Monitored company
Greenlight
clause.watch tracks 1 legal document published by Greenlight, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Greenlight Guru Clinical Privacy Policy — User Overview
1. Data Collection and Use
What is collected
The policy says Greenlight Guru collects, processes, and stores personal data when you create a user account. However, the provided text does not list the specific data categories—such as name, email address, employer, job title, or login information. This omission makes it difficult to determine exactly what information is collected.
The platform may also contain clinical-trial data uploaded or stored by users or Greenlight Guru customers. The policy distinguishes this clinical data from ordinary product-user personal data.
How data is used
Personal data may be used for:
- Administering and maintaining your user account
- Security and fraud-prevention measures
- Statistics and analytics
- Developing and improving products and services
- Customer service and support
- Complying with legal obligations
The stated legal bases under the GDPR are generally:
- Contract: providing and managing your account
- Legitimate interests: analytics, security, product improvement, and business operations
If your account is connected to a clinical trial or Greenlight Guru customer, retention and processing may also follow that customer’s instructions. Anonymized information may be retained longer.
2. User Rights
Subject to applicable law and the data-processing terms governing your account, you may have the right to:
- Access your personal data
- Object to collection or further processing
- Correct inaccurate or incomplete data
- Request deletion, subject to legal exceptions
- Receive a copy of your data
- Request portability of data you provided, where applicable
- Withdraw consent at any time
Withdrawal of consent does not necessarily stop all processing. Greenlight Guru may continue processing where another legal basis exists or where the law requires it.
You may contact Greenlight Guru with questions or complaints. If the issue is not resolved, you may complain to the data-protection authority in your country.
3. Third-Party Sharing and International Transfers
Greenlight Guru may share or provide access to personal data with contracted service providers, such as:
- IT and hosting providers
- Email providers
- Other vendors supporting the service
These providers are supposed to process data only under Greenlight Guru’s instructions and pursuant to data-processing agreements.
Data may also be disclosed, where legally permitted or required, to:
- Police or law-enforcement authorities
- Lawyers and auditors
- Courts and public authorities
- Affiliated companies
- Prospective buyers in a merger, sale, or transfer of assets
The policy says clinical data for users in the EEA, UK, and Switzerland is localized and processed within the European Union. However, product-user personal data may sometimes be processed in the United States under the separate master Privacy Policy.
Transfers outside the EU/EEA lacking an adequate protection level are stated to rely on EU Standard Contractual Clauses or Binding Corporate Rules.
4. AI/ML Training
The policy does not state whether personal data, clinical data, or user-generated content is used to train artificial-intelligence or machine-learning models. It refers broadly to statistics, analysis, and product development, but that language should not be interpreted as express permission for AI training.
Users should review the master Privacy Policy, customer data-processing terms, and contractual documentation or obtain written clarification if AI training is a concern.
5. Key User Obligations and Restrictions
- Read the policy before submitting personal data.
- Your account may be subject to additional data-processing instructions or terms imposed by your employer, study sponsor, or Greenlight Guru customer.
- The policy does not provide a detailed list of prohibited conduct or user security duties.
- Users should avoid uploading unnecessary personal or sensitive information and should follow their organization’s clinical-trial and confidentiality procedures.
6. Liability and Disputes
This document is a privacy policy, not a complete liability or dispute-resolution agreement. It does not specify:
- Liability caps or exclusions
- Indemnification obligations
- Governing law or venue
- Arbitration requirements
- A private lawsuit process
The stated escalation route is to contact Greenlight Guru first and then complain to the relevant data-protection supervisory authority. Any broader contractual remedies would likely appear in the platform agreement, customer contract, or master Privacy Policy.
7. Changes to the Policy
Greenlight Guru may change the policy from time to time. It states that:
- The date at the top will be updated
- The current version will remain available on its websites
The policy does not promise individual email notice or advance notification. Users should periodically check the website and version date.
Change history
2026-09-04 · Privacy Policy
Structured Summary of Important Changes
1. Data collected and processing purposes
- The policy no longer presents a detailed list of user data categories in this section (such as name, email, phone number, country, newsletter status, occupation, employer, staff ID, IP address, geolocation, and device/internet information).
- It instead describes broad processing purposes, including:
- User-account administration
- Product security
- Statistics and analysis
- Product and service development
- Customer service and support
- This restructuring creates less transparency about exactly what data is collected and may make it harder for customers to assess whether particular data uses are permitted.
2. New or clarified legal bases
- Processing for product improvement and development is expressly based on Greenlight Guru’s “legitimate interests” under GDPR Article 6(1)(f).
- Account-related processing is expressly based on contractual necessity under Article 6(1)(b).
- The new legitimate-interest language is broader than the prior purpose list and could support additional analytics, service-development, and potentially technology-development activities.
3. AI model training
- The diff does not expressly mention artificial intelligence, machine learning, model training, generative AI, foundation models, or use of customer data to train AI systems.
- However, the newly stated purposes—“statistics, analysis” and “improving and developing our products and services”—are broad. Depending on the underlying processing, Greenlight Guru might argue that certain de-identified, aggregated, or potentially personal data uses for developing AI-enabled features fall within these purposes.
- The policy does not clarify:
- Whether customer data is used to train AI models;
- Whether clinical or user-submitted content is excluded from training;
- Whether data is anonymized or aggregated before such use;
- Whether data is shared with AI vendors;
- Whether customers can opt out; or
- Whether trained models retain or reproduce customer information.
- Customers should seek an explicit contractual commitment addressing AI training and model-development use.
4. Retention
- The prior wording specifically referred to retaining anonymized personal data for longer periods.
- The revised wording appears to allow personal data associated with a clinical-trial customer to be retained longer under the customer’s processing instructions, while also preserving broader retention for business or asset-transfer purposes. The duration remains unspecified.
5. Disclosures and business transfers
- Processing by service providers is described more clearly as processor activity governed by data-processing agreements and Greenlight Guru’s instructions.
- Disclosures are expanded or expressly listed to police, lawyers, auditors, courts, public authorities, prospective buyers, and affiliated companies.
- Greenlight Guru may transfer data as part of a full or partial sale or other commercial restructuring, relying generally on legitimate interests.
6. International transfers
- The policy now states that product-user data may be processed in the United States.
- Transfers outside the EU/EEA to countries lacking adequate protection may rely on EU Standard Contractual Clauses or binding corporate rules.
- This increases cross-border transfer exposure and may involve access by U.S. authorities or overseas vendors.
7. Data-subject rights
- Rights are stated more fully, including objection, rectification, deletion, portability, and withdrawal of consent.
- The right to object is expressly subject to the applicable Data Processing terms, potentially limiting practical exercise of that right.
2026-09-04 · Privacy Policy
Summary of Important Changes
1. Expanded personal-data categories
The policy now expressly states that Greenlight Guru may collect and process a substantially broader range of user information, including:
- Name and email address
- Phone number and physical address
- Country
- Newsletter-consent status
- Occupation, employer, and staff ID
- IP address and geolocation
- Information about the user’s internet connection and access equipment
Risk: This is a material expansion or clarification of the data covered by the policy. Some information—particularly geolocation, device/network data, staff ID, and employment details—may increase privacy, security, and employee-monitoring concerns. Customers should verify that they have appropriate notices, consents, and internal policies for providing this information.
2. Processing purposes reorganized and potentially broadened
The policy now identifies the following purposes:
- User-account administration
- Product-security measures
- Statistics and analysis
- Product and service development
- Customer service and support
The revisions make “statistics and analysis” and “product and service development” more prominent and connect them to the company’s legitimate interests.
Risk: The wording may support broader secondary use of user data for analytics and improving products and services. The policy does not clearly define whether data will be aggregated, de-identified, or used for commercial product development.
3. Legal basis clarified
The policy now states that processing may rely on one or more legal bases, including legitimate interests under Article 6(1)(f) GDPR. It also retains or references contractual necessity under Article 6(1)(b) GDPR.
Risk: Reliance on legitimate interests requires a documented balancing test and appropriate transparency. The revised language is general and does not identify which data or purposes rely on which legal basis. This may create uncertainty regarding objection rights and the limits of processing.
4. AI-model training
No express change concerning AI or training AI models is shown in this diff. The revised references to statistics, analysis, product development, and service improvement could potentially be broad enough to encompass machine-learning activities, but the policy does not expressly authorize, describe, or limit:
- Training or fine-tuning AI models
- Use of customer content or clinical data for training
- Whether data is anonymized or de-identified
- Sharing data with AI vendors
- Opt-out, objection, or deletion rights relating to training data
Customers should request written confirmation that their data—including clinical-trial data, metadata, prompts, outputs, and support content—is not used to train general-purpose or vendor AI models unless expressly agreed.
5. Corporate identity and contact details
The policy adds SMART-TRIAL ApS’s Danish CVR number and Danish contact details. It also states that Greenlight Guru is headquartered in the United States.
Risk: The relationship between the Danish legal entity and the U.S. business, including controller/processor roles and international-transfer responsibilities, should be clarified.
6. International transfers
References to EU Commission standard contractual clauses and binding corporate rules remain, with minor formatting corrections. No clear substantive improvement to transfer safeguards is shown.
2026-08-31 · Privacy Policy
Summary
The provided diff states only that approximately 52 words were removed from the document. It does not identify which words, clauses, or sections were deleted.
Key Legal Implications
- Substantive impact cannot be determined: Without the actual deleted text, it is not possible to assess whether the changes affect liability, confidentiality, termination, intellectual property, data security, or other obligations.
- Potential narrowing of protections: Deletions could remove customer rights, provider obligations, limitations on data use, warranties, indemnities, or compliance requirements.
- Potential expansion of discretion: If deleted language imposed restrictions or conditions on the provider, its removal may give the provider broader contractual rights.
AI Training and Customer Data
- The diff provides no identifiable information about whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Shared with model providers or other third parties;
- Used in aggregated, de-identified, or identifiable form;
- Retained after termination; or
- Excluded from training by default or only upon opt-out.
- Accordingly, no conclusion can be reached about whether the customer’s data-use protections have improved or weakened.
Recommended Next Step
Provide the actual deleted language, ideally with the surrounding clause or a full redline. The removed text should then be reviewed specifically for changes to:
1. Customer data ownership and permitted uses;
2. AI training, model improvement, and human review;
3. De-identification and aggregation standards;
4. Data retention and deletion;
5. Subprocessors and third-party model providers; and
6. Opt-out, consent, and contractual remedies.
2026-08-30 · Privacy Policy
Summary of Important Changes
1. Company identity and contact details
- The policy now identifies the entity as SMART-TRIAL ApS (d.b.a. Greenlight Guru) and adds its CVR number.
- It states that Greenlight Guru is headquartered in the United States.
- A new contact block provides the Aalborg, Denmark address and clinical.info@greenlight.guru email address.
- These changes improve identification and contactability, but the policy should clearly explain which entity is the data controller for different processing activities, particularly given the Danish legal entity and U.S. headquarters.
2. Expanded categories of personal data
The revised text expressly lists a broader range of information, including:
- Name, email address, phone number, and physical address
- Country, occupation, employer, and staff ID
- IP address and geolocation
- Information about the user’s internet connection and equipment
- Whether the user has accepted marketing/newsletter communications
This is a significant clarification and expansion of the disclosed data categories. Customers should assess whether the product actually collects all of these fields and whether any may constitute sensitive or indirectly identifiable information in a clinical-trial context.
3. Processing purposes reorganized and clarified
The policy now identifies purposes including:
- User-account administration
- Product security
- Statistics and analysis
- Product and service development
- Customer service and support
The substance is broadly similar to the previous wording, but the revised presentation makes the purposes more explicit. “Product and service development” remains broad and could potentially encompass analytics, testing, and improvement activities beyond strictly necessary account administration.
4. Legal basis changes
The previous language referred primarily to Greenlight Guru’s legitimate interest in statistics, analysis, and improving and developing products and services.
The revised wording states that personal data may be processed on “one or more” legal bases, and identifies legitimate interests under Article 6(1)(f) GDPR. The surrounding text also refers to Article 6(1)(b) GDPR, apparently for contractual processing.
This may broaden or clarify the claimed legal bases, but it does not specify which legal basis applies to each individual purpose. That lack of mapping may make it harder for customers to evaluate necessity, objection rights, and whether consent is required—for example, for newsletters or optional analytics.
5. AI-model training
No express change concerning AI or the training, fine-tuning, or evaluation of AI models appears in the supplied diff.
The references to “statistics,” “analysis,” and “product and service development” could theoretically cover machine-learning activities, but the text does not expressly authorize AI training or explain whether customer data is used for that purpose. The policy should not be read as providing clear, specific notice of AI-model training without additional language.
6. Other changes
- Minor punctuation, formatting, and grammatical changes were made.
- The international-transfer wording continues to reference EU Commission standard contractual clauses or binding corporate rules.
- The version/history section appears reformatted, with no clear substantive change.
2026-08-29 · Privacy Policy
Summary of Important Changes
1. AI model training
- No express reference to artificial intelligence, machine learning, generative AI, or training models appears in the diff.
- The policy now expressly permits processing for “statistics, analysis, as well as improving and developing our products and services” based on Greenlight Guru’s legitimate interest under GDPR Article 6(1)(f).
- This wording is broad and could potentially be interpreted to cover activities such as product analytics, algorithm development, or AI-model improvement, but it does not clearly authorize or explain training AI models using customer or clinical data.
- The policy should clarify:
- Whether customer content or clinical-trial data is used for AI training;
- Whether data is de-identified, anonymized, aggregated, or retained for that purpose;
- Whether training is performed by Greenlight Guru or third-party providers;
- Whether customers can opt out; and
- Whether trained models can retain or reproduce information from the data.
2. Purposes and legal bases
- The policy replaces a relatively detailed list of personal-data categories and processing purposes with a more structured statement of purposes, including:
- User-account administration;
- Product security;
- Statistics and analysis;
- Product and service development; and
- Customer service and support.
- Processing for product and service improvement is now expressly tied to legitimate interests, while account provision is tied to contractual necessity under Article 6(1)(b).
- The change may broaden Greenlight Guru’s claimed ability to use user data for internal analysis and development. The legitimate-interest assessment and the relationship between this policy and customer contractual restrictions should be reviewed.
3. Retention
- For accounts associated with a clinical trial or customer, Greenlight Guru will follow the customer’s processing instructions.
- Anonymized personal data may be retained longer, without a defined retention period. This creates a risk if data described as “anonymized” is only pseudonymized or could reasonably be re-identified.
4. Disclosure and corporate transactions
- The policy now distinguishes between data processors and data controllers and states that service providers will process data under Greenlight Guru’s instructions and data-processing agreements.
- Disclosure is expanded or clarified to include police, lawyers, auditors, courts, public authorities, prospective buyers, and affiliated companies.
- Greenlight Guru claims a legitimate interest in transferring personal data during a full or partial sale or other asset transaction. This may permit disclosure without individual permission.
5. International transfers
- Clinical data is stated to be stored and processed in the EU.
- Product-user data may nevertheless be processed in the United States under the master Privacy Policy.
- Transfers outside the EU/EEA may rely on EU Standard Contractual Clauses or binding corporate rules, creating additional cross-border access and compliance risks.
6. Individual rights and policy updates
- Rights are restated, including objection, rectification, deletion, portability, consent withdrawal, and complaints to a supervisory authority.
- The right to object is expressly made subject to the applicable Data Processing terms, potentially limiting practical exercise of that right.
- The policy may be updated from time to time, with the effective date posted online.
2026-08-28 · Privacy Policy
Summary
The supplied diff does not include the actual amended contractual language. It only states: “Added approximately 52 words to the document.”
Changes Identified
- No specific additions, deletions, or replacements are shown.
- No legal terms, obligations, rights, or limitations can be evaluated from the information provided.
- The affected section of the agreement is unknown.
AI Training and Customer Data
- The diff does not reveal whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Shared with model providers or other third parties;
- Used in aggregated, de-identified, or anonymized form;
- Retained for training or model-development purposes; or
- Excluded from training and limited to providing the contracted services.
- Accordingly, no conclusion can be reached about whether the amendment creates new risks concerning AI training, data ownership, confidentiality, privacy, or deletion obligations.
Information Needed
Please provide the actual text of the additions, deletions, and replacements using the stated notation. The relevant surrounding provisions would also be helpful, particularly any sections concerning:
- Customer data and content;
- Confidentiality and privacy;
- Service improvement or analytics;
- Artificial intelligence or machine learning;
- Data retention and deletion; and
- Subprocessors or third-party service providers.
2026-08-28 · Privacy Policy
Summary
The diff only states that approximately 52 words were removed from the document. It does not identify:
- Which provisions were deleted;
- Whether the deletions alter the parties’ rights or obligations;
- Whether any limitations, warranties, confidentiality terms, or liability provisions were affected; or
- Whether the customer’s data may be used to train AI models.
AI-Training and Data-Use Impact
No specific change concerning AI training or model development can be determined from the information provided. The deleted text could potentially have addressed matters such as:
- Permission to use customer data, prompts, outputs, or usage information to train or improve AI models;
- Whether data is used for general model training or only to provide the services;
- Opt-out or consent requirements;
- De-identification, aggregation, or anonymization standards;
- Retention and deletion of training data;
- Ownership or licensing of customer data and model outputs; or
- Restrictions on using confidential or personal information for training.
However, there is no basis to conclude that any of these terms were added, removed, or modified.
Key Risk
The principal risk is lack of visibility into the deleted language. A deletion of only 52 words could still materially change the agreement, particularly if it removed an exception, limitation, consent requirement, or restriction on data use. The change should not be approved without comparing the full prior and revised versions or obtaining the exact deleted text.
Recommended Follow-Up
Request:
1. The exact 52 words that were removed;
2. The surrounding provision and section heading;
3. Confirmation of whether the deletion affects customer-data use, AI training, confidentiality, privacy, security, or liability; and
4. Any updated data-processing or AI-use documentation incorporated by reference.
2026-08-26 · Privacy Policy
Summary of Important Changes
1. Company identification and contact details
- The policy now identifies the entity as SMART-TRIAL ApS (d.b.a. Greenlight Guru) and adds its CVR number (35 13 97 10).
- The policy continues to state that Greenlight Guru is headquartered in the United States.
- A Danish postal address and clinical privacy email address are added under the contact information:
- SMART-TRIAL ApS, K. Christensens Vej 2L, 9200 Aalborg SV, Denmark
- clinical.info@greenlight.guru
Risk/impact: The added corporate details may clarify which legal entity is responsible for processing, but the policy should be checked for consistency regarding the Danish entity’s role versus the U.S. headquarters and any controller/processor allocation.
2. Expanded categories of personal data
The revised text expressly lists substantially more information that may be collected, including:
- Name, email address, phone number, and physical address
- Country and geolocation
- Newsletter-consent status
- Occupation, employer, and staff ID
- IP address
- Internet-connection information
- Information about the equipment used to access the services
Risk/impact: This is a material expansion and clarification of the data scope. Geolocation, device, staff-ID, employment, and network information may create additional privacy, security, transparency, and data-minimization obligations. Customers should confirm whether these fields are actually collected, necessary, and appropriately disclosed to trial participants and users.
3. Processing purposes
The revised policy describes processing for:
- User-account administration
- Product-security measures
- Statistics and analysis
- Product and service development
- Customer service and support
The wording now more clearly ties the listed data to these purposes.
Risk/impact: “Statistics,” “analysis,” and “product and service development” are broad purposes. They could permit wider internal analytics or product-improvement use unless limited elsewhere by contract, data-processing terms, or technical controls.
4. Legal bases
The policy changes from referring primarily to a legitimate-interest basis to stating that processing may rely on one or more legal bases. It continues to identify legitimate interests under GDPR Article 6(1)(f), particularly for statistics, analysis, and improving or developing products and services.
Risk/impact: The broader wording may give Greenlight Guru flexibility to rely on additional legal bases, although the diff does not clearly identify all of them. Customers should request clarification about the legal basis for each processing activity, especially analytics and development.
5. AI-model training
No express change concerning AI or training AI models appears in the diff. The revised references to statistics, analysis, and product/service development do not expressly authorize using customer data to train, fine-tune, evaluate, or improve AI models.
Risk: Because “product and service development” is broad, it could potentially be interpreted to cover AI-related development unless restricted elsewhere. The policy should be reviewed together with the agreement, DPA, and any AI terms for an explicit prohibition or authorization concerning model training.
6. Other changes
- Minor punctuation and formatting changes were made.
- The policy retains language concerning international transfers and standard contractual clauses.
- The version/search-result formatting appears updated or cleaned up, but no clear substantive retention-period change is shown.
2026-08-24 · Privacy Policy
Summary
The diff only states that approximately 52 words were removed, but does not identify which words, clauses, or sections were deleted.
Legal and Commercial Impact
Because the deleted text is not provided, it is not possible to determine whether the changes affect:
- Customer data ownership or usage rights
- Confidentiality obligations
- Permission to use customer data to train, fine-tune, or improve AI models
- Data retention, deletion, or security requirements
- Service-provider access to customer content
- Compliance, audit, indemnity, or liability provisions
- Customer termination or data-export rights
AI Training Provisions
No conclusion can be reached about changes to AI-model training. The deletion could potentially:
- Remove an express prohibition on using customer data for AI training;
- Remove or narrow customer consent for such use;
- Eliminate restrictions on using data to improve products or services;
- Remove obligations to anonymize or de-identify data; or
- Delete language requiring the provider to disclose or obtain permission for AI training.
However, none of these effects can be confirmed from the information supplied.
Risk Assessment
The principal risk is lack of visibility into the deleted language. A deletion of only 52 words could materially change the agreement if it removed a short but important sentence, such as a data-use restriction, consent requirement, or confidentiality exception.
Information Needed
Please provide the actual deleted text, preferably with the surrounding unchanged language. Without it, a reliable legal comparison and assessment of AI-training or customer-data risks is not possible.
2026-08-24 · Privacy Policy
Summary of Important Changes
1. Controller identity and company details
- The policy now identifies SMART-TRIAL ApS (d.b.a. Greenlight Guru) and adds its CVR registration number.
- It continues to state that Greenlight Guru is headquartered in the United States.
- The punctuation and quotation style were standardized, but these changes are not legally significant.
Risk/impact: The addition of the Danish legal entity and registration number improves identification of the relevant data controller, but the policy should clearly explain the relationship between SMART-TRIAL ApS and any U.S. Greenlight Guru entity.
2. Expanded categories of personal data
The revised text expressly lists a broader range of data, including:
- Name, email address, phone number, address, and country
- Newsletter-consent status
- Occupation, employer, and staff ID
- IP address and geolocation
- Internet-connection and device information
Risk/impact: This is a material expansion in transparency about data collection. Customers should verify that the service actually collects all listed categories and that the relevant collection notices, consent mechanisms, and security controls are in place. Geolocation, device information, and employment identifiers may create additional privacy and regulatory obligations.
3. Broader and clearer processing purposes
The revised policy lists purposes including:
- User-account administration
- Product security
- Statistics and analysis
- Product and service development
- Customer service and support
The language now says data “may be processed” for these purposes, rather than describing processing more narrowly.
Risk/impact: The broader wording may give Greenlight Guru greater flexibility to reuse customer and user data for analytics, product improvement, and service development. Customers should assess whether their contractual terms limit such use, particularly for clinical-trial information.
4. Changes to legal bases
- The revised wording states that processing may rely on one or more legal bases.
- It expressly identifies legitimate interests under Article 6(1)(f) GDPR, including statistics, analysis, and improving and developing products and services.
- The surrounding text still references contractual necessity under Article 6(1)(b) GDPR.
Risk/impact: Reliance on legitimate interests may permit processing beyond what is strictly necessary to perform the contract. Greenlight Guru should be able to explain its balancing assessment and how individuals can object.
5. AI-model training
No express change or new provision concerning AI or training artificial-intelligence models appears in this diff.
The references to statistics, analysis, and improving or developing products and services could potentially encompass machine-learning activities, but the revised language does not expressly authorize AI training, identify training data, describe anonymization, or state whether customer content is used to train general-purpose or customer-specific models.
Risk/impact: The policy is ambiguous if Greenlight Guru intends to use data for AI training. Customers should seek express contractual confirmation that clinical, trial, or other customer data will not be used for AI-model training unless specifically authorized.
6. Contact and rights information
- A specific Danish postal address and email address were added for privacy inquiries.
- The rights section remains, including the ability to complain if the issue is not resolved.
Risk/impact: This improves practical access to the controller, although the formatting should be corrected for readability.
2026-08-22 · Privacy Policy
Summary of Important Changes
1. AI-model training
- No express authorization to train AI models was added or removed. The revised text does not specifically mention artificial intelligence, machine learning, model training, prompts, or using customer data to develop or train AI systems.
- However, the policy newly/clearly identifies “statistics, analysis, as well as improving and developing our products and services” as purposes for processing personal data, relying primarily on legitimate interests under GDPR Article 6(1)(f).
- This language is broad enough that it could potentially be interpreted to cover product analytics or development activities involving automated systems, including AI, depending on the company’s actual practices and other contractual terms. It does not, however, clearly state that identifiable customer or clinical data may be used for AI training.
- Customers should review the master privacy policy, Data Processing Agreement, and any AI-specific terms for express restrictions or permissions concerning model training and whether data is anonymized, aggregated, or used only to provide the service.
2. Processing purposes and legal bases
- The policy replaces a detailed list of collected data—including name, email, phone number, country, newsletter status, occupation, employer, staff ID, IP address, geolocation, internet connection, and device information—with a more structured list of processing purposes:
- User-account administration
- Product security
- Statistics and analysis
- Product and service development
- Customer service and support
- Processing is described as “will” be based on specified legal bases, rather than “may” be processed under those bases. The policy adds:
- Legitimate interests for statistics, analysis, and product/service development
- Contractual necessity for providing the user account
Risk: The revised policy is less specific about the categories of personal data collected and gives a broader, more business-oriented description of permitted uses.
3. Retention
- For accounts associated with a clinical trial or customer, Greenlight Guru will follow processing instructions from the customer.
- Anonymized personal data may be retained longer, without a defined period.
Risk: “Anonymized” is not defined, and retention may be extended indefinitely if data is considered sufficiently anonymized.
4. Disclosures and corporate transactions
- Service-provider disclosures are reframed as transfers to data processors, acting under Greenlight Guru’s instructions and data-processing agreements.
- The policy expressly permits disclosure in connection with a full or partial sale of Greenlight Guru or its assets, relying generally on legitimate interests.
- Disclosures may also be made to police, lawyers, auditors, courts, public authorities, prospective buyers, and affiliated companies.
5. International transfers
- Clinical data is stated to be stored and processed in the EU, but product-user data may be processed in the United States.
- Transfers outside the EU/EEA may rely on EU Standard Contractual Clauses or binding corporate rules.
6. Data-subject rights and updates
- Rights are expanded or clarified to include objection, correction, deletion, portability, and withdrawal of consent.
- The policy may be updated periodically, with the revised date posted on Greenlight Guru’s websites.
2026-08-21 · Privacy Policy
Structured Summary of Important Changes
1. Expanded personal-data categories
The policy now expressly lists a broader range of information collected from users, including:
- Name, email address, telephone number, and physical address
- Country, occupation, employer, and staff ID
- Newsletter-consent status
- IP address and geolocation
- Internet-connection information and details of the equipment used to access the services
Risk/impact: This is a material expansion and clarification of the data covered by the policy. Customers should assess whether these categories are actually collected and whether appropriate notices, consent mechanisms, security controls, and retention practices are in place. Geolocation, device, and employment-related information may be particularly sensitive in some jurisdictions.
2. Processing purposes clarified and potentially broadened
The revised text identifies the following purposes:
- User-account administration
- Product-security measures
- Statistics and analysis
- Product and service development
- Customer service and support
The policy now more clearly links the listed data to these purposes.
Risk/impact: “Statistics and analysis” and “product and service development” are broad terms. They could permit use of customer or user data for analytics, product improvement, or development activities beyond strictly providing the Clinical product unless limited elsewhere in the agreement.
3. Legal bases revised
The prior wording referred generally to processing based primarily on Greenlight Guru’s legitimate interests. The new wording states that processing may rely on one or more legal bases, including legitimate interests under Article 6(1)(f) GDPR, and references Article 6(1)(b) GDPR in connection with contractual processing.
Risk/impact: The change provides greater flexibility to rely on different legal bases. However, the policy does not clearly map each processing purpose and data category to a specific legal basis. Customers may wish to request that mapping, particularly for analytics, development, marketing-related consent status, geolocation, and employee information.
4. Corporate identity and contact details updated
The policy identifies SMART-TRIAL ApS (d.b.a. Greenlight Guru), provides its Danish CVR number and Aalborg address, and states that Greenlight Guru is headquartered in the United States. A specific clinical privacy contact email is also added.
Risk/impact: This improves transparency but highlights potential cross-border processing between Denmark, the United States, and other locations. The policy refers to EU Commission standard contractual clauses or binding corporate rules where required.
5. AI-model training
No express change concerning AI training was identified. The diff does not add language expressly authorizing Greenlight Guru to use customer data, clinical-trial data, prompts, outputs, or personal data to train, fine-tune, or improve artificial-intelligence or machine-learning models.
However, the broad purposes of “statistics and analysis” and “product and service development” could create ambiguity if AI-related development is later conducted under those purposes. Customers should seek an explicit contractual statement that customer data and clinical-trial data will not be used for AI-model training without prior written consent, subject to agreed de-identification and security requirements.
2026-08-19 · Privacy Policy
Summary
The provided diff does not include the actual deleted language. It only states:
> “[Removed approximately 52 words from the document]”
Accordingly, it is not possible to determine:
- What contractual obligations or rights changed;
- Whether liability, confidentiality, intellectual property, privacy, security, or termination provisions were affected;
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether any consent, opt-out, ownership, or data-retention terms were removed; or
- Whether the deletion creates new legal or commercial risks.
AI Training and Data-Use Analysis
No specific change concerning AI-model training or use of customer data can be identified from the supplied diff. The deleted 52 words could potentially have addressed topics such as:
- Authorization to use customer data or prompts for model training;
- A prohibition or restriction on training using customer data;
- De-identification or aggregation requirements;
- Customer consent or opt-out rights;
- Ownership of inputs, outputs, or model improvements;
- Retention and deletion of data used for training; or
- Restrictions on using confidential or personal information.
Without the deleted text, the legal effect cannot be assessed.
Risk Assessment
The principal risk is informational: an important limitation or protection may have been removed, but the nature and significance of that change cannot be determined. The actual redline, including the 52 deleted words and any surrounding provisions, is required for a reliable review.
Please provide the full diff or the relevant before-and-after text.
Between 2024-10-06 and 2025-01-22 · Privacy Policy
Summary of Important Changes
1. Customer data use and AI-model training
- No express authorization to train AI models appears in the diff. The revised policy does not state that customer data, clinical-trial data, prompts, outputs, or personal data may be used to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.
- The policy newly identifies broad purposes including “statistics, analysis, as well as improving and developing our products and services.” This language is supported by Greenlight Guru’s stated legitimate interest under GDPR Article 6(1)(f).
- Although this wording could potentially be argued to cover certain AI development activities, it does not clearly define:
- whether customer content or clinical data is used;
- whether data is anonymized or de-identified first;
- whether third-party AI providers receive the data;
- whether data is used to train general-purpose models or only customer-specific features;
- whether customers can opt out; or
- how long training data or model artifacts are retained.
- Customers should seek clarification in the master privacy policy, Data Processing Agreement, product terms, and any AI-specific terms. Contractually, the absence of an express AI-training permission is important and may create ambiguity rather than a clear grant of rights.
2. Processing purposes and legal bases
- The revised policy replaces a detailed list of collected user data—including name, email, phone number, country, newsletter status, occupation, employer, staff ID, IP address, and geolocation—with a more purpose-oriented structure.
- New or clarified purposes include:
- user-account administration;
- product security;
- statistics and analysis;
- product and service development; and
- customer service and support.
- Processing is stated to be based mainly on:
- legitimate interests, particularly product analysis and development; and
- contractual necessity for providing user accounts and services.
- This broader legitimate-interest language may expand Greenlight Guru’s asserted ability to use personal data for analytics and development without consent.
3. Retention
- Customer-controlled clinical-trial data remains subject to processing instructions from the customer.
- Anonymized personal data may be retained for a longer period, without a specific time limit. The policy does not explain the anonymization standard or whether re-identification is technically possible.
4. Vendors, disclosures, and corporate transactions
- The policy more clearly permits access by contractual data processors, such as IT and email providers, acting under Greenlight Guru’s instructions and processor agreements.
- Disclosures may also occur to police, lawyers, auditors, courts, public authorities, prospective buyers, and affiliated companies.
- A new provision expressly addresses transfers of data in a full or partial sale of Greenlight Guru or its assets, relying generally on legitimate interests.
5. International transfers
- Clinical data is stated to be stored and processed in the EU, but product-user data may be processed in the United States under the master privacy policy.
- Transfers outside the EU/EEA may rely on EU Standard Contractual Clauses or binding corporate rules.
6. Individual rights and policy changes
- Rights are expanded or clarified to include objection, rectification, deletion, data portability, withdrawal of consent, and complaints to supervisory authorities.
- The policy may be updated from time to time, with the date changed on the website.
2024-10-08 · Privacy Policy
The publisher records this document as revised on this date (“Last Updated: October 08, 2024”).