Provision Registry

12505 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
medium Data retention
Medium · Medium Privacy Policy
This clause defines the operational framework for data retention duration and grounds for post-termination retention. It establishes that retention extends beyond active account status for specified institutional purposes, rather than limiting retention to the active service period alone.
CA-P-006299 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Calendly · Calendly Privacy Notice
This clause defines the operational scope and duration of Calendly's data stewardship obligations. It establishes that retention decisions are tied to stated business purposes and legal requirements, with a requirement to dispose of or de-identify data once those purposes no longer apply.
CA-P-006426 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Rumble · Rumble Privacy Policy
The clause creates a standard data retention framework tied to operational necessity while preserving Rumble's ability to maintain data longer when legally required, establishing the institutional basis for how long personal data remains in active use or storage systems.
CA-P-004492 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Dropbox · Dropbox Privacy Policy
The clause defines the operational retention timeline for user data and establishes a deletion initiation process rather than immediate deletion upon account termination. The 30-day window creates a defined transition period between account closure and data removal completion.
CA-P-001040 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Privacy rights
Replicate · Replicate Privacy Policy
The retention period is not specified in concrete terms, meaning your data could be kept for an indefinite period under the broadly stated 'legitimate interests' justification, and residual backup copies may persist even after a deletion request.
CA-P-004182 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
DocuSign · DocuSign Privacy Statement
The clause defines the operational parameters for data lifecycle management by tying retention duration to stated business and legal purposes rather than establishing a fixed time period, which affects the scope and duration of DocuSign's data stewardship obligations.
CA-P-001056 First tracked Apr 3, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Udemy · Udemy Privacy Policy
The provision establishes a flexible retention framework that ties data persistence to operational and legal necessity rather than fixed time periods. This structure authorizes retention decisions based on multiple justifications, each with potentially different duration implications.
CA-P-006796 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Figma · Figma Privacy Policy
The clause establishes retention criteria based on functional necessity rather than fixed time periods, meaning data persistence is tied to stated operational and legal purposes rather than automatic deletion schedules. This framework allocates responsibility for determining retention duration based on the purposes identified at collection.
CA-P-001112 First tracked Apr 3, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Squarespace · Squarespace Privacy Policy
The clause creates a need-based retention standard rather than fixed retention periods, authorizing Squarespace to maintain data for operational and compliance purposes while establishing obligations to remove or isolate data when business justification ends. This affects the duration and scope of data processing the company conducts.
CA-P-006878 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
AWS · AWS Privacy Notice
This provision establishes the data retention framework governing how long AWS maintains personal information in its systems. The retention period is tied to service delivery necessity, stated purposes, legal mandates, and specific communications to users rather than a fixed timeframe.
CA-P-005587 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Thomson Reuters · Thomson Reuters Privacy
The provision operationalizes how long Thomson Reuters maintains personal data across its systems and establishes the criteria governing retention decisions. This framework directly affects data lifecycle management, compliance with regulatory retention mandates, and the timing of data deletion or anonymization processes.
CA-P-006159 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Home Depot · Home Depot Privacy Policy
This provision establishes Home Depot's operational framework for data lifecycle management, defining both the retention period (tied to stated purposes and legal obligations) and the company's obligation to dispose of data upon purpose completion. The clause creates a time-limited retention model rather than indefinite data storage.
CA-P-006761 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Glean · Glean Privacy Policy
The clause establishes the operational framework for data retention periods across different processing contexts. It distinguishes between Glean's independent data controller retention practices and its processor obligations, which are governed by customer instructions rather than unilateral Glean policy.
CA-P-004387 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Data retention
Kick · Kick Privacy Policy
The clause defines the retention standard as tied to legitimate business necessity rather than establishing fixed retention periods, which means data retention duration depends on the classified purpose of collection and applicable regulatory obligations.
CA-P-005953 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Waze · Waze Privacy Policy
The provision defines the operational scope of data retention by linking persistence to service delivery and legal obligations, while separately authorizing prolonged retention of location and usage data as a distinct operational practice for service enhancement.
CA-P-001592 First tracked Apr 3, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Headspace · Headspace Privacy Policy
The retention policy creates a tiered framework that ties data persistence to operational relationship status and legal requirements rather than a fixed retention schedule. This structure permits extended retention periods when legal obligations or litigation risk factors are present, giving the entity discretion in applying retention timeframes within the bounds stated.
CA-P-001140 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Webull · Webull Privacy Policy
This clause defines the operational boundaries for how long Webull stores user data, establishing that retention periods are governed by necessity of purpose and legal compliance rather than indefinite storage. The provision creates a structured framework requiring ongoing assessment of retention appropriateness based on specified criteria.
CA-P-000496 First tracked Apr 3, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Binance.US · Binance.US Privacy Policy
This provision establishes the temporal scope and operational basis for data retention. By anchoring retention to legal compliance obligations and dispute resolution, the clause creates an indefinite retention framework where retention duration is determined by regulatory requirements and contractual enforcement needs rather than a fixed time period.
CA-P-000542 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Bumble · Bumble Privacy Policy
The clause operationalizes data retention constraints by tying data lifecycle management to dual criteria: functional necessity and legal compliance ceilings. This establishes a procedural framework for when Bumble must delete or depersonalize user data rather than maintaining indefinite archives.
CA-P-001200 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Privacy rights
Midjourney · Midjourney Privacy Policy
The policy does not specify fixed retention periods for most data categories, instead using purpose-based retention language; the carve-out allowing extended retention to improve service functionality could cover a broad range of operational activities.
CA-P-000674 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Eufy · Eufy Privacy Policy
Without specific retention periods stated for sensitive data categories like video footage and biometric data, users cannot know how long their most sensitive information is kept, and regulators may view this as inconsistent with data minimization principles.
CA-P-009532 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
OpenAI · Privacy Policy (ROW)
The clause operationalizes data lifecycle management by anchoring retention to multiple justified purposes rather than a fixed timeline. This structure permits extended retention where legal or operational justification exists while establishing that retention is not indefinite.
CA-P-000046 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Ledger · Ledger Privacy Policy
This provision establishes the operational framework for data retention duration, permitting extended retention periods when justified by legal compliance requirements or contractual enforcement needs, rather than restricting retention to a fixed timeframe.
CA-P-003655 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Tabnine · Tabnine Privacy Policy
The provision creates a dual retention framework: a service-necessity standard for ongoing operations, and a broader set of institutional purposes (legal compliance, dispute resolution, fraud prevention, agreement enforcement, legitimate interests) that may extend retention beyond active service provision. This structure allows data retention across multiple operational and legal contexts.
CA-P-004225 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Privacy rights
Netflix · Netflix Privacy Statement
The policy does not state specific retention durations for most data categories, instead reserving discretion to determine retention based on business and legal purposes; this may be relevant to users exercising deletion rights under GDPR, CCPA, or other applicable law.
CA-P-000350 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TransUnion · TransUnion Privacy Policy
There is no fixed maximum retention period for most personal data at TransUnion, and anonymized data derived from your information may be kept and used forever, even if you later request deletion of your identifiable data.
CA-P-009413 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
OnlyFans · OnlyFans Privacy Policy
The provision creates dual retention standards: a primary baseline tied to operational necessity and legal requirements, and an extended retention authorization upon occurrence of specified conditions. This structure establishes the operational parameters governing data lifecycle management and compliance duration.
CA-P-006088 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
BeReal · BeReal Privacy Policy
The provision creates a defined data lifecycle management framework that complies with regional data protection standards while establishing the temporal boundaries for information storage. This structure governs when user data is subject to deletion or archival under the service's operational requirements.
CA-P-001314 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Suno · Suno Privacy Policy
Data retention policies establish the operational timeline for when personal information is deleted or anonymized from company systems, which affects the scope and duration of data processing activities.
CA-P-004403 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Data retention
Databricks · Databricks Privacy Notice
This clause operationalizes Databricks' retention obligations by establishing the criteria and decision-making framework that governs how long personal data remains in the company's systems. It creates a standard tied to purpose fulfillment and regulatory compliance rather than indefinite retention or user-directed deletion timelines.
CA-P-004412 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial