision establishes the behavioral safety standard Anthropic applies to agentic deployments, which is operationally significant for enterprises using Claude in automated workflows, API integra…
This provision establishes that CBRN-related AI capabilities are subject to a defined threshold that triggers mandatory safeguard requirements, reflecting a specific operational constraint on model d…
This provision discloses a structural trust limitation in multi-agent architectures that is operationally significant for enterprises building complex AI pipelines, as it means Claude will not automa…
This clause creates a carve-out from the general privacy policy framework, establishing that customer-specific data processing obligations are defined through individual service agreements rather tha…
The provision creates a procedural requirement that allocates responsibility for transaction monitoring between the bank and customer. By establishing a fixed deadline, the clause defines the tempora…
This provision establishes a financial ceiling on Customer's recoverable damages against Baseten that is limited to historical fees paid, and categorically excludes recovery for categories of harm th…
This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full c…
This provision asserts broad set-off rights across all accounts, including joint accounts and deposited federal benefit payments. Federal law, including 31 C.F.R. Part 212, restricts financial instit…
This provision names the specific biometric data categories collected, the two third-party cloud processors receiving that data, and establishes a 365-day outer retention limit, each of which are ope…
This provision establishes that automated processing may directly affect a consumer's ability to complete a transaction or access a service, and the right to request human review is stated to be juri…
This provision establishes that Kit may terminate account access and withhold both payment refunds and subscriber data export without prior notification, creating material operational exposure for bu…
This provision establishes a permanent platform ban as a consequence of policy-based termination, with no stated appeal or reinstatement process, creating an irreversible operational consequence for …
This provision routes all contractual disputes to SIAC arbitration seated in Singapore, a forum that may be practically inaccessible or legally unenforceable for consumer claimants in the EU, UK, Aus…
This provision requires users to bear defense costs and indemnify Anker across a broad set of triggering circumstances, including the user's general relationship with Anker and provision of data, whi…
This provision extends the release and assumption of risk to bodily injury, wrongful death, and loss of privacy claims, and purports to bind not only the user but also their heirs and personal repres…
This provision establishes that Experian's data broker subsidiaries have sold or disclosed sensitive personal information categories, some of which are subject to heightened protections or opt-in con…
This provision contractually shortens the limitations period for all causes of action related to the Web site. The default statutory limitations period for many claim types in New York and other stat…
This provision places full contractual responsibility for third-party tag compliance on the user and establishes a user-side guarantee of rights to uploaded tags. Google's right to screen tags is per…
This provision contractually obligates GTM users to comply with the EU user consent policy, which operationalizes consent requirements under the ePrivacy Directive and GDPR for EU/EEA user data. The …
This provision establishes a direct contractual obligation on GTM users to configure tags and data layer implementations so that no personally identifiable or reasonably linkable data is transmitted …
This provision places the full burden of regulatory compliance on Customers, including compliance with the EU AI Act, which imposes obligations that vary by AI system risk classification and operatio…
This provision establishes a contractual liability allocation under which Groq bears no responsibility for harms arising from Customer reliance on AI-generated outputs, including inaccurate outputs, …
This provision requires enterprise customers deploying Groq AI in any of the named high-risk domains to establish and maintain human oversight mechanisms as a contractual condition of service use, an…
This provision establishes a prerequisite BAA execution for any use of PHI with the Service, consistent with HIPAA requirements for covered entities and business associates. The explicit PCI non-comp…
This provision places the technical and operational responsibility for data minimization on the Customer rather than Contentsquare, covering keystroke data, prefilled form data, HTML-displayed data, …
This provision extends the liability exclusion to cover physical injuries, bodily injury, and death arising from Third-Party Provider services, which may interact with state consumer protection and p…
This provision requires U.S. residents to submit covered claims to binding arbitration on an individual basis, with the arbitrator holding exclusive authority to decide questions of arbitrability und…
This provision extends the waiver to claims arising from Instacart's own negligence and from sensitive health information disclosure, including information relating to mental health, HIV status, and …
This provision requires users to grant broad intellectual property rights in submitted content as a condition of participation in Interactive Areas. The license is irrevocable and perpetual, meaning …
This provision establishes a unilateral option mechanism by which Provider may acquire full intellectual property ownership of patentable user submissions at a predetermined, fixed consideration. The…
This provision restricts use cases that would trigger obligations under the Fair Credit Reporting Act, which governs the use of consumer reports for eligibility determinations. The prohibition places…
This provision establishes a $100 USD aggregate damages cap as Provider's maximum financial exposure to any individual user. The clause excludes direct, indirect, incidental, punitive, and consequent…
This provision establishes that material billing terms and data processing obligations for AI features are located in a document external to this Agreement, meaning the full contractual scope of AI S…
This provision establishes a combined damages exclusion and aggregate liability cap that limits LlamaIndex's financial exposure to $100 or amounts paid, whichever is greater, regardless of the nature…
This provision authorizes deployment of third-party session-recording tools that may capture text inputs in real time, including content entered into LLM-related chat or communication features, which…
This provision requires disputes to proceed through individual JAMS arbitration rather than federal or state court, and the agreement assigns to the arbitrator exclusive authority to resolve question…
This provision establishes the financial ceiling on Atlassian's liability for data security failures, with the Special Claims cap creating a specific recovery ceiling for unauthorized Customer Data d…
This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibil…
This provision establishes that KYC service outputs cannot be used as a basis for FCRA adverse action decisions, which means Customer cannot use identity verification results to deny credit, employme…
This provision requires Customer to pay remaining term fees even in circumstances where termination is triggered by external regulatory or network events outside Customer's control, such as Issuer wi…
This provision authorizes Marqeta to apply funds from Customer's Custodial Account against outstanding Customer liabilities on a continuous basis without requiring a separate triggering event or cour…
This provision requires Customer to absorb financial and legal exposure arising not only from its own conduct but also from the acts or omissions of its customers, Retail Partners, and Lending Bank i…
This provision establishes a contractual liability ceiling tied to Marqeta's revenue rather than Customer's potential losses, and imposes a one-year contractual limitations period on all breach claim…
This provision establishes that special category data under GDPR and equivalent frameworks may be collected and processed for personalization and analytics purposes, subject to the user voluntarily p…
This provision introduces the first explicit disclosure of agentic AI capabilities in Meta's Privacy Policy, establishing that AI systems operating on Meta's platforms may perform autonomous actions …
This provision establishes that ad personalization is based in part on data sourced from outside Meta's own platforms, and that this processing applies regardless of whether a user is logged in or ho…
This provision authorizes use of user-generated public content and AI interaction metadata for AI model development that extends beyond Meta's own product ecosystem to include third-party beneficiari…
This provision establishes that the safety assurances described in the model card apply to the base model as released by Meta, and that deploying organizations must independently conduct safety evalu…
This provision establishes that data collected on one Meta platform, such as Facebook or Instagram, may be shared with and processed by other Meta Companies including WhatsApp, affecting the scope of…
This provision establishes Microsoft's procedural obligations regarding AI system design and evaluation. It creates an operational framework requiring bias identification and mitigation activities du…
This provision establishes an operational requirement that human review and decision authority remain embedded in AI system workflows for high-risk applications. The commitment creates a structural c…
This provision establishes that user data collected across Microsoft's product ecosystem is shared with multiple named external advertising entities, and the breadth of this sharing may require evalu…
This provision establishes Microsoft's authorization to collect and process biometric identifiers, a category of sensitive personal data subject to heightened regulatory requirements including Illino…
This provision establishes a broad authorization for AI training as a secondary use of personal data collected across Microsoft's consumer product portfolio, which may require evaluation under GDPR l…
The provision establishes a dual consent framework for Memory feature operation: general service personalization proceeds under legitimate interest, while storage of sensitive health information requ…
This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining th…
This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational …
This provision requires that any deployment of OpenAI services involving automated decisions in the named sensitive domains include human review as a condition of permitted use. Organizations integra…
This routing mechanism creates a bifurcated terms structure, with EU-jurisdiction users operating under distinct contractual provisions designed to address regional legal requirements. The provision …
This provision discloses OpenAI's active reporting practice to NCMEC, which is consistent with obligations established under US federal law for electronic service providers that obtain apparent CSAM.…
This provision establishes a categorical prohibition on using OpenAI services for weapons-related purposes including CBRNE, which is operationally significant for defense contractors, research instit…
This provision prohibits emotion inference in workplace and educational contexts and criminal risk prediction based on personal traits, both of which are among the prohibited AI practices enumerated …
This provision discloses an active reporting practice: OpenAI states it reports apparent CSAM and child endangerment to NCMEC, which is consistent with obligations under federal law for electronic se…
This provision imposes a human-in-the-loop requirement for a broad set of consequential decision domains, which is operationally significant for enterprise and API customers building automated decisi…
This provision establishes a categorical prohibition on a class of AI applications that regulatory frameworks including the EU AI Act designate as prohibited practices, creating a policy-level alignm…
This provision establishes a categorical prohibition on weapons-related use cases across all OpenAI products and services. The explicit inclusion of CBRNE weapons alongside conventional weapons refle…
This provision creates opt-out obligations under CCPA, the California Privacy Rights Act, and analogous statutes in the approximately eighteen additional states named in the policy, and the explicit …
This provision places responsibility for verifying AI-generated outputs on users and discloses the risk of hallucinations and inaccuracies in AI content. In a health insurance context where AI featur…
This provision asserts that Oscar owns derivative AI assets, specifically vectorized data and model relationship information, developed from User Submissions. This assertion of ownership over AI-deri…
This provision requires disputes to proceed through individual arbitration administered by JAMS in New York, New York, and includes an explicit waiver of jury trial and class action participation. Th…
This provision establishes a $100 ceiling on all financial claims against Oura that survive the broader damages exclusion, covering a health-monitoring wearable that collects physiological and biomet…
This provision requires that disputes proceed through individual arbitration rather than court litigation, and prohibits class or representative actions. The provision includes a self-referential cla…
This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categor…
This provision grants PlanetScale unilateral suspension authority triggered by subjective determinations including 'may subject PlanetScale to third party liability' and 'suspected unauthorized acces…
This provision requires customers to prospectively waive all IP-related claims arising from AI-generated output, including direct and indirect infringement claims. For organizations deploying AI outp…
This provision requires disputes to proceed through individual arbitration before a sole arbitrator whose decision is final subject to limited FAA review, and prohibits users from participating in cl…
These provisions impose use-case specific restrictions that go beyond Replicate's own acceptable use policy, including prohibitions on competitive product development using model outputs, surveillanc…
This provision establishes that the act of publishing a community model on the platform creates a permanent, non-revocable license running to all platform users, which the publisher cannot subsequent…
This provision sets an exceptionally low monetary ceiling on recoverable damages from Replicate, including for claims involving data loss, security breach, service interruption, and breach of contrac…
This provision asserts contractual limitations on customers' ability to dispute charges through external mechanisms including card network chargebacks, and places the burden of proof on the customer …
This provision requires customers to assume defense costs and liability for a broad range of claims arising from their use of the platform, including claims arising from AI-generated outputs and thir…
The provision establishes Robinhood's disclosure obligation regarding options risk characteristics and allocates financial risk responsibility to the user. This framing creates a contractual record t…
The clause establishes Robinhood's unilateral authority to execute forced liquidations based on margin thresholds it sets (which may exceed regulatory minimums) or its own risk assessment, without re…
The clause establishes the firm's unilateral authority to adjust margin terms and execute account liquidations based on its assessment of risk exposure, without requiring advance customer notificatio…
This provision establishes the regulatory framework governing cryptocurrency transactions on the platform. By clarifying that crypto assets are not securities and that the crypto subsidiary operates …
The risk disclosure serves an informational function within the margin account agreement, establishing that Robinhood has communicated known hazards of leveraged trading. This disclosure creates a do…
The disclosure provision functions as a foundational risk communication requirement within margin account agreements, ensuring that account holders receive structured information about options tradin…
This provision requires that unresolved disputes between U.S. users and Roblox proceed through individual arbitration administered under AAA Consumer Arbitration Rules, rather than through state or f…
This provision establishes the legal basis under which Roblox asserts that users cannot claim monetary compensation or legal title to virtual items or Robux, including in the event of account suspens…
This provision engages right-of-publicity law, GDPR Article 9 (where biometric data is implicated), and state biometric privacy statutes (including Illinois BIPA) by prohibiting the input or generati…
This provision addresses the use of AI generation tools to produce NCII, an area of active state and federal legislative development in the United States and under the EU AI Act framework; the prohib…
This provision establishes a mandatory reporting and indefinite suspension mechanism that engages U.S. federal CSAM reporting obligations applicable to electronic service providers; it also operates …
This provision discloses that third-party social media cookies embedded in Spotify's web properties are capable of cross-site browser tracking and interest profiling, with downstream effects on conte…
This provision creates a two-tier dispute resolution framework: users who have executed the Advisory Agreement are subject to mandatory arbitration as defined in that separate document, while users w…
This provision restricts a specific category of potentially harmful synthetic media use involving the attribution of sensitive personal characteristics including medical conditions, disabilities, and…
This provision conditions the applicability of the DPA's processor obligations and protections on formal execution, meaning organizations that have not completed this step may not have a compliant Ar…
This provision restricts a category of high-risk synthetic media deployment involving political, journalistic, and public interest content, and establishes a consent-gated framework that differentiat…
This provision establishes that account termination for code of conduct violations may result in ticket cancellation without refund, and that Ticketmaster may take enforcement action against accounts…
This provision establishes a monetary ceiling on all claims against Ticketmaster and Live Nation, including claims arising from ticket purchases, marketplace use, and event attendance, and asserts a …
This provision establishes an absolute prohibition category with no stated carve-outs, and its scope extends to content that facilitates harm in addition to content that depicts it. The provision eng…
This provision establishes a unilateral change mechanism under which the data practices governing health, financial, and behavioral information may be altered without advance individual notification,…
This provision requires evaluation under the HIPAA Security Rule and Breach Notification Rule, which establish standards for the protection of electronic Protected Health Information in transmission.…
This provision authorizes cross-site behavioral tracking and targeted advertising on digital properties through which users may also access health plan information, benefit details, and medical recor…
This provision establishes a permanent, royalty-free IP assignment covering any content, ideas, or know-how submitted through the site, with no carve-out for proprietary or commercially sensitive sub…
This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreem…
This provision places affirmative opt-in verification obligations on customers, aligning with TCPA, CAN-SPAM, and CASL requirements, and establishes that failure to comply exposes customers to accoun…
This clause establishes eligibility criteria for platform access that are not defined by objective thresholds, granting ActiveCampaign unilateral authority to restrict or terminate service to custome…
This provision establishes that use of purchased or rented contact lists through the platform constitutes a policy violation, which could trigger account suspension under the general enforcement prov…
This clause establishes that continued use of the platform following any form of notice constitutes binding acceptance of revised terms, including changes that could alter permitted use categories, r…
This clause establishes that ActiveCampaign conducts ongoing automated monitoring of both customer-side activity and recipient-side engagement data, with unilateral authority to remove content and in…
This provision establishes the operational authority and standards under which the carrier may exercise passenger denial or removal authority. It codifies the carrier's discretionary gatekeeping func…
This clause operationalizes federal accessibility requirements by explicitly binding the carrier to statutory compliance standards and establishing a service obligation framework. It clarifies the re…
This provision establishes an internal whistleblower mechanism specific to RSP compliance, with anti-retaliation protections, providing a formal channel through which employees can raise concerns abo…
This provision discloses Anthropic's internal governance mechanism for frontier AI risk management, which is operationally relevant to enterprise customers and regulators assessing whether the model …
This provision defines the operational permission architecture that governs what Claude will and will not do in any given deployment, making it the primary mechanism by which operators customize mode…
This provision allocates tax compliance responsibility to Customer and implements a gross-up mechanism to protect Anthropic's net revenue. The gross-up calculation compounds by including taxes on the…
This provision discloses that Anthropic conducts and publishes model welfare assessments, including evaluations of functional emotional states, task preferences, and the model's expressed attitudes t…
The revised CB-2 threshold introduces greater operational specificity into the definition of what constitutes a threshold-crossing capability, which affects how future model assessments are conducted…
This provision establishes that the operational scope of permitted and prohibited uses of Opus 4.8 is governed by a separate Usage Policy document, meaning the system card alone does not constitute a…
This provision discloses the categories of training data sources and the operational practices of Anthropic's web crawler, which are relevant to copyright, data rights, and consent considerations tha…
This provision establishes a structural check on Anthropic's unilateral control over its own safety audit process by vesting reviewer selection approval authority in the LTBT, an entity distinct from…
This provision describes the access control architecture for model weights as a core ASL-3 security requirement, establishing procedural controls including multi-party authorization and hardware auth…
This provision describes the technical architecture through which Anthropic monitors and filters user interactions with its models at ASL-3 capability levels, establishing that both real-time and asy…
This provision discloses that Anthropic's adherence to its own stated RSP requirements has not been complete, with specific procedural gaps identified in evaluation timelines, methodology, and buffer…
This provision establishes a non-negotiable safety floor across all deployment contexts, meaning operators building products on the Claude API cannot contractually or technically override these restr…
This provision provides documented evidence that Anthropic conducted structured pre-deployment safety evaluations for catastrophic risk scenarios, which is operationally relevant to enterprise custom…
This provision is a material disclosure of known limitations in the model's safety architecture, which is operationally significant for any operator making safety representations to their own users b…
This provision establishes the core operational trigger mechanism of the RSP: internally defined capability benchmarks that create mandatory internal obligations for Anthropic to upgrade safeguards a…
This provision establishes a gatekeeping mechanism for adjusted safeguard access, requiring partners to satisfy Anthropic's assessment of trustworthiness and use-case benefit before receiving modifie…
This provision establishes Apple's stated architectural data handling commitment for server-side AI processing, asserting a no-retention and no-access design for Private Cloud Compute. The operationa…
This provision discloses a third-party data routing pathway that is activated when users enable the ChatGPT extension, with data handling for those requests governed by OpenAI's terms rather than App…
This provision is operationally significant because AI-related subprocessors may process customer content data, not merely metadata, which creates additional considerations under GDPR's requirements …
This provision is operationally significant for EU, UK, and Australian customers because it establishes that personal data may be transferred to and processed in the United States, requiring valid tr…
This provision establishes the operational mechanism for GDPR Article 28(2) compliance, requiring Atlassian to provide prior notice of subprocessor changes and permitting customers to object to new s…
This provision establishes the formal subprocessor register that Atlassian is contractually and regulatorily required to maintain under its DPA and GDPR Article 28. Enterprise customers rely on this …
This provision establishes that Baseten holds ownership rights over a category of data derived from Customer platform activity, which may have implications for Customer data governance policies and c…
This provision establishes a fixed twenty-day data retrieval window post-termination, after which Customer Content is destroyed, requiring Customer organizations to operationalize data extraction bef…
This provision establishes that Customer organizations have no mechanism to withdraw or restrict Baseten's use of feedback once submitted, and that Baseten may sublicense such feedback, which may hav…
This provision establishes the operational mechanism through which GDPR Article 28 sub-processor approval obligations are managed, and limits Customer's recourse upon unresolvable sub-processor objec…
This provision establishes a sixty-day advance written notice requirement to prevent automatic renewal, which creates a contract management trigger for enterprise procurement calendars managing annua…
This provision establishes that Baseten may suspend access to production ML deployments for overdue payments, which may affect Customer's operational continuity and downstream End User services if bi…
This provision places defense and indemnification obligations on Customer for claims arising from alleged warranty breaches, including claims based on the allegation of a breach even where no actual …
This provision establishes the operational basis for Bumble's content moderation infrastructure and investigation procedures. It clarifies that message collection and automated scanning are integral …
Contractually shortened statutes of limitations in consumer financial services agreements are subject to enforceability challenges in certain jurisdictions, particularly where state law establishes m…
The collection and retention of biometric data (selfie) and government-issued identity document images during trusted device enrollment implicates state biometric privacy statutes including the Illin…
This provision establishes that early CD withdrawals result in penalties that may reduce principal if accrued interest is insufficient to cover the penalty amount, with the penalty magnitude increasi…
This provision implements the Regulation E affirmative opt-in requirement for overdraft fees on everyday debit card transactions. The default opt-out position means that without affirmative election,…
This provision defines the primary fee trigger and waiver mechanism for overdraft charges across eligible Chase personal checking accounts. The $50 threshold and next-business-day cure window are ope…
This provision establishes that Chase retains unilateral discretion over the foreign exchange rate applied to international wire transfers, and that the rate includes a commission component, which is…
This provision creates a unilateral enrollment and cancellation right for any individual co-owner on joint accounts, which means one co-owner can modify the overdraft protection status of a shared ac…
The unilateral closure right without prior notice is a standard term in retail banking agreements but has operational significance for customers who rely on the account for direct deposits, automated…
This provision requires individual arbitration for dispute resolution and forecloses class action participation, which are standard but material terms in consumer financial services agreements. The C…
The authorization to apply Social Security and federal benefit payment deposits to overdraft repayment intersects with federal protections under 31 C.F.R. Part 212, which governs the treatment of cer…
The scope of disclosure permitted under the Privacy Notice category is not defined within the agreement itself and requires reference to the separate Privacy Notice incorporated into the document. Th…
This provision establishes that the accountability and transparency obligations for Merchant Customer data may rest with the Merchant rather than Checkout in certain processing contexts, which has di…
This provision identifies the categories of third-party recipients of personal data and notably includes advertising networks and background screening companies among the service provider categories,…
This provision establishes the operative mechanism for individuals to exercise data subject rights and qualifies the scope of those rights by jurisdiction and by Checkout's legal retention obligation…
This provision establishes an operative opt-out right for California residents under CPRA for cross-context behavioral advertising, which is a distinct mechanism from a sale opt-out, and the notice s…
This provision establishes the legal transfer mechanisms Checkout relies on for cross-border data flows from the UK and EEA, and discloses that transfer impact assessments are conducted, which are op…
This provision establishes a secondary automated biometric processing mechanism, distinct from the primary identity verification function, that may impose a temporary service access block on individu…
This provision reserves to Kit open-ended enforcement authority over content that does not fall within enumerated prohibited categories, based on an undefined standard of 'potentially harmful or misl…
This provision establishes that ongoing platform access is contingent on maintaining acceptable email performance metrics as assessed by Kit, with termination consequences and no data portability ent…
This provision establishes a platform-level permission standard that requires documented proof of consent for each subscriber, and limits purchase-based consent to a 12-month window, creating an ongo…
This provision establishes that accounts operating in enumerated industry categories do not have guaranteed platform eligibility and are subject to individual assessment, creating operational uncerta…
This provision establishes that list collection methodology is a condition of platform access, and that accounts using non-permission-based lists are subject to immediate termination without refund o…
This provision establishes the mechanism and conditions under which the contractual relationship between Cursor and users may be altered. It allocates to Cursor the authority to change material terms…
This provision references specific remediation timeline commitments as a contractual obligation, but the actual timelines are not disclosed in this public document and must be reviewed in the Securit…
This provision discloses that Databricks' internal security monitoring operations run on the same platform sold to customers, processing security signals from systems that may include customer-adjace…
This provision establishes that the enforceable security obligations are located in the Security Addendum of the customer agreement rather than in the public Trust Center disclosure, making the Adden…
This provision discloses that employee access to customer data is subject to internal controls, but the document does not specify the mechanisms, such as role-based access control, audit logging, or …
This provision distinguishes between certifications Databricks holds as an organization and compliance frameworks for which it offers specific product configurations, a distinction that is operationa…
This provision establishes a data sharing mechanism that extends beyond Disney's own platforms to third-party advertising ecosystems, using identifiers and hashed email addresses as linkage data. Und…
This provision discloses that personal and viewing information shared with Hulu's business partners exits the scope of this privacy policy and becomes subject to each partner's own privacy practices.…
This provision establishes a dual-role access structure across a portfolio of more than 40 named brands, under which each subsidiary entity may use personal information for its own independent data c…
The collection of video and still images at physical properties engages biometric privacy frameworks in jurisdictions such as Illinois (BIPA), Texas, and Washington, depending on whether collected im…
This provision authorizes account termination for any reason without prior notice, which may affect access to purchased products' cloud-connected features, stored data, and active services. The autom…
This provision allocates full verification responsibility and reliance risk to the user for all AI-generated outputs across text, image, and audio modalities, and disclaims Anker's liability for any …
This provision establishes that account creation and mobile number provision each independently constitute affirmative consent to receive marketing communications across all Anker brands, with opt-ou…
This provision permits Anker to assign the entire agreement, including all rights and obligations, to a third party without user notification or consent. This means users' contractual relationship co…
This provision requires users to make affirmative representations regarding their sanctions status and affiliations at the point of purchase or use, and prohibits downstream re-export to embargoed re…
The irrevocable and sublicensable nature of this license means that once content is submitted, the agreement does not provide a mechanism for users to revoke Anker's right to use that content in conn…
This provision authorizes Anker to unilaterally modify device and app functionality through mandatory updates on terms defined solely by Anker, including the criteria for what constitutes a critical …
This provision establishes a dual-role framework under which Experian may operate as either a data controller or a processor depending on the context, and directs consumers to the relevant business c…
This provision establishes that retention periods are not fixed and may vary by data category, product, and purpose, without specifying maximum retention durations. The absence of stated retention ti…
This provision acknowledges the use of traffic analysis technology on experian.com but does not specify the types of data collected, the technologies used, or any retention or sharing practices at th…
This provision establishes the scope and mechanism of consumer opt-out rights, including the specific clarification that profiling for legal or significant effects is not offered as an opt-out option…
This provision establishes a geographic differentiation in Experian's sensitive personal information collection practices, with consumers in seventeen named states excluded from the collection and sa…
This provision establishes a categorical exclusion of all damage categories, including those arising from negligence or tortious action, which represents the broadest possible liability shield availa…
This provision establishes that GPC-based opt-outs operate at the browser identifier level and do not automatically extend to a consumer's full Experian account or other personal information records …
This provision establishes a unilateral modification mechanism that requires no affirmative user notification beyond a site posting and deems continued use as contractual acceptance, which has known …
This provision disclaims all warranties covering the accuracy and reliability of information presented on the site, which has operational significance for users who access credit-related information …
This provision distinguishes the treatment of User Comments from User Videos: while the video license terminates within a commercially reasonable time after removal, the comment license has no termin…
This provision requires users to bear financial responsibility for defending GM against third-party claims that arise from user conduct or content, including attorney's fees. The obligation survives …
This provision requires users in all U.S. states and internationally to pursue claims against GM in New York courts under New York law, which may create a practical barrier for users located outside …
This provision disclaims liability for unauthorized access to personal and financial information stored on GM's servers, as well as for personal injury and property damage arising from use of the Web…
This provision establishes that GM may modify material terms without prior notification and that continued site use operates as acceptance of changes. Users bear the responsibility of independently m…
This provision establishes a broad license that extends beyond operating the Web site to encompass GM's general business, promotional activity, and redistribution through any media channel. The licen…
This provision grants GM unrestricted discretion to terminate accounts and delete content without prior notice, and imposes a permanent ban on new account creation following termination. The absence …
This provision incorporates three external policy documents by reference, including a Microsoft policy, creating a multi-document compliance obligation. The Required Mitigations at aka.ms/AIfilters e…
Organizations with Copilot Business or Enterprise subscriptions renewing on or after 5 March 2026 are subject to different governing terms, requiring a contract transition review to assess whether ma…
This provision establishes the contractual ownership position as between GitHub and the user for AI-generated output. However, the agreement does not address ownership questions that may arise under …
This provision establishes the default data lifecycle for Prompt data and defines the conditions under which retention is triggered. Enterprise organizations with source code confidentiality requirem…
This provision establishes that GitHub contractually allocates all responsibility for Suggestion-related outcomes to the user, including potential third-party intellectual property claims. Organizati…
This provision establishes that the operative terms governing GTM use are distributed across at least three external documents, each subject to unilateral modification, meaning the full scope of user…
This provision establishes that a data processing agreement under the Google Ads Data Processing Terms governs applicable GTM deployments, which is operationally significant for GDPR Article 28 compl…
This provision discloses that Google collects operational and tag deployment data from GTM users, but includes a specific limitation that this data will not be shared with other Google products witho…
The provision creates a bifurcated update framework: user-configurable updates for routine content changes, and automatically-applied updates when Google determines a critical security, operability, …
The clause operationalizes a unilateral amendment mechanism whereby Google can alter the governing terms with advance notice, and automatically apply those modifications retroactively to a user's ent…
This provision establishes an explicit prohibition on autonomous lethal weapon applications, requiring human authorization or control as a precondition for any weapons-related use, which directly eng…
This provision establishes that prompt engineering or other technical methods used to elicit policy-violating outputs from Groq models constitutes a policy violation, extending acceptable use obligat…
This provision extends Customer compliance obligations to third parties accessing Groq services through the Customer, creating a due diligence responsibility for API operators and platform developers…
This provision establishes that Groq retains discretionary authority to investigate Customer conduct and take enforcement action based on suspected rather than confirmed violations, without specifyin…
This provision grants Groq the contractual right to request use-case and compliance information from Customers at any time, which may require Customers to disclose operational details about their AI …
This provision establishes procedural constraints on Harvey's unilateral modification authority and creates a contractual termination right tied to adverse term changes. The absolute restriction on u…
This provision establishes a 30-day deadline for disputing invoices and authorizes Harvey to assess compounding interest on overdue undisputed amounts and to suspend Service access for nonpayment. Th…
This provision creates an operational CCPA compliance obligation requiring a functioning opt-out mechanism for targeted advertising data flows. The terms authorize disclosure of website visitor Perso…
DPF certification establishes the legal transfer mechanism for Personal Data flowing from the EU, UK, and Switzerland to Harvey's US servers, and the provision states that DPF Principles override con…
This provision authorizes disclosure of Personal Data to third-party counterparties during due diligence processes before any transaction is completed. The notification commitment is stated but does …
This provision establishes a structural bifurcation of data controller and data processor responsibilities that directly determines the path for data subject rights requests. End users whose employer…
This provision establishes an explicit contractual prohibition on AI model training from customer inputs and outputs, and extends that restriction to Subprocessors. The carve-out for cloud storage pr…
This provision allocates third-party claim risk between the parties based on the source of the allegedly infringing or harmful content. The customer's indemnification obligation for claims arising fr…
This provision requires disputes to proceed through private arbitration under specified institutional rules, with the seat and governing rules varying by customer geography. The threshold of $250,000…
This provision establishes the maximum recoverable damages under the agreement for most claim types and sets a distinct higher threshold for data breach and confidentiality-related claims. Compliance…
This provision establishes that Harvey collects Personal Data about individuals who have not directly interacted with Harvey, sourced from third-party marketing vendors, research firms, and event org…
This provision grants a data use license that is perpetual and survives contract termination, covering anonymized Customer Data and Usage Data for machine learning model training, benchmarking, produ…
The indemnification obligation for the nature, origin, or content of Customer Data is broad and applies to any third-party claim connected to that data, including privacy and data protection claims a…
The refund mechanism for Customer-initiated termination for cause is conditioned on the termination being both proper and undisputed, which introduces a potential dispute resolution dependency before…
This provision establishes a 90-day advance written notice requirement to prevent automatic renewal, which applies at the end of both the Initial Term and each subsequent Renewal Term. Enterprise cus…
This provision establishes that executed Order Forms create irrevocable payment commitments for the full term, absent specific Order Form carve-outs. The annual CPI-indexed fee adjustment mechanism m…
This provision authorizes Contentsquare to charge overage fees at its then-applicable rate when usage thresholds are exceeded, invoiced annually in arrears. Customers may accumulate significant overa…
Deemed execution of the DPA and SCCs at MSA signing means the parties are contractually bound by those documents without separate signature, and the DPA terms are subject to unilateral update by Cont…
This provision establishes a mutual 12-month fee-based liability cap and a broad exclusion of consequential and indirect damages. The carve-outs for gross negligence and willful misconduct are mutual…
This provision extends indemnification obligations to actions taken by AI agents operating on the user's behalf, to disputes with third-party retailers and delivery providers, and to the user's downs…
The provision expressly discloses that automated messages may be delivered outside quiet hours defined by federal, state, or local law, which engages the Telephone Consumer Protection Act (TCPA) and …
This provision authorizes Instacart to charge any active payment method on file at renewal, including updated card information provided by card issuers through card-updater services, without requirin…
This provision extends the prohibition on AI training to open-source and non-commercial research purposes, which is a notably broad restriction relative to terms that limit prohibitions to commercial…
This provision establishes that users bear full legal responsibility for automated systems and AI agents acting on their behalf, including sub-agents and downstream processes, and requires technical …
This provision explicitly includes AI prompts, feedback, and voice submissions within the content license scope, and expressly authorizes use of that content for developing and evaluating machine-lea…
This provision places full responsibility on users to identify and withhold HIPAA and HITECH-covered information before posting, and does not establish any technical or administrative safeguards by P…
This provision requires users outside Ohio to litigate any claims in Montgomery County, Ohio, which may create a practical barrier to pursuing legal claims depending on the user's location and the na…
This provision establishes that users are bound by updated terms immediately upon posting, without affirmative notice or a waiting period, and that continued site use operates as consent to any modif…
This provision requires users to bear the full cost of defending Provider and its third-party information providers against any claims arising from user-submitted content or Terms of Use violations, …
This provision authorizes disclosure of a defined set of user data categories including IP addresses, usage history, and posted materials to law enforcement and unspecified third parties based on Pro…
This provision is operationally significant for a legal information platform because it establishes that content, including content provided by attorneys in Interactive Areas, carries no confidential…
This provision establishes that fees paid under an active Order are non-refundable except in the specific termination-for-cause scenario described in Section 5.3, and that recurring billing proceeds …
This provision establishes Linear's unrestricted right to use Service Data once aggregated and anonymized, and asserts Linear's ownership of that data. The practical scope of this right depends on th…
This provision requires that all disputes be litigated in Delaware courts under Delaware law, and establishes a mutual jury trial waiver applicable to any action arising from or related to the Agreem…
This provision establishes a unilateral amendment mechanism that does not require affirmative Customer re-acceptance; continued use of the Service after the 30-day notice period constitutes acceptanc…
This provision establishes that data deletion following termination is not automatic but is triggered by Customer request or workspace deletion, and is subject to a 30-day processing period. Customer…
This provision establishes a mutual liability cap tied to 12 months of fees paid, which may be substantially lower than the value of data or business operations at risk in the event of a service fail…
This provision establishes a structural limitation on the scope of data subject rights exercisable directly against LlamaIndex, creating a dependency on enterprise customers' own privacy notices and …
This provision asserts that LlamaIndex holds exclusive ownership over Usage Data collected from user systems and software interactions, and authorizes its use for any lawful purpose including product…
This provision establishes a usage-triggered automatic billing cycle on a weekly basis, meaning charges can be incurred without a separate affirmative enrollment action each billing period once the t…
This provision creates a broad user-side indemnification obligation covering not only intentional violations but also third-party use of the user's account credentials, which may include unauthorized…
This provision authorizes cross-context behavioral advertising using persistent identifiers shared with third-party ad networks, enabling user tracking across nonaffiliated websites and services beyo…
This provision authorizes disclosure of personal data to prospective acquirers or creditors during deal negotiations and in insolvency proceedings, which may occur before any transaction is finalized…
This provision operates as a present-tense IP assignment: upon submission of any feedback, all intellectual property rights in that feedback transfer to LlamaIndex. The clause covers not only direct …
The policy does not specify fixed retention periods for any personal data category, applying instead a general reasonableness standard with open-ended extensions for legal and business purposes, whic…
This provision authorizes disclosure of individual user activity data to employers without specifying what categories of usage data may be shared or what notice, if any, is provided to the individual…
This provision authorizes LlamaIndex to create derived data profiles about users beyond the information directly collected, which may be used for targeted advertising, personalization, or other purpo…
This provision grants LlamaIndex broad discretion to terminate or suspend access without notice, cause, or liability, which may affect organizational users who depend on the Service for operational w…
This provision establishes an automatic renewal obligation at rates that may differ from the original Order price, creating a billing exposure if Customer fails to provide timely non-renewal notice b…
This provision determines the legal framework under which disputes are resolved and the forum in which litigation must occur, with direct implications for the cost and procedural context of any dispu…
This provision establishes that non-payment with ten days written notice is sufficient to trigger suspension of all Product access and Support, creating a direct operational risk for organizations th…
This provision establishes Atlassian's obligation to defend and indemnify the Customer for IP infringement claims arising from authorized product use, while identifying four categories of use that re…
This provision permits Atlassian to modify the Agreement, including the DPA governing Customer Data processing, mid-term for paid subscriptions where legal compliance or product changes are cited, wi…
This provision authorizes recurring charges to a stored payment method across multiple billing events, including scope-of-use overages that may not be individually pre-approved by Customer, creating …
The use of data providers and aggregators to supplement first-party data collection is a practice that may require evaluation under applicable law, particularly regarding notice and consent obligatio…
This provision grants a broad set of parties, including Marqeta's third-party designees, audit access to Customer's business practices and compliance records for the duration of the agreement and at …
This provision permits Marqeta to commercially use and disclose pseudonymized transaction and cardholder data derived from Customer's program at a population level. While Customer's identity is prote…
This provision authorizes Marqeta to alter operational, pricing-adjacent, and service-related terms with 30 days' notice without Customer's consent, while protecting a defined set of core legal provi…
This provision establishes that Customer feedback, enhancement requests, and recommendations become Marqeta's exclusive intellectual property. Customer's license to use the system and deliverables is…
This provision establishes that individuals whose personal data is processed through Marqeta's payment and card program infrastructure are subject to different and separately published privacy terms,…
This provision establishes a joint controller arrangement across three legal entities under GDPR, which requires a documented joint controller agreement under GDPR and requires that the essence of th…
This provision establishes Alameda County, California as the exclusive litigation forum for all disputes and eliminates jury trial rights for both parties. Business customers located outside Californ…
This provision requires Marqeta to maintain a compliant CCPA opt-out mechanism for California residents and to honor Global Privacy Control signals as an opt-out preference signal, with the Californi…
The explicit reference to logging text entered during sessions is operationally distinct relative to commonly observed tracking disclosures and may encompass form field content entered before submiss…
This provision establishes the legal basis under which Meta processes, distributes, and modifies user-generated content across its platform and with service providers. The license is transferable and…
This provision establishes that the model's safety design assumes the presence of additional system-level guardrails, meaning deployments that omit these tools operate outside the safety architecture…
This provision creates an explicit responsibility boundary: Meta's safety evaluations cover 12 languages and up to 5 input images, and any deployment extending beyond those parameters operates withou…
This provision establishes that a broad range of user data, including content, messages, device identifiers, location data, and transaction records, may be accessed and shared with government and civ…
This provision establishes a two-tier dispute resolution framework: consumer disputes are subject to the user's local law and courts, while business and non-consumer disputes are exclusively assigned…
This provision establishes the contractual framework within which commercial and research use of Llama 4 is permitted, and incorporates by reference both the Acceptable Use Policy and the Llama 4 Com…
This provision establishes the operational timeline and conditions under which user content is retained after a deletion request. The retention carve-outs for legal obligations, safety, technical lim…
This provision establishes that Meta may incorporate user identity signals including name and profile photo into commercial advertising displays without user compensation. The practical scope is limi…
This provision establishes that there is no uniform or disclosed maximum retention period for user data, and that Meta may retain information for extended durations based on internally assessed crite…
This provision creates a layered contractual structure in which supplemental terms are automatically incorporated based on product usage, with those terms superseding the base agreement in cases of c…
This provision establishes the foundational commercial model of the agreement: free service access in exchange for personalized advertising consent. The terms authorize use of personal data including…
This provision discloses that identifiable categories of user-generated content and AI interaction logs from Meta's consumer platforms were incorporated into model pretraining. Organizations deployin…
This provision establishes that user identification and ad personalization based on Meta's collected data extends to third-party app environments through Meta Audience Network, meaning Meta's data pr…
The governance structure operationalizes Microsoft's responsible AI commitments through defined accountability assignments, systematic review procedures, and regulatory reporting mechanisms. This est…
This provision establishes that a persistent identifier enabling cross-app tracking is generated by default in Windows and made available to third-party developers and advertising networks, which may…
This provision establishes that voice data, a category that may constitute biometric information under some state laws and a sensitive personal data category under others, is collected across multipl…
This provision establishes the legal mechanism Microsoft relies on for transfers of personal data from the EU, UK, and Switzerland to the United States, and defines Microsoft's liability posture for …
This provision establishes a hierarchy of contractual terms that is directly relevant to enterprise customers assessing their privacy and data protection posture under Microsoft contracts, and determ…
This provision establishes that users of preview and free products operate under a materially different data collection and privacy control environment compared to standard Microsoft products, which …
This provision discloses a data enrichment practice that may implicate state data broker registration laws, GDPR transparency requirements regarding data sourced from third parties, and CCPA notice o…
The clause operationalizes a specific legal mechanism under data protection frameworks that permits data processing for product improvement and feature development without requiring explicit user con…
This scope exclusion establishes that the Privacy Policy's protections and obligations apply only to non-business use cases. For commercial users processing personal data, the data controller-process…
IP addresses are classified as personal data under GDPR in the EU, and the inclusion of 'other statistics' creates an open-ended category of automatically collected data that is not bounded by the pr…
The provision uses an open-ended 'including but not limited to' formulation that does not limit collection to the listed categories, which means actual data collection could extend beyond name, phone…
The provision does not identify the specific cookies used, distinguish between functional and tracking cookies, or describe what information is collected through cookies, which may be insufficient un…
This provision establishes a mutual cap on aggregate liability equal to 12 months of fees under the applicable Service Order and excludes recovery of consequential and indirect damages by either part…
This provision establishes a post-termination data retention and use right for Modal covering aggregate and anonymized usage data, which operates as an exception to the general data deletion obligati…
The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insu…
The provision establishes that policy changes become effective immediately upon posting without advance notice, email notification, or a defined review period, which may be inconsistent with GDPR req…
This provision establishes a processor-to-controller breach notification timeline of 48 hours, which is shorter than the GDPR's 72-hour controller-to-supervisory-authority window, providing Customer …
This provision establishes that Customer cannot block a new subprocessor appointment without exiting the service entirely, and that email notification of subprocessor changes requires Customer to aff…
This provision establishes a contractual prohibition on AI model training using Customer Data as a default, requiring affirmative written consent before any such use. Because Input and Output are cla…
This provision establishes that Customer bears the full defense and indemnification burden for any third-party claims arising from Customer Data, including claims that Customer Data infringes third-p…
This provision establishes that any suggestions, comments, or other feedback submitted by Customer to Modal are subject to a broad, perpetual, and irrevocable license that cannot be withdrawn, and th…
This provision establishes the legal basis for cross-border personal data transfers by Modal, incorporating EU SCCs (Modules 1-3), UK IDTA, and Swiss law provisions by reference into the DPA. The adv…
The provision does not identify the third parties receiving personal data, does not describe the contractual mechanism through which the stated obligation is enforced, and does not specify which cate…
This provision establishes that Customers are financially obligated for the full committed service term and amount regardless of whether they use the Service, creating a fixed cost exposure that does…
This provision establishes that monday.com sources personal data about prospective customers from commercial data brokers and professional networking platforms, meaning individuals may have profile d…
This provision establishes that interactions with monday.com personnel including customer experience and product consultants may be subject to automatic recording and transcription, and that session …
This provision establishes a contractual allocation of data controller responsibilities to Customers for all personal data submitted to the platform as Customer Data, requiring Customers to independe…
This provision asserts that a single act of accepting the terms of service operates as consent to all data processing purposes described in the policy for users in consent-required jurisdictions. Whe…
This provision establishes that privacy designations applied to boards within the platform do not restrict access by Account Admins acting on behalf of the Customer organization, meaning personal dat…
This provision may require evaluation under GDPR Article 28, which requires that controllers engage processors only under a binding contract specifying specific data protection obligations. Reliance …
This provision authorizes AI-powered processing of communication content across three channels (calls, chatbot, email) for operational and commercial analytics purposes. The scope of AI processing ap…
This provision discloses a substantial advertising technology ecosystem operating on Quest's website, with data flowing to approximately 30 named third parties for targeted advertising, analytics, an…
This clause establishes that users bear the full financial obligation for the billing period regardless of usage or cancellation timing, and that non-payment triggers a monthly compounding late fee, …
Collection of Social Security Numbers and government identifiers from job applicants constitutes Sensitive Personal Information under CCPA/CPRA, triggering specific use limitation and opt-out rights.…
This provision establishes the transfer mechanisms Quest asserts for cross-border Personal Data flows, including the EU-U.S. DPF, UK Extension, Swiss-U.S. DPF, and EU SCCs. DPF certification is subje…
This clause establishes that account access and continuity are not contractually guaranteed and that termination does not require cause, notice, or a cure period, which is operationally significant f…
This clause establishes that users are contractually bound by updated terms upon continued use, without requiring affirmative notification or re-consent, which means material changes to rights, oblig…
This clause establishes a broad user-side indemnification obligation that includes attorneys' fees and any claims of any kind arising from use of the Service, which creates financial exposure for use…
This provision creates a bifurcated terms structure based on user location, ensuring compliance with EU and UK regulatory frameworks that may impose requirements distinct from those in the primary te…
This provision establishes an internal governance gate that defines the conditions under which a frontier model may be released, creating a documented procedural commitment that downstream API operat…
This provision establishes a 30-day deletion timeline with multiple categorical exceptions, and separately acknowledges that content already de-identified and incorporated into model training dataset…
This provision establishes a technical enforcement mechanism restricting voice output to a defined set of pre-approved voices, directly addressing fraud, impersonation, and voice cloning risks identi…
This provision establishes a post-training behavioral restriction targeting voice-based biometric identification, addressing privacy and surveillance risks associated with audio input processing in a…
This provision establishes that employer-level administrators have access to individual user content within enterprise accounts, and separately that OpenAI may disclose account existence to an employ…
This provision establishes a behavioral distinction between prohibited ungrounded inference and permitted hedged sensitive trait attribution, addressing allocative and representational harms identifi…
This provision establishes a prohibition on use of OpenAI services for election-related influence operations, including domestic political campaigning and demobilization, which is operationally signi…
This disclosure establishes that GPT-4o's safety mitigations may not perform consistently across all real-world audio conditions, which is operationally relevant for API operators deploying voice-ena…
This provision establishes OpenAI's enforcement authority, including access termination, and discloses the existence of an appeals mechanism, though the policy does not specify timelines, standards, …
This clause establishes the procedural mechanism by which contractual obligations may be unilaterally modified by the service provider, requiring users to either accept changes through continued use …
This provision aligns with prohibitions established under the EU AI Act for real-time remote biometric identification systems in publicly accessible spaces, and its inclusion signals that OpenAI's co…
This provision establishes the documented basis for GPT-4o's medium overall risk classification under the Preparedness Framework and discloses the methodology and findings of a structured persuasion …
This clause creates a binding compliance obligation tied to external policy documents, meaning the substantive conduct rules users must follow are defined in policies separate from the main agreement…
This provision establishes that government and defense sector entities seeking to use OpenAI services for national security or intelligence functions must obtain prior approval from OpenAI. The absen…
This provision establishes OpenAI's unilateral authority to revoke access based on a reasonableness standard, without specifying procedural requirements, timelines, or defined criteria beyond the rea…
These prohibitions mirror prohibited AI practices enumerated in the EU AI Act, including social scoring by public authorities, emotion recognition in the workplace and educational settings, and crimi…
This provision authorizes the collection and retention of personal data belonging to individuals who have not agreed to any OpenAI terms of service, creating a data processing relationship with non-u…
This provision discloses an inbound data flow from third-party advertisers that includes individual purchase transaction data, which is used for ad measurement and personalization; this practice enga…
This provision establishes a default opt-in posture for AI model training using personal user content, requiring users to affirmatively opt out rather than affirmatively consent; in jurisdictions whe…
This provision establishes a disclosed data minimization practice and an operational opt-out mechanism for image training data that the document states was applied to the GPT-4o series, creating a do…
This clause establishes an external policy document as a binding component of the service agreement, creating enforceable requirements that govern how users may distribute or publicize service output…
This provision establishes that cross-site behavioral tracking and sharing of online activity with advertising partners occurs through Oscar's Sites; the policy provides an opt-out mechanism via the …
This provision authorizes pre-transaction disclosure of personal information to potential acquirers or transaction counterparties before any transaction is completed, which means personal data may be…
This provision operationally limits the scope of state consumer privacy rights, including CCPA access, correction, and deletion rights, for personal information that qualifies as Protected Health Inf…
This provision authorizes a use of personal information, including de-identification and third-party disclosure for AI development, that is operationally distinct from standard service delivery purpo…
This provision establishes that any content a user posts or submits through the Services is subject to a perpetual and irrevocable license granted to Oscar, including the right to sublicense. The irr…
This provision sets a damages cap of $100.00 or three months of fees paid, whichever is greater, for direct damages, and excludes all indirect and consequential damages. In the context of a health in…
This provision asserts a waiver of California Civil Code Section 1542 for California residents, which, if enforceable, would mean that any release of claims against Oscar in connection with these Ter…
This provision operationalizes state consumer privacy rights for residents of approximately nineteen states and establishes a two-step appeal process, first to Oscar and then to the state Attorney Ge…
This provision requires users to bear the cost of defending Oscar against claims arising from third-party use of the user's account identity, in addition to their own misuse. The indemnification obli…
This provision establishes that Oscar can unilaterally modify the Terms and that continued use of the Services after modification constitutes binding acceptance of the new terms. Users who disagree w…
This provision bundles consent to marketing communications, including automated dialing and pre-recorded messages, into the general agreement acceptance flow. The agreement states that consent to mar…
This provision asserts a non-medical-device characterization and disclaims all liability for health record information, which may warrant evaluation under FDA guidance on mobile medical applications …
This provision establishes that the agreement is subject to unilateral modification by Oura at any time, with continued service use constituting acceptance of modified terms, and that Oura bears no l…
This provision establishes that subscription charges are assessed at the beginning of each term, cancellations do not yield prorated refunds, and the agreement's general refund policy is limited to l…
This provision shortens the limitations period for claims against Oura to one year for non-EU users, which is shorter than the default statutes of limitations in most US states for contract and tort …
This provision extends the indemnification obligation to cover claims arising from use of the user's account by any third party, not only the user themselves. The provision covers attorneys' fees and…
This provision establishes that research participants may have restricted access to their own biometric data during study periods, that the governing agreement and data rights framework shifts to the…
This provision establishes that customers bear the full financial obligation for fees incurred regardless of service outcome, and that PlanetScale retains the right to accrue interest charges and sus…
This indemnification obligation places defense and indemnification costs on the customer for third-party claims arising from Customer Content and any AUP or agreement breach, including breaches by en…
This provision establishes that customer data stored on PlanetScale may be deleted upon account termination, including termination for inactivity, with PlanetScale bearing no retention obligation pos…
This provision grants PlanetScale an irrevocable and perpetual intellectual property license over a broadly defined category of customer-provided materials, including proposals and documents, without…
This provision establishes a liability ceiling tied to recent fee payments, which for low-spend or new customers may represent a materially limited recovery amount relative to potential data loss or …
This provision authorizes physical and records-based audits of customer infrastructure, which may extend to sensitive business systems and data beyond the scope of PlanetScale's database service. The…
The exclusive venue clause requires all disputes to be litigated in San Francisco, California federal or state courts, which may create practical barriers for non-California customers. The agreement …
This indemnification obligation shifts legal defense costs and liability to the user for TCPA-related claims that may arise if the user provides an incorrect or third-party phone number, which is ope…
This provision grants Progressive an unlimited license over submitted materials without time restriction, geographic limitation, or compensation obligation, covering a broad range of content categori…
This provision places the burden on users to monitor the terms page for changes and treats continued site use as binding acceptance of modifications, without requiring affirmative notice or consent f…
This provision requires all website-related disputes to proceed in a specific Ohio county venue, which may present practical barriers for users located outside Ohio, and the enforceability of this fo…
This provision establishes that Progressive bears no liability for credential-based unauthorized access except in cases of its own gross negligence, and that Progressive may suspend account access wi…
This provision limits Progressive's financial exposure for website-related harms including unauthorized data access, with a carve-out only for gross negligence or intentional misconduct, which means …
This provision establishes that prepaid balances are subject to automatic expiration and forfeiture after 12 months, and that customers have no property right or refund entitlement in unused balances…
This provision permits Replicate to alter or discontinue paid service features without notice and without liability, while fee changes require reasonable prior notice before the next renewal period. …
This provision authorizes Replicate to use aggregated and anonymized customer usage data for any legal purpose in perpetuity, including after the agreement ends. The scope of the resultant data licen…
The clause establishes the operational basis for aggregating financial data across multiple accounts held by the user at other institutions, enabling Revolut to perform financial analysis, creditwort…
This clause defines Revolut's data monetization boundaries by restricting a specific category of data transfer—the sale of personal data—while other forms of data sharing (such as with service provid…
Legitimate interests is a legal basis under data protection frameworks that permits processing without explicit user consent when the organization's interests are balanced against individual rights. …
The provision operationalizes a data protection contact channel, enabling users to initiate communication with the Data Protection Officer regarding data handling practices. This establishes a proced…
This clause establishes the mechanism by which the service provider can alter contractual obligations without executing a new written agreement. It designates website posting or email as the binding …
The multi-entity structure clarifies operational responsibility allocation among Robinhood entities, which affects how margin account obligations, risk management, and regulatory requirements are dis…
The provision establishes the operational mechanics of margin account lending, which generates revenue for the broker while creating a contractual authorization for securities lending that occurs wit…
The provision functions as a risk acknowledgment mechanism that conditions options trading access on documented investor comprehension and financial capacity. It creates an evidentiary record that th…
This provision establishes the contractual basis under which Roblox asserts that virtual currency and content purchases are non-refundable, which has particular operational significance for minor use…
Because the Creator Terms are incorporated by reference into the User Terms and apply to all users who access the Services, all users, including those who do not self-identify as creators, are subjec…
The provision delegates to Roblox the determination of what constitutes a material versus non-material change, and what qualifies as a modification made for legal reasons, both of which affect whethe…
The regional appendices establish that users in major regulatory jurisdictions operate under modified terms designed to address local legal requirements, including GDPR for EU users, UK GDPR for UK u…
This provision assigns contractual liability to parents and guardians for all minor account activity, including financial transactions, which has direct implications for purchase disputes, unauthoriz…
The program establishes the sole mechanism through which creators can convert Robux earnings into real currency, and Roblox reserves the right to set and modify the exchange rate, eligibility require…
This provision addresses an area of active copyright and right-of-publicity litigation in the context of AI-generated content; the restriction applies to living artists only and does not extend to hi…
This provision grants Runway broad discretionary authority to suspend accounts without specifying procedural standards, notice periods, or timelines for the appeal process, which may affect enterpris…
These product-specific prohibitions engage COPPA's restrictions on content and data collection directed at children under 13, and extend further to cover all minors under 18 in the context of likenes…
This provision directly engages the FTC Act's Section 5 prohibition on unfair or deceptive practices and may also implicate the Computer Fraud and Abuse Act, wire fraud statutes, and state consumer p…
This provision establishes a data retention and use restriction applicable to third-party LLM interactions within the Salesforce platform, which is a material term for enterprise customers assessing …
This provision establishes that customer AI use is subject to the terms of the Acceptable Use Policy, which governs permitted and restricted uses of Salesforce AI capabilities and may include enforce…
This provision describes a technical de-identification mechanism that operates on data in transit to third-party LLMs, which is directly relevant to compliance obligations under GDPR, CCPA, and HIPAA…
This provision establishes a stated data ownership principle that has direct implications for data portability, deletion, and secondary use rights under GDPR, CCPA, and applicable contractual data pr…
This provision establishes that Cloudflare, Akamai Technologies, and Amazon CloudFront, each designated as Global CDN providers for multiple covered services including B2C Commerce, Commerce Cloud Ei…
Under GDPR Article 28, controllers are entitled to object to changes in sub-processor arrangements. This provision establishes the operational mechanism through which Salesforce delivers advance sub-…
This provision establishes a conditional cross-regional data routing mechanism that activates automatically during failover events without requiring a separate customer election. For customers with c…
The document establishes that generative AI processing by OpenAI and Microsoft Azure is integrated across a broad range of covered services, meaning Customer Data from financial services, education, …
This provision establishes temporary cross-regional data routing affecting customers in the UAE, Israel, Lebanon, Bahrain, Oman, Jordan, Qatar, Kuwait, and Egypt, creating a situation where Customer …
This provision establishes that a category of data, specifically identifying information about customer instances and users, may be processed across Salesforce's global infrastructure regardless of t…
This provision creates a direct operational link between feature configuration decisions and sub-processor inventory: enabling Einstein NLP, generative AI, speech, or analytics features introduces ad…
This provision establishes a bifurcated consent architecture in which browser-level and account-level personal data are governed by separate opt-out mechanisms. Compliance teams should evaluate wheth…
This provision establishes the legal basis and operational scope for Spotify's cross-platform advertising data sharing, authorizing disclosure of browser- and device-associated personal data to third…
This provision discloses that targeting cookies enable cross-site tracking and interest profiling shared with third-party advertisers. Under GDPR and the ePrivacy Directive, processing of this nature…
This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected …
This provision disclaims all warranties applicable to the platform and its content, including warranties of accuracy and security. For a financial services platform where users rely on market data, i…
This provision extends indemnification obligations to claims arising from use of the user's account by any person, including unauthorized users, which may create financial exposure for users in the e…
This provision establishes blanket recording consent as a condition of platform use, covering communications with Stash representatives and agents. The scope of permitted use extends to any use in th…
This provision caps aggregate financial liability at twelve months of fees paid, which for users on lower-tier subscription plans may represent a minimal dollar amount relative to potential investmen…
This provision grants Stash and its successors and assigns the right to derive commercial revenue from user-submitted content for the full term of any applicable intellectual property rights, without…
This provision reserves broad termination authority for Stash, including the ability to delete account data without advance notice. For users holding financial accounts through the platform, this ter…
This provision establishes that any amendment to the Terms of Use becomes binding upon the user through continued platform use, provided notification was delivered through any of the listed channels.…
The scope of data covered by the DPA determines which processing activities are subject to its protections and obligations. Without the full addendum text, it is not possible to confirm whether all p…
This provision restricts deceptive identity representation in AI-generated content, with the scope of the prohibition differentiated by service plan tier; the explicit non-enterprise qualifier create…
This provision establishes the enforcement mechanism for the AUP, granting Synthesia discretionary authority to suspend or terminate access based on its assessment of violation severity and intent, w…
This provision establishes an explicit contractual prohibition mirroring obligations under US, UK, and EU counterterrorism laws, and reflects the multi-jurisdictional compliance framework applicable …
This provision establishes a consent-gated permission structure for commercial advertising use of avatar content, requiring affirmative written authorization from Synthesia for Stock Avatars and indi…
This provision bars a specific category of data extraction activity that has become a contested area in AI development and intellectual property law, placing contractual restrictions on users who may…
This provision establishes a contractual obligation to preserve AI content provenance mechanisms, which aligns with emerging regulatory requirements under the EU AI Act and voluntary industry framewo…
This provision establishes the legal framework under which Synthesia processes Customer Data, positioning the business customer as the data controller and Synthesia as the data processor. This design…
These restrictions establish specific commercial and revenue-based thresholds for permissible stock audio use, with the billion-dollar revenue threshold creating a differentiated permission structure…
Version updates to a DPA may alter sub-processor lists, transfer mechanisms, security obligations, or data subject rights procedures. Organizations that executed a prior version should review the Jan…
This provision establishes that the DPA operates alongside the Customer Terms of Service, which means terms in both documents apply to the processing relationship. Compliance teams should assess both…
The provision includes an authorization for wireless carriers to disclose user account and device information to Ticketmaster, which is a disclosure mechanism distinct from Ticketmaster's own data co…
This provision permits users as young as 13 to hold accounts with parental authorization, and places responsibility for minors' conduct and use of the Marketplace on parents or legal guardians who ac…
This provision extends the user's indemnification obligation to cover event organizers, suppliers, advertisers, and sponsors in addition to Ticketmaster itself, and grants Ticketmaster the right to a…
This provision establishes a distinct procedural track for coordinated consumer claims that meet the 75-demand threshold, which may affect the pace and structure of resolution for large-scale consume…
This provision establishes a mandatory procedural prerequisite to arbitration that requires personal participation in a teleconference or videoconference meet-and-confer, with a 60-day window, before…
This provision creates a tiered access structure for commercial content involving regulated goods, where platform-verified sellers may access permissions unavailable to general users. The reference t…
This provision covers both the operation of deceptive accounts and the commercial trade of engagement manipulation services, creating two distinct prohibited conduct categories. It directly affects b…
This provision establishes a harm-linked standard for prohibited personal information sharing, covering doxing and information disclosure that enables identity theft, stalking, or fraud. The scope of…
This provision establishes content standards that may engage election law and campaign communications regulations across multiple jurisdictions, and introduces a harm-magnitude threshold ('significan…
This provision establishes both a disclosure obligation and a content prohibition for AI-generated content, creating two distinct compliance requirements: affirmative labeling for realistic AI depict…
This provision defines the operational enforcement architecture of TikTok's moderation system, establishing that FYF suppression is a distinct enforcement action that does not constitute content remo…
This provision establishes a platform-level obligation that aligns with FTC endorsement and disclosure guidance, requiring the use of a specific in-platform tool rather than any self-selected disclos…
This provision establishes a consent-based restriction on a core commercial use of user-submitted data in AI development contexts. The opt-in framing represents a specific commitment that may require…
This provision creates a technical and contractual limitation on the company's ability to fulfill data subject rights requests for data processed under ZDR, which may require evaluation under GDPR Ar…
The consent-as-transfer-mechanism framing for general users may require evaluation under GDPR, where valid cross-border transfer requires specific legal mechanisms under Chapter V rather than general…
This provision authorizes Personal Data to be transferred to a successor entity in a corporate transaction without requiring individual user consent for that specific transfer, which is a standard bu…
The explicit non-sale affirmation is a material CCPA compliance disclosure; the commitment to provide notice and opt-out rights before any future sale establishes a procedural obligation that would a…
This provision establishes the operational rights framework for GDPR-covered users and identifies the contact mechanism for exercising rights not available through account settings; the consent withd…
This provision asserts that the Privacy Policy does not establish enforceable rights or contractual obligations, which may be cited by the company in response to user claims arising from data handlin…
This provision establishes an automatic login mechanism for accounts that may contain health plan information, medical records, and financial data, and states that users who do not affirmatively log …
This provision requires users outside Minnesota to litigate disputes in Minnesota courts under Minnesota law, which may present practical barriers to pursuing claims for users in other states. The en…
This provision makes continued platform use the mechanism for consent to modified terms, with no requirement for affirmative acknowledgment, separate notification to users, or advance notice period b…
This provision discloses the company's non-compliance with browser-level Do Not Track signals in the context of a platform that collects health, financial, and behavioral data. Several US state priva…
This provision addresses California's Shine the Light statute obligations but does not address California Consumer Privacy Act rights such as the right to know, right to delete, or right to opt out o…
This provision describes mobile data collection encompassing health information, precise location data, and personal device files, which represents a broad range of sensitive data categories collecte…
This provision authorizes data aggregation across online behavioral data, health and medical information, financial data, and offline records from vendors, which may produce enriched data profiles ex…
This provision establishes a minimum age of 13 and a parental consent requirement for minor users, engaging COPPA's applicability threshold and state-specific age of majority requirements. The agreem…
This provision asserts a broad limitation of liability covering all legal theories and all losses arising from platform use or company acts. The document itself acknowledges that state law may limit …
This provision grants the company unilateral termination authority without procedural prerequisites or advance notice requirements. For members who rely on the Online Services to access plan document…
This provision establishes a contractual limitations period shorter than the default statutory limitations period applicable to many claim types under Minnesota law and the laws of many other states.…
This provision asserts that unsolicited submissions transfer automatically to company ownership with no compensation or confidentiality obligation, and explicitly permits the company to develop compe…
This provision requires users to cover the company's legal defense costs, including attorneys' fees for counsel selected by the company rather than the user, arising from third-party claims connected…
This provision asserts a broad, perpetual, and sublicensable license over user-submitted content with no compensation obligation and no expiration tied to account termination or service discontinuati…
This provision establishes that personal information handling is governed by site-specific privacy policies rather than a unified global framework, and that terms may vary materially across regional …
This provision expressly disclaims implied warranties including merchantability and fitness for a particular purpose, and also states that Visa does not warrant that site content is free from third-p…
This provision establishes that Visa may update the website terms of use at any time without advance notice, and that users are bound by revisions upon posting. There is no stated mechanism for notif…
This provision establishes that any use of site content beyond personal, non-commercial downloading requires Visa's written consent, and explicitly identifies patent coverage of site features. The no…
This clause covers the full scope of damage categories and extends the disclaimer to all parties involved in creating or delivering the site, not only Visa itself. The qualification 'to the maximum e…
This provision asserts that the website terms of use take precedence over separately negotiated agreements with Visa in the event of any conflict, which may affect the terms of commercial, financial,…
This provision establishes Delaware as the governing law for site-level terms and designates the FAA as the governing framework for Section 10, which by reference indicates an arbitration clause. The…
This provision establishes that the legal terms governing site use can change without direct user notification, placing the obligation to monitor for changes on users. The characterization of continu…
This provision establishes a $100.00 ceiling on the Zelle Network's financial liability in states where broader damage exclusions cannot be fully enforced, which applies to claims arising from site u…
This provision asserts an automatic IP assignment from the submitter to Zelle for any unsolicited material, with no compensation obligation and no confidentiality requirement. Under this clause, Zell…
This provision establishes that Zelle may disclose user identity to law enforcement based on suspected violations of these Terms, and that users waive claims arising from those disclosures or any res…
This provision requires users to waive, irrevocably and in advance, all claims against Zelle arising from third-party site interactions, including those involving credit card and personal data exposu…
This provision authorizes account suspension and termination without notice at Zelle's sole discretion, including during an ongoing investigation. The absence of a required pre-suspension notice or a…
This provision places the legal responsibility for obtaining all consents and providing all notices necessary for lawful processing of Service Data on the Customer rather than Zendesk. This allocatio…
This provision authorizes Service Data sharing with third-party providers as a consequence of enabling integrations, without requiring a separate disclosure or consent step at the time of each integr…
The fifth suspension ground, which permits suspension based on Zendesk's reasonable determination that it is necessary to avoid material harm to Zendesk, its affiliates, or customers, is a broad disc…
This provision establishes a financial ceiling on liability claims under the agreement. The Excluded Claims definition carves out several categories, including payment obligations, indemnification ob…
This provision establishes that customers are financially committed for the full subscription term regardless of reduced usage, business changes, or service dissatisfaction, with limited exceptions e…
This provision authorizes Zendesk to use Service Data for product improvement purposes, which may extend beyond the scope of processing strictly necessary to deliver contracted services. Depending on…
This provision authorizes Zendesk to modify agreement terms and incorporated policies on a rolling basis. For the core agreement, continued use after the notice period constitutes consent. For URL-in…
This clause creates a binding renewal obligation at potentially updated pricing unless the Customer takes affirmative action within the specified notice window. The combination of auto-renewal at the…
This clause establishes a specific operational limitation on the permitted use of ActiveCampaign's messaging infrastructure, which is operationally significant for any organization that manages emerg…
This provision discloses that crowd worker welfare obligations are contractually delegated to platform intermediaries, which determines the mechanism and enforceability of these standards. The docume…
The Frontier Safety Roadmap provision establishes a public disclosure mechanism for Anthropic's AI safety objectives and their completion status, creating a trackable record of stated safety commitme…
The clause establishes Anthropic's right to use Customer identity for marketing and business development purposes while creating an opt-out mechanism. It further obligates the Customer to consider in…
This provision changes the internal transparency posture for unredacted safety risk information, reducing the employee population with guaranteed access to unredacted Risk Reports from all regular-cl…
This provision establishes the consent basis and opt-out mechanism for Apple's use of Apple Intelligence content data for product improvement, applying only to users who have previously opted into De…
This provision defines the scope of data Apple asserts it collects in connection with server-side AI processing, establishing the boundary between content data (not collected) and operational metadat…
This provision establishes a user-accessible transparency mechanism that documents server-side data routing for Apple Intelligence requests, providing an auditable log of off-device processing. The a…
This provision establishes that on-device processing is the default architectural approach for Apple Intelligence, with server-side routing to Private Cloud Compute occurring only when the task requi…
This provision establishes that customer-facing interaction data and platform usage analytics are processed by third parties, which is operationally significant for customers whose support communicat…
This provision establishes that payment-related personal data is processed by third-party subprocessors, which is relevant for customers' PCI DSS compliance assessments and for understanding the data…
This provision establishes Delaware as the exclusive legal and procedural forum for claims brought by Baseten against Customer, while the venue consent is unilaterally directed at Customer, which may…
This provision reserves Chase's right to override customer routing or transfer system instructions and to charge wire transfer fees on transactions completed as internal transfers, which may affect t…
This provision establishes consent to automated dialing and prerecorded voice messages upon providing a mobile number, which implicates the Telephone Consumer Protection Act (TCPA). The agreement sta…
The early withdrawal penalty structure for personal CDs caps penalties at the total interest earned during the current term, which limits but does not eliminate potential principal reduction in low-i…
The agreement explicitly states that rate changes require no advance notice, which means account holders may not receive advance disclosure before a rate reduction takes effect on their savings or in…
This provision reserves Chase's right to alter the interest rate and APY on interest-bearing accounts without restriction on frequency or magnitude and without advance notice, which is an operational…
The waiver conditions for monthly service fees establish the specific operational requirements account holders must meet each statement period to avoid recurring charges, with thresholds varying sign…
This provision extends account termination authority to conduct in customer communications, not only to content or list management practices, and applies the same no-refund and discretionary data exp…
This provision defines the operational scope of Craigslist's data monetization and sharing practices by explicitly restricting several common data commercialization mechanisms. The clause establishes…
This provision discloses the existence of an ongoing public vulnerability disclosure channel, which is operationally relevant for security researchers and for customers evaluating the scope of indepe…
This provision establishes a specific, measurable penetration testing cadence with a mandatory remediation gate for material findings, and discloses that the third-party test report is available to c…
This provision establishes the legal transfer mechanisms Disney intends to rely upon for cross-border personal information flows, specifically naming standard contractual clauses (SCCs) and consent a…
This provision consolidates US state privacy rights into a single notice, covering rights established under CCPA (California), and analogous frameworks in states including Virginia, Colorado, Connect…
This provision establishes that notice of material policy changes may be delivered to the email address last provided by the user, making the accuracy of contact information on file operationally sig…
This provision establishes that Experian accepts no liability for third-party sites accessed through links on experian.com, which is operationally relevant where the site links to partner, affiliate,…
This provision establishes that any reproduction or redistribution of experian.com content or use of Experian trademarks requires affirmative written authorization, which applies to media organizatio…
This provision reflects a mandatory disclosure obligation under the Texas Data Privacy and Security Act and Texas data broker registration requirements. The registration creates a public compliance r…
This provision establishes a categorical prohibition on data collection and sale for minors under 16, which aligns with the CCPA's prohibition on selling personal information of minors under 16 witho…
This provision constitutes a mandatory CCPA compliance disclosure and provides a quantitative record of Experian's rights request processing performance for the 2025 calendar year. The disclosure of …
This provision establishes the mechanism through which copyright holders can request removal of infringing content from gm.com and through which GM may assert safe harbor protection under the Digital…
This provision permits GM to transfer the terms and associated content licenses to a successor entity, acquirer, or third party without user consent or notice. In the context of a corporate transacti…
This provision establishes that the applicable governing terms for GitHub Copilot depend on the procurement channel and plan type, creating three parallel governance tracks. Organizations should conf…
This provision establishes that users who opt into experimental Copilot features are subject to different and separately published terms, which may contain different data handling, liability, or acce…
This provision establishes that policy flexibility is available only through individual exception requests approved at Groq's discretion, and that approved exceptions create no binding precedent for …
This provision establishes that rate limit and parameter compliance is a contractual obligation enforced across the account and organizational level, not just at the individual API request level, and…
This provision defines the scope of Harvey's processing rights over Customer Data and Input. The license is limited in purpose to service provision, technical problem resolution, and legal compliance…
This provision defines the contractual confidentiality standard governing Harvey's handling of Customer Content and Customer Data as the customer's Confidential Information. The provision that Harvey…
The retention period for end users whose employers hold a Customer Agreement is governed by that agreement rather than solely by this policy, creating a dependency on enterprise contract terms for de…
This provision authorizes ongoing collection and use of behavioral and interaction data for platform development purposes. The definition of Usage Data explicitly excludes Customer Data and Content, …
This provision establishes the available data subject rights mechanisms and confirms access to regulatory complaint channels including EU DPAs and the UK ICO. The rights are subject to exceptions and…
The Feedback license is irrevocable, perpetual, sublicensable, and transferable, meaning Customer retains no control over how submitted Feedback is used or disclosed after submission. The agreement e…
This provision confirms Customer ownership of User Submissions while establishing that Linear's license to process and display them is limited to Service delivery purposes. The license is transferabl…
This provision establishes that any suggestions, comments, or feedback submitted by Customer regarding the Service are subject to an unrestricted, perpetual, irrevocable license in favor of Linear, i…
The license granted is perpetual and irrevocable in its terms, but the agreement expressly limits its scope to actions reasonably necessary to provide and maintain the Service, and provides operation…
The policy establishes an age threshold of 18, which exceeds the COPPA threshold of 13, and may interact with state-level minor protection statutes such as California's Age-Appropriate Design Code, d…
The policy explicitly identifies investors and shareholders as a distinct data subject category and describes specific financial and transactional personal data categories collected from them, includ…
Appointment of an EU representative under GDPR Article 27 is required for controllers established outside the EU that offer goods or services to EU data subjects or monitor their behavior. This provi…
This provision grants Atlassian an unrestricted license to use Customer feedback and suggestions, including for product development purposes, without creating any obligation to compensate or attribut…
This provision establishes a defined window for no-fault product return and full fee refund on initial orders, providing a concrete mechanism for Customers to exit subscriptions that do not meet thei…
The document sets the age threshold for children's data protection at 16, which aligns with GDPR Article 8's default age of digital consent in the absence of member state modification, and exceeds th…
Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement author…
The policy does not publish specific retention periods for individual data categories in this notice, instead referencing an internal records retention policy and schedule that is not reproduced here…
This provision describes the technical scope and limitations of Marqeta's GPC signal recognition mechanism, which is the primary opt-out pathway for CCPA sale and sharing disclosed in Section 3 of th…
The distinction between material and non-material changes determines whether users receive advance notice or consent requests before new data practices take effect. The document does not define the c…
This provision constitutes a voluntary ESG disclosure quantifying the energy and emissions footprint of Llama 4 training. The distinction between location-based and market-based emissions figures ref…
This provision documents the scope and methodology of Meta's pre-release safety evaluation for Llama 4, providing institutional deployers with a basis for assessing the categories of risk that were f…
This provision establishes a notification obligation for material policy changes and frames continued product use after notification as an implicit acceptance mechanism, which is a standard practice …
This provision establishes that user data constitutes a transferable asset in corporate transactions, and that the new owner of Meta's business or a portion of it may receive user information, with t…
This provision establishes the mechanism by which updated terms are communicated and accepted, with continued platform use constituting agreement to modified terms. The 30-day notice period is a spec…
This provision explicitly authorizes a category of use, synthetic data generation and model distillation, that has been restricted or contested in licenses for other large language models. Organizati…
This request cannot be evaluated because no enforceable provision text exists to describe. Responsible AI Reports document corporate practices and commitments but do not establish binding contractual…
This provision establishes that all disputes must be litigated in California courts under California law, regardless of where the Customer is located or incorporated. The forum non conveniens waiver …
This provision reflects a standard COPPA-aligned disclosure for services not directed at children. The policy does not provide a specific contact address for parental requests, which may create a pra…
This provision establishes that contact, business, and usage data may be shared with an unspecified set of business partners and resellers, and that once a user engages with a partner independently, …
This provision establishes that policy amendments take effect upon publication and that continued use of the platform constitutes acceptance, with the adequacy of notice (prominent in-service display…
This provision does not specify fixed retention periods for any category of personal data, instead reserving retention duration determinations to monday.com's reasonable discretion and an internal po…
This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability…
This provision directly states that Do Not Track browser signals are not honored, meaning users relying on this browser-level control will not have their tracking preferences implemented through this…
This clause requires all dispute resolution to occur in San Francisco, California courts, which establishes a defined legal forum and governing law for contractual claims, and may affect the practica…
This provision authorizes de-identification of Personal Data and its unrestricted sharing with third parties. The adequacy of de-identification techniques is not specified in the document; GDPR and C…
This clause establishes that any technical, product, or operational feedback submitted by users, including bug reports and improvement suggestions, becomes the sole property of OneLogin upon submissi…
This provision operationalizes GDPR and CCPA/CPRA data subject rights through a unified request mechanism and provides an alternative dispute resolution pathway via TrustArc in addition to supervisor…
This provision operationalizes marketing opt-out rights and data retention terms. The 10-day opt-out processing deadline and the carve-out for transactional communications are operationally specific …
This provision establishes the procedural requirements for exercising statutory privacy rights, including the verification requirement that may limit the ability of users without accounts or whose id…
This provision establishes an input-side moderation mechanism for audio content that blocks erotic and violent speech generation based on transcription analysis, creating a disclosed content restrict…
This provision establishes that personal data may be transferred to and processed in the United States and other jurisdictions, and that OpenAI relies on legally valid transfer mechanisms; for users …
This provision establishes the minimum age requirement for Service use, provides a reporting mechanism for suspected under-13 data collection, and creates a parental permission requirement for users …
This provision directly engages state privacy law definitions of cross-context behavioral advertising and targeted advertising sharing, provides multiple opt-out pathways including recognition of Glo…
This provision discloses that OpenAI conducts monitoring of service use for policy compliance and states that such monitoring is conducted with privacy safeguards, though the specific nature of those…
The provision's statement that the Sites are not intended to subject Oscar to the jurisdiction of countries other than the United States, combined with acknowledgment of transfers to countries that m…
The age 13 to 16 protection is conditioned on Oscar having 'actual knowledge' of the individual's age, which is a standard limitation that means the protection may not apply where age is not verified…
The absence of defined retention periods for specific data categories means the policy does not establish a maximum retention timeline, and the stated standard of 'as long as we believe it is necessa…
This provision establishes that privacy policy changes take effect through continued use without requiring affirmative consent or direct notice to users, which may be evaluated against state law requ…
This provision assigns to Oura the right to use any user-submitted feedback, including ideas and concepts, for any purpose without compensation or attribution. This is a standard clause in consumer t…
This provision discloses the use of IP-based geolocation for content personalization and asserts that the process does not constitute collection of personal information, though the classification of …
This provision establishes Progressive's unilateral right to discontinue the Mobile Alerts service without advance notice for any reason, while providing users with two specific opt-out mechanisms; t…
This provision establishes Progressive's DMCA safe harbor compliance mechanism under the Digital Millennium Copyright Act, designating a specific agent and contact information for copyright infringem…
This provision disclaims Progressive's responsibility for the accuracy, availability, or security of the website content to the fullest extent permitted by law, which in practice means users cannot a…
This provision operates as an automatic IP assignment clause, transferring ownership of any service-related suggestions or ideas to Replicate without requiring a separate signed agreement or compensa…
This provision creates a single authoritative text for policy interpretation and dispute resolution. It ensures consistent policy application across all users regardless of the language version they …
This provision establishes account transfer restrictions that affect creators operating as businesses, while creating a limited exception for commercial transactions involving virtual content revenue…
This provision establishes an automated content moderation mechanism within the Einstein Trust Layer that operates on all AI-generated outputs, with direct implications for enterprise customers in re…
This provision establishes that AI outputs within the Salesforce platform are grounded in customer-approved data sources and that existing data access controls are maintained during AI processing, wh…
This provision establishes a transparency mechanism directly relevant to enterprise customers' AI governance obligations, including requirements under the EU AI Act for documentation of high-risk AI …
This provision establishes that the sub-processor table may disclose processing relationships and locations for products that are not yet commercially available, meaning the listed sub-processors and…
This provision establishes that NLP-processed data from Einstein Bots is stored in a location determined by the customer's primary org region rather than by a separate regional election, and that APA…
This provision establishes that regional data hosting is not uniformly available as a self-service configuration and that region selection for one service may produce downstream region assignments fo…
The designation of functional cookies as 'always active' alongside strictly necessary cookies may require evaluation under GDPR and ePrivacy Directive guidance, which generally permits exemption from…
This provision establishes that content posted on the platform, described as limited in the clause header but irrevocable and sublicensable in its operative terms, can be redistributed by Stash to th…
This provision establishes the minimum age requirement for service enrollment. As a financial services platform offering investment and banking products, this age restriction aligns with legal requir…
This provision establishes a contractual restriction on competitive use of platform access, a common clause in SaaS agreements that may interact with competition law principles in certain jurisdictio…
The provision states that updated Terms bind users only upon their affirmative agreement, which is a consumer-favorable mechanism relative to terms that take effect automatically upon continued use; …
This provision prohibits conduct that would independently constitute violations of the Computer Fraud and Abuse Act and comparable international cybersecurity statutes, and its scope covers attempts,…
The notification mechanism is conditional on legal obligation rather than a proactive commitment to direct user notice, meaning users bear responsibility for monitoring the policy page for changes ab…
This provision establishes a transparency commitment regarding government data requests that is operationally distinct from policies that provide no such notification; the practical scope of this com…
This provision establishes COPPA-aligned age restriction and data removal commitments; the absence of a defined response timeline for parental notification or removal requests may warrant operational…
This provision governs electronic delivery of regulated communications, including explanation of benefits and privacy notices, which are subject to federal and state insurance requirements. The provi…
This provision establishes COPPA compliance intent for Online Services that may be accessed by minors in the context of family health plan management or dependent benefit access. The qualifier 'inten…
This provision establishes a comprehensive disclaimer of all warranties for site functionality, content accuracy, and security, to the fullest extent permitted by applicable law. As a site-level disc…
The exclusive venue requirement means that customers outside California who pursue litigation must do so in San Francisco County, California courts, which may affect the practical accessibility of di…
Monitor emails you the same day a platform you choose changes these clauses.
A unknown / unclassified clause is a provision in a platform's terms of service or privacy policy governing unknown / unclassified-related rights, obligations, or restrictions.
ConductAtlas tracks 60 platforms with unknown / unclassified clauses - roughly 17% of platforms in the archive. 112 are classified as high severity.
Severity reflects the magnitude of rights waived, availability of opt-out, breadth of users affected, financial or legal exposure created, and the degree of discretion retained by the platform.