Monitored company
Bird
clause.watch tracks 2 legal documents published by Bird (bird.com), re-reading each one every six hours. Below is what each document covers, in plain English.
Legal
Bird CRM Terms: Practical Overview
*This summary is based only on the General Terms and Conditions provided. The referenced Privacy Statement, Data Processing Agreement (DPA), Acceptable Use Policy (AUP), Product Specific Terms, and Order Form may materially change the analysis.*
1. Data Collection and Usage
Information expressly mentioned
Bird may receive or process:
- Account information: email address, phone number, password, registration and contact details.
- Billing information: credit-card, direct-debit, invoice, tax, payment, and transaction information.
- Customer Data: content, communications, applications, software, web-domain data, and other information submitted by you, your employees, affiliates, or end users through the Services.
- Account and usage information: access credentials, API keys, usage volumes, account activity, and information relevant to security or compliance audits.
- Feedback: suggestions and recommendations, which Bird generally owns or receives a broad perpetual license to use.
- Derived data: Bird may create “Provider Data,” including de-identified and aggregated information derived from Service usage.
Bird may process Customer Data to provide, maintain, secure, optimize, and support the Services, consistent with the Agreement, DPA, and Privacy Statement. You retain ownership of Customer Data, but grant Bird and its Affiliates a broad license to reproduce, adapt, modify, translate, publish, perform, display, and distribute it as necessary to provide the Services.
Important gap: The supplied terms do not specify all categories of personal information, retention practices, international transfers, cookies, or detailed purposes. Consult the Privacy Statement and DPA.
2. User Rights
- You retain intellectual-property ownership of Customer Data.
- After termination, Bird generally says it will delete Customer Data and Confidential Information within 45 days, unless a statutory retention period applies or retention is needed for legal claims. Data may also remain where needed for other active Services.
- The terms do not provide a detailed list of privacy rights such as access, correction, portability, objection, or deletion requests. Those rights likely appear in the Privacy Statement or DPA and depend on applicable law.
- Customers are responsible for obtaining all legally required permissions and consents from individuals whose data they submit.
3. Third-Party Sharing
Bird may share data with:
- Affiliates providing Services, billing, or support.
- Contractors, representatives, and service providers with a need to know, subject to confidentiality obligations.
- Partners and consultants for referrals, implementation, or Partner Sales Agreements. Customer Data may be exchanged with partners for those purposes.
- Payment processors, debt collectors, and debt-factoring agencies for billing and collection.
- Law enforcement, regulators, communications providers, or courts when legally compelled or responding to emergency disclosure requests.
- Third-party communications providers and integrations, as relevant to the Services.
Bird may use and own de-identified and aggregated Provider Data. The agreement also permits Bird to use your name, logo, and use case for marketing unless separately restricted by trademark guidelines.
4. AI/ML Training
The supplied terms do not expressly state that Customer Data is used to train AI or machine-learning models, nor do they expressly prohibit it. The Provider Data clause permits Bird to use derived data that is de-identified and aggregated, but this is not the same as an explicit AI-training authorization.
Review the Privacy Statement, DPA, Product Specific Terms, and any AI-specific terms for a definitive answer. If sensitive or confidential data is involved, seek written clarification or contractual limits.
5. Key User Obligations and Restrictions
You must:
- Provide accurate, current account and billing information.
- Protect passwords, API keys, and other access controls.
- Be responsible for all account activity, including affiliates, employees, and end users.
- Ensure Customer Data is lawful, authorized, and non-infringing.
- Comply with the AUP, applicable law, trade restrictions, and third-party provider rules.
- Promptly report unauthorized access.
- Pay fees, taxes, surcharges, overages, and disputed invoices within 15 days of the invoice date if disputing.
- Avoid reverse engineering, copying, modifying, reselling, leasing, or unauthorized third-party access.
Bird may suspend accounts for suspected breaches, illegal or fraudulent activity, security risks, incomplete information, nonpayment, or AUP violations—potentially without liability for resulting data loss or business harm.
6. Liability and Disputes
- Services are largely provided “as is,” with limited express warranties.
- Bird’s main warranty remedy is correction or a refund for the affected period.
- Neither party is generally liable for indirect or consequential losses, including lost profits, revenue, goodwill, business interruption, or data loss.
- Aggregate liability is generally capped at fees paid or payable for the relevant Services during the preceding 12 months.
- The cap does not apply to your payment obligations, indemnities, or breaches of core responsibilities.
- You may owe broad indemnification for claims arising from your data, applications, users, legal violations, or misuse.
- Disputes go to the exclusive courts specified by contracting entity—generally Amsterdam courts for non-U.S. customers and Wilmington, Delaware courts for applicable U.S. customers. Class actions are waived to the extent permitted by law.
7. Changes and Renewal
Bird may materially change the Services or Agreement by website announcement, in-application notice, or email. Changes generally take effect immediately, and continued use constitutes acceptance. Users should monitor the website and keep contact details current.
Subscriptions automatically renew for equal periods unless either party gives at least 30 days’ non-renewal notice. Renewal pricing may change, including a possible annual cost-of-living adjustment of up to 5%.
Privacy
Privacy Statement Overview
*This summary is informational and not a substitute for reviewing Bird’s full Privacy Statement, Terms, Product-Specific Terms, Acceptable Use Policy, and Data Processing Agreement (DPA).*
1. Data Collection and Use
Bird processes data in three broad categories:
- Website visitor data: Information submitted through forms, cookies, analytics tools, advertising technologies, IP addresses, and web beacons.
- Customer account data: Information needed to create and manage an account, provide services, communicate with customers, process payments, and support sales and marketing.
- End-user data: Information your business uploads or processes through Bird, such as names, email addresses, phone numbers, message content, channel IDs, traffic data, job titles, payment details, and contact-profile information.
Depending on the product, Bird may process:
- Email, SMS, WhatsApp, voice, and social-message content
- Phone numbers, email addresses, IP addresses, cookies, and routing/traffic data
- Customer-support and workflow data
- Payment and expense information, including bank details and billing addresses
- Video, widget, push-notification, and communications data
Purposes include providing and securing services, transmitting communications, preventing spam and fraud, customer support, billing, legal compliance, marketing and sales, service improvement, and developing new functionality. Bird may create anonymized or aggregated data for business and statistical purposes.
Bird states that it does not sell personal data and does not use data for purposes beyond those authorized by law, contract, its Terms, or this statement. Some required data is necessary to use particular services.
2. Retention
Retention varies significantly:
- Email, SMS, and voice data: Generally six months after transmission; some jurisdictions may require retention for up to two years.
- Email content: Listed as retained for up to 72 hours.
- Other products: Usually retained while the account or contract remains active.
- Marketing and sales data: Generally up to 12 months after the last interaction, or throughout the customer relationship for existing customers.
- Financial, tax, and corporate records: Up to 10 years.
- Consent records and rights-request confirmations: Up to five years.
Bird may retain anonymized data indefinitely where individuals cannot be identified. Erasure may be refused when legal retention duties apply.
3. User Rights
Depending on your location, you may have the right to:
- Access and obtain a copy of your data
- Correct, delete, or transfer data
- Restrict or object to processing, including legitimate-interest processing
- Withdraw consent
- Control cookie preferences
- Request information about sources, purposes, recipients, retention, automated decision-making, and international transfers
- File a complaint with a data-protection regulator
Requests may be made through the account privacy dashboard or by emailing privacy@bird.com. Bird generally responds within one month, with a possible two-month extension for complex or high-volume requests. Identity verification may be required.
For customer-controlled end-user data, the customer—not Bird—generally handles end-user rights requests and legal compliance.
4. Third-Party Sharing and International Transfers
Bird may share data with:
- Cloud hosts, technology vendors, and approved subprocessors
- Affiliates and service providers supporting Bird’s operations
- Government authorities where legally required
Bird says subprocessors must apply comparable privacy and security protections. Subprocessor changes can be monitored through the Help Center. Data may be transferred internationally, including outside the EEA, using contractual safeguards, adequacy mechanisms, technical measures, and impact assessments where required.
Bird USA claims certification under the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks. Certain individuals may pursue regulator review or, in limited circumstances, binding arbitration.
5. AI/ML Training
Bird states that:
- AI customer-support tools process organization/user IDs, representative email addresses, and issue descriptions.
- An external LLM provider may be used under contractual safeguards.
- Customer data and interactions are not used to train or improve LLM models.
- Support data is retained for the contractual relationship.
- Optional, self-hosted spam filtering processes email content but does not retain personal data after processing and does not use third-party providers.
- AI interaction logs may be maintained for security and accountability.
6. Key User Obligations and Risks
Customers must:
- Have a lawful basis and all necessary notices or consents before sending end-user data to Bird.
- Ensure end-user data is accurate and complete.
- Handle data-subject requests and compliance duties when acting as controller.
- Avoid processing sensitive/special-category data unless Bird agrees in writing and all legal safeguards exist.
- Protect account credentials, enable two-factor authentication where possible, and report compromises immediately.
- Review the Terms, DPA, Product Terms, Acceptable Use Policy, and subprocessor list.
A key risk is that Bird places substantial compliance responsibility on customers for marketing recipients and other end users.
7. Liability and Disputes
This Privacy Statement does not itself provide detailed liability caps, warranties, indemnities, or governing-law terms. Those appear to be incorporated through Bird’s Terms, which govern unresolved disputes after contacting privacy@bird.com. Users should review those Terms carefully because they may limit available remedies or require particular procedures, forums, or arbitration.
8. Changes
Bird may modify, remove, or update the statement. It says it will notify users “where possible” of substantial changes affecting rights. Users who disagree may discontinue using the services. This wording does not guarantee individualized advance notice for every change, so users should monitor the policy and subprocessor notices.
Change history
2026-09-06 · Privacy
2026-09-04 · Privacy
No
2026-09-04 · Privacy
2026-09-03 · Privacy
2026-09-03 · Privacy
2026-09-01 · Privacy
Summary
The supplied diff does not include the actual contract language. It only states:
> “Added approximately 227 words to the document”
Accordingly, it is not possible to determine:
- What contractual terms were added or changed;
- Whether customer data may be used to train, fine-tune, test, or improve AI models;
- Whether any consent, opt-out, or deletion rights were added or removed;
- Whether the provider may share customer data with affiliates, vendors, or model providers;
- Whether confidentiality, security, intellectual-property, or liability protections changed; or
- Whether the customer’s data may be retained after termination.
AI-Training Issues to Check
The added language should be reviewed for terms such as:
- “Improve,” “develop,” or “enhance” services — these may permit use of customer data for AI training even if “training” is not expressly mentioned.
- “De-identified,” “aggregated,” or “anonymized” data — determine whether the provider may use derived data indefinitely and whether re-identification is realistically prevented.
- “Inputs,” “outputs,” prompts, or usage data — check whether these are treated differently and whether outputs may be used to train models.
- Third-party or public models — determine whether customer data may be sent to external AI providers.
- Opt-out or consent provisions — assess whether use is automatic, optional, or available only on a paid plan.
- Retention and deletion — verify whether data used for training remains in model weights or other systems after deletion.
- Ownership and license rights — look for broad, perpetual, worldwide, royalty-free licenses to use customer content.
- Confidentiality and security — confirm that training use does not override confidentiality obligations or applicable data-protection restrictions.
Information Needed
Please provide the full redline text, with additions, deletions, and replacements shown. The statement that approximately 227 words were added is insufficient to identify the legal effect or any new AI-training risks.
2026-09-01 · Privacy
Executive Summary
The changes materially expand Bird’s handling and retention of identity-verification data. Bird will now retain specific identity information and verification outcomes, may allow authorized employees to view ID images and selfies during manual review, and identifies itself as the controller for this processing. The changes also extend certain retention and deletion periods. No express change concerning use of customer data to train AI models appears in the supplied diff.
Important Changes and Risks
1. Bird will retain more identity data
Previously, Bird stated that it stored only the verification outcome and did not receive or store ID images, selfies, or biometric identifiers. The revised language says Bird will store information extracted from verification, including:
- Name
- Date of birth
- Document number
- Document type
- Issuing country
- Verification outcome
Risk: This is a significant expansion of the personal-data record retained by Bird. Document numbers and dates of birth are sensitive identity information and may create greater security, breach, access-request, and regulatory exposure.
2. Employee access to ID images and selfies
The revised notice says that, where verification is not automatically approved, an authorized Bird employee may retrieve and view the image and selfie through Persona for manual review, although Bird will not store them.
Risk: This introduces human access to highly sensitive identity and potentially biometric information. The notice should ideally clarify access controls, logging, employee confidentiality obligations, review criteria, and whether Persona or Bird determines the biometric-comparison process.
3. Bird expressly acts as controller
The revised text states that Bird is the controller for processing the extracted identity information and verification outcome. It also provides purposes and legal bases: service enablement, fraud prevention, and demonstrating that verification occurred in connection with a legal claim or regulatory requirement.
Risk: Bird assumes clearer and potentially broader legal responsibility for this processing, including transparency, security, retention, rights handling, and lawful-basis compliance. The biometric comparison itself is stated to rely on the user’s explicit consent.
4. Broader retention and longer deletion periods
- Persona’s destruction period for ID images and selfies increases from 7 to 30 days after verification.
- Bird will retain extracted information and the verification outcome for the account relationship plus five years, or, for financial-administration records, potentially seven years from the end of the relevant financial year.
- Deletion requests may be refused while retention is legally or regulatorily required.
Risk: Data remains available for substantially longer, increasing privacy and security exposure. The notice should distinguish clearly between ordinary five-year retention and the potentially longer tax/financial-administration period.
5. Expanded deletion mechanics
Bird will request deletion from Persona of images and selfies still held by Persona when requested, but the extracted information may remain unavailable for deletion during mandatory-retention periods.
Risk: Users may reasonably expect deletion of the entire verification record; the revised language limits that expectation.
6. More time to contest automated verification
The period to request human review of a failed automated verification increases from 7 to 30 days.
Benefit: This improves user rights and reduces the risk that users lose the opportunity to challenge an automated decision.
AI-Training Changes
No provision in the supplied diff expressly authorizes, prohibits, or modifies use of customer data—including identity-verification data—to train, fine-tune, evaluate, or improve AI models. The continued prohibition on advertising, profiling beyond verification, or secondary purposes is helpful, but it does not expressly address AI training.
2026-08-31 · Privacy
2026-08-31 · Privacy
2026-08-22 · Privacy
2026-08-19 · Privacy
2026-08-19 · Privacy
2026-08-18 · Privacy
2026-08-18 · Privacy
Between 2025-10-02 and 2025-11-17 · Legal
Executive Summary
The diff is largely a formatting, punctuation, and section-renumbering update. However, several substantive changes affect contract formation, applicability to existing customers, customer authority, notices, and dispute administration.
Important Substantive Changes
1. Revised contract acceptance and authority requirements
The introductory language has been reorganized and clarified. The revised terms provide that:
- Customers who do not agree may not access or use the Services.
- The agreement becomes binding when the customer creates an account or accepts electronically.
- A person acting for an entity represents that they have authority to bind:
- The entity; and
- Its end users, where applicable.
- The customer must be legally able to enter into the agreement and provide information required by the terms on behalf of the entity and its end users.
Risk: This creates an express customer warranty regarding authority over end users and information provided about them. A breach could potentially support suspension, termination, indemnification, or other contractual remedies, particularly where the customer lacks proper consent or authorization.
2. Expanded or clarified retroactive application
The revised applicability language states that the terms apply to Services signed up for on or after 21 November 2024, and adds that they also apply from 22 December 2024 to customers who signed up before 21 November 2024.
Risk: This appears to impose the updated terms on certain pre-existing customers from 22 December 2024. Customers should verify whether this is effective under the agreement’s amendment provisions and whether prior versions remain applicable for historical use or disputes.
3. Updated notice mechanics
The customer’s notice address is expressly updated to:
legalnotice@bird.com; and- A PDF copy to the same address in specified circumstances.
A new grievance provision also allows complaints concerning the agreement or Services to be sent to that address.
Practical effect: Customers should update internal notice procedures and ensure notices satisfy any registered-mail or entity-specific requirements in addition to email delivery.
4. End-user responsibility is more explicit
The revised language repeatedly refers to the customer providing required information on behalf of its “end users (as applicable).”
Risk: This reinforces the customer’s responsibility for permissions, lawful use, and compliance relating to end-user data and activity. It may increase exposure under the customer indemnity for data-protection or legal violations.
5. No apparent change to AI-model training rights
The supplied diff does not show any express addition, deletion, or modification concerning:
- Training AI or machine-learning models;
- Using Customer Data to train models;
- Using prompts, outputs, communications, or usage data for model improvement;
- Opt-out rights; or
- Restrictions on retaining or anonymizing data for training.
The data provisions shown primarily correct punctuation and formatting, including references to Customer Data, Provider Data, the Data Processing Agreement, and Privacy Statement. Any AI-training terms may exist in documents incorporated by reference—especially the Data Processing Agreement, Privacy Statement, Product Specific Terms, or Documentation—but they cannot be assessed from this diff alone.
Overall Assessment
The main legal risks are the stronger authority/end-user representations and the apparent application of updated terms to existing customers. The diff does not itself establish a new right to train AI models using customer data.
Between 2024-09-12 and 2025-05-13 · Legal
Summary
The diff only states: “Added approximately 130 words to the document.” It does not provide the actual added language or identify where the additions were made.
Important Changes
- No substantive contractual changes can be assessed from the information provided.
- The nature, scope, and legal effect of the approximately 130 new words are unknown.
- It is not possible to determine whether the additions modify:
- Customer obligations or rights
- Provider warranties, disclaimers, or liability
- Data ownership or confidentiality
- Security or privacy obligations
- Termination rights
- Governing law or dispute procedures
- Fees, renewal, or service levels
AI Training and Data Use
The provided diff does not reveal whether the customer’s data may be used to:
- Train, fine-tune, validate, or improve artificial-intelligence or machine-learning models
- Develop products or services
- Create aggregated, anonymized, or de-identified datasets
- Permit human review or vendor access for model development
- Share data with affiliates, subprocessors, or third-party AI providers
- Retain data after termination for AI-related purposes
Accordingly, no conclusion can be reached about whether the contract has expanded or restricted AI training rights.
Risk Assessment
The principal risk is that the actual added language is missing. A reliable legal analysis requires the full text of the additions, including any surrounding provisions they modify or qualify. The placeholder description alone is insufficient to identify new rights, obligations, or risks.
Recommended Next Step
Provide the actual 130-word addition and, ideally, the immediately preceding and following contract language. Particular attention should be given to terms such as “use,” “improve,” “train,” “develop,” “machine learning,” “artificial intelligence,” “de-identified,” “aggregated,” “retain,” and “service data.”
Between 2025-01-11 and 2025-04-05 · Privacy