Provision Registry

12505 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
WhatsApp · WhatsApp Privacy Policy
The policy authorizes disclosure of user information in response to government requests and legal process, including on a good-faith basis, which means data may be shared without a court order in some circumstances as WhatsApp interprets applicable law.
CA-P-011432 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Ledger · Ledger Privacy Policy
Legitimate interest as a legal basis permits data processing without requiring explicit user consent, provided the organization's interests do not override privacy protections. This basis enables Ledger to conduct certain processing activities—such as fraud prevention, service improvement, or analytics—through a balancing test rather than through affirmative opt-in mechanisms.
CA-P-001468 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
Oura · Oura Privacy Policy
This provision applies the legitimate interest basis to processing that includes health-adjacent data (service improvement involving sleep and readiness data), which EU supervisory authorities may scrutinize given the sensitivity of the underlying data and the availability of consent as an alternative basis. The policy does not provide a publicly disclosed legitimate interest assessment.
CA-P-012696 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
Klarna · Klarna Privacy Policy
Using legitimate interest rather than consent as a legal basis means Klarna does not need to ask your permission for certain profiling and marketing activities, though you retain the right to object, which may not be prominently communicated in the user experience.
CA-P-009283 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Visa · Visa Privacy Notice
This clause establishes the legal basis under which Visa processes personal data without requiring separate opt-in consent. It permits data processing for operational security, fraud prevention, and business analytics as core institutional functions of payment network administration.
CA-P-002663 First tracked Apr 10, 2026 Last seen Apr 10, 2026 Compare across platforms →
Oura · Oura Privacy Policy
Legitimate interest as a lawful basis for marketing-related processing means Oura may use your data for these purposes without a separate consent prompt, though you have the right to object to this processing under GDPR.
CA-P-007772 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
HubSpot · HubSpot Privacy Policy
Legitimate interests is a flexible legal basis that does not require your consent but is subject to a balancing test. Individuals in the EU and UK have the right to object to processing based on legitimate interests.
CA-P-009805 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Adobe · Adobe Privacy Policy
This is a broad assertion that allows Adobe to process your data for marketing and sharing purposes by default, without your explicit consent, in jurisdictions where this basis is available. Users who wish to stop this processing must actively exercise their right to object.
CA-P-008258 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Monday.com · Monday.com Privacy Policy
This clause establishes the legal foundation for data processing activities that do not require explicit user consent under GDPR. It permits the entity to conduct processing for operational and business purposes while maintaining that data subjects retain the ability to object where their rights outweigh the stated interests.
CA-P-005665 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Privacy rights
Palantir · Palantir Privacy Statement
Legitimate interests is a flexible but contestable lawful basis; individuals in the EU and UK have the right to object to processing conducted on this basis, and Palantir must stop if it cannot demonstrate compelling grounds that override those interests.
CA-P-009643 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Calendly · Calendly Privacy Notice
Legitimate interests is a flexible legal basis that does not require user consent, but under GDPR users have the right to object to processing based on legitimate interests, which Calendly must honor.
CA-P-009710 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Checkout.com · Checkout.com Privacy
Legitimate interests is a flexible but contested legal basis under GDPR; individuals have the right to object to processing on this basis, and Checkout.com must stop unless it can demonstrate compelling grounds that override the individual's interests.
CA-P-010387 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Klarna · Klarna Privacy Policy
Legitimate interests is one of several legal bases that permits data processing without explicit user consent. This authorization enables Klarna to conduct certain processing activities—such as fraud prevention, analytics, or service optimization—based on institutional determinations of proportionality rather than affirmative user permission.
CA-P-000923 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
Stripe · Stripe Privacy Policy
Reliance on legitimate interests as a processing basis under GDPR requires a balancing test against data subject rights and interests; the policy directs users to the Privacy Center for specifics, meaning the legal basis documentation is distributed across multiple documents rather than consolidated in this policy.
CA-P-012530 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Databricks · Databricks Privacy Notice
This provision establishes the institutional framework for personal data processing activities that do not require explicit consent. By relying on legitimate interests as a legal basis, Databricks can conduct specified processing operations according to GDPR Article 6(1)(f) standards, subject to balancing tests between organizational and individual interests.
CA-P-004411 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Adyen · Adyen Privacy Policy
Legitimate interests is a flexible legal basis that does not require your consent, meaning Adyen can process your data for analytics and product improvement without asking you, though you have the right to object to such processing.
CA-P-008768 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Hugging Face · Hugging Face Privacy Policy
The policy invokes legitimate interests as a processing basis for a broad range of purposes including business operations and scientific research, without specifying the balancing test or safeguards applied; under GDPR this basis requires documented proportionality analysis and may be challenged where it overrides user interests.
CA-P-011664 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Telegram · Telegram Privacy Policy
Relying on legitimate interests rather than consent means Telegram does not need to ask your permission to collect and process data, though you have the right to object to such processing under GDPR.
CA-P-007307 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Adobe · Adobe Privacy Policy
This clause establishes the legal framework under which Adobe processes content data without explicit user consent, relying instead on a balancing test between Adobe's business interests and user privacy expectations. The provision operationalizes a mechanism for users to challenge specific processing activities while preserving Adobe's ability to continue processing where business or legal necessity applies.
CA-P-001076 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Hugging Face · Hugging Face Privacy Policy
The legitimate interests basis expands the permissible scope of data processing beyond consent-dependent activities, enabling the entity to conduct processing necessary for service operation, fraud prevention, security, analytics, and business development without obtaining affirmative consent. This provision establishes the procedural framework through which the entity assesses and implements data uses that fall outside explicit consent requirements.
CA-P-001644 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
Skillshare · Skillshare Privacy Policy
Legitimate interests is a flexible legal basis that does not require user consent, and its application to marketing and corporate transaction purposes may be subject to challenge under GDPR if the balancing test does not adequately weigh user privacy interests against Skillshare's business interests.
CA-P-010479 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
OpenAI · OpenAI Terms of Use
The terms disclaim all warranties on AI-generated outputs and service availability, which places reliance risk entirely on users and is particularly significant for users who use AI outputs in professional, medical, legal, or financial contexts.
CA-P-011782 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Liability limitation
Google AI Studio · Gemini API Terms of Service
This provision caps potential developer recovery at 12 months of fees paid, which may be a modest amount for developers on free-tier or low-spend plans. It limits financial recourse in the event of service failures, data incidents, or other breaches regardless of the magnitude of harm experienced.
CA-P-011804 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Liability limitation
Duolingo · Duolingo Terms of Service
The liability cap defines the maximum financial exposure Duolingo assumes under the service agreement and restricts the categories of compensable harm to direct damages only. This structure allocates risk by excluding indirect and consequential losses from recovery, which are often the largest components of claimed damages in service disruption scenarios.
CA-P-011172 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
medium Liability limitation
Fitbit · Fitbit Terms of Service
For a platform that collects sensitive health and biometric data, a maximum liability of one hundred dollars is a very low ceiling if a data breach or service failure causes real harm.
CA-P-010460 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Liability limitation
Mistral AI · Mistral AI Terms of Service
For free users, the maximum compensation Mistral AI could owe is 50 euros regardless of the harm caused. This provision significantly limits users' ability to recover financially in the event of a serious failure, though applicable consumer protection laws in some jurisdictions may limit how enforceable such a cap is.
CA-P-010131 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Liability limitation
Cohere · Cohere SaaS Agreement
Liability caps create predictable cost structures for service providers and define the outer boundary of financial exposure in the event of service failures or breaches. This affects risk allocation between the parties and the economic basis upon which the agreement operates.
CA-P-010563 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Liability limitation
Perplexity AI · Perplexity API Terms of Service
This provision significantly limits the financial recourse available to developers who suffer business losses due to API failures, outages, or data incidents, even if those losses are substantially larger than the capped amount.
CA-P-010512 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
Adyen · Adyen Terms
For businesses with high transaction volumes but relatively low fee rates, the cap may be significantly lower than the actual financial loss caused by a platform outage or processing error.
CA-P-008723 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Revolut · Revolut Terms of Service
The liability cap restricts the range of damages Revolut may be required to pay in breach scenarios to direct losses caused by contractual violations, while excluding entire categories of loss from recovery. This allocation establishes the financial scope of Revolut's exposure under the agreement and defines which loss categories fall outside the liability framework.
CA-P-004645 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial