Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
medium Privacy rights
Rumble · Rumble Privacy Policy
This provision establishes the procedural mechanism through which users may exercise deletion rights, which is a required operational disclosure under CCPA and CPRA for covered businesses, and creates compliance obligations regarding response timelines and verification procedures.
CA-P-012649 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cohere · Cohere Enterprise Data Commitments
The right to request data deletion is a core data governance right for enterprise customers and aligns with regulatory requirements under GDPR and CCPA. The document's recognition of this right indicates a process is available, though the specific mechanism and timeline are not fully detailed in the commitments page.
CA-P-011333 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Ring · Ring Privacy Notice
The ability to delete your Ring account data, including stored videos, is a fundamental privacy right under laws like GDPR and CCPA, and Ring's stated commitment to user control implies these mechanisms should be available.
CA-P-009814 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Spotify · Spotify Privacy Policy
The clause operationalizes data deletion rights by defining the boundaries of those rights through enumerated retention exceptions. This establishes the conditions under which Spotify's obligation to delete data upon user request does not apply, creating a framework for balancing deletion requests against institutional, legal, and protective obligations.
CA-P-000329 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Privacy rights
Weights & Biases · Weights & Biases Privacy Policy
Third-party disclosure provisions determine which external entities receive user personal information and under what conditions, a material consideration for enterprise customers whose employees or end-users interact with CoreWeave's platform.
CA-P-012608 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Anthropic · Anthropic Commercial Terms
The DPA governs how personal data submitted through the API is processed; because it is incorporated by reference rather than reproduced in the main terms, customers must review it separately to understand their data processing rights and obligations.
CA-P-010634 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Miro · Miro Terms of Service
For business customers under GDPR or other data protection laws, the DPA is the operative legal instrument defining Miro's obligations as a data processor, and the subprocessors list determines which third parties may access the personal data you upload to Miro.
CA-P-009406 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Atlassian · Atlassian Cloud Terms
The DPA is the operative document for GDPR and CCPA compliance purposes, and its terms govern data controller and processor obligations, sub-processor authorization, and cross-border transfer mechanisms for personal data processed through Atlassian products.
CA-P-010943 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Synthesia · Synthesia Terms of Service
The specific obligations, data subject rights, sub-processor disclosures, and security measures that protect your personal data under GDPR are governed by the DPA, which is not reproduced in the main terms and requires separate review.
CA-P-004394 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
AWS Bedrock · AWS Service Terms
The terms explicitly state that customer prompts and content submitted through Bedrock inference are not used to train Amazon foundation models by default, which is a material data handling commitment relevant to customers submitting proprietary or sensitive data.
CA-P-011415 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
AWS · AWS Customer Agreement
This provision establishes both the data ownership framework (customer retains content ownership) and the permitted scope of AWS's access to customer content (limited to service provision and maintenance). For customers processing personal data on AWS, this provision works in conjunction with the separately available Data Processing Addendum, which governs GDPR and equivalent regulatory obligations.
CA-P-013188 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
LangChain · LangChain Terms of Service
Developers and businesses using LangSmith's tracing and evaluation features may transmit sensitive data, personal information, or proprietary business logic to LangChain's infrastructure, and the terms governing how that data is processed are material to compliance with GDPR, CCPA, and industry-specific regulations.
CA-P-011872 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Vercel · Vercel Terms of Service
For businesses and developers who deploy applications handling personal data, the quality and scope of these data protection commitments directly affects GDPR and CCPA compliance obligations and the adequacy of Vercel as a data processor.
CA-P-010177 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Adyen · Adyen Terms
Merchants who do not have adequate privacy notices or data processing agreements in place with Adyen may face GDPR compliance exposure if their customers' payment data is processed without proper legal basis.
CA-P-008728 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Duo Security · Duo Terms of Service
Incorporating data protection obligations by reference to a separate DPA means customers must actively identify and review an additional document to understand how their users' authentication data is processed, stored, and protected, which is critical for GDPR and CCPA compliance.
CA-P-007721 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Cloudflare · Cloudflare Terms of Use
Incorporating the privacy policy by reference means changes to that document affect your rights under this agreement, and the acknowledgment that transmissions are never fully secure may affect any expectation of confidentiality for data transmitted through Cloudflare's network.
CA-P-003009 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
Dun & Bradstreet · D&B Privacy Policy
The breadth and scale of D&B's data processing means that a significant proportion of business professionals worldwide may have data held about them in the D&B Data Cloud, often without having a direct relationship with or awareness of D&B.
CA-P-007993 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Perplexity AI · Perplexity Data Processing Addendum
This clause establishes the foundational processor-controller relationship required by GDPR Article 28, and its scope directly determines whether Perplexity's AI processing activities remain within the customer's instructed purposes or constitute independent controller activity.
CA-P-012519 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
GOAT · GOAT Privacy Policy
Open-ended retention periods mean your data could be held indefinitely under broad business justifications, with limited ability for users in most jurisdictions to compel deletion beyond what specific privacy rights provide.
CA-P-008266 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Udemy · Udemy Privacy Policy
This provision establishes the temporal scope of Udemy's data processing activities and determines how long personal data including learning activity, payment records, and communications content remains subject to Udemy's use and sharing permissions.
CA-P-010208 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
StockX · StockX Privacy Policy
Without specific retention periods defined for different data types, users cannot easily predict when their personal information, including sensitive data like government IDs, will be deleted.
CA-P-009219 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
OpenAI · Privacy Policy (ROW)
The absence of fixed retention timelines means users cannot rely on a defined period after which their data will be deleted, and the scope of legitimate retention grounds is broad.
CA-P-011111 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
ElevenLabs · ElevenLabs Privacy Policy
The absence of specific retention periods for individual data categories, particularly voice recordings and voice models, creates potential tension with GDPR's data minimization and storage limitation principles, which require that retention periods be specified or determinable.
CA-P-004373 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
T-Mobile · T-Mobile Privacy Policy
Open-ended retention language tied to 'business needs' and 'legal obligations' without specific retention periods means consumers have limited visibility into how long sensitive data such as location records, call logs, and financial information is actually stored.
CA-P-010245 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Duo Security · Duo Privacy
The absence of defined retention periods for specific data types like authentication logs means Cisco may retain this data for an extended and indeterminate period, which is relevant to privacy rights and data minimization requirements.
CA-P-007442 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Walgreens · Walgreens Privacy Policy
The absence of specific retention periods for individual personal information categories, particularly health and pharmacy data, creates compliance considerations under CCPA/CPRA's data minimization requirements and HIPAA's record retention standards. Retention periods that are not bounded by specific timelines may face scrutiny under CPRA's proportionality standard.
CA-P-009635 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Verizon · Verizon Privacy Policy
Open-ended retention periods tied to broadly defined purposes such as 'legal obligations' and 'enforcing agreements' may result in personal data being retained for extended periods without a clear maximum duration disclosed to consumers.
CA-P-003776 First tracked Apr 28, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Intuit · Intuit Privacy Statement
Open-ended retention language tied to legal obligations and dispute resolution means sensitive financial data, including tax records and government identifiers, could be retained for extended periods without a specific deletion deadline.
CA-P-008515 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Public.com · Public.com Privacy Policy
The absence of specific retention periods for sensitive financial and identity data means Public may retain your SSN, trading history, and financial account information for an indeterminate period after you close your account.
CA-P-008308 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Stability AI · Stability AI Privacy Policy
The retention standard is tied to broadly stated purposes rather than specific time periods, which means the duration of data retention may vary and is not fixed to a defined schedule visible to users.
CA-P-003730 First tracked Apr 28, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial