clause.watch Contracts Recent changes Start monitoring

Monitored company

Acquia

clause.watch tracks 1 legal document published by Acquia, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

28,333 characters · Read the original

Privacy Policy Overview — Acquia

1. Data Collection & Usage

Acquia collects information depending on how you interact with its Sites and Services, including:

  • Identity and contact data: name, email, phone number, address, employer, job title, username, password, and similar details.
  • Payment data: billing information, credit-card or bank-account details when purchasing products or registering for events.
  • Device and usage data: IP address, operating system, browser/server versions, cookies, web-beacon activity, email opens, website activity, and information identifying the organization using the Site.
  • Service and technical data: Drupal configuration, PHP/database versions, software versions, code modifications, site availability, user counts, nodes, comments, search queries, index size, and performance information.
  • Potentially broad customer-controlled data: Acquia may process information submitted by its business customers, potentially including employee details, credentials, device identifiers, logs, activity records, photographs, social-media information, localization data, and other data selected by the customer.
  • Communications: Acquia may record telephone calls. Information submitted in forums may be publicly visible.

Acquia uses data to provide and support Services, process orders, manage accounts, communicate with users, improve products and Sites, conduct analytics, provide targeted or behavioral advertising, send marketing, and support sales campaigns. Acquia may link website activity and cookies to registered-account information.

Important risk: If Acquia Search is enabled, it may index and store the content of your site. A backup copy may be retained for up to 14 days, while search activity and operational information may be stored indefinitely.

2. User Rights

Depending on applicable law, users may request:

  • Access to their data
  • Correction
  • Deletion
  • Restriction of processing
  • Objection or opt-out
  • Withdrawal of consent
  • Data portability

Requests may be submitted through Acquia’s privacy request form or by contacting privacy@acquia.com. EU/EEA, UK, California, and India residents may have additional rights under separate notices or applicable laws.

Marketing emails can generally be unsubscribed from. However, users cannot normally opt out of essential service, account, security, or maintenance communications.

If Acquia acts as a processor for an Acquia customer, affected end users should generally direct complaints and rights requests to that customer, which controls the processing.

3. Third-Party Sharing

Acquia says it does not sell personal information, but it may share data with:

  • Affiliates and corporate-group companies
  • Payment processors, vendors, consultants, and service providers
  • Business partners and technology partners, including for complementary product marketing
  • Government authorities where legally required
  • Successor entities in a merger, reorganization, asset sale, or acquisition

Service providers are generally required by contract to protect data and use it for limited purposes. Acquia may transfer data internationally, including to the United States, relying on the Data Privacy Framework (DPF), Standard Contractual Clauses, or other safeguards.

External websites linked from Acquia are governed by their own privacy policies.

4. AI/ML Training

The Policy does not expressly state whether personal data, Site content, search indexes, support communications, or usage data is used to train artificial-intelligence or machine-learning models. It permits broad uses to “improve” Services and for internal analysis, but that language does not clearly confirm or exclude AI training.

Users handling confidential or proprietary information should seek clarification from Acquia or review the applicable customer agreement and security/data-processing terms.

5. Key User Obligations and Restrictions

Users should:

  • Obtain authority and any required consent before providing Acquia with another person’s data.
  • Avoid posting personal or confidential information in forums.
  • Avoid sending proprietary ideas, suggestions, or confidential content by email; Acquia states email content, other than contact information, may be treated as non-confidential and used for any purpose.
  • Review third-party and customer-specific privacy notices.
  • Understand that cookies and tracking may support advertising, sales outreach, and activity-based campaigns.
  • Be at least 13, as the Site is not intended for younger children.

6. Liability and Disputes

The Policy describes security safeguards but does not provide a detailed financial liability cap, warranty disclaimer, or damages exclusion. It does not guarantee that security will prevent every breach.

Complaints should generally first go to the relevant Acquia customer when Acquia is processing data for that customer. Otherwise, users may contact Acquia’s Privacy Officer. Acquia may cooperate with the FTC and European or UK data-protection authorities.

For DPF-related complaints, unresolved matters may be referred to JAMS at no cost, with limited circumstances allowing binding arbitration. The Policy does not replace contractual dispute provisions in an Acquia service agreement.

7. Policy Changes

Acquia may update the Policy by posting a revised version online. It says users will see notice when logging in after a change is posted. Material changes may also be announced by email or a homepage notice.

Continued Site use or continued provision of personal data after changes generally constitutes acceptance of the then-current Policy. Regular review is therefore important.

Change history

2026-09-06 · Privacy Policy

shrank 9.1% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-05 · Privacy Policy

grew 10.0% · Observed by clause.watch

Executive Summary

The diff is extensive but appears to be primarily a rewrite, reorganization, and expansion of the Privacy Policy rather than a targeted change to AI-related data use. The most important substantive changes concern expanded data collection, broader use of customer and website data, marketing, and categories of data subjects.

Important Changes and Risks

1. Expanded categories of personal data collected

The revised text adds or expressly identifies:

  • Device and usage identifiers, including IP addresses, cookies, web beacons, and similar technologies.
  • Financial and billing information.
  • Call recordings.
  • Visitor information, including name, contact details, company, and visit date/time.
  • Employment and professional data, including job title, department, supervisor, employment history, employer, business travel, training, and work status.
  • Photographs, biographical information, social-media-related information, login identifiers, and localization data.
  • Information about users’ devices, access to IT systems, actions performed within the Services, and usage logs.

Risk: The policy now clearly covers substantially more sensitive or operational data, including employee information, credentials-related identifiers, location data, and website telemetry.

2. Broader collection through Drupal and subscription modules

The revised language states that Drupal installations connected to Acquia subscription services may report:

  • IP address and operating-system details;
  • Web-server, PHP, database, and software-version information;
  • Website availability;
  • Website statistics, including nodes, users, and comments.

This information may be linked to personally identifiable information and user accounts and used to provide technical support, support customers, and improve Acquia’s services.

Risk: Customer website and operational data may be associated with identifiable accounts and used for purposes beyond strictly delivering the service. Customers should assess whether this conflicts with their own privacy notices, data-processing instructions, or regulatory obligations.

3. Expanded marketing and partner communications

The revised policy adds or restores broader communications regarding products, services, special deals, promotions, and future purchases, including communications from third-party providers and Acquia technology partners. Opt-out rights remain available for some communications, but service-related communications generally cannot be opted out of except by deactivating the account.

Risk: Customers may receive more marketing communications and may have less practical control over service-related messaging.

4. Customer-controller framework clarified

The policy states that the customer determines and controls the type and extent of personal data processed by Acquia, while Acquia processes it to provide contractually agreed Services. It also adds detailed categories of customer representatives and end users.

Risk: Customers remain responsible for ensuring they have authority and, where required, consent to provide data concerning employees, contractors, users, and other individuals.

AI Model Training

No express change regarding AI training was identified in the supplied diff. The revised language does not expressly state that customer data, customer content, website statistics, support data, or personal data may be used to train, fine-tune, evaluate, or improve generative-AI or machine-learning models.

However, the broader purposes—particularly “improve” services, automated processing, technical support, and use of website and usage data—could create ambiguity if Acquia later uses such data for AI development. Customers should seek confirmation that customer data is not used for model training unless expressly authorized, and should check any separate Services Agreement, Data Processing Addendum, or AI terms.

2026-09-04 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary

The provided diff does not include the actual amended legal language. It only states:

> “Added approximately 372 words to the document”

Accordingly, it is not possible to identify the substantive changes, new obligations, allocation of risk, or effects on customer data and AI-model training.

AI Training and Data Use

No language is provided addressing whether customer data may be:

  • Used to train, fine-tune, or improve artificial-intelligence or machine-learning models;
  • Used to develop products, services, or features;
  • De-identified, aggregated, or combined with other data;
  • Shared with affiliates, vendors, or third-party AI providers;
  • Retained after termination;
  • Used for automated decision-making; or
  • Excluded from model-training activities unless the customer opts in or opts out.

Because the added text is unavailable, no conclusion can be drawn about whether the amendment expands or restricts these rights.

Risks That Cannot Yet Be Assessed

The missing language may materially affect:

  • Confidentiality: Whether customer information remains confidential when used for model development.
  • Intellectual property: Whether the provider receives rights in customer content, outputs, derivatives, or model parameters.
  • Privacy and regulatory compliance: Whether personal data may be processed for purposes beyond providing the contracted services.
  • Control and consent: Whether the customer has an opt-out, deletion, audit, or approval right.
  • Security: Whether data is transferred to third-party model providers or processed outside the customer’s approved environment.
  • Retention: Whether data or derived information remains available after account termination.
  • Indemnification and liability: Whether the provider disclaims responsibility for AI-related errors, unauthorized use, or regulatory violations.

Information Needed

Please provide the actual 372 words added to the document, together with any surrounding provisions that the new language modifies or references. The full redlined text is necessary to determine the legal effect and identify any new or heightened risks, especially concerning customer-data use for AI training.

2026-09-03 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary of Important Changes

1. Expanded categories of personal data collected

The revised policy substantially expands the examples of information Acquia may collect. New or more specific categories include:

  • Employment history, employer, job title, department, supervisor, and work status
  • Personal and business contact details, including home address, emergency contacts, and phone numbers
  • Photographs and biographical information
  • Social-media profiles or posts
  • User names, IDs, login credentials, and identifiers associated with devices or access to IT systems
  • Employee actions performed while using the Services
  • Business travel, training, localization, and other workforce-related information
  • Visitor information, including arrival date and time
  • Recorded telephone calls
  • Financial and billing information

Risk: The policy now supports collection of significantly more sensitive, employment-related, behavioral, and account-access information. Customers should verify that they have appropriate notices, consents, and contractual authority for supplying this data.

2. Increased monitoring of websites and service usage

Acquia may collect and link to customer accounts:

  • IP addresses and device or server configuration data
  • Drupal version, PHP and database versions
  • Website availability or “live/down” status
  • Website statistics, including numbers of nodes, users, and comments
  • Performance, security, configuration, and availability information

Drupal modules connecting installations to Acquia’s subscription services may automatically report this information to Acquia.

Risk: The revised wording more clearly permits telemetry and operational monitoring, and expressly allows this information to be linked to personally identifiable information and user accounts. This may create profiling, confidentiality, and data-minimization concerns, particularly where website statistics or technical data reveal customer operations.

3. Broader marketing and third-party communications

The prior policy focused more narrowly on service-related communications. The revised language permits communications about products, services, special deals, and promotions, potentially involving third-party service providers or Acquia technology partners. Service-related communications remain generally non-optional, and users may need to deactivate their accounts to avoid them.

Risk: Customers may receive broader marketing communications, with limited opt-out rights for service-related messages.

4. Customer data processing framework

The policy continues to state that the customer determines the type and extent of customer personal data and acts as controller, while Acquia processes it to provide contractual Services. The revised text adds more detailed categories of customer representatives and end users.

Risk: The policy alone does not establish clear limits on retention, subprocessors, international transfers, or use beyond service delivery. Those matters should be checked in the applicable data processing agreement.

5. AI-model training

No express change addressing AI training was identified in this diff. The revised text does not expressly say that customer data, prompts, content, telemetry, or personal data may—or may not—be used to train, fine-tune, evaluate, or improve Acquia’s or third parties’ AI models.

Key risk: The absence of an AI-specific restriction leaves uncertainty. Customers should seek written confirmation that customer content and personal data will not be used for model training except with explicit authorization, and should clarify treatment of de-identified, aggregated, telemetry, and support data.

2026-09-02 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary

The provided diff does not include the actual contractual language. It only states:

> “Added approximately 372 words to the document”

Accordingly, it is not possible to determine:

  • What legal terms were added, deleted, or replaced;
  • Whether liability, indemnity, confidentiality, termination, or other obligations changed;
  • Whether the customer granted new rights to use its data;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, vendors, or other third parties;
  • Whether the customer can opt out of AI training or request deletion of training data; or
  • Whether new security, privacy, retention, or intellectual-property risks were introduced.

Please provide the full redline text, including the words shown in {additions}, [deletions], and []{replacements}. Once provided, the changes can be analyzed for their legal effect and AI-training implications.

2026-09-01 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary

The provided diff does not include the actual amended legal language. It only states:

> “Added approximately 372 words to the document”

As a result, it is not possible to identify the substantive legal changes, new obligations, allocation of risk, or effects on customer data.

AI Training and Data Use

No language is provided addressing whether customer data may be:

  • Used to train, fine-tune, or improve AI models;
  • Used to develop products, services, or algorithms;
  • Retained after the customer relationship ends;
  • Shared with affiliates, vendors, or model providers;
  • De-identified, aggregated, or otherwise transformed before use;
  • Excluded from model training by default or only upon opt-out;
  • Used to generate or retain prompts, outputs, embeddings, logs, or metadata.

Accordingly, no conclusion can be reached about whether the amendment expands or restricts AI-related data use.

Important Risks Requiring Review

The missing text should be checked for:

1. Consent and scope — Whether customer data can be used for purposes beyond providing the contracted services.

2. Training rights — Whether the provider receives a broad, perpetual, irrevocable, worldwide, or royalty-free license to use data for AI training.

3. Confidentiality — Whether data used for training remains confidential and subject to contractual safeguards.

4. Deletion and retention — Whether training datasets, backups, logs, and derived data are deleted upon request or contract termination.

5. Third-party access — Whether data may be sent to external AI providers or used to train third-party models.

6. Customer control — Whether customers can opt out, and whether the opt-out applies retroactively.

7. Ownership and outputs — Whether the provider claims rights in customer data, derived data, models, or AI-generated outputs.

8. Compliance and liability — Whether the amendment changes responsibility for privacy, confidentiality, intellectual-property infringement, or regulatory violations.

Information Needed

Please provide the actual added, deleted, and replacement language. Without the text of the 372-word addition, a reliable legal comparison cannot be performed.

2026-08-30 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary of Important Changes

1. AI-Model Training

  • No express change addresses training, fine-tuning, evaluating, or improving AI models.
  • The revised text does not state whether customer data, usage data, support communications, website content, or personal data may be used to train Acquia’s or third-party AI models.
  • Because the policy adds broad language about using information to “better provide technical support,” improve content, administer services, and maximize the digital experience, there is some ambiguity about whether data could be used for automated analytics or AI-enabled service improvement.
  • Customers should seek clarification or contractual restrictions confirming that customer content and personal data will not be used for AI training unless expressly authorized.

2. Expanded Categories of Personal Data

The revised policy substantially expands the categories of information that may be collected, particularly in the customer-data processing section. New or more detailed categories include:

  • Employment history, employer, department, title, supervisor, and employment status.
  • Personal and business contact details, including home address, phone number, emergency contact information, and physical business address.
  • Photographs, biographical and directory information.
  • Linked social-media profiles or posts.
  • Usernames, IDs, login credentials, and identifiers associated with devices used to access IT systems.
  • IT-system logs, actions performed while using the services, training information, business-travel arrangements, and localization data.

Risk: The policy now potentially covers sensitive workforce, authentication, behavioral, and location-related information. Customers may need to verify that their notices, consents, data inventories, and data-processing agreements cover these categories.

3. Expanded Telemetry and Service Monitoring

The revised language more clearly permits Acquia to collect and link:

  • IP addresses and operating-system, web-server, PHP, database, and service-version information.
  • Drupal code and technical configuration information.
  • Website availability status.
  • Website statistics, including numbers of nodes, users, and comments.
  • Information linked to personally identifiable information and user accounts.

This information may be used to provide technical support, improve Acquia’s services, administer the Site, and support the customer relationship.

Risk: Linking technical telemetry and website statistics to identifiable accounts increases profiling and re-identification risks. Customers should confirm whether this telemetry includes customer content, end-user activity, or regulated data.

4. Broader Marketing and Disclosure Language

  • Marketing language changes from limited service-related announcements to communications about products, services, special deals, and promotions.
  • Communications may involve third-party service providers and Acquia technology partners.
  • Global transfers and disclosures to affiliates, partners, vendors, and service agencies remain broadly permitted.

5. Other Changes

  • The policy adds recording of phone calls.
  • It adds visitor information collection, including name, contact details, company, and arrival date/time.
  • It adds clearer procedures and contact details for privacy requests and regional representatives.

Overall assessment: The revision significantly broadens data collection and operational uses, but contains no clear AI-training authorization or prohibition.

2026-08-30 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary

The diff only states that approximately 372 words were added, but does not include the added language or identify where it appears in the agreement.

AI Training and Data Use
  • It is not possible to determine whether the changes permit, restrict, or otherwise affect the use of customer data to train AI models.
  • The diff does not reveal whether the agreement now addresses:
  • Training or fine-tuning AI or machine-learning models using customer data;
  • Whether customer data, prompts, outputs, or usage data may be used;
  • Whether data is used for general product improvement or only to provide services;
  • Opt-out rights or consent requirements;
  • Retention, deletion, anonymization, or aggregation of data;
  • Whether subcontractors or third-party AI providers may access the data;
  • Ownership of customer inputs, outputs, or models;
  • Confidentiality and security protections applicable to AI processing; or
  • Restrictions on using personal, sensitive, or regulated information.
Legal and Commercial Risks

Because the actual added wording is missing, the following potential risks cannot be assessed:

  • Expansion of the provider’s license to use customer content;
  • Use of customer data for purposes beyond contract performance;
  • Disclosure of data to affiliates, vendors, or AI providers;
  • Reduced confidentiality or privacy protections;
  • Broad rights to retain or reuse data after termination;
  • Unclear ownership or permitted use of AI-generated outputs; and
  • New customer obligations, warranties, indemnities, or liability limitations.
Conclusion

No substantive legal analysis can be performed from the provided diff. The approximately 372 added words—or a redline showing the actual additions—are needed to identify the changes, assess their effect, and determine whether customer data may be used to train AI models.

2026-08-28 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary of Important Changes

1. Expanded categories of personal data collected

The revised policy substantially expands the types of information Acquia may collect, including:

  • Employment information, such as job title, department, supervisor, employment history, employer, work status, training, and business travel.
  • Personal and business contact details, including home address, emergency contacts, phone numbers, and physical addresses.
  • Photographs, biographical and directory information.
  • Social-media profile links or posts, company usernames or IDs, and login credentials.
  • Device and access information, including identifiers, IP address, operating-system and server details, software versions, localization data, and activity logs.
  • Website and service usage information, including website availability, user statistics, number of nodes, users, and comments.
  • Financial and billing information, including credit-card or bank-account information.

Risk: The collection scope is materially broader and may include sensitive employment, security, authentication, and operational information. Customers should verify that they have appropriate notices, permissions, and legal bases for providing this information, particularly where it relates to employees, end users, or other individuals.

2. Increased monitoring of customer websites and service usage

The revised language more clearly states that Drupal modules connected to Acquia subscription services may report information to Acquia. Acquia may collect technical data and website statistics, link that information to personally identifiable information and user accounts, and use it to provide technical support and improve Acquia’s sites and services.

Risk: Customer activity and website telemetry may be associated with identifiable customer accounts. The policy does not, in this diff, specify detailed retention periods, aggregation standards, or limits on secondary use.

3. Broader marketing and communications use

The policy changes from primarily service-related or limited communications to allowing information about products, services, special deals, and promotions, including communications from third-party providers and Acquia technology partners. Users may opt out of promotional communications, but service-related communications generally cannot be opted out of except by deactivating the account.

Risk: Customers and users may receive broader marketing communications, and data may be shared with partners for those purposes. The distinction between “service-related” and promotional communications could be disputed or applied broadly.

4. New collection practices

The revised policy adds or clarifies collection of:

  • Information submitted through surveys, events, webinars, contests, questionnaires, support requests, and content downloads.
  • Device and usage data collected through cookies, web beacons, and similar technologies.
  • Financial information for purchases.
  • Recorded phone calls.
  • Visitor information for Acquia offices.

It also adds an express requirement that individuals providing information about others have authority and, where required, consent.

5. AI-model training

No express change regarding AI or use of customer data to train AI models is identifiable in this diff. The revised language does not mention artificial intelligence, machine learning, model training, model improvement, prompts, outputs, or training datasets.

However, the broader rights to collect, link, analyze, and use website, account, usage, and technical information to improve Acquia’s sites and services could create ambiguity if Acquia later applies those data to AI-related development. Customers should seek separate contractual confirmation that customer content, service data, prompts, and outputs will not be used to train or improve models without express authorization.

2026-08-26 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary

The provided diff states only that “approximately 372 words” were added. It does not include the actual added language, deletions, or replacements.

Key Legal Changes

  • Cannot be determined: The substance of the changes, including modifications to rights, obligations, liability, confidentiality, data processing, termination, or governing law, is not provided.
  • No comparison possible: Because the original and revised wording are absent, it is not possible to identify whether provisions were expanded, narrowed, or otherwise changed.

Customer Data and AI Training

  • No determination possible: The provided information does not reveal whether customer data may be:
  • Used to train, fine-tune, evaluate, or improve AI or machine-learning models;
  • Shared with affiliates, vendors, or other third parties for model development;
  • Used in aggregated, de-identified, or anonymized form;
  • Retained after termination for AI-related purposes; or
  • Excluded from training or subject to an opt-out.
  • Important risk to check: Any newly added language permitting use of customer content, inputs, outputs, usage data, or telemetry for AI training could materially expand the provider’s rights and create confidentiality, privacy, intellectual-property, or regulatory risks.

Information Needed

Please provide the actual redline text, including:

1. The original language;

2. The revised language; and

3. The additions, deletions, and replacements.

Without the underlying wording, no reliable legal-risk analysis can be performed.

2026-08-24 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary of Important Changes

AI Model Training

  • No express provision addressing AI training was added or removed in the supplied diff.
  • The revised text does, however, expand the categories of information Acquia may collect and link to identifiable users or accounts. This could become relevant if such information is later used in AI systems, but the policy does not state:
  • whether customer data is used to train, fine-tune, or evaluate AI models;
  • whether customer content is excluded from training;
  • whether data is anonymized or de-identified before AI use;
  • whether third-party AI providers receive the data;
  • how customers or individuals can opt out; or
  • how long AI-related copies or derived data are retained.
  • Customers should seek clarification in the services agreement, data-processing addendum, or a specific AI/data-use policy. The absence of a restriction is a potential interpretive and compliance risk, particularly for confidential customer content and regulated personal data.

Expanded Data Collection

The revised policy substantially broadens the information Acquia may collect, including:

  • employment and organizational information, such as job title, department, supervisor, employment history, employer, and work status;
  • personal and business contact details, physical addresses, emergency contacts, photographs, and biographical information;
  • social-media profiles or posts, usernames, login credentials, device identifiers, localization data, and activity logs;
  • information about access to a customer’s IT systems and actions performed while using the Services;
  • business travel, training, and device-use information; and
  • financial and billing information, including credit-card or bank-account information.

Risk: The expanded categories may increase privacy, security, breach, minimization, and employee-monitoring obligations. Some data may be sensitive depending on context.

Customer Website and Service Telemetry

  • Acquia now states that Drupal modules connected to its subscription services may report technical information, including IP address, software versions, website availability, and website-user statistics such as numbers of users, nodes, and comments.
  • This information may be linked to personally identifiable information and user accounts and used to improve technical support, the Site, and Acquia’s services.

Risk: Linking operational or usage data to identifiable individuals increases profiling and re-identification concerns. Customers should confirm whether this telemetry can include customer content, end-user data, or production identifiers.

Marketing and Third-Party Disclosures

  • Marketing language is broader: Acquia may send information about products, services, deals, and promotions, including communications from third-party providers and technology partners.
  • It may share information with affiliates, partners, vendors, and service agencies.

Risk: Customers and users may receive broader marketing communications and may need to rely on opt-out mechanisms.

Other Changes

  • Acquia may record telephone calls.
  • Global transfers and access by affiliates and third parties are expressly described.
  • The policy adds more detailed rights-request contacts and regional representatives.
  • Customers providing information about other individuals must represent that they have authority and, where required, obtained consent.

2026-08-23 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary of Important Changes

AI Model Training

  • No express reference to artificial intelligence, machine learning, generative AI, model training, fine-tuning, or use of customer data to develop AI models appears in the supplied diff.
  • The revised language does, however, expand the categories of data Acquia may collect and use—including website telemetry, user statistics, Drupal code, device identifiers, usage information, support communications, and extensive employee information. Those provisions could create practical concern if such data is later used for analytics, product improvement, or AI-related purposes, but the diff itself does not authorize AI training expressly.
  • Customers should confirm whether Acquia’s broader terms, service-specific notices, or data-processing addenda contain separate AI-training rights or restrictions.

Expanded Data Collection

The revised policy adds or clarifies collection of:

  • Device and usage data, including IP addresses and other identifiers, cookies, web beacons, and email-interaction data.
  • Financial and billing information, including credit-card or bank-account information.
  • Telephone-call recordings.
  • Visitor information, including name, email, phone number, company, arrival time, and date.
  • Extensive business and employee data, including employment history, manager, work status, business travel, training, localization data, social-media information, login credentials, device-access data, and employee actions within systems.
  • Website and Drupal telemetry, including IP address, operating-system and server versions, PHP/database versions, Drupal code, website availability, number of nodes, users, comments, and other user statistics.

Risk: The scope is materially broader and includes potentially sensitive information and credentials. Customers should assess whether the listed data is actually necessary and whether the policy aligns with their notices, consents, and contractual data-minimization obligations.

Linking and Use of Customer Data

  • Website, service, and usage information is expressly stated to be linked to personally identifiable information and user accounts.
  • Acquia may use this information to provide technical support, support customers, improve the Site and services, administer content, and maximize the customer’s digital experience.
  • Drupal modules may automatically report technical and usage information to Acquia.

Risk: Linking telemetry to identifiable accounts increases profiling and re-identification risks. Customers may need to disclose this processing to their users and ensure contractual authorization exists.

Marketing and Communications

  • Promotional communications expand from product/service updates to products, services, special deals, and promotions, potentially involving third-party providers and Acquia technology partners.
  • Service-related communications remain generally non-optional, although the revised wording says users may deactivate their accounts instead.

Risk: Broader marketing disclosures and third-party involvement may create consent, electronic-marketing, and employee-communication compliance issues.

Customer Responsibilities and Transfers

  • The policy reinforces that the customer controls the type and extent of customer personal data processed by Acquia.
  • Customers providing data about others represent that they have authority and, where required, obtained consent.
  • Global transfers to Acquia affiliates and third-party processors remain contemplated.

Risk: Customers should verify processor terms, international-transfer mechanisms, subprocessor disclosures, retention provisions, and security obligations separately.

2026-08-22 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary

The provided diff does not include the actual contractual language that was added, deleted, or replaced. It only states:

> “Added approximately 372 words to the document”

Accordingly, it is not possible to determine:

  • What legal obligations or rights changed;
  • Whether liability, indemnity, confidentiality, security, or termination provisions were modified;
  • Whether customer data may be used for artificial intelligence or machine-learning purposes;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, subprocessors, or third-party AI providers;
  • Whether customer consent, opt-out rights, deletion rights, or ownership protections were added or removed.

AI Training and Data-Use Analysis

No substantive language concerning AI models or training is included in the supplied diff. Therefore, no conclusion can be reached about whether the revised agreement:

  • Permits training on customer content or personal data;
  • Limits training to aggregated, de-identified, or anonymized data;
  • Prohibits using customer data to train general-purpose models;
  • Allows human review or access to data for model improvement;
  • Gives the customer an opt-out or requires affirmative consent;
  • Requires deletion of training data, model inputs, outputs, or derived information; or
  • Allocates responsibility for confidentiality, privacy, intellectual-property, or regulatory risks arising from AI use.

Recommended Next Step

Provide the full redline or the actual 372 words, including the relevant additions, deletions, and replacements. The changes can then be reviewed for legal effect and specifically assessed for customer-data use in AI training.

2026-08-22 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary of Important Changes

1. Expanded categories of personal data collected

The revised policy substantially expands the examples of data Acquia may collect, including:

  • Device and usage data, such as IP addresses, operating-system and server versions, PHP/database versions, cookies, web beacons, and email interaction data.
  • Financial and billing information, including credit-card or bank-account information.
  • Office-visitor information, including name, email, phone number, company, arrival time, and date.
  • Recorded telephone calls.
  • Employment and professional information, including job title, department, supervisor, employment history, employer, work contact details, business-travel arrangements, training, and full- or part-time status.
  • Photographs, biographical information, social-media profiles or posts, login credentials, device identifiers, localization data, and activity performed while accessing customer IT systems.

Risk: The policy now supports collection of a much broader and potentially more sensitive dataset. Some categories—credentials, employment records, location data, and financial information—create heightened security, proportionality, and regulatory risks.

2. Broader monitoring of customer websites and services

The policy newly or more clearly states that Drupal modules connected to Acquia subscription services may report information to Acquia, including:

  • IP address and technical configuration;
  • Website availability;
  • Website user statistics, including numbers of nodes, users, and comments; and
  • Performance, security, configuration, and availability information.

This information may be linked to personally identifiable information and user accounts and used to provide technical support, improve Acquia’s services, and administer websites.

Risk: Customers may have less control or visibility over telemetry collected from their environments. Linking technical and usage data to identifiable accounts may increase profiling and confidentiality concerns, particularly where website statistics could reveal business operations or user activity.

3. Expanded marketing and partner communications

The prior focus on occasional service-related announcements is replaced or supplemented with broader communications about products, services, special deals, and promotions. The policy also refers to communications from third-party providers and Acquia technology partners.

Service-related communications generally remain non-opt-out, while promotional communications are subject to the stated opt-out process.

Risk: Customers and users may receive more marketing communications, and personal data may be used or shared for partner-related marketing. The distinction between service-related and promotional messages could be disputed.

4. Customer responsibility for third-party data

The revised language expressly states that a person providing personal data about others represents that they have authority and, where required, obtained consent.

Risk: This increases the customer’s compliance responsibility and may create contractual or regulatory exposure if employee, contractor, customer, or end-user data is provided without an appropriate legal basis.

5. AI-model training

No express change concerning AI or use of customer data to train AI models was identified in the supplied diff. The revisions do not expressly authorize or prohibit using customer content, telemetry, or personal data to train, fine-tune, or evaluate AI models. This absence leaves an important issue unresolved and should be clarified in the contract or a data-processing addendum.

6. Other changes

The policy updates privacy-contact details, adds EU, UK, and India representative information, and continues to permit global transfers and processing through affiliates and third parties.

2026-08-21 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary

The provided diff does not include the actual added, deleted, or replaced legal language. It only states:

> “Added approximately 372 words to the document”

As a result, it is not possible to determine:

  • What contractual terms changed;
  • Whether liability, indemnity, confidentiality, intellectual-property, termination, or governing-law provisions were modified;
  • Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, subprocessors, vendors, or model providers;
  • Whether the customer has any opt-out, deletion, audit, or data-use control rights; or
  • Whether new security, retention, or regulatory obligations were added.
AI Training Review

No substantive language concerning AI-model training or related data use is included in the supplied diff. Therefore, no conclusion can be reached about whether the revised agreement:

  • Permits training on customer content or prompts;
  • Uses customer data to improve shared or general-purpose models;
  • Restricts training to de-identified or aggregated data;
  • Requires customer consent or provides an opt-out;
  • Gives the provider ownership or broad licensing rights over training outputs; or
  • Applies different rules to personal data, confidential information, or usage data.
Information Needed

Please provide the actual redline text, including the words shown in braces, brackets, and replacement combinations. The substantive additions and deletions are necessary to identify legal risks and explain the practical effect of the changes.

2026-08-20 · Privacy Policy

grew 10.0% · Observed by clause.watch

Summary of Important Changes

AI Model Training

  • No express provision concerning AI or training AI models appears in the supplied diff.
  • The revised language does, however, expand the types of information Acquia may collect and use, including:
  • Website and user statistics;
  • IP addresses, device and software information;
  • Drupal code and service configuration data;
  • Availability and performance information;
  • User-account-linked data;
  • Support and communications data; and
  • Information submitted in surveys, forums, events, and other interactions.
  • The policy states that this information may be used to provide technical support, improve Acquia’s services and content, and administer the Site. It does not say whether any of this information may be used to train, fine-tune, evaluate, or improve AI models.
  • Accordingly, the diff does not create a clearly stated AI-training right, but the broadened “improve” and service-administration purposes could create ambiguity if Acquia later uses collected data in AI development. Customers should seek confirmation that customer content, telemetry, support communications, and end-user data will not be used for AI training unless expressly authorized.

Expanded Data Collection

The revised policy substantially broadens and clarifies collection activities. New or more explicit categories include:

  • Financial and billing information;
  • Recorded phone calls;
  • Visitor information, including name, contact details, company, and arrival time;
  • Device identifiers, cookies, web beacons, IP addresses, and usage data;
  • Drupal installation data, technical configuration, code-related information, website status, and user statistics;
  • Employment and business information, including job history, manager, employer, work status, travel, training, emergency contacts, photographs, biographies, social-media information, login credentials, and localization data.

Risk: The scope of personal data is materially broader, and some data may be sensitive or security-critical, particularly login credentials, employee information, emergency contacts, and detailed technical data.

Linking and Profiling Risk

  • Technical and usage information may be linked to personally identifiable information and user accounts.
  • This increases the possibility of user profiling and makes supposedly technical or aggregate data more readily attributable to individuals or organizations.

Marketing and Communications

  • Marketing purposes are broadened to include products, services, special deals, promotions, and communications from third-party providers and Acquia technology partners.
  • Service-related communications remain generally non-optional, while promotional communications retain an opt-out mechanism.

Risk: Customers and users may receive more marketing communications and may have limited ability to opt out of operational messages.

Customer and Third-Party Data

  • Individuals providing data about others must represent that they have authority and, where required, obtained consent.
  • This places additional compliance responsibility on customers supplying employee, contractor, collaborator, or end-user data.

International Transfers and Representatives

  • The policy continues to permit global transfers and access by affiliates and third parties.
  • It adds or updates EU, UK, and India representative and contact information, including a dedicated privacy email address.

Drafting/Implementation Concern

  • The diff contains substantial duplicated, reordered, and apparently malformed text. Acquia should confirm the published final version and ensure the policy accurately reflects the intended purposes, data categories, retention practices, and any AI-related restrictions.

2026-08-19 · Privacy Policy

shrank 9.1% · Observed by clause.watch

Summary

The diff only states that approximately 372 words were added; it does not include the actual added language or identify where the additions occur.

AI Training and Customer Data
  • No conclusion can be reached about whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models.
  • The diff does not reveal whether:
  • Customer prompts, inputs, outputs, files, or personal information may be used for model training;
  • The customer must opt in or may opt out;
  • Data is anonymized, de-identified, aggregated, or retained;
  • human reviewers or service providers may access the data;
  • the provider may use data to train models for itself or third parties; or
  • separate restrictions apply to confidential information or regulated data.
Other Legal Risks

The actual legal effect cannot be assessed without the text of the 372 added words. Important potential changes could involve confidentiality, data ownership, licensing rights, retention, security, indemnification, liability limits, or regulatory compliance.

Required Information

Please provide the full diff, including the text within the additions marked with {} and any deletions or replacements. Without that language, there are no substantive contractual changes that can reliably be identified.

Between 2018-01-31 and 2020-09-03 · Privacy Policy

grew 21.8% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2016-07-22 and 2018-01-31 · Privacy Policy

grew 21.6% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2015-03-30 and 2016-04-02 · Privacy Policy

shrank 2.7% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2008-03-09 and 2015-03-30 · Privacy Policy

grew 90.8% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free