Monitored company
Holded
clause.watch tracks 2 legal documents published by Holded, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Terms and Conditions
Holded Terms and Conditions: Key User Implications
*Based on the Terms last updated 26 February 2025. This is a practical summary, not legal advice. Important privacy details are contained in Holded’s separate Privacy Policy and Data Processing Agreement (DPA), which are not included here.*
1. Data Collection and Usage
Information collected
The Terms expressly require users to provide:
- Full legal name
- Email address
- Other information requested during account creation
- Valid bank-card details for paid subscriptions
- Account, billing, usage, and uploaded business content, such as invoices, payment notices, messages, inventory, payroll, CRM, project, and order information
Holded also collects and analyzes aggregated usage data, including how often users engage with features such as invoicing, quotes, inventory, payroll, projects, and CRM functions. Holded says this data cannot identify individuals and is used for:
- Statistical analysis
- Product and service improvement
- Performance assessment
- User-experience enhancements
Roles under data-protection law
Under the DPA, Holded generally acts as a data processor handling customer data on the customer’s instructions. Holded may also act as a data controller for its own activities, governed by its Privacy Policy—for example, account administration, billing, service analytics, and marketing.
The Terms do not specify the full categories of data, retention periods, international transfers, security measures, or legal bases. Those details must be checked in the Privacy Policy and DPA.
2. User Rights
The document does not list specific data-subject rights or explain how to exercise them. Depending on applicable law, users or individuals whose data is uploaded may have rights such as:
- Access, correction, or deletion
- Restriction or objection to processing
- Data portability
- Withdrawal of consent where consent is the legal basis
- Complaining to a data-protection authority
The customer, as data controller, may also have contractual rights under the DPA concerning processor assistance, security, deletion, and data-subject requests. Users should consult the DPA and Privacy Policy for procedures and contact details.
Users can unsubscribe from marketing emails at any time using the unsubscribe link. Creating an account constitutes agreement to receive promotional communications, although the Terms do not distinguish clearly between marketing consent and other lawful marketing bases.
3. Third-Party Sharing
The Terms state that uploaded content may be viewed and shared by third parties. This is especially significant for invoices, payment notices, messages, and other business information transmitted through the platform.
However, the Terms do not identify:
- Specific third-party providers or subprocessors
- Payment processors
- Hosting or analytics providers
- Whether data is transferred outside the European Economic Area
- The safeguards used for such transfers
The DPA and Privacy Policy should be reviewed for these details. Confidentiality obligations apply between Holded and the customer, but they do not prevent disclosures permitted under the DPA, Privacy Policy, law, or service operation.
4. AI/ML Training
The Terms do not state that customer content or personal data is used to train AI or machine-learning models. Section 9 permits analysis of aggregated, non-identifying usage data for service improvement, but it does not expressly authorize AI training.
This is not a definitive prohibition. The Privacy Policy, DPA, or other product-specific terms may address AI separately. Users should seek clarification before uploading sensitive data if AI training is a concern.
5. Key User Obligations and Restrictions
Users must:
- Be at least 16 years old
- Provide truthful and complete account information
- Protect login credentials and account privacy
- Control which people receive account access and permissions
- Pay applicable subscription fees, taxes, and duties
- Use the service lawfully and in good faith
- Avoid malware, viruses, worms, spam, or harmful content
- Avoid reselling, copying, reproducing, scraping, reverse engineering, or exploiting the service
- Comply with the Scanner fair-use limit of 500 scans per month
Holded may suspend or terminate accounts for violations, non-payment, suspected inaccurate information, or misuse. Scanner access may also be limited or suspended for exceeding limits or adversely affecting the platform.
6. Liability, Payments, and Disputes
Subscriptions are generally charged in advance and are non-refundable, with important exceptions:
- First-month refund for monthly plans if the user is dissatisfied and contacts Holded
- First 30-day refund for annual plans
- Full refund if cancellation occurs within seven business days after renewal
- No refund where access was terminated for breach
Cancellation does not eliminate charges already incurred, including the full charge for the cancellation month. Content is deleted 30 days after cancellation, while personal and usage data may be retained for up to 18 months after termination or non-payment.
Holded disclaims warranties regarding availability, uninterrupted operation, accuracy of calculations, error correction, and user satisfaction. It excludes liability for direct, indirect, consequential, special, punitive, and other damages. The Terms do not state a monetary liability cap, which may create uncertainty.
Spanish law governs the agreement, and disputes are subject to the exclusive jurisdiction of the courts of Barcelona.
7. Changes to the Terms and Service
Holded may change the Terms without prior notice by posting an updated version online. Continued use after changes means acceptance. Fee changes require 15 days’ notice, posted on the website and provided in writing. Holded may also modify or suspend the service at any time, potentially with or without notice.
Change history
2026-09-06 · Privacy Policy
Summary
The provided diff states only that approximately 374 words were removed. It does not identify the deleted language or show any replacement text.
Key Legal Implications
- Unable to assess substantive changes: Without the actual deleted wording, it is not possible to determine whether the changes affect:
- Customer data ownership or licensing
- Confidentiality obligations
- Data retention or deletion
- Security commitments
- Liability or indemnification
- Subprocessors or third-party sharing
- Compliance obligations
- Service termination rights
- Potential risk from deletions: Removing approximately 374 words could eliminate customer protections, restrictions, disclosures, or obligations. The risk cannot be evaluated based solely on the word count.
AI Training and Data Use
- The diff provides no information about whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- It is therefore impossible to determine whether the revision:
- Adds or removes a prohibition on AI training;
- Expands the provider’s license to use customer data;
- Allows use of customer content for service improvement;
- Permits human review or use by AI vendors;
- Distinguishes between inputs, outputs, prompts, telemetry, and de-identified data; or
- Changes opt-out, consent, deletion, or data-retention rights.
Recommended Follow-Up
Please provide the full redline or the specific 374 words that were removed, including any surrounding sections. The deleted language is necessary to identify the legal and AI-data-use consequences accurately.
2026-09-05 · Privacy Policy
Summary
The provided diff does not include the actual amended legal language. It only states:
> “Added approximately 374 words to the document”
Because the added text is not shown, it is not possible to reliably identify:
- Changes to the parties’ rights or obligations
- New warranties, indemnities, limitations of liability, or termination rights
- Changes to confidentiality or data-security obligations
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
- Whether customer data may be shared with affiliates, vendors, or third-party AI providers
- Whether customer data may be retained after termination
- Whether the customer has any opt-out, deletion, or audit rights
- Whether prompts, outputs, metadata, or usage information are treated as customer data
- Whether the provider receives a license or ownership interest in customer data or derived data
AI-Training Risk Assessment
No conclusion can be reached regarding AI-model training from the information provided. The phrase indicating that approximately 374 words were added does not reveal whether those additions:
- Permit training on customer content or inputs;
- Restrict training to de-identified or aggregated data;
- Allow use of data for product improvement or analytics;
- Permit human review of customer data;
- Apply different rules to consumer-facing and enterprise services; or
- Override restrictions elsewhere in the agreement.
Required Information
Please provide the actual redlined text, including the words shown in braces, brackets, and replacement notation. The relevant new language should be reviewed particularly for terms such as “train,” “improve,” “develop,” “machine learning,” “AI,” “models,” “inputs,” “outputs,” “content,” “aggregated,” “de-identified,” “service providers,” “retain,” and “license.”
2026-09-05 · Privacy Policy
Summary of Important Changes
AI model training
- No express change addresses AI training or model development. The diff does not add or remove language authorizing HOLDED to use customer data, personal data, chats, support content, or other user-provided information to train, fine-tune, evaluate, or improve AI models.
- The new references to chat support, webinars, third-party providers, statistics, and historical purposes do not, by themselves, create a clear AI-training permission. However, the policy remains broad enough that the absence of an explicit prohibition may create uncertainty, particularly if AI tools are used by HOLDED or its service providers.
- If AI training is intended, the policy should clearly identify: the data categories used, whether data is de-identified, the purpose and legal basis, retention, recipients/model providers, international transfers, and available objection or consent mechanisms.
Expanded purposes and legal bases
- The policy now expressly covers additional activities, including:
- job applications;
- webinar registration;
- chat-based customer support;
- optional cookies accepted by the user;
- fraud prevention;
- communications with public authorities; and
- third-party claims.
- Consent is identified as a legal basis for more activities, including demo forms, newsletters, webinars, chat assistance, and optional cookies. This is clearer, but the policy should ensure consent is genuinely optional and separately obtained where required.
- Legal-obligation processing and processing to administer HOLDED’s rights and pursue claims are added, expanding the possible uses of personal data beyond service delivery.
Retention and deletion
- The former general retention wording is replaced with category-based criteria, such as retaining inquiry data until the inquiry is resolved and consent-based data until the relevant period ends.
- HOLDED may retain data for legal/regulatory obligations, exercising legal rights, and statistical or historical purposes. This could permit longer retention and should clarify when data is anonymized or restricted.
- Job-application data will be deleted from systems or retained in records/anonymized form when no longer needed.
Third parties and international transfers
- The policy adds detailed disclosures concerning service providers, including Livestorm for webinars, processors for communications, and other auxiliary providers.
- Providers may access data only under HOLDED’s instructions and for contractual purposes; Article 28 GDPR processor agreements are referenced.
- The policy now expressly permits transfers outside the EEA, relying on adequacy safeguards, Binding Corporate Rules, or European Commission standard contractual clauses. This is a material expansion and should identify relevant countries or provider categories where practicable.
- A statement that data “will never be sold” to third parties is retained/clarified.
Rights, security, and liability
- Data-subject rights are expanded or clarified, including information, rectification, erasure, restriction, portability, objection, and safeguards regarding solely automated decisions.
- A right to complain to the competent supervisory authority is added.
- Security language is updated to mention TLS/RSA encryption and acknowledges that internet security is not impenetrable.
- HOLDED adds broad disclaimers for outages, cyber incidents, third-party intrusion, inaccurate user-provided information, and external-source information. These may limit practical remedies but cannot override mandatory GDPR responsibilities.
2026-09-04 · Privacy Policy
Executive Summary
The diff appears to substantially rewrite and reorganize HOLDED’s privacy policy, rather than making a narrow amendment. The revised text adds more detailed processing purposes, data categories, service providers, retention grounds, international-transfer safeguards, and data-subject rights.
Key Changes and Risks
1. Expanded personal-data collection and processing
The revised policy expressly covers:
- Free-trial registration, including name, surname, phone, email and password.
- Registration through Google and Facebook, with personal data processed by those providers.
- Customer support through chat or instant messaging, including email and information users choose to provide.
- Job applications, including CVs and optional photographs, with applications potentially submitted through LinkedIn and Indeed.
- Webinar registration through Livestorm.
- Marketing concerning products, services, promotions and events.
Risk: The policy now clearly authorizes processing of broader categories of information and use of additional third-party platforms. Users may have less visibility or control over how information supplied through those platforms is handled.
2. Marketing use and opt-out language
Marketing data may be used to send communications about products, services, promotions and events. The revised wording states that users can opt out at any time through email instructions or by contacting HOLDED.
Risk: The policy does not clearly explain whether marketing is based on consent or legitimate interests, nor whether withdrawing consent affects other services.
3. Broader retention grounds
The revised policy permits retention for:
- The original collection purposes.
- Legal or regulatory obligations.
- Administration of HOLDED’s rights and legal claims.
- Statistical or historical purposes.
- Anonymization where the individual can no longer be identified.
Risk: Specific retention periods are largely replaced by flexible, purpose-based standards, potentially allowing data to be retained longer than users might expect.
4. Third-party recipients and international transfers
The policy identifies reliance on external service providers and states that they may access data to perform services. It adds references to GDPR Article 28 processor agreements, Binding Corporate Rules and European Commission model clauses for transfers outside the EEA. Provider details are available by contacting the DPO.
Risk: The policy does not provide a complete provider list in the text. International transfers and provider access may therefore be difficult for users to assess.
5. Data-subject rights
The revised policy provides more complete descriptions of erasure, restriction, portability, objection, complaints to a supervisory authority, and safeguards concerning automated decision-making.
AI-Training Review
No express provision authorizing the use of customer or user data to train, fine-tune, evaluate or improve AI models appears in the supplied diff. There is also no express prohibition on such use. The references to “statistical or historical purposes,” anonymization and service providers are not, by themselves, equivalent to AI-training authorization, but their breadth could create ambiguity if HOLDED later uses data for AI development. A separate, explicit AI-data-use clause would be advisable.
2026-09-04 · Privacy Policy
Structured Summary of Important Changes
1. Scope and data-processing purposes expanded
The policy now expressly covers additional activities, including:
- Job applications and recruitment.
- Webinar registration.
- Customer support through chat.
- Optional cookies accepted by the user.
- Fraud prevention.
- Communications with public authorities.
- Handling third-party claims.
- Statistical or historical purposes.
- Administration and enforcement of HOLDED’s legal rights.
Risk: The purposes are materially broader and may permit use of personal data beyond the user’s original expectations. The policy should clearly link each purpose to the relevant data categories and legal basis.
2. Legal bases clarified and expanded
Consent is identified as the legal basis for activities such as:
- Demo application forms.
- Newsletter registration.
- Webinars.
- Chat support.
- Job applications.
- Optional cookies.
Processing is also stated to be based on legal obligations, including fraud prevention, public-authority communications and third-party claims.
Risk: The wording appears grammatically inconsistent and may not clearly distinguish consent-based processing from processing necessary for legal obligations or contractual performance. Consent should be specific, informed, freely given and separately withdrawable.
3. Retention rules become more detailed
The policy replaces a general retention statement with criteria based on the purpose of processing. It states that data may be retained:
- Until an inquiry is resolved.
- Until the relevant consent or support period ends.
- To comply with legal or regulatory obligations.
- To pursue legal claims.
- For statistical or historical purposes.
- In deleted, anonymized or archived form where appropriate.
Risk: “Statistical or historical purposes” and retention for legal rights are broad. Specific periods or clearer criteria would provide greater certainty.
4. New and revised recipients and international transfers
The policy adds or clarifies disclosures to:
- External service providers.
- Livestorm for webinars.
- Marketing providers.
- Public authorities where legally required.
- Other processors operating under Article 28 GDPR agreements.
It also expressly addresses transfers outside the EEA, referring to adequacy safeguards, Binding Corporate Rules and European Commission Standard Contractual Clauses.
Risk: The policy does not identify all relevant providers, countries or transfer mechanisms. Users may need more transparency about the actual destinations and categories of recipients.
5. Sale of data expressly prohibited
The updated wording states that personal data will never be sold to third parties.
However, third-party processors may still access data for service delivery, marketing, webinars and other stated purposes.
6. Data-subject rights expanded
The policy adds or clarifies rights of:
- Access/information.
- Rectification.
- Erasure.
- Restriction.
- Portability.
- Objection.
- Protection against solely automated decisions producing significant effects.
- Complaints to the competent supervisory authority.
7. Security and liability language revised
The policy adds TLS/HTTPS encryption language and describes measures against loss, misuse and unauthorized access. It also significantly broadens disclaimers for outages, viruses, overloads, third-party intrusions and other technical failures.
Risk: These disclaimers may attempt to limit HOLDED’s responsibility, but they cannot override mandatory GDPR security and liability obligations.
8. AI-model training
No express change concerning AI or training models was identified. The diff does not state that customer data, prompts, account information or other personal data may be used to train, fine-tune, evaluate or improve AI models. It also does not expressly prohibit such use. This omission should be clarified if HOLDED offers AI-enabled features.
2026-09-03 · Privacy Policy
Summary
The diff does not include the actual wording of the approximately 374 added words. It only states that words were added, so the legal effect of the changes cannot be evaluated.
AI Training and Customer Data
- The provided diff does not identify whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- It is not possible to determine whether the new language:
- Grants the provider ownership or broad usage rights over customer data;
- Permits use of customer content for model training or product improvement;
- Allows anonymized, aggregated, or de-identified data to be used for those purposes;
- Requires customer consent or provides an opt-out;
- Applies to prompts, outputs, uploaded files, personal data, or usage metadata;
- Allows data to be shared with affiliates, vendors, or third-party AI providers; or
- Imposes deletion, retention, confidentiality, or security obligations.
Other Legal Risks
No other contractual changes can be assessed because the actual additions, deletions, and replacements are missing. In particular, the available information does not show whether the new language changes:
- Liability limits or indemnities;
- Confidentiality obligations;
- Data protection or international transfer terms;
- Intellectual-property ownership;
- Service warranties or disclaimers;
- Suspension or termination rights;
- Audit rights; or
- Governing law and dispute procedures.
Required Information
Please provide the full redline text, including the approximately 374 added words and any surrounding provisions. Without the actual language, no reliable conclusion can be reached about the customer’s rights, obligations, or exposure—especially regarding the use of customer data to train AI models.
2026-09-03 · Privacy Policy
Key Changes and Risks
1. AI-model training and use of customer data
- No express provision addresses AI training, machine learning, generative AI, model improvement, or use of customer content for training.
- The revised policy does not state whether customer data—particularly data submitted through chats, support interactions, forms, webinars, or the platform—may be:
- used to train or fine-tune AI models;
- used to evaluate or improve automated systems;
- shared with AI vendors; or
- excluded from model-training datasets.
- The revised wording refers generally to processing by service providers and providers acting on HOLDED’s instructions. This could encompass AI or analytics vendors, but it does not clearly authorize or limit such use.
- Risk: Customers cannot determine from this policy whether their data or content may be incorporated into AI models, whether it will be anonymized, how long it will be retained, or whether they can object or opt out. A separate AI/data-processing provision or contractual commitment would be advisable.
2. Expanded purposes and legal bases
The policy adds or clarifies processing for:
- job applications;
- webinar registration;
- chat-based customer support;
- optional cookies accepted by the user;
- fraud prevention;
- communications with public authorities; and
- third-party claims.
Consent is identified as a legal basis for a broader range of activities, including demo forms, newsletters, webinars, chat support, and optional cookies. Legal obligations are added as a basis for fraud prevention, regulatory communications, and claims.
Risk: The expansion may permit more processing than the previous wording, but the policy does not always clearly distinguish consent-based processing from contract, legitimate-interest, or legal-obligation processing. Consent should be specific, informed, freely given, and separately withdrawable.
3. Retention rules are more detailed but broader
The revised policy replaces a general retention statement with criteria based on:
- resolving inquiries;
- the duration of consent or requested support;
- legal and regulatory obligations;
- exercising or defending legal rights; and
- statistical or historical purposes.
Data that is no longer needed will be deleted, retained in records, or anonymized.
Risk: “Statistical or historical purposes” and legal-claims retention could support prolonged retention without fixed periods. The policy should provide clearer time limits or objective retention schedules.
4. Third-party access and international transfers
- The policy now expressly states that data will never be sold to third parties.
- It identifies external providers, including Livestorm, and states that providers may access data solely to perform services under HOLDED’s instructions.
- It adds Article 28 GDPR processor agreements and safeguards for transfers outside the EEA, including adequacy mechanisms, Binding Corporate Rules, and EU model clauses.
Risk: The policy does not provide a complete provider list or clearly identify all countries involved. “Adequate safeguards” should be supported by transparent transfer information and supplementary measures where required.
5. Liability and security changes
The revised text adds broad disclaimers for outages, viruses, unauthorized intrusions, third-party conduct, and other technical failures. It also states that internet security measures are not impregnable and describes TLS/HTTPS encryption.
Risk: These disclaimers may attempt to limit HOLDED’s responsibility, but they cannot override mandatory GDPR obligations or liability rules.
6. User rights and administrative changes
The revision more fully describes GDPR rights, including access, rectification, erasure, restriction, portability, objection, and safeguards against certain solely automated decisions. It also expressly mentions complaints to the competent data protection authority.
The policy is reorganized and renumbered, with a September 2025 last-modification date.
2026-09-02 · Privacy Policy
Summary of Important Changes
1. Expanded identification and contact information
- The policy now identifies the controller as HOLDED TECHNOLOGIES SL, with its Barcelona address, tax ID, and DPO email address.
- The DPO contact information is repeated throughout the policy, including for data-subject requests and provider information.
Risk/impact: This improves transparency, but the duplicated and poorly formatted wording may create ambiguity about the policy’s structure and applicable roles.
2. New and expanded processing purposes
The revised policy adds or clarifies processing for:
- “Contact us” forms, including name, email, telephone number, and message content.
- Registration for a 14-day free trial, including name, surname, telephone, email, and password.
- Registration through Google and Facebook, with the statement that those providers process the relevant personal data.
- Customer support through chat or instant messaging.
- Job applications, including CVs and optionally photographs, with applications through LinkedIn and Indeed.
- Webinar registration through Livestorm.
- Marketing communications concerning products, services, promotions, and events.
Risk/impact: The scope of data collection and third-party involvement is materially broader and more specific than before. Users may need separate, clear notices and consents where required, particularly for marketing, recruitment data, social-login data, and photographs.
3. Marketing and opt-out rights
- Marketing use is now expressly linked to products, services, promotions, and events.
- The policy states that users may opt out at any time using email instructions or by contacting HOLDED.
- The prior wording about deleting data from systems or anonymizing it has been replaced with an opt-out mechanism.
Risk/impact: Opting out of marketing no longer necessarily means deletion of the underlying personal data. HOLDED should clearly distinguish withdrawal of marketing consent from erasure rights and explain retention of suppression lists.
4. Retention provisions
- Retention rules are reorganized and expanded by processing category.
- Data may be retained to meet legal or regulatory obligations, administer HOLDED’s rights, pursue claims, or for statistical or historical purposes.
- The policy no longer gives a general fixed retention approach and instead relies heavily on purpose- and legal-obligation-based periods.
Risk/impact: The criteria are broader and less definite, potentially making retention periods difficult for users to understand and assess for GDPR compliance.
5. Recipients and international transfers
- The policy now states that data will not be sold to third parties.
- Service providers may access data to perform services, subject to confidentiality, security measures, and Article 28 GDPR processor agreements.
- International transfers outside the EEA may use processor agreements, Binding Corporate Rules, or European Commission standard contractual clauses.
- Users may request information about providers by emailing the DPO.
Risk/impact: The policy expressly permits international transfers and access by a wider range of named or implied providers. The actual provider list and transfer locations should be made readily available.
6. Data-subject rights
- Rights are restated and expanded, including erasure, restriction, portability, objection, and safeguards concerning solely automated decisions and profiling.
- The request process is centralized at dpo@holded.com.
- The right to complain to a competent data-protection authority is retained.
7. AI-model training
- The diff contains no express provision authorizing or describing use of customer data to train, fine-tune, evaluate, or improve AI models.
- It also does not state that customer data is excluded from AI training, nor identify AI providers, purposes, legal bases, retention rules, or opt-out rights.
- If HOLDED uses customer content or personal data for AI development, this policy appears insufficiently specific and should be supplemented with clear AI-related disclosures and contractual terms.
2026-09-01 · Privacy Policy
Summary of Important Changes
AI Model Training and Data Use
- No express change concerning AI training was identified.
- The diff does not add or remove language authorizing HOLDED to use customer or user data to train, fine-tune, evaluate, or improve artificial-intelligence models.
- It also does not address whether data submitted through chats, forms, webinars, cookies, or the platform may be used for AI purposes.
- Risk: The absence of an AI-specific provision leaves the position unclear. If HOLDED uses customer content for AI training, the policy may not clearly disclose the purpose, legal basis, data categories, retention period, recipients, or opt-out rights. A separate contractual or privacy-policy review would be advisable.
Expanded Processing Purposes and Legal Bases
- The policy now expressly covers additional activities, including:
- Job applications;
- Webinar registration;
- User support through chat;
- Processing of optional cookies accepted by the user; and
- Fraud prevention, communications with public authorities, and third-party claims.
- Consent is identified as a legal basis for more activities, including demo forms, registrations, newsletters, webinars, chat support, and optional cookies.
- Legal obligations are added as a basis for fraud prevention, regulatory communications, and claims.
- Risk: The broader list increases the scope of permitted processing. The policy should clearly distinguish consent-based processing from processing necessary for contracts or legal obligations, and explain how consent can be withdrawn.
Retention and Deletion
- Retention language is expanded from a general “as long as necessary” standard to criteria based on the purpose of collection.
- HOLDED may retain data to comply with legal or regulatory obligations, administer legal rights and claims, and for statistical or historical purposes.
- Data that is no longer needed will generally be deleted or anonymized, but legal-retention exceptions remain.
- Risk: “Statistical or historical purposes” is broad and does not specify retention periods or safeguards.
Third-Party Disclosures and International Transfers
- The policy identifies service providers, including Livestorm, and states that processors may access data only under HOLDED’s instructions and for specified purposes.
- It adds references to GDPR Article 28 processor agreements.
- Data may be transferred outside the EEA, using safeguards such as Binding Corporate Rules or European Commission standard contractual clauses.
- HOLDED states that data will never be sold to third parties.
- Risk: The policy does not provide a complete list of processors, locations, or transfer destinations. Users must contact the DPO for further information.
User Rights and Security
- Rights are expanded and clarified, including access/information, rectification, erasure, restriction, portability, objection, and safeguards against solely automated decisions with significant effects.
- Users may complain to the competent data-protection authority.
- Security disclosures now mention TLS/RSA encryption and HTTPS.
- HOLDED adds broad disclaimers for outages, attacks, viruses, overloads, and other events beyond its control. These may limit practical remedies, subject to mandatory law.
2026-08-31 · Privacy Policy
Summary
The supplied diff does not include the text of the approximately 374 added words. It only states:
> “Added approximately 374 words to the document”
Because the actual additions, deletions, and replacements are not provided, it is not possible to reliably identify:
- Changes to customer data rights or obligations
- New permissions to use customer data
- Whether customer data may be used to train, fine-tune, validate, or improve AI models
- Whether data may be shared with affiliates, vendors, or AI providers
- Changes to confidentiality, security, retention, or deletion requirements
- New indemnities, liability limitations, audit rights, or compliance obligations
- Whether the customer can opt out of AI training or request deletion of training-related data
AI Training and Data-Use Analysis
No conclusion can be reached regarding AI-model training from the information provided. The diff does not reveal whether the added language:
- Authorizes training on customer content, inputs, outputs, prompts, or usage data
- Limits training to de-identified, aggregated, or anonymized data
- Permits human review or use by third-party model providers
- Grants the provider ownership or broad licensing rights
- Applies only to business customers, specific services, or an opt-in/opt-out program
- Imposes restrictions on using personal data or confidential information for training
Required Information
Please provide the actual marked-up text, using the stated notation:
- Additions:
{new language} - Deletions:
[removed language] - Replacements:
[old language]{new language}
Without the underlying text, any legal-risk assessment would be speculative.
2026-08-30 · Privacy Policy
Summary of Important Changes
1. Scope and organization
- The policy is renumbered and substantially reorganized, with sections on legal bases, retention, recipients, international transfers, rights, accuracy, security, and policy changes.
- The controller is identified simply as HOLDED, replacing the fuller corporate identification details. The DPO reference remains, but the revised wording is grammatically unclear.
- The new text appears to consolidate information from several separate processing activities, including forms, registrations, webinars, chat, cookies, recruitment, marketing, and fraud prevention.
2. New or expanded processing purposes and legal bases
The revised policy adds or expressly identifies processing for:
- Demo applications and registrations;
- Newsletters and commercial communications;
- Job applications;
- Webinar registration;
- Customer support through chat;
- Optional cookies accepted by the user;
- Fraud prevention;
- Communications with public authorities; and
- Third-party claims and administration of HOLDED’s legal rights.
Consent is stated as a legal basis for several activities. However, the revised wording is not always clear about which specific purposes require consent and whether consent is separately collected for each purpose. This may create transparency and consent-validity risk under GDPR standards.
3. Retention and deletion
The former general retention language is replaced with more detailed criteria:
- Inquiry data is retained as long as needed to resolve the inquiry.
- Consent-based data is retained until the relevant support or communication period ends.
- Data may be retained for legal or regulatory obligations, litigation, statistical, or historical purposes.
- Data that is no longer needed will generally be deleted, although it may instead be retained in records or anonymized.
This is more specific but still does not provide fixed retention periods. The broad references to statistical or historical purposes could permit longer retention and may require additional safeguards.
4. Recipients and international transfers
- The policy expressly permits access by external service providers acting on HOLDED’s instructions.
- Livestorm is identified for webinar registration.
- Provider agreements under Article 28 GDPR are expressly referenced.
- The policy now contemplates transfers outside the EEA, relying on adequacy safeguards, Binding Corporate Rules, or European Commission standard contractual clauses.
- The prior statement that data would “never be sold” is retained for recruitment data and appears to be replaced or narrowed elsewhere by a general statement that data may be provided to third parties when necessary. The distinction between “access,” “disclosure,” and “sale” should be clarified.
5. Data-subject rights
The revised policy adds or clarifies rights to:
- Information and rectification;
- Erasure;
- Restriction of processing;
- Data portability;
- Objection; and
- Protection against solely automated decisions producing legal or similarly significant effects.
It also expressly mentions complaints to the competent data-protection authority.
6. Security and liability
- Security language is expanded to include TLS/HTTPS encryption and measures against loss, misuse, unauthorized access, and theft.
- HOLDED adds broad disclaimers for outages, viruses, overloads, third-party intrusions, and other electronic-system failures. These may limit contractual expectations but cannot eliminate mandatory GDPR security or liability obligations.
7. AI-model training
No express change concerning use of customer data to train, fine-tune, evaluate, or improve AI models is visible in the supplied diff. The revised policy does not grant an identifiable AI-training right, nor does it expressly prohibit such use. If HOLDED uses customer data for AI purposes, the policy should address that purpose directly, including data categories, legal basis, model providers, retention, opt-out rights, and whether data is anonymized or shared with third parties.
2026-08-30 · Privacy Policy
Summary of Important Changes
1. No express AI-training provision identified
The diff does not appear to add or amend any clause expressly permitting HOLDED to use customer or user data to train, fine-tune, evaluate, or improve AI models. It also does not mention generative AI, machine-learning models, model training, prompts, inputs, outputs, or AI providers.
Accordingly, based on the supplied diff alone:
- There is no clear new authorization to use customer data for AI training.
- There is no express restriction prohibiting such use.
- The general references to processing data through service providers are not, by themselves, an AI-training permission.
- If HOLDED uses AI-enabled vendors, the policy does not clearly explain whether submitted content may be retained or used for model improvement. This creates ambiguity and should be clarified in the policy and customer contract.
2. Expanded data collection and processing purposes
The revised policy adds or specifies processing for:
- “Contact us” forms, including name, surname, email, telephone number, and optional text messages.
- Registration for a 14-day free trial, including a password.
- Registration through Google or Facebook, with data processed by those providers.
- Customer support through chat or instant messaging, including the email address and information voluntarily submitted in chat.
- Job applications, including CVs and optional photographs, with applications submitted through LinkedIn and Indeed.
- Webinar registration, including use of Livestorm.
- Marketing communications concerning products, services, promotions, and events.
Risk: The policy now covers a broader range of data and vendors, including potentially sensitive free-text communications and employment-related information.
3. Marketing and communications
The policy changes the language from deletion of marketing data to use of account or newsletter data to send communications about products, services, promotions, and events. Users may opt out through email instructions or by contacting HOLDED.
Risk: The revised wording may support broader marketing activity. The policy should clearly distinguish consent-based marketing from other legal bases and explain whether withdrawal affects only future messages.
4. Retention and anonymization
Retention is described more generally as lasting as long as necessary for the relevant purpose, legal obligations, rights administration, claims, or statistical/historical purposes. Data may be deleted or anonymized so the individual can no longer be identified.
Risk: The revised wording provides fewer specific retention periods and may permit longer retention for legal, statistical, or historical purposes.
5. Third parties and international transfers
The policy identifies service providers as processors and references GDPR Article 28 agreements. It adds international-transfer safeguards, including processor contracts, Binding Corporate Rules, and European Commission model clauses. Provider details may be requested from the DPO.
Risk: The policy does not provide a clear provider list or identify which providers may access particular categories of data.
6. Data-subject rights and liability
The revised policy relocates and expands GDPR rights, including erasure, restriction, portability, objection, and rights concerning solely automated decisions. It also states that users are responsible for the accuracy and authenticity of submitted data.
Risk: The accuracy disclaimer should not be interpreted as removing HOLDED’s own GDPR obligations regarding data accuracy and accountability.
2026-08-29 · Privacy Policy
Summary
The diff only states that approximately 374 words were removed from the document; it does not identify which provisions were deleted or provide the original and revised language.
Key Legal Implications
Because the deleted text is not included, it is not possible to determine whether the changes affect:
- Customer data ownership or permitted uses
- Data sharing with affiliates, vendors, or third parties
- Confidentiality or security obligations
- Intellectual-property rights or licenses
- Liability, indemnification, or warranties
- Termination and data-deletion requirements
- Governing law or dispute procedures
- Use of customer data to train, fine-tune, evaluate, or improve AI or machine-learning models
AI Training Assessment
No conclusion can be reached about changes to AI-model training. The deleted language could have:
- Authorized or restricted training on customer data
- Required anonymization, aggregation, or de-identification
- Allowed use of prompts, inputs, outputs, or usage metadata
- Given the provider rights to retain data after termination
- Required opt-in consent or provided an opt-out right
- Addressed whether customer data may be used to improve products or services
Information Needed
Please provide the actual deleted and added language, or the complete before-and-after versions of the document. Without that text, the legal and commercial significance of the change cannot be reliably assessed.
2026-08-29 · Privacy Policy
Summary of Important Changes and Risks
1. No express AI-training provision
- The diff does not expressly authorize HOLDED or its service providers to use customer data to train, fine-tune, evaluate, or improve AI models.
- It also does not state that customer data will be excluded from AI training or describe safeguards for AI systems.
- The revised policy does permit retention and use of data for “statistical or historical purposes” and allows third-party providers to access data to provide services. These provisions are broad, but they should not automatically be read as authorization for AI training.
- If HOLDED uses customer content in AI tools, the policy should clearly identify:
- whether customer data is used for model training or product improvement;
- whether data is anonymized or aggregated first;
- whether providers may use the data for their own model training;
- retention, deletion, opt-out, and confidentiality controls.
2. Expanded categories of data and collection sources
The revised policy adds or clarifies processing of:
- Free-trial registration data, including name, surname, phone, email, and password.
- Social-login data from Google and Facebook.
- Customer-support chat information and any information voluntarily submitted through chat.
- Job-application data, including CVs and optional photographs, with LinkedIn and Indeed identified as providers.
- Webinar registration data processed through Livestorm.
- Marketing data used for communications about products, services, promotions, and events.
Risk: The policy increases the amount and variety of personal data covered, including employment-related information and potentially sensitive free-text communications, without explaining detailed necessity, security, or access controls.
3. Broader purposes and retention
- Processing purposes are reframed around managing registrations, support, marketing, legal obligations, fraud prevention, claims, and administration of HOLDED’s rights.
- Retention is no longer described mainly by specific periods. It is generally tied to the time necessary for the relevant purpose, legal obligations, claims, or statistical/historical purposes.
Risk: “As long as necessary” and “statistical or historical purposes” may allow longer retention and provide less certainty about deletion timelines.
4. Third-party providers and international transfers
- The policy names or references Google, Facebook, LinkedIn, Indeed, and Livestorm.
- It states that providers may access data under HOLDED’s instructions and Article 28 GDPR processor agreements.
- International-transfer language is revised to refer to processor contracts, Binding Corporate Rules, and European Commission model clauses.
- The prior statement that data is generally stored within the EU is removed or substantially diluted.
Risk: Data may be processed outside the EEA, and the policy does not provide a complete provider list or clearly identify relevant countries and safeguards.
5. Marketing and user rights
- Marketing purposes are expanded to include promotions and events.
- Users may opt out through email instructions or by contacting HOLDED.
- GDPR rights are reorganized and clarified, including erasure, restriction, portability, objection, and automated decision-making.
Risk: The revised wording appears to narrow certain rights by describing exceptions where deletion may be refused for legal compliance, claims, or statistical purposes.
2026-08-28 · Privacy Policy
Summary of Important Changes
AI-model training and data use
- No express provision authorizes HOLDED to use customer or user data to train, fine-tune, evaluate, or improve AI models.
- The diff does not add terms referring to “artificial intelligence,” “machine learning,” “models,” “training,” “prompts,” or similar processing.
- Accordingly, this privacy-policy revision does not clearly expand or restrict AI-training rights. Any AI-related processing would need to be supported by other contractual or privacy terms, a separate notice, or a valid GDPR legal basis.
- The policy does add broader categories of processing—such as chat support, webinars, recruitment, cookies, fraud prevention, legal compliance, and statistical or historical purposes—but these additions should not automatically be treated as consent to AI training.
Expanded processing purposes and legal bases
- New processing activities are expressly listed, including:
- job applications;
- webinar registration;
- chat-based customer support;
- optional cookies accepted by the user;
- fraud prevention;
- communications with public authorities; and
- handling third-party claims.
- Consent is identified as a legal basis for additional activities, including demo forms, newsletters, webinars, chat support, and optional cookies.
- Legal obligation is added as a basis for fraud prevention, regulatory communications, and third-party claims. This gives HOLDED additional grounds to retain or disclose data without relying on consent.
Retention and deletion
- Retention language is substantially expanded and made more specific:
- inquiry data may be retained until the inquiry is resolved;
- consent-based communications may be retained until consent is withdrawn or the relevant period ends;
- data may be retained for legal obligations, rights enforcement, court claims, and statistical or historical purposes.
- When data is no longer needed, HOLDED states it will delete it, or retain it in records/anonymized form so the individual can no longer be identified.
- Risk: “Statistical or historical purposes” and legal-claim retention are broad and may allow longer retention than users might expect.
Disclosures and service providers
- The policy replaces a more specific statement that data would never be sold with a broader description of third-party disclosures. It still states that applicant data will never be sold.
- External providers may access data only to perform services under HOLDED’s instructions, with Article 28 GDPR processor agreements.
- Livestorm is specifically identified for webinars.
- International transfers outside the EEA are now addressed, using adequacy safeguards, Binding Corporate Rules, or European Commission standard contractual clauses.
User rights and security
- User rights are expanded or clarified, including access, rectification, erasure, restriction, portability, objection, and protections against solely automated decisions.
- Users are expressly directed to the competent data-protection authority for complaints.
- Security language is updated to mention TLS/RSA encryption and HTTPS, while adding broad disclaimers for outages, attacks, viruses, and other events beyond HOLDED’s control.
Overall risk assessment
The revision is primarily a GDPR-structure and disclosure update, with broader purposes, retention exceptions, processors, and international-transfer language. The main unresolved issue is that it provides no clear AI-training commitment or prohibition.
2026-08-27 · Privacy Policy
Summary
The provided diff does not include the actual added contractual language. It only states:
> “Added approximately 374 words to the document”
Accordingly, it is not possible to determine:
- What contractual terms changed;
- Whether obligations, rights, liability, or termination provisions were modified;
- Whether customer data may be used for AI model training;
- Whether any consent, opt-out, confidentiality, or data-retention terms were added; or
- Whether the changes create new legal or commercial risks.
AI Training and Data-Use Review
No specific language concerning AI, machine learning, model training, customer data, prompts, outputs, telemetry, or de-identification is included in the diff provided. Therefore, no conclusion can be reached about whether customer data may be used to train AI models.
Required Information
Please provide the actual 374-word addition, preferably with the original and revised text or the full redline. The analysis should specifically examine whether the new language:
- Permits use of customer data, content, prompts, or outputs to train or improve models;
- Applies that permission by default or only with consent;
- Allows sharing with affiliates, vendors, or third-party AI providers;
- Uses data in identifiable, aggregated, anonymized, or de-identified form;
- Gives the customer an opt-out or deletion right;
- Imposes confidentiality, security, retention, or data-localization limits; and
- Disclaims ownership or responsibility for AI-generated outputs.
2026-08-27 · Privacy Policy
Summary of Important Changes
1. Scope and Legal Basis of Processing
- The policy is reorganized and expanded to identify additional processing activities, including:
- Job applications.
- Webinar registration.
- Customer support through chat.
- Optional cookies accepted by the user.
- Fraud prevention, communications with public authorities, and third-party claims.
- Consent is now expressly identified as the legal basis for demo forms, registrations, newsletters, webinars, chat support, job applications, and optional cookies.
- Processing necessary to comply with legal obligations is added, particularly for fraud prevention, regulatory requests, public-authority communications, and claims.
- Risk: The policy may not clearly distinguish which processing relies on consent, contract, legitimate interests, or legal obligation. Consent must be specific, informed, freely given, and separately withdrawable for each relevant purpose.
2. Retention and Deletion
- The former general retention language is replaced with purpose-based criteria:
- Inquiry data is retained while necessary to resolve the request.
- Consent-based data is retained until consent is withdrawn or the relevant period ends.
- Some data may be retained for legal or regulatory obligations, exercising legal rights, litigation, statistical purposes, or historical purposes.
- Data that is no longer needed will be deleted or anonymized.
- Risk: “Statistical or historical purposes” and legal-rights retention are broad and do not specify periods or safeguards. The policy should explain when data is merely archived, anonymized, or still identifiable.
3. Disclosures and Service Providers
- The policy adds more detailed disclosures to third-party processors, including webinar provider Livestorm and other auxiliary service providers.
- Providers may access personal data only under HOLDED’s instructions and for the contractual purpose. Article 28 GDPR data-processing agreements are referenced.
- Job-application data is stated not to be sold, and the prior references to LinkedIn and Indeed processing applications are removed.
- Risk: “May have access” remains broad and does not identify all categories of providers, locations, or categories of data. The policy should maintain an up-to-date provider list or explain how users can obtain it.
4. International Transfers
- The policy changes from stating that data is generally stored in the EU to acknowledging that chat and other processing may involve transfers outside the European Economic Area.
- HOLDED refers to safeguards including Binding Corporate Rules and European Commission Standard Contractual Clauses.
- Risk: The revised language permits non-EEA transfers and should identify destinations, transfer mechanisms, and any supplementary measures where required.
5. Data-Subject Rights and Security
- Rights are expanded and clarified, including access, rectification, erasure, restriction, portability, objection, and rights concerning solely automated decision-making and profiling.
- Users may complain to the competent data-protection authority.
- Security language is expanded to mention technical measures and HTTPS/TLS encryption, while adding extensive liability disclaimers for outages, cyberattacks, and third-party interference.
- Risk: Security and liability disclaimers do not remove HOLDED’s statutory GDPR duties or responsibility for processor oversight.
6. AI Model Training
- No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models was identified.
- The revised policy does not grant an explicit AI-training right, prohibit such use, or explain whether customer content, prompts, support chats, or personal data may be used for AI development.
- Risk: If HOLDED uses customer data for AI training, the policy appears insufficiently transparent regarding purpose, legal basis, opt-out rights, retention, anonymization, and third-party AI providers.
2026-08-26 · Privacy Policy
Summary of Important Changes
1. No express AI-training provision identified
- The diff does not expressly mention artificial intelligence, machine learning, model training, model improvement, prompts, inputs, outputs, or use of customer data to train AI models.
- It therefore does not create a clearly stated authorization to use customer data for AI training—but it also does not expressly prohibit that use.
- The revised wording refers generally to processing data to provide services, customer support, marketing, legal compliance, statistical or historical purposes, and use of third-party service providers. Depending on how broadly “provide services” or “statistical purposes” is interpreted, this could leave some uncertainty about whether de-identified or aggregated data may be used for analytics or model development.
- If AI training is relevant to the relationship, the policy should expressly state:
- whether customer content, personal data, prompts, outputs, or usage data may be used for training;
- whether training is performed by HOLDED or third-party providers;
- whether data is anonymized, aggregated, or retained;
- whether customers can opt out; and
- whether business/customer account data is excluded from general-purpose model training.
2. Expanded categories of data and collection points
The revised policy adds or clarifies processing for:
- “Contact us” forms, including name, surname, email, phone number, and optional text message;
- 14-day free-trial registration, including name, surname, phone, email, and password;
- registration through Google or Facebook;
- customer support through chat, including information voluntarily provided by the user;
- job applications, including CVs and optional photographs, with applications submitted through LinkedIn and Indeed;
- webinars through Livestorm; and
- marketing communications concerning products, services, promotions, and events.
This increases the number of data sources and third-party platforms involved.
3. Broader purposes and retention
- Marketing use is expanded from communications/newsletters to promotions and events.
- Data may be retained for legal or regulatory obligations, administration of HOLDED’s rights and claims, and statistical or historical purposes.
- Marketing data may be anonymized rather than deleted, meaning identifiable data may be retained in transformed form.
- Retention language remains largely open-ended (“as long as necessary”), creating uncertainty about exact deletion timelines.
4. Third-party disclosures and international transfers
- The policy now identifies or references Google, Facebook, LinkedIn, Indeed, and Livestorm as providers that may process personal data.
- HOLDED may disclose data to providers and public authorities where necessary.
- International-transfer language is revised to reference processor agreements, Binding Corporate Rules, and European Commission standard contractual clauses. This provides safeguards but does not identify all destinations or providers.
5. Data-subject rights and risk allocation
- Rights are reorganized and clarified, including erasure, restriction, portability, objection, and limits on solely automated decision-making.
- The policy places stronger responsibility on users for the accuracy, validity, authenticity, and updating of their data, while purporting to limit HOLDED’s liability for inaccurate information.
2026-08-25 · Privacy Policy
Summary of the Diff
Scope of the Change
The diff states that approximately 374 words were removed, but it does not identify which provisions were deleted or provide the surrounding text.
Because the deleted language is not shown, it is not possible to determine reliably:
- Which contractual rights or obligations changed;
- Whether liability, confidentiality, security, indemnity, termination, or governing-law provisions were affected;
- Whether any customer protections were removed; or
- Whether the changes affect the use of customer data for artificial intelligence or machine-learning training.
AI Training and Customer Data
No specific change concerning AI-model training, machine learning, data analysis, or use of customer data can be confirmed from the available diff.
However, if the removed text addressed any of the following, its deletion could materially change the customer’s risk:
- A prohibition or limitation on using customer data to train AI models;
- A requirement to obtain the customer’s consent before such use;
- Restrictions on using customer data to improve products or services;
- Commitments to de-identify, anonymize, or aggregate data;
- Limits on retaining prompts, inputs, outputs, or usage data;
- Restrictions on sharing data with third-party AI providers;
- Ownership or licensing rights in customer data, inputs, or outputs; or
- Security, deletion, or opt-out obligations relating to AI systems.
Potential Risk
The principal risk is that deleted language may have removed a customer-friendly restriction or consent requirement. If so, the provider might have broader rights to collect, retain, analyze, share, or use customer data—including potentially for AI-model development or product improvement.
Conversely, the deletion could also have removed a provider-favorable permission, limitation, or disclaimer. The direction of the legal impact cannot be determined without seeing the actual text.
Recommended Follow-Up
Obtain either:
1. The full redline showing the deleted 374 words; or
2. The prior and revised versions of the relevant provision.
Particular attention should be given to clauses titled “Data Use,” “Customer Data,” “Privacy,” “Confidentiality,” “Service Improvement,” “Artificial Intelligence,” “Machine Learning,” “Aggregated Data,” or “Product Analytics.”
2026-08-25 · Privacy Policy
Summary of Important Changes
AI Model Training
- No express provision addresses AI, machine learning, generative AI, model training, fine-tuning, testing, or service improvement using customer data.
- The revised policy therefore does not grant or clearly deny HOLDED or its providers the right to use customer data to train AI models.
- This omission creates uncertainty, particularly for data submitted through chats, forms, webinars, support channels, or the platform. A separate contractual or product-specific AI data-use policy should be reviewed.
Legal Basis and Processing Purposes
- The policy is substantially reorganized and expands the listed processing activities.
- Consent is now stated as the legal basis for additional activities, including:
- Demo applications and registrations;
- Newsletters;
- Job applications;
- Webinar registration;
- Chat-based user support;
- Optional cookies accepted by the user.
- New legal bases include compliance with legal obligations, such as fraud prevention, communications with public authorities, and responding to third-party claims.
- Risk: The policy appears to group several different purposes under consent rather than clearly identifying the data, purpose, and separate consent mechanism for each activity. This may create GDPR transparency and consent-validity concerns.
Retention
- The former general retention language is replaced with purpose-based criteria.
- Data may be retained:
- For as long as needed to resolve inquiries or provide support;
- Until the end of a consent or regulatory period;
- To comply with legal obligations;
- To administer legal rights and pursue claims;
- For statistical or historical purposes.
- Data no longer needed will be deleted, retained in records, or anonymized.
- Risk: “Statistical or historical purposes” and legal-claim retention are broad and do not specify concrete periods or safeguards.
Recipients and Service Providers
- The policy expressly identifies Livestorm for webinar processing and allows external service providers access to personal data under HOLDED’s instructions.
- It adds processor agreements under Article 28 GDPR and states that data will never be sold to third parties.
- It also permits disclosure where legally required.
- Risk: Providers and possible international transfers may expose data to additional jurisdictions and subprocessors.
International Transfers
- The revised policy acknowledges transfers outside the EEA and refers to safeguards including adequacy measures, Binding Corporate Rules, and European Commission standard contractual clauses.
- Risk: It does not identify the countries, specific providers, or applicable transfer mechanism for each transfer.
Rights, Security, and Liability
- Data-subject rights are expanded or clarified, including access, rectification, erasure, restriction, portability, objection, and safeguards against solely automated decisions.
- A right to complain to the competent data-protection authority is added.
- Security language now references TLS/RSA encryption and HTTPS.
- HOLDED adds broad disclaimers for outages, attacks, viruses, third-party intrusions, and other technical failures, potentially limiting practical recourse.
2026-08-24 · Privacy Policy
Summary
The supplied diff only states:
> “Added approximately 374 words to the document”
It does not include the actual added, deleted, or replaced legal language. Accordingly, it is not possible to determine:
- What contractual terms changed;
- Whether liability, indemnity, confidentiality, pricing, termination, or governing-law provisions were affected;
- Whether customer data may be accessed, retained, shared, commercialized, or transferred;
- Whether customer data, prompts, outputs, or usage information may be used to train, fine-tune, evaluate, or improve AI models;
- Whether the customer has an opt-out, deletion, audit, or approval right; or
- Whether the provider may use data for its own purposes or permit third parties to do so.
AI-Training Issues Requiring Review
Please provide the actual 374 words, including the markup showing additions, deletions, and replacements. The following terms should be examined specifically:
1. Training permission
Whether the provider may use customer data, prompts, inputs, outputs, or metadata to train or improve artificial-intelligence or machine-learning models.
2. Scope of permitted use
Whether use is limited to providing the services or extends to product development, analytics, research, commercialization, or other purposes.
3. De-identification
Whether data must be anonymized or de-identified before training, and whether the provider guarantees that re-identification will not occur.
4. Opt-out or consent
Whether training use is automatic, requires affirmative consent, or can be disabled by the customer.
5. Confidentiality and ownership
Whether customer data remains confidential and owned by the customer, and whether the provider receives broad rights to derived data, model weights, or outputs.
6. Retention and deletion
Whether data used for training is retained after termination and whether deletion applies to training datasets, logs, backups, and trained models.
7. Third-party access
Whether subcontractors or external AI providers may receive customer data or use it for their own model training.
8. Sensitive data and compliance
Whether the provision addresses personal data, regulated information, cross-border transfers, and applicable data-protection laws.
The actual redlined language is necessary for a reliable legal-risk analysis.
2026-08-24 · Privacy Policy
Summary of Important Changes
1. Controller Identity and Contact Details
The policy now identifies the organization more fully as HOLDED TECHNOLOGIES SL, with:
- Barcelona address
- Tax identification number
- DPO email address: dpo@holded.com
- Express reference to the appointment of a Data Protection Officer
This improves transparency and gives customers a clearer contact point for privacy requests.
2. Expanded Data Collection and Processing Purposes
The revised policy substantially expands the categories of processing and the data collected, including:
- Free-trial registration: name, surname, phone number, email address and password
- Third-party sign-up: registration through Google or Facebook, with the relevant personal data processed by those providers
- Customer support/chat: email and any information the user chooses to submit through the chat
- Job applications: name, surname, email, telephone number, CV and optionally photograph
- Recruitment platforms: applications through LinkedIn and Indeed, with data processed by those providers
- Webinars: email address and registration information, including use of Livestorm
- Marketing: communications concerning products, services, promotions and events
These additions broaden the stated purposes and the types of personal data HOLDED may process.
3. Marketing Communications and Opt-Out
The policy now states that personal data may be used to send marketing communications about HOLDED’s products, services, promotions and events. Users may opt out through the instructions in each email or by contacting HOLDED.
Risk: The policy should clearly distinguish consent-based marketing from marketing based on another legal basis, and explain whether consent is separate from acceptance of the general policy.
4. Retention Periods
The former general retention wording has been replaced with more detailed, purpose-based criteria. Data may be retained:
- For as long as necessary to resolve inquiries
- Until the end of a recruitment or webinar-related period
- To comply with legal or regulatory obligations
- To administer HOLDED’s rights, including legal claims
- For statistical or historical purposes
Risk: “As long as necessary” and “statistical or historical purposes” remain relatively broad and may not provide clear time limits.
5. Third-Party Providers and International Transfers
The revised policy identifies broader use of external providers and states that providers may access data to perform services. It refers to:
- GDPR Article 28 processor agreements
- Confidentiality and security obligations
- International transfers outside the EEA
- Appropriate safeguards, including Binding Corporate Rules and European Commission standard contractual clauses
- Contacting the DPO for provider information
The policy also says data will not be sold to third parties.
6. Data Subject Rights
The rights section has been reorganized and expanded, including:
- Access/information
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection
- Rights concerning solely automated decision-making and profiling
- Complaints to the competent data protection authority
7. AI Training
No express change concerning the use of customer data to train, develop or improve AI models appears in the supplied diff. The revised policy does not appear to grant a specific right to use customer content, account data or support communications for AI training. However, the broad references to “statistical or historical purposes,” service provision and product-related processing could create ambiguity if HOLDED later uses data for model development.
Recommended clarification: expressly state whether customer data, uploaded content, prompts, support chats or usage data may be used to train or improve AI models, identify the legal basis, explain anonymization or opt-out controls, and distinguish provider processing from HOLDED’s own model training.
2026-08-23 · Privacy Policy
Summary of Important Changes
1. Scope and organization of the policy
- The policy is reorganized and renumbered, with expanded sections on legal bases, retention, recipients, data-subject rights, security, and policy modifications.
- HOLDED’s corporate details are simplified to identify only “HOLDED,” while the prior address, tax ID, and email details are removed from the introductory text. The DPO reference remains, but the drafting is grammatically unclear.
- The stated last-modification date remains September 2025.
2. New or expanded processing purposes
The revised policy expressly covers additional activities, including:
- Job applications and recruitment.
- Webinar registration.
- Customer support through chat and instant messaging.
- Optional cookies accepted by the user.
- Fraud prevention, communications with public authorities, and handling third-party claims.
- Statistical or historical purposes.
- Administration and pursuit of HOLDED’s legal rights and claims.
Risk: The broader list of purposes may permit more extensive use of personal data. Several purposes are described generally, which could create uncertainty about necessity, proportionality, and the applicable GDPR legal basis.
3. Legal bases
- Consent is stated as the legal basis for demo forms, registrations, newsletters, webinars, chat support, job applications, and optional cookies.
- Compliance with legal obligations is added for fraud prevention, public-authority communications, and third-party claims.
- The former wording appears to have focused more narrowly on registration and commercial communications.
Risk: The policy should clearly distinguish consent-based processing from processing necessary for a contract, legitimate interests, or legal obligations. Treating support or registration activities as consent-based may raise issues if service access depends on consent that is not genuinely optional.
4. Retention and deletion
- Retention language is substantially expanded. Data may be retained to resolve inquiries, provide support, send communications, comply with laws, administer rights, pursue claims, or preserve statistical/historical records.
- Data no longer needed will generally be deleted or anonymized.
- Recruitment data is no longer described with the same detailed categories, such as CVs and photographs.
Risk: “Statistical or historical purposes” and legal-claim retention could extend storage periods without specific time limits. The policy should provide clearer retention schedules or objective periods.
5. Recipients and international transfers
- The policy confirms data will not be sold to third parties.
- External providers may access data solely to provide services under HOLDED’s instructions and contractual arrangements.
- Specific references include LinkedIn, Indeed, and Livestorm.
- International transfers outside the EEA are addressed through adequacy safeguards, Binding Corporate Rules, or European Commission Standard Contractual Clauses.
Risk: The policy does not provide a complete, current provider list or clearly identify all transfer destinations. Users may need to contact the DPO for details.
6. Rights and security
- Rights are expanded and restated, including access, rectification, erasure, restriction, portability, objection, and safeguards concerning solely automated decisions and profiling.
- TLS/HTTPS encryption is specifically mentioned.
- HOLDED adds broad disclaimers for outages, viruses, third-party attacks, and other technical failures.
Risk: The liability disclaimers may not eliminate HOLDED’s statutory GDPR responsibilities or liability for inadequate security.
7. AI-model training
- No express change addresses the use of customer data to train, fine-tune, evaluate, or improve AI models.
- The revised purposes do not expressly authorize AI training, nor do they expressly prohibit it.
- The broad references to statistical/historical purposes, service improvement, providers, and automated processing should not be assumed to cover AI training.
Key concern: If HOLDED uses customer content or personal data for AI training, the policy should state this clearly, identify the data involved, purposes, legal basis, retention, providers, transfers, opt-out rights, and whether data is anonymized or used only in aggregated form.
2026-08-22 · Privacy Policy
Summary of Important Changes
1. Corporate identity and contact details
- The policy now identifies the controller as HOLDED TECHNOLOGIES SL, with its Barcelona address, tax ID, and DPO email address.
- The DPO contact details are repeated in the sections concerning data rights and service providers.
- Risk: The revised policy is more specific, but duplicated and poorly integrated wording may create ambiguity about the applicable section or contact process.
2. Expanded data collection and processing purposes
The revised policy adds or clarifies processing for:
- 14-day free trials, including name, surname, phone number, email, and password.
- Registration through Google and Facebook, whose providers will process the relevant personal data.
- Customer and user support through instant messaging/chat, including email and information voluntarily provided in chat.
- Job applications, including name, contact details, CV, and optional photograph.
- Job applications submitted through LinkedIn and Indeed, which will process applicants’ data.
- Webinar registration through Livestorm, including email address.
- Marketing concerning products, services, promotions, and events.
Risk: The policy now covers more data sources, platforms, and purposes. Users may have less practical control over data submitted to third-party platforms, and the wording does not clearly distinguish HOLDED’s role from the providers’ roles.
3. Marketing and retention
- Marketing data may be used to send communications about products, services, promotions, and events.
- Users may opt out using email instructions or by contacting HOLDED.
- Data may be retained for legal/regulatory obligations, exercising legal rights, statistical or historical purposes, or until the relevant requested period ends.
- The revised policy states that data may be deleted or anonymized when no longer needed, but broad exceptions allow continued retention.
Risk: Retention periods remain largely open-ended (“as long as necessary”), with broad legal, statistical, historical, and claims-related exceptions.
4. Third-party recipients and international transfers
- The policy continues to state that data will not be sold to third parties.
- It expressly identifies external service providers and says they may access data only to perform the contractual relationship.
- The policy references GDPR Article 28 processor agreements.
- International transfers outside the EEA may use processor contracts, Binding Corporate Rules, or European Commission Standard Contractual Clauses.
- Users may request information about providers by contacting the DPO.
Risk: The policy does not provide a concrete provider list, countries, or transfer-specific details, requiring users to make a separate request.
5. Data-subject rights
- Rights are reorganized and expanded to include information, rectification, erasure, restriction, portability, objection, and complaints to a supervisory authority.
- The automated-decision section is reformulated but continues to address decisions based solely on automated processing that significantly affect individuals.
6. AI-model training
- No express reference to artificial intelligence, machine learning, generative AI, model training, model improvement, profiling for AI development, or use of customer data to train AI models appears in the diff.
- Accordingly, the revised policy does not appear to grant or restrict a specific right for HOLDED to use customer data for AI training.
- If HOLDED intends to use customer or user content for training or improving AI models, this policy does not transparently describe that purpose, legal basis, retention, anonymization, opt-out mechanism, or sharing arrangements.
2026-08-22 · Privacy Policy
Summary of Important Changes
1. Expanded processing purposes and legal bases
- The policy now identifies additional activities, including:
- Job applications and recruitment.
- Webinar registration.
- Customer support through chat and instant messaging.
- Optional cookies accepted by the user.
- Fraud prevention, communications with public authorities, and third-party claims.
- Consent is stated as the legal basis for more activities, including demo forms, registrations, newsletters, webinars, chat support, and optional cookies.
- Legal obligations are added as a basis for fraud prevention, regulatory communications, and claims handling.
Risk: The expanded purposes and broad references to “consent” may require clearer, purpose-specific consent notices. Consent may not be valid if bundled or insufficiently distinguishable from other processing.
2. Retention rules are more detailed but broader
The policy replaces a general retention statement with criteria based on:
- The time needed to resolve inquiries.
- The duration of consent or requested support.
- Legal and regulatory obligations.
- Pursuing or defending legal claims.
- Statistical or historical purposes.
- Deletion, or conversion into anonymized records, when data is no longer needed.
Risk: “Statistical or historical purposes” and legal-claims retention may permit longer retention than users expect. The policy does not provide precise periods or objective limits.
3. Third-party access and international transfers
- The policy now expressly permits service providers to access personal data under HOLDED’s instructions and for contractual purposes.
- It refers to GDPR Article 28 processor agreements.
- It confirms that data may be transferred outside the EEA and references Binding Corporate Rules and European Commission standard contractual clauses.
- Providers are described as subject to confidentiality and security obligations.
- The previous statement that data would “never be sold” appears retained in substance, although the restructured wording is difficult to follow.
Risk: The policy does not identify specific providers or destination countries, making it difficult to assess transfer exposure. The wording should clearly distinguish processors from independent controllers and specify applicable safeguards.
4. New or expanded user rights
The revised policy expressly describes rights to:
- Information/access.
- Rectification.
- Erasure.
- Restriction.
- Data portability.
- Objection.
- Protection against solely automated decisions producing legal or similarly significant effects.
- Complaints to a data protection authority.
This is generally more complete, but some wording is unclear and appears poorly integrated.
5. Liability and security disclaimers
HOLDED adds or strengthens disclaimers for outages, viruses, third-party intrusions, telecommunications failures, and other events outside its control. It also states that internet security measures are not impregnable and describes TLS/HTTPS encryption.
Risk: These disclaimers may be challenged if interpreted as excluding mandatory data-protection duties or liability that cannot legally be excluded.
6. AI-model training
No express change addresses AI training. The diff does not state that customer data, account data, chat content, support interactions, or other personal data may—or may not—be used to train, fine-tune, evaluate, or improve AI models.
Accordingly, the revised policy provides no clear customer-facing commitment regarding AI training, data de-identification, opt-out rights, model providers, retention, or safeguards. A separate, explicit AI-data-use provision should be added if such processing occurs.
2026-08-21 · Privacy Policy
Summary of Important Changes
1. New or Expanded Data Collection
The revised policy identifies HOLDED more completely, including:
- HOLDED TECHNOLOGIES SL’s Barcelona address, tax ID, and DPO email.
- Data collected for a 14-day free trial, including name, surname, phone, email, and password.
- Registration through Google and Facebook, with the policy stating that those providers process the associated personal data.
- Customer-support chat data, including email and any information voluntarily submitted through the chat.
- Job-application data, including name, contact details, CV, and optional photograph, with applications potentially submitted through LinkedIn and Indeed.
- Webinar registration data, including email, with Livestorm identified as a provider.
These additions broaden the categories of personal data and external services involved.
2. Expanded Processing Purposes
The revised policy more specifically authorizes processing for:
- Free-trial and platform registration.
- Customer and user support through chat.
- Marketing communications about HOLDED’s products, services, promotions, and events.
- Job applications and recruitment administration.
- Webinar administration.
- Fraud prevention, communications with public authorities, legal obligations, third-party claims, and exercising HOLDED’s legal rights.
- Statistical or historical purposes.
The marketing provision is broader and clearer than the previous wording. Users may opt out through email instructions or by contacting HOLDED directly.
3. Retention Periods
The prior general approach—retaining data only as long as necessary for the relevant purpose—is replaced with detailed, purpose-based criteria. However, the revised language expressly permits retention for:
- Legal or regulatory obligations.
- Managing or pursuing legal claims.
- Statistical or historical purposes.
This may allow some data to be retained longer than users might expect, particularly after the original business purpose ends.
4. Third-Party Providers and International Transfers
The revised policy:
- Lists or identifies more providers, including Google, Facebook, LinkedIn, Indeed, and Livestorm.
- States that providers may access data only to perform services for HOLDED.
- Refers to GDPR Article 28 processor agreements.
- Adds international-transfer safeguards, including processor contracts, Binding Corporate Rules, and European Commission standard contractual clauses.
- Provides a process for requesting information about providers.
This improves transparency but also confirms broader third-party access and potential transfers outside the EEA.
5. Data-Subject Rights
The rights section is reorganized and expanded, including rights to:
- Access, correction, erasure, restriction, portability, and objection.
- Object to solely automated decisions, including profiling, where legally significant.
- Lodge a complaint with a data-protection authority.
6. AI Training and Model Use
No express authorization to use customer data to train, fine-tune, evaluate, or improve AI models appears in the supplied diff. The revised policy does add “statistical or historical purposes,” but that wording should not automatically be treated as permission for AI training. It is nevertheless broad and could create uncertainty if HOLDED later uses data analytics or AI systems for those purposes.
The policy does not clearly state:
- Whether customer content or account data is used for AI training.
- Whether data is shared with AI vendors or model providers.
- Whether customer data is anonymized before such use.
- Whether users can opt out of AI-related processing.
Customers should seek confirmation in the service terms, DPA, or AI-specific documentation.
2026-08-21 · Privacy Policy
Summary of Important Changes
1. AI-model training and use of customer data
- No express provision authorizing or prohibiting AI-model training appears in the diff.
- The revised policy does not state whether customer, user, chat, webinar, cookie, trial, or other personal data may be used to:
- train, fine-tune, or evaluate AI models;
- improve artificial-intelligence products or services;
- create aggregated or anonymized training datasets; or
- permit third-party AI providers to use the data for their own model development.
- This omission is important because the policy adds or expands references to chat support, optional cookies, external service providers, statistical or historical purposes, and third-party processing. None of these clauses clearly addresses AI training.
- Customers should not assume that the policy provides a clear “no training” commitment. Any AI-training terms may instead appear in separate product terms, data-processing agreements, cookie notices, or vendor documentation.
2. Expanded processing purposes and legal bases
The revised policy adds or clarifies processing for:
- job applications and recruitment;
- webinar registration;
- chat-based customer support;
- optional cookies accepted by the user;
- fraud prevention;
- communications with public authorities; and
- third-party claims.
Consent is identified as a legal basis for more activities, including demo forms, registration, newsletters, webinars, chat support, and optional cookies. Legal obligations are also added as a basis for fraud prevention and disclosures to authorities.
Risk: The broader and sometimes compressed wording may make it difficult to determine which purpose relies on consent, contract, legitimate interests, or legal obligation. This could create transparency and consent-compliance concerns under the GDPR.
3. Retention and deletion
The policy replaces a general retention statement with purpose-based criteria, including retention:
- while an inquiry is resolved;
- until the end of a consent or regulatory period;
- to comply with legal obligations;
- to pursue legal claims; and
- for statistical or historical purposes.
Data that is no longer needed will be deleted, retained in records, or anonymized.
Risk: “Statistical or historical purposes” and legal-claim retention may permit longer retention than users might expect, without specific periods.
4. Third-party access and international transfers
- The policy now states that data will never be sold to third parties.
- It expressly permits access by external providers, including Livestorm and other service providers, under instructions and contractual safeguards.
- International transfers outside the EEA are addressed through adequacy safeguards, Binding Corporate Rules, or European Commission standard contractual clauses.
Risk: Provider categories remain broad, and the policy does not identify all providers, locations, or any AI vendors.
5. Rights, security, and liability
The revision adds clearer GDPR rights, including access, rectification, erasure, restriction, portability, objection, and protections against solely automated decisions.
It also adds TLS/HTTPS security language but broadens disclaimers for outages, intrusions, viruses, overloads, and other events beyond HOLDED’s control.
Risk: The disclaimer may attempt to limit HOLDED’s responsibility, although it cannot override mandatory GDPR duties or applicable liability rules.
2026-08-20 · Privacy Policy
Summary of Important Changes
1. Expanded Controller Identification
The policy now identifies HOLDED as HOLDED TECHNOLOGIES SL, including its Barcelona address, tax ID, email address, and Data Protection Officer contact.
Risk/impact: This improves transparency, but the wording is grammatically inconsistent and should be checked for accuracy and completeness.
2. Broader and More Detailed Processing Activities
The revised policy adds or clarifies processing for:
- Free-trial platform registration, including name, surname, phone, email, and password.
- Registration through Google and Facebook, with the statement that those providers process the relevant personal data.
- Customer and user support through chat or instant messaging, including email and any information voluntarily provided.
- Job applications, including CVs and optional photographs, with applications submitted through LinkedIn and Indeed.
- Webinar registration through Livestorm.
- Marketing communications concerning products, services, promotions, and events.
Risk/impact: The policy now covers substantially more data sources, providers, and purposes. “Any other information you decide to communicate” may be broad and could capture sensitive or confidential information without clearly limiting how it will be used.
3. Marketing and Opt-Out Rights
Marketing use has been expanded from general communications to communications about products, services, promotions, and events. The policy states that users may opt out at any time through email instructions or by contacting HOLDED directly.
Risk/impact: The broader marketing scope may increase consent and e-privacy compliance requirements, particularly where consent is the legal basis.
4. Retention Periods Are Broader and Less Specific
The previous approach referred generally to retaining data only as long as necessary for the stated purpose. The revised policy adds retention for:
- Legal or regulatory obligations.
- Managing and enforcing HOLDED’s rights and court claims.
- Statistical or historical purposes.
- Anonymization where data is no longer identifiable.
Risk/impact: These additional retention grounds may permit longer retention, especially because no concrete time limits are provided. “Statistical or historical purposes” should be narrowly defined and supported by appropriate safeguards.
5. Third-Party Providers and International Transfers
The revised policy names or references Google, Facebook, LinkedIn, Indeed, and Livestorm. It states that providers may access data to perform services, are subject to confidentiality and security obligations, and may be covered by GDPR Article 28 processor agreements.
International-transfer language has been updated to refer to processor contracts, Binding Corporate Rules, and European Commission model clauses. Provider details can be requested by email.
Risk/impact: The policy does not provide a clear, readily accessible provider list or identify transfer destinations. Users may need to request important information separately.
6. Data Subject Rights
The rights section is reorganized and expanded, including erasure, restriction, portability, objection, automated decision-making, and the right to complain to a supervisory authority.
7. AI Model Training
No express provision authorizing or prohibiting the use of customer data to train, fine-tune, evaluate, or improve AI models appears in the supplied diff.
The revised wording does not create a clear AI-training permission. However, the expanded references to support chats, voluntarily submitted information, statistical purposes, and service providers could create ambiguity about secondary uses of data.
Recommended action: Add a dedicated AI clause stating whether customer data, prompts, outputs, account information, support communications, or business content may be used for AI training or model improvement, whether data is anonymized, whether consent or opt-out applies, and whether third-party AI providers receive the data.
2026-08-20 · Privacy Policy
Summary of Important Changes
1. Expanded processing purposes and legal bases
The policy now expressly covers additional activities, including:
- Job applications and recruitment;
- Webinar registration;
- Customer support through chat and instant messaging;
- Optional cookies accepted by the user;
- Fraud prevention;
- Communications with public authorities;
- Handling third-party claims; and
- Statistical or historical purposes.
Consent is identified as the legal basis for more activities, including demo forms, registrations, newsletters, webinars, chat support and optional cookies. Legal obligations are added as a basis for fraud prevention, regulatory communications and third-party claims.
Risk: The policy appears to group many unrelated purposes under broad consent language. Consent may not be sufficiently specific or freely given if users cannot clearly distinguish between the separate purposes.
2. More detailed retention rules
The former general retention wording is replaced with purpose-specific criteria. Data may be retained:
- Until an inquiry is resolved;
- For the period necessary to provide consent-based communications or support;
- To comply with legal or regulatory obligations;
- To administer legal rights and pursue claims; or
- For statistical or historical purposes.
Job-application data will be deleted from systems or converted into records that are anonymized so the individual can no longer be identified.
Risk: “Statistical or historical purposes” and retention for legal rights are broad and may permit longer retention than users expect. The policy does not give concrete retention periods.
3. Expanded disclosures to service providers
The revised policy states that third-party service providers may access personal data where necessary to provide auxiliary services, including webinar services such as Livestorm. It adds commitments concerning confidentiality, security measures and GDPR Article 28 processor agreements.
The policy also states that data will not be sold to third parties, replacing the narrower previous wording concerning certain providers.
Risk: The policy does not provide a clear, complete list of providers or identify all processing locations. Users must contact the DPO for more information.
4. International transfers
The policy now expressly addresses transfers outside the European Economic Area. It refers to safeguards including:
- Binding Corporate Rules; and
- European Commission standard contractual clauses.
Risk: The wording is general and does not identify the countries, recipients or specific transfer mechanism used for each provider. The policy should be checked against actual vendor arrangements.
5. Expanded data-subject rights
The revised policy adds or clarifies rights under the GDPR, including:
- Access/information;
- Rectification;
- Erasure;
- Restriction;
- Data portability;
- Objection; and
- Rights concerning solely automated decision-making and profiling.
It also explains that certain deletion requests may be refused where retention is legally required and directs complaints to the competent data-protection authority.
6. Security and liability wording
The policy adds TLS/HTTPS encryption language but also significantly expands disclaimers for outages, viruses, overloads, unauthorized intrusions and other events outside HOLDED’s control.
Risk: These disclaimers may attempt to limit HOLDED’s responsibility for security or service failures, although they cannot override mandatory GDPR obligations or applicable liability law.
7. AI-model training
No express change concerning AI training was identified. The diff does not state whether customer data, user content, support conversations, analytics or other personal data may be used to train, fine-tune, evaluate or improve AI models.
Key risk: The policy remains silent on AI training. If HOLDED uses customer data for that purpose, the policy may not adequately disclose the purpose, legal basis, data categories, recipients, retention, opt-out rights or safeguards.
2026-08-20 · Privacy Policy
Summary of Important Changes
1. Expanded processing purposes and legal bases
- The policy replaces the former, narrower descriptions of website-form processing with a broader list covering:
- Demo applications and registrations
- Newsletters
- Job applications
- Webinar registration
- Chat-based customer support
- Optional cookies accepted by the user
- New legal bases are added, including:
- Consent
- Compliance with legal obligations
- Fraud prevention
- Communications with public authorities
- Third-party claims
Risk: The revised wording substantially broadens the purposes for which data may be used. The policy should clearly link each data category to a specific purpose and legal basis. Combining many unrelated purposes under “consent” may create GDPR transparency and consent-validity concerns if consent is not granular and optional.
2. More detailed retention rules
The former general retention statement is replaced with criteria-based periods, including:
- Inquiry data: retained while necessary to resolve the inquiry
- Consent-based communications: retained until consent is withdrawn or the relevant support period ends
- Data retained for legal, regulatory, statistical, historical, or litigation purposes
- Job-application data: deleted, anonymized, or retained in records when no longer needed
Risk: Retention periods remain largely open-ended (“as long as necessary”), particularly for legal, statistical, historical, and claims-related purposes. More precise maximum periods would reduce uncertainty and compliance risk.
3. Expanded third-party disclosures
- The policy now expressly permits disclosures to third parties where necessary.
- It adds external providers for webinars, including Livestorm.
- Service providers may access data under HOLDED’s instructions and for contractual purposes.
- Article 28 GDPR data-processing agreements are referenced.
- Data will “never be sold” to third parties.
Risk: The policy does not provide a complete or specific provider list, making it difficult for users to understand who receives their data. The “never sold” statement does not prevent other forms of sharing or processing, including use by providers for their own purposes unless contracts prohibit it.
4. International transfers
- The policy now addresses transfers outside the EEA.
- It refers to Binding Corporate Rules and European Commission Standard Contractual Clauses.
- Users are directed to contact the DPO for more information.
Risk: The policy does not identify destination countries, transfer mechanisms used for particular providers, or supplementary safeguards. This may be insufficiently transparent under GDPR requirements.
5. New user rights and complaints process
The revised policy adds or clarifies rights to:
- Information and rectification
- Erasure
- Restriction
- Data portability
- Objection
- Protection against certain solely automated decisions
It also states that complaints may be filed with the competent data-protection authority.
6. AI-model training
No express change addresses AI or model training. The diff contains no language authorizing or prohibiting the use of customer data, prompts, outputs, account information, or other personal data to train, fine-tune, evaluate, or improve AI models.
Risk: If HOLDED uses customer data for AI training, the policy is currently unclear and may not provide adequate transparency regarding purpose, legal basis, retention, recipients, anonymization, or opt-out rights. An explicit AI-data-use clause should be added.