Provision Registry

3805 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: High × Clear all
high Data usage
Fastly · Fastly Terms of Service
This provision creates a multi-document framework for data governance by incorporating privacy obligations by reference rather than specifying them within the main service agreement. It establishes that actual data processing requirements are defined in separate, potentially negotiated documents (the Privacy Policy and DPA) rather than solely in the Terms.
CA-P-005007 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
AWS · AWS Customer Agreement
The Data Processing Addendum is a separate document that must be actively executed by customers who process personal data subject to GDPR or similar frameworks; it is not automatically incorporated into the main agreement.
CA-P-007748 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Vercel · Vercel Terms of Service
The incorporation by reference mechanism makes privacy obligations enforceable as part of the contractual agreement, while the DPA requirement establishes a conditional obligation for certain jurisdictions to formalize data processor roles and responsibilities under regulatory frameworks.
CA-P-006769 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Google Maps · Google Maps Platform Terms of Service
This clause allocates data protection compliance responsibilities to the customer rather than Google, establishing the customer as the party responsible for ensuring lawful processing and user transparency. The incorporation of the Data Processing Addendum creates a separate contractual framework governing the specifics of data handling obligations.
CA-P-002380 First tracked Apr 9, 2026 Last seen Apr 28, 2026 Compare across platforms →
Segment · Segment Terms of Service
The clause creates a binding framework for how personal data is handled during service delivery by making a separate data protection document an enforceable part of the primary service agreement. This establishes specific compliance requirements and allocates data processing responsibilities between the parties.
CA-P-006413 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Auth0 · Auth0 Terms of Service
Auth0 handles login credentials, authentication tokens, and user identity information for the end users of its customers' applications, making the data processing terms central to GDPR, CCPA, and other privacy law compliance for those businesses.
CA-P-008707 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Fastly · Fastly Terms of Service
Customers handling personal data subject to GDPR, UK GDPR, or CCPA need a Data Processing Addendum to meet their legal obligations, but this document indicates it is not automatically part of the agreement and must be separately requested.
CA-P-007911 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Neon · Neon Terms of Service
The provision creates a structured allocation of data protection obligations between Neon and its customers. By incorporating the DPA by reference, the clause establishes that data processing terms are documented in a separate agreement and that customers retain responsibility for compliance with applicable data protection laws and notification requirements.
CA-P-004894 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Stripe · Stripe Terms of Service
The incorporation of the DPA establishes a framework that specifies how each party must handle Personal Data processing, including mechanisms for international data transfers. This creates enforceable obligations for data handling practices that supplement the primary service agreement.
CA-P-000756 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Segment · Segment Terms of Service
The provision defines the scope and mechanics of data handling within Segment's platform infrastructure. It establishes the operational framework under which customer data is processed and classified for analytics and segmentation purposes.
CA-P-009678 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
Perplexity AI · Perplexity Enterprise Terms
This provision governs the scope of Perplexity's rights to use enterprise-submitted data, which is a primary compliance consideration for organizations deploying AI platforms that process employee queries, customer information, or proprietary business data.
CA-P-012336 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Mixpanel · Mixpanel Terms of Use
This provision determines where legal accountability sits for end-user data. Because the business deploying Mixpanel is the data controller, end users must direct data rights requests such as access, deletion, and opt-out to the deploying business, not to Mixpanel.
CA-P-011157 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
high Privacy rights
Cohere · Cohere Enterprise Data Commitments
Data residency options are operationally significant for enterprises subject to data localization laws or contractual requirements restricting cross-border data transfers. The availability of these options depends on Cohere's infrastructure and the specific regions offered.
CA-P-011331 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Plaid · Plaid End User Privacy Policy
Secondary use of financial transaction data for Plaid's own benefit (product development, analytics) is a purpose that goes beyond what you likely intended when connecting your bank account to a specific app, and the adequacy of de-identification for longitudinal financial data is an open technical and legal question.
CA-P-007181 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Binance.US · Binance.US Privacy Policy
The provision defines the foundational scope of the privacy framework governing data handling practices across Binance.US and affiliated entities. It establishes that the Privacy Policy applies to the full corporate group rather than a single legal entity.
CA-P-005369 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
high Data retention
Plaid · Plaid Terms of Use
This provision defines the operational scope of data persistence within Plaid's systems and establishes the regulatory and business bases that govern retention duration. The framework creates distinct retention periods based on service necessity versus legal or accounting obligations, which determines how long personal information remains subject to processing.
CA-P-003488 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
high Data retention
Synthesia · Synthesia Privacy Policy
The provision operationalizes data retention by establishing multiple retention triggers—account activity status, service delivery requirements, legal compliance obligations, and dispute resolution needs—which extend the retention period beyond active use. This structure creates ongoing data stewardship responsibilities and establishes the framework for biometric data management tied to avatar functionality.
CA-P-004287 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Skillshare · Skillshare Privacy Policy
The clause establishes a data sharing practice for advertising purposes as a standard operational term, while creating a compliance pathway for California residents under applicable state privacy law requirements.
CA-P-007046 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Paramount+ · Paramount+ Privacy Policy
The clause operationalizes Paramount+'s obligations under California privacy law (CCPA/CPRA) by creating a documented process for opt-out requests and establishing that the company will cascade opt-out instructions to third parties in its service provider and partner network.
CA-P-006257 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Walmart · Walmart Privacy Policy
The notice's acknowledgment that Walmart Connect data flows may constitute a 'sale' or 'sharing' under CCPA/CPRA triggers opt-out rights for California residents and GPC signal recognition obligations for Walmart's digital properties.
CA-P-011361 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Peacock · Peacock Privacy Policy
The opt-out right is meaningful but requires affirmative action on every browser and device separately, and users outside the listed 19 states may have no enforceable opt-out right under this policy regardless of their preferences.
CA-P-005070 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
FanDuel · FanDuel Privacy Policy
The provision operationalizes user choice regarding data commercialization by conditioning the availability of opt-out functionality on affirmative user action through a specific portal. The requirement for per-site, per-device renewal and cookie-dependent persistence creates ongoing administrative obligations for maintenance of the opt-out preference.
CA-P-004522 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
high Liability limitation
T-Mobile · T-Mobile Privacy Policy
The provision outlines T-Mobile's operational cybersecurity framework and the mechanisms through which the company implements security measures. It establishes that the company's cybersecurity program operates on a continuous basis and incorporates third-party testing and employee training as part of its security infrastructure.
CA-P-001701 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Equifax · Equifax Privacy Policy
This provision establishes Equifax's security obligations and the standard of care (reasonable measures rather than absolute protection) applicable to personal information in its possession. The clause operationalizes breach notification requirements under applicable state and federal law as a contractual obligation, defining the scope of Equifax's security commitments and the regulatory threshold triggering user notification.
CA-P-006953 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
T-Mobile · T-Mobile Privacy Policy
T-Mobile has experienced multiple significant data breaches affecting tens of millions of customers, making this provision's practical meaning directly relevant; the commitment to notify 'as required by applicable law' means the timing and scope of notification depends on jurisdiction-specific legal requirements, not a uniform standard.
CA-P-010246 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
high Liability limitation
FanDuel · FanDuel Terms of Use
This clause establishes FanDuel's position regarding the inherent security risks associated with digital information transmission and storage, placing the burden of understanding these risks on users prior to service use.
CA-P-006591 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Runway · Runway Privacy Policy
The provision clarifies Runway's position on data sharing disclosures and establishes an opt-out mechanism to comply with privacy regulations that require such choice for sales of personal information. It also acknowledges that certain browser tools or privacy signals may interfere with the opt-out functionality.
CA-P-007575 First tracked May 9, 2026 Last seen May 11, 2026 Compare across platforms →
Inflection AI · Inflection AI Privacy Policy
This provision establishes the operational framework for data continuity during corporate restructuring events. It clarifies that personal information held by Inflection AI may be transferred as an asset or business function to a successor entity without requiring separate user consent for the transfer itself.
CA-P-004146 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Adobe · Adobe Privacy Policy
The provision establishes the scope of third-party recipients of user data and specifies that behavioral data collected across Adobe properties may be transferred to advertising and marketing partners. This defines the operational data flow between Adobe and its advertising ecosystem partners.
CA-P-001074 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Lyft · Lyft Privacy Policy
This provision establishes the operational basis for Lyft's use of personal data in marketing activities and creates authorization for data sharing with third-party advertisers and marketing partners. It permits the use of inferred information about users, expanding the categories of data that can be deployed for advertising purposes beyond directly provided information.
CA-P-000845 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial