Monitored company
Crownpeak
clause.watch tracks 2 legal documents published by Crownpeak, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy and Consent Management
Privacy Policy
Crownpeak Privacy Notice: Key Points for Users
1. Data Collection and Use
Crownpeak may collect:
- Identity and contact details: name, job title, company, email, phone, postal address, username, user ID and password.
- Professional information: employer and employment details.
- Health information: dietary requirements for Crownpeak events.
- Online and technical data: IP address, URL, domain, browser, operating system, internet provider, approximate location, pages viewed, visit duration, referring websites and browsing activity.
- Communications data: comments, contact-form submissions, correspondence, customer-support records and meeting video recordings.
Data may be collected directly from you, automatically through websites and platforms, or from third parties such as social-media platforms and content syndicators.
Crownpeak says it uses data to:
- Create accounts, verify identity and secure services.
- Provide products, customer support and responses to inquiries.
- Operate, troubleshoot, test, analyze and improve its websites and services.
- Send and personalize marketing communications.
- Identify business prospects and opportunities.
- Administer events, including dietary accommodations.
- Maintain accurate records of contractors and third-party personnel.
- Produce aggregated reports about website interactions for partners.
- Comply with legal obligations and defend legal claims.
For EU/UK processing, Crownpeak relies primarily on contractual necessity, legitimate interests, legal obligations and—where applicable—consent. It may retain data as long as necessary for contractual, legal or legitimate business purposes; no specific retention periods are provided.
Important risk
“Legitimate interests” is used broadly, including for analytics, marketing, personalization and prospecting. Users may object in certain circumstances, but Crownpeak may continue processing if it believes its interests override the objection.
2. User Rights
EU, UK and Swiss residents may have rights to:
- Receive information about processing.
- Access and correct personal data.
- Request deletion or restriction of processing.
- Receive data in a portable format.
- Object to processing based on legitimate interests.
- Withdraw consent.
- Avoid certain solely automated decisions or profiling.
- Complain to the relevant data-protection authority.
Requests should be sent to DPM@rezolve.com or the listed Denver address. Crownpeak states it will handle requests, where possible, within one month.
US residents may have rights to notice, access, correction, deletion, portability and opting out of the sale or sharing of personal data, subject to applicable state-law exceptions and identity verification. Crownpeak states that it has not sold personal data during the prior 12 months.
3. Third-Party Sharing
The policy expressly refers to disclosure to:
- Crownpeak affiliates and subsidiaries.
- Service providers acting for Crownpeak.
- Social-media companies, including Facebook, Instagram, LinkedIn and X.
- Business partners receiving aggregated website-interaction or trend information.
- Authorities or other parties where legally required or necessary to defend claims.
US examples of potentially disclosed information include name, email, job title, financial information and employment details. The policy does not provide a detailed vendor list or specify all categories of service providers.
Social-media services operate independently, and Crownpeak disclaims responsibility for how those services handle data. Crownpeak also operates social-media pages under joint-responsibility arrangements with some platforms.
4. AI/ML Training
The notice does not state that personal data is used to train artificial-intelligence or machine-learning models, nor does it expressly prohibit such use. It mentions “research,” “data analysis,” personalization and statistical purposes, but these provisions do not clearly establish AI-training practices.
Users seeking certainty should request clarification about whether recordings, support communications, usage data or other content are used for model training, and whether an opt-out is available.
5. Key User Responsibilities and Restrictions
The notice imposes few explicit obligations on users. Practical expectations include:
- Provide accurate information and verify identity when exercising privacy rights.
- Protect account credentials.
- Follow unsubscribe procedures or contact Crownpeak to stop marketing.
- Understand that third-party social-media integrations are governed partly by those providers’ terms and policies.
- Consent may be required for processing dietary or newsletter information.
The policy does not describe detailed user conduct rules, prohibited uses or consequences for violating platform terms.
6. Liability and Disputes
Crownpeak describes security controls and says it will notify affected parties of breaches when legally required. However, it does not provide a broad security guarantee.
The policy states Crownpeak is not liable for the operation or fairness of integrated third-party social-media services. It does not contain a general damages cap, warranty disclaimer or governing-law clause.
For EU/UK/Swiss data transferred to the US, complaints may proceed through Crownpeak, the Data Privacy Framework Services dispute process, relevant regulators, and in limited circumstances binding arbitration under the Data Privacy Framework. These mechanisms do not replace statutory rights or ordinary legal remedies where available.
7. Policy Changes
Crownpeak says it keeps the notice under review and will reflect operational or processing changes in the notice. It does not promise direct email notice or specify an advance-notice period. Users should periodically check the published policy, particularly before continuing to use the services.
Change history
2026-09-06 · Privacy Policy
Analysis
The provided material does not include the actual contract language. It only states:
> “Added approximately 138 words to the document”
Without the added, deleted, or replacement text, it is not possible to determine:
- What legal obligations or rights changed;
- Whether liability, confidentiality, intellectual property, security, termination, or payment terms were modified;
- Whether customer data may be used for artificial intelligence (AI) training;
- Whether such use is optional, mandatory, or subject to consent;
- Whether data may be shared with affiliates, vendors, or third-party AI providers;
- Whether customer data may be retained after termination; or
- Whether the customer receives any opt-out, deletion, or audit rights.
AI Training Review
No conclusion can be drawn regarding AI-model training because the relevant wording is not included. The key provisions to look for are language stating that the provider may:
- Use customer data, content, prompts, inputs, outputs, or usage data to train, fine-tune, improve, or evaluate AI models;
- Create or use aggregated, anonymized, or de-identified data;
- Permit subcontractors or third-party model providers to access or train on the data;
- Retain data for model development after the customer relationship ends; or
- Use data without additional notice, approval, or compensation.
Information Needed
Please provide the full marked-up diff, including the text shown in {additions}, [deletions], and []{replacements}. Once provided, the changes can be assessed for their legal effect and summarized in a structured format.
2026-09-05 · Privacy Policy
Summary of Important Changes
1. AI-model training
- No express change addresses AI, machine learning, or training of AI models.
- The revised text does not add a right to use customer data to train AI systems, nor does it expressly prohibit such use.
- However, the new broad sharing language permits disclosure to:
- Crownpeak group companies for “marketing purposes, internal reporting, customer insights” and “service optimization”; and
- Service providers and business partners assisting with platform functionality, information collection, IT, management, analytics, and marketing optimization.
- Depending on how these terms are interpreted, such recipients could potentially process data for analytics or model-development activities. The policy should expressly state whether customer data, prompts, content, usage data, or derived data may be used to train or improve AI models, and whether identifiable or de-identified data is included.
2. Expanded and changed data sharing
- The prior references to Crownpeak’s Facebook, Instagram, LinkedIn, and X profiles are replaced with broader disclosures to:
- Crownpeak subsidiaries;
- Service providers and business partners;
- Data analytics, marketing optimization, search-engine providers, and social-media management providers.
- The revised wording is broader and less specific about recipient identity, purposes, and safeguards. This creates increased transparency and purpose-limitation risk, particularly for regulated data.
- The policy now describes Crownpeak and Facebook, LinkedIn, and X as having a joint responsibility agreement, with those platforms responsible for responding to data-subject requests. This may make accountability and rights enforcement more complex.
3. Broader disclosure to authorities and transaction parties
- New language permits disclosure to a prospective buyer or seller in connection with a business or asset transaction.
- Government and law-enforcement disclosures are broadened to include subpoenas, legal processes, fraud investigations, government requests, and protection of Crownpeak’s or third parties’ rights.
- These provisions may permit disclosure in more circumstances than the previous wording.
4. Security and breach notifications
- Detailed commitments regarding security controls, audits, certifications, and breach procedures are removed or substantially replaced.
- The revised language says Crownpeak will notify individuals or regulators only where legally required, rather than describing a broader notification commitment. This reduces the company’s stated notification obligation.
5. International transfers
- The detailed transfer framework is rewritten and now emphasizes global transfers using adequacy decisions, standard contractual clauses, other safeguards, legal exceptions, and applicable Data Privacy Framework certifications.
- The framework remains broad, but the revised presentation is less specific about particular transfer mechanisms and onward-transfer obligations. Certification status and current transfer safeguards should be verified.
6. Data-subject rights and drafting quality
- Rights are reorganized and generally retained, but the deletion, restriction, and request procedures are materially reworded.
- The diff contains extensive duplicated, reordered, and run-together text, creating ambiguity about the operative policy. A clean consolidated version should be reviewed before publication.
2026-09-05 · Privacy Policy
Summary of Important Changes and Risks
1. AI model training
- No express provision has been added authorizing use of customer or personal data to train, fine-tune, evaluate, or improve AI models.
- The revised language does, however, permit broader use and sharing of personal data for:
- “customer insights”;
- internal reporting;
- service optimization;
- improving platform and website functionality;
- analytics and marketing optimization; and
- improving the company’s website and services.
- These purposes are broad enough that, depending on how the company operates its AI tools, data could potentially be used in analytics or service-improvement systems, but the policy does not clearly say whether AI training is included or excluded.
- Risk: The policy may be viewed as insufficiently transparent if customer data is in fact used to train AI models. Customers should seek an explicit statement addressing AI training, including data categories, purposes, retention, anonymization, opt-out rights, and whether data is shared with model providers.
2. Expanded data sharing and business purposes
The revised policy replaces a description of Crownpeak’s social-media pages with broader disclosures to:
- Crownpeak group companies for marketing, internal reporting, customer insights, and service optimization;
- service providers and business partners acting on Crownpeak’s behalf;
- providers supporting platform functionality, information collection, IT, social-media management, analytics, and marketing optimization;
- search-engine providers; and
- sponsors in the context of hosted events and webinars.
Risk: These changes substantially broaden the categories of recipients and purposes. “Customer insights” and “service optimization” are not precisely defined, potentially permitting extensive secondary use.
3. Social-media processing
The new language states that Crownpeak and Facebook, LinkedIn, and X have a joint responsibility agreement, and that those platforms are responsible for responding to data-subject requests. Links to the platforms’ privacy policies are provided.
Risk: Personal data may be processed directly by major social-media companies under their own policies, including for profiling, advertising, and international transfers. The division of responsibility may make enforcement of individual rights more difficult.
4. International transfers
The revised policy:
- expands the description of global transfers;
- expressly covers the UK, EEA, and Switzerland;
- references adequacy decisions, standard contractual clauses, international transfer agreements, and lawful exceptions; and
- updates reliance on the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks.
This is generally more comprehensive, but the policy still permits transfers to a wide range of countries and recipients.
5. Government disclosures and asset transactions
The company may disclose data where it believes necessary to comply with subpoenas, legal processes, government requests, investigate fraud, protect rights, or respond to legal obligations. It may also disclose data during a sale or purchase of a business or assets.
Risk: The revised wording is broader and more discretionary than the prior breach-focused language.
6. Rights and drafting quality
The rights section is reorganized and expanded, but the diff contains extensive formatting problems, duplicated text, and apparent sentence-fragment substitutions.
Risk: Ambiguous or corrupted wording could undermine transparency and regulatory compliance. The final published policy should be carefully proofread and legally validated.
2026-09-03 · Privacy Policy
Summary
The diff does not include the actual added, deleted, or replaced contract language. It only states that approximately 138 words were added. As a result, the legal and commercial impact cannot be assessed reliably.
AI Training and Customer Data
There is no language in the supplied diff identifying whether:
- Customer data may be used to train, fine-tune, or improve AI models;
- Customer prompts, inputs, outputs, or account information may be retained or reviewed;
- Data may be used in aggregated, de-identified, or anonymized form;
- the provider may permit affiliates, vendors, or third parties to use customer data for AI development;
- customers can opt out of AI training or data-use practices;
- the provider must delete data after processing or contract termination;
- customer data may be used to train general-purpose models whose outputs benefit other customers; or
- the provider offers confidentiality, security, or ownership protections for AI-related data use.
Risk Assessment
No specific new risks can be identified without the wording of the 138 added words. In particular, it is not possible to determine whether the additions:
- expand the provider’s license to use customer data;
- create a broad or perpetual right to use data;
- permit model training without customer consent;
- weaken confidentiality obligations;
- change ownership of inputs, outputs, or derived data; or
- limit the customer’s ability to object, opt out, or seek deletion.
Information Needed
Please provide the actual redlined text, including the additions and any surrounding provisions. The complete language is necessary to assess the changes, especially any provisions concerning data use, artificial intelligence, machine learning, model training, service improvement, confidentiality, retention, ownership, or de-identification.
2026-09-03 · Privacy Policy
Summary
The diff only states that approximately 138 words were added, but it does not include the actual added language or identify where it appears in the agreement.
Legal and Commercial Impact
- The substance of the changes cannot be evaluated from the information provided.
- It is not possible to determine whether the additions affect:
- Customer or provider obligations
- Fees, renewal, or termination rights
- Liability, indemnification, or warranties
- Confidentiality or intellectual-property ownership
- Data security, privacy, or regulatory compliance
- Audit rights or use of subcontractors
- Governing law or dispute resolution
AI Training and Customer Data
The diff does not provide enough information to determine whether the agreement now:
- Allows the provider to use customer data, content, prompts, outputs, or usage data to train or improve AI models
- Allows such use for commercial or product-development purposes
- Uses customer data in aggregated, de-identified, or identifiable form
- Applies training-related rights to historical data or only data submitted after the amendment
- Gives the customer an opt-out right
- Provides deletion, retention, confidentiality, or security protections for training data
- Grants the provider ownership or broad licensing rights over customer inputs or outputs
- Permits sharing of data with affiliates, vendors, or third-party model providers
Risk Assessment
No specific new legal risk can be identified without the text of the 138 added words. In particular, the word-count description alone does not establish whether customer data may be used to train AI models.
Information Needed
Please provide the actual redlined language, including the surrounding provisions and any additions shown in {braces}. The AI-training terms should be reviewed especially closely for broad licenses, “service improvement” language, de-identification standards, opt-out mechanisms, and limits on retention and third-party sharing.
2026-09-02 · Privacy Policy
Key Changes and Risks
1. AI-model training
- No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models was identified.
- The revised notice refers generally to:
- “service optimization”;
- “customer insights”;
- improving platform and website functionality; and
- analytics and marketing optimization.
- These terms could potentially encompass machine-learning or AI-related analytics, but the language does not expressly authorize AI training or explain whether customer content, prompts, outputs, usage data, or personal data may be used for that purpose.
- Risk: If Crownpeak’s services use AI, the notice may be insufficiently specific for transparency, purpose limitation, or contractual requirements—particularly where customers expect their submitted data to remain confidential or excluded from model training. A separate product notice, DPA, or agreement should clarify:
- what data is used;
- whether it is used to train shared or customer-specific models;
- whether data is anonymized or aggregated;
- retention and deletion rules; and
- available opt-out or restriction rights.
2. Expanded disclosure and internal use
The revised sharing section adds or clarifies disclosure to:
- Crownpeak subsidiaries for marketing, internal reporting, customer insights, and service optimization;
- service providers and business partners performing services on Crownpeak’s behalf, including platform improvement, information collection, IT assistance, and data analytics; and
- search-engine providers.
This replaces the more specific discussion of Crownpeak’s Facebook, Instagram, LinkedIn, and X pages with broader language concerning social-media management, analytics, and marketing optimization.
Risk: The new wording is broader and less precise about the categories of recipients, purposes, and data involved. It may permit wider intra-group and vendor use of personal data than the previous language clearly described.
3. Social-media processing
The revised notice states that Crownpeak maintains social-media profiles and has entered into corresponding joint-responsibility arrangements with Facebook, LinkedIn, and X. It says those platforms are responsible for responding to data-subject requests.
Risk: Responsibility for compliance and rights handling may be unclear, particularly where Crownpeak and the platforms jointly determine processing purposes.
4. Business transfers and legal disclosures
New language permits disclosure to a prospective seller or buyer if Crownpeak sells or acquires a business or assets. It also permits disclosure to authorities or other third parties where Crownpeak believes this is necessary to comply with legal obligations, subpoenas, investigate fraud, or protect rights.
Risk: The legal-disclosure standard appears broader (“where we believe this is necessary”) and may allow disclosure without prior notice where legally permitted.
5. International transfers
The detailed transfer framework is replaced or reorganized to cover the UK, EEA, and Switzerland, relying on adequacy decisions, standard contractual clauses, other safeguards, exceptions, and the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks.
Risk: The revised text appears heavily reformatted and contains potential drafting inconsistencies. The final published version should be checked for accuracy, especially regarding DPF certification, onward-transfer obligations, and applicable safeguards.
6. Data-subject rights and presentation
Rights are reorganized into clearer categories, including access, rectification, erasure, restriction, and portability. The notice retains limited deletion exceptions and may retain minimum data to document requests.
Risk: The redline contains substantial formatting and sentence-structure problems. These should be corrected before publication to avoid ambiguity or an allegation that required privacy disclosures are unclear.
2026-09-02 · Privacy Policy
Structured Summary of Important Changes
Executive Overview
The diff substantially rewrites the privacy notice, particularly the sections on data sharing, international transfers, security, data-subject rights, and regulatory disclosures. Much of the replacement appears mechanically misaligned, so the final document should be reviewed for formatting, missing text, and legal coherence before publication.
AI Model Training
- No express provision authorizes using customer or personal data to train, fine-tune, evaluate, or improve AI models.
- The revised language refers generally to:
- “service optimization”
- “customer insights”
- “improving functionality of our platforms and websites”
- “collecting information about you”
- These phrases could potentially support broad product-improvement activities, but they do not clearly state that data will be used for AI training.
- The notice also does not clarify:
- whether customer content or inputs are used to train third-party or Crownpeak models;
- whether data is de-identified before model use;
- whether customers can opt out;
- whether prompts, outputs, telemetry, or usage data are retained; or
- whether data is shared with AI vendors.
- If AI training is intended, a specific disclosure and contractual allocation of rights should be added. If it is not intended, the customer agreement should state that customer data will not be used for model training except as expressly authorized.
Expanded or Changed Data Sharing
The revised text replaces detailed references to Crownpeak’s social-media pages with broader disclosures permitting sharing with:
- Crownpeak subsidiaries for marketing, internal reporting, customer insights, and service optimization;
- service providers and business partners performing services on Crownpeak’s behalf;
- providers supporting platform and website functionality, information collection, IT, social-media management, data analytics, marketing optimization, and search-engine services;
- prospective buyers or sellers in connection with a sale or purchase of a business or assets; and
- government authorities or other third parties where Crownpeak believes disclosure is necessary to comply with legal obligations, investigate fraud, respond to government requests, or protect rights.
Risk: These categories are broader and less specific than the deleted language, potentially increasing uncertainty about recipients and purposes.
International Transfers
- The notice now describes global transfers outside the UK and EEA using adequacy decisions, safeguards such as Standard Contractual Clauses or the International Data Transfer Agreement, and legal exceptions.
- It adds or reorganizes reliance on the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks.
- The revised wording appears to preserve onward-transfer responsibility but is materially restructured and should be checked for accuracy.
Security and Breach Notification
- Detailed security-audit and certification language is replaced with a more general statement about operational controls, information-security practices, audits, and certifications.
- Breach language is narrowed from procedures addressing suspected breaches and notification where legally required to notification where legally required.
Risk: This may reduce the appearance of a proactive security commitment and should be reconciled with contractual security obligations.
Data-Subject Rights
- Rights are reformatted and generally restated for EU, UK, and Swiss individuals.
- Deletion language now expressly permits retaining the minimum data necessary to document requests and avoid further use.
- The request process remains relatively general but requires a description of the request and the data at issue.
Other Issues
- Contact details and punctuation/spacing have been altered.
- References to “Rezolve” remain in the contact email, which may create entity-identity confusion.
- The diff contains extensive apparent text-order and formatting corruption. A clean consolidated version should be legally proofread before reliance.
2026-08-31 · Privacy Policy
Summary
The provided diff does not include the text of the approximately 138 added words. It only states that words were added, without showing their content.
Legal and Commercial Impact
Because the actual additions are missing, it is not possible to determine:
- Whether the contract’s rights, obligations, or liability provisions changed.
- Whether new fees, renewal terms, termination rights, warranties, or indemnities were added.
- Whether confidentiality, security, privacy, or data-processing obligations changed.
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models.
- Whether data may be shared with affiliates, vendors, subprocessors, or third-party AI providers.
- Whether the customer has any opt-out, deletion, audit, or access rights concerning AI training.
- Whether the provider receives broader rights to use customer content, usage data, prompts, outputs, metadata, or de-identified information.
- Whether the contract limits the provider’s responsibility for AI-generated outputs or data leakage.
AI Training Review
No specific language addressing AI model training or use of customer data is visible in the supplied diff. Accordingly, no conclusion can be reached about whether the revised contract:
1. Permits training on customer content by default;
2. Restricts training to de-identified or aggregated data;
3. Prohibits use of customer data for model training;
4. Allows use of data to improve products or services;
5. Applies different rules to inputs, outputs, telemetry, or personal information; or
6. Provides contractual safeguards concerning retention, deletion, confidentiality, or third-party model providers.
Required Information
Please provide the actual 138-word addition, using the indicated {added} notation and, if applicable, the corresponding deleted or replaced text. The legal and AI-data implications can then be analyzed reliably.
2026-08-30 · Privacy Policy
Executive Summary
The update substantially rewrites the privacy notice’s data-sharing, international-transfer, security, and data-subject-rights provisions. It does not expressly authorize using customer data to train AI models, nor does it mention artificial intelligence, machine learning, model training, model improvement, prompts, outputs, or retaining data for those purposes.
AI Model Training and Data Use
- No explicit AI-training provision added or removed. The revised notice does not state that customer data, content, inputs, outputs, usage data, or personal data may be used to train or fine-tune AI models.
- The new wording permits sharing data for:
- “customer insights”;
- “service optimization”;
- “improving functionality” of platforms and websites;
- analytics and marketing optimization; and
- internal reporting.
- These purposes are broader and could potentially support analytics or product-improvement activities, including AI-related development, but the notice does not clearly say that data will be used for model training. If AI training is intended, the privacy notice should address it expressly, including data categories, purposes, legal basis, retention, opt-out/objection rights, de-identification, and whether data is used to train general-purpose or customer-specific models.
Important Changes and Risks
Expanded data sharing
The revised notice adds or clarifies sharing with:
- Crownpeak group companies for marketing, internal reporting, customer insights, and service optimization;
- service providers and business partners supporting platform functionality, information collection, IT, and social-media management;
- analytics, marketing-optimization, and search-engine providers; and
- Facebook, Instagram, LinkedIn, and X, with revised language describing Crownpeak’s social-media pages and joint responsibility arrangements.
Risk: The purposes and recipient categories are broader, potentially increasing secondary use, profiling, marketing, and onward-disclosure exposure.
Business transactions and legal disclosures
New language permits disclosure to a prospective buyer or seller if Crownpeak sells or buys a business or assets. It also broadens government and third-party disclosures where Crownpeak believes disclosure is necessary to comply with legal or regulatory obligations, subpoenas, fraud investigations, or protection of rights.
Risk: Data may be disclosed during corporate transactions or under a broader “necessary” standard, with less emphasis on breach-related notification.
International transfers
The detailed transfer section is replaced with a more general framework covering transfers outside the UK and EEA. It references adequacy decisions, standard contractual clauses, international transfer agreements, lawful exceptions, and the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks.
Risk: The revised language is less specific about particular transfer mechanisms and onward-transfer obligations, potentially reducing transparency about where data goes and which safeguards apply.
Security and breach language
Specific descriptions of audits, certifications, and security procedures are removed or condensed. The revised notice states Crownpeak will address breaches and notify users or regulators where legally required.
Risk: The commitment is less detailed and appears more legally conditional.
Data-subject rights
The rights section is reorganized and expanded for EU, UK, and Swiss individuals, including access, rectification, erasure, restriction, objection, and portability. Crownpeak may retain minimum data to document deletion requests and comply with legal obligations.
Risk: Rights remain subject to legal exceptions, and retention after deletion requests is expressly preserved.
2026-08-27 · Privacy Policy
Summary
The provided diff does not include the actual added, deleted, or replaced contractual language. It only states:
> “Added approximately 138 words to the document”
Accordingly, it is not possible to identify the legal or commercial effect of the changes.
AI Training and Customer Data
No substantive language concerning any of the following is provided, so no conclusion can be reached about whether the contract has changed its treatment of customer data:
- Using customer data to train, fine-tune, or improve AI or machine-learning models
- Using customer content for product development, analytics, or benchmarking
- Whether customer data may be used in aggregated, de-identified, or anonymized form
- Whether inputs, outputs, prompts, or usage data are retained
- Whether data is shared with affiliates, vendors, or third-party AI providers
- Whether the customer can opt out of AI training or data-use practices
- Ownership, confidentiality, or intellectual-property rights in customer data and AI outputs
- Security, deletion, retention, or cross-border transfer obligations
- Whether the provider may use data from one customer to benefit other customers
Risk Assessment
No specific new risks can be identified without the text of the 138-word addition and any surrounding provisions it modifies. The missing language could materially affect:
- The scope of the provider’s license to customer data
- Confidentiality protections
- The customer’s ability to restrict secondary uses
- Compliance with privacy and data-protection laws
- Responsibility for AI-generated outputs
- The provider’s rights to retain or reuse data after termination
Information Needed
Please provide the actual redlined wording, including:
1. The 138 added words;
2. Any deleted or replaced wording;
3. The relevant surrounding section, if the change depends on existing definitions or obligations.
Once provided, the changes can be analyzed for specific legal effects and AI-training risks.
2026-08-24 · Privacy Policy
2026-08-18 · Privacy Policy
2026-08-18 · Privacy and Consent Management
Summary of Legal Changes
Scope of the Diff
The diff only states that approximately 366 words were removed. It does not identify:
- Which provisions were deleted;
- Whether the deletions were replaced with new language;
- Whether the changes affect customer data, confidentiality, security, intellectual property, or liability; or
- Whether any AI-training provisions were added, removed, or modified.
Customer Data and AI Model Training
No reliable conclusion can be drawn about the use of customer data to train AI models from the information provided.
The deleted text could have included restrictions or permissions concerning:
- Using customer data to train, fine-tune, or improve artificial-intelligence or machine-learning models;
- Using customer data to generate anonymized, aggregated, or de-identified datasets;
- Retaining customer prompts, inputs, outputs, or usage data for model development;
- Sharing data with affiliates, subprocessors, or AI service providers;
- Opt-out rights or customer consent requirements;
- Deletion obligations after termination; or
- Ownership and permitted use of data-derived models, outputs, or analytics.
If any of these provisions were removed without replacement, the deletion may create ambiguity or materially broaden the provider’s rights—particularly if other general-purpose data-use language remains in the agreement.
Potential Legal Risks from Unspecified Deletions
Depending on the deleted language, the changes could:
1. Expand data-use rights by eliminating limitations on secondary use of customer data.
2. Remove customer protections relating to confidentiality, security, deletion, or data minimization.
3. Reduce transparency regarding subcontractors or third-party AI providers.
4. Affect compliance obligations under privacy and data-protection laws.
5. Change allocation of risk by deleting warranties, indemnities, audit rights, or liability protections.
6. Create interpretive uncertainty if defined terms or cross-references remain after the deletions.
Conclusion
The provided diff is insufficient for a substantive legal comparison. The full redline, or at least the 366 deleted words and the surrounding provisions, is needed to determine whether customer data may now be used for AI training and whether the changes create new legal or commercial risks.
2026-08-18 · Privacy Policy
Between 2024-04-30 and 2024-07-18 · Privacy Policy
Between 2023-09-12 and 2024-01-16 · Privacy Policy
Between 2023-03-29 and 2023-12-27 · Privacy and Consent Management
Executive Summary
The diff appears to replace a substantial portion of the website’s prior marketing copy with new promotional, investor, and product content. It does not appear to amend customer-facing contractual terms, privacy terms, data-processing provisions, or AI-training permissions. However, the changes introduce several legal and compliance risks through new factual and performance claims.
Key Changes
1. New AI product and performance claims
The revised content describes Rezolve Ai as offering:
- A “proprietary Large Language Model” designed for retail;
- “Business-safe AI solutions”;
- AI-driven tools for customer engagement, productivity, and performance;
- Conversational commerce and product-discovery solutions;
- A “patent-backed AI provenance platform”;
- Watermarking and global infrastructure capabilities.
The prior language included stronger technical claims that the proprietary LLM was “immune to model drift and hallucinations.” Those statements appear to be removed or replaced with more general claims about reliability, safety, and performance.
Risk: The replacement language is less absolute in some respects, but claims such as “business-safe,” “patent-backed,” “proven,” “reliable,” and “superior productivity and performance” may still be treated as objective representations. They should be supported by evidence and appropriately qualified.
2. Expanded commercial and financial claims
The revised content refers to:
- Driving sales and ROI;
- Improving conversion, average order value, and customer satisfaction;
- Transforming customer engagement and digital transactions;
- Commerce.com’s results allegedly validating Rezolve Ai’s strategic case;
- Rezolve Ai’s outlook and expected continued leadership.
Risk: These statements may create advertising, securities-law, or investor-communications exposure if they are inaccurate, misleading, insufficiently qualified, or presented as verified results. The phrase “outlook deteriorates” is particularly sensitive in an investor-facing context and should be reviewed for accuracy and disclosure consistency.
3. Third-party endorsements and affiliations
The page adds or prominently uses references to Google Cloud, Microsoft, Commerce.com, Liverpool Mexico, and named executives, including testimonial-style statements and claims of “deep integration with Google.”
Risk: Confirm written authorization for names, logos, testimonials, affiliations, integration claims, and any implication that Google Cloud or Microsoft endorses or validates the product. Testimonials should identify whether they are current, representative, compensated, or subject to applicable advertising rules.
4. Data collection and marketing technology
The diff contains a HubSpot form script with portal, form, Salesforce campaign, and submission-handling identifiers.
Risk: The form may collect personal information and transmit it to HubSpot/Salesforce-related systems. The privacy notice, consent language, cookie disclosures, retention practices, international-transfer terms, and vendor disclosures should match this implementation.
AI Training / Customer Data
No express change is shown concerning whether customer data, prompts, inputs, outputs, account information, or other customer content may be used to train, fine-tune, evaluate, or improve AI models. The diff contains marketing claims about a proprietary LLM and AI provenance, but does not grant or restrict any data-training rights.
The applicable contract, privacy policy, and data-processing addendum should nevertheless be checked separately for AI-training language, especially regarding customer content, de-identification, service improvement, subprocessors, and opt-out rights.