Monitored company
Draw.io
clause.watch tracks 1 legal document published by Draw.io, re-reading each one every six hours. Below is what each document covers, in plain English.
Legal & Privacy
Overview of Draw.io Privacy Statement (v2.1, 30 August 2023)
1. Data Collection and Use
Draw.io Limited says it is a UK GDPR/data protection “controller.” The statement says it generally collects only information users provide, such as:
- Name and contact details when contacting the company
- Account or contract information
- Job-application information
- Business, identity, tax, payment-related, and transaction information
- Information entered into diagrams
The Application reportedly does not collect personal data during login and use, except where a user places personal information in a diagram. However, if an action requires a diagram to be sent to a server for processing, personal information in that diagram may be processed temporarily on the server. Users should therefore avoid including sensitive or confidential personal information unless necessary.
Draw.io may also obtain information from public sources, Companies House, background-check agencies, business partners, directories, tax authorities, and other websites. It may use this information to confirm identity, assess businesses, improve services, administer its business, prevent fraud, provide services, and meet legal obligations.
The company states that it will generally use data only for the purposes collected, or for compatible purposes. However, clause 7.4 broadly says it reserves the right to use information provided “in the future in any way we decide.” This is unusually broad and potentially conflicts with the more restrictive UK GDPR language elsewhere in the statement.
Payment card information is handled by Stripe or another payment provider, not directly by Draw.io. Those providers’ own privacy terms apply.
2. User Rights
Subject to legal exceptions, users may have the right to:
- Access a copy of their personal data
- Correct inaccurate or incomplete information
- Request deletion
- Object to processing based on legitimate interests
- Object to direct marketing
- Restrict processing
- Request data portability
- Withdraw consent where consent is the legal basis
Identity verification may be required. Draw.io may refuse some requests where legally permitted and may charge a fee where allowed by law. Withdrawal of consent does not necessarily stop processing if another lawful basis applies, such as contractual, legal, or legitimate-interest grounds.
Users may complain to the UK Information Commissioner’s Office (ICO), although Draw.io asks users to contact it first.
3. Third-Party Sharing
Draw.io says it does not sell or generally disclose website/Application information to third parties, but it may share data with:
- Telecommunications, messaging, postal, and courier providers
- IT, computer-system, and security providers
- Accountants and solicitors
- Advertisers
- Regulators, including the ICO and tax authorities
- Other contractors, agents, or service providers with a business need to know
These parties are supposed to act on Draw.io’s instructions and maintain confidentiality. The statement says data is not stored or transmitted outside the UK by Draw.io, although organizations using Draw.io as a processor may transfer data elsewhere. Users should check the privacy statement of the relevant organization or integrated service.
4. AI/ML Training
The statement does not expressly say whether user data, diagram content, or other information is used to train artificial intelligence or machine-learning models. It mentions improving services and temporary server processing of diagrams, but does not provide a specific AI-training commitment or prohibition. Users seeking certainty should request clarification from Draw.io before entering confidential or personal information into diagrams.
5. Key User Obligations and Risks
Users are responsible for:
- Providing accurate, current personal information
- Updating information when it changes
- Keeping account passwords complex, secure, and confidential
- Avoiding unnecessary special-category data, such as health, biometric, political, religious, or sexual-orientation information
- Understanding that personal data inserted into diagrams may be sent to servers when processing requires it
Basic customer information may be retained for six years after the customer relationship ends for tax purposes. Other data may be retained to provide services, comply with law, or establish or defend legal claims. Data may be anonymized and then retained indefinitely.
6. Liability and Disputes
This document contains no detailed liability disclaimer, governing-law clause, arbitration requirement, court-jurisdiction clause, or dispute-resolution process. It mainly provides a privacy complaint route through Draw.io and the ICO. Any liability limits or dispute rules may appear in separate Terms of Service or contract documents.
Although security controls are described—including encryption, firewalls, vulnerability testing, and restricted access—Draw.io acknowledges that internet transmission and electronic storage can never be completely secure.
7. Changes to the Policy
Draw.io may amend the statement. Changes may be posted:
- On the privacy-policy webpage
- To the email address associated with an account
- Through a notice on the homepage
The revision date indicates when the statement changed. Continued use of the site or services is treated as acceptance of the updated statement. Users should monitor notices because continued use may amount to consent to revised processing terms.
Change history
Between 2023-05-30 and 2024-05-15 · Legal & Privacy
Summary
The provided diff only states that approximately 21 words were removed. It does not identify the deleted language or show the surrounding provision.
Key Legal Implications
Because the actual text is unavailable, it is not possible to determine whether the changes affect:
- Customer data ownership or licensing rights
- Provider rights to access, retain, disclose, or commercially use customer data
- Confidentiality or data-security obligations
- Data deletion, return, or retention periods
- Use of customer data to train, fine-tune, evaluate, or improve AI models
- Whether customer data may be used for generalized or shared model training
- Opt-out, consent, or notification requirements
- Allocation of liability for unauthorized use or disclosure
AI Training Risk
No conclusion can be reached about changes to AI-model training. The deleted 21 words could potentially have:
- Removed a restriction on using customer data for training;
- Removed an exception permitting training or service improvement;
- Narrowed or expanded the definition of “Customer Data”;
- Eliminated an opt-out or consent requirement; or
- Changed whether de-identified, aggregated, or derived data may be used.
The deletion could therefore be legally significant, but its effect cannot be assessed without the actual wording.
Information Needed
Please provide either:
1. The full redline showing the 21 deleted words; or
2. The original and revised versions of the affected clause, preferably with surrounding text.
Without that information, any assessment of the change would be speculative.