Monitored company
Kandji
clause.watch tracks 2 legal documents published by Kandji (kandji.io), re-reading each one every six hours. Below is what each document covers, in plain English.
Legal
Platform Services Agreement: Key Terms and Risks
*This is a business-to-business agreement between the customer (“Licensee”) and Iru, Inc. It is not primarily a consumer privacy policy. Important privacy terms are incorporated through a separate Data Processing Addendum (“DPA”) and online documentation.*
1. Data Collection & Usage
Data covered
“Licensee’s Data” is defined broadly and may include:
- Logs, session data, telemetry, usage data, and statistics
- Support data and threat-intelligence or actor data
- Potentially malicious files detected by the Services
- Data generated through management of the Licensee’s secure environment
- Derivatives of the above
- Personal data submitted by the Licensee or on its behalf
The agreement does not provide a detailed list of individual data fields, retention periods, cookies, or tracking practices. Those details may appear in the DPA or Documentation.
How Iru may use it
The Licensee retains ownership, but grants Iru and its affiliates and contractors permission to host, copy, use, transmit, and display the data as reasonably necessary to:
- Operate, maintain, update, and secure the Services
- Provide support and associated systems
- Produce statistical insights and usage analysis
- Create anonymized and aggregated reports, studies, analyses, and other work products
Iru states it will not distribute or make available to third parties data identifiable as the Licensee’s Data. However, anonymized or aggregated data belongs to Iru and may be used broadly.
Risk: “Anonymized” is not further defined here, and the agreement does not expressly prohibit re-identification attempts or specify technical anonymization standards.
2. User Rights
The Licensee—not individual employees or end users—controls the contractual data rights. The Licensee exclusively owns its Data and must ensure it has all required consents and notices for lawful processing.
After termination or expiration, Iru will make data available for export or download only if requested within 60 days. After that, Iru generally has no obligation to retain or provide it and may delete it, unless legally prohibited.
There is no express right in this agreement for individuals to:
- Access, correct, or delete their personal data
- Restrict processing or object to processing
- Receive data portability assistance beyond the contractual export period
Those rights, if applicable, must be addressed through the DPA and relevant privacy laws.
3. Third-Party Sharing
Iru may disclose confidential data to:
- Its affiliates and contractors as needed to perform the agreement
- Service providers or subcontractors under confidentiality obligations
- Authorized Licensee users, employees, contractors, and agents
- Government or other parties when legally compelled, generally with advance notice where legally permitted
Third-party integrations may access Licensee Data as required for their operation. The Licensee authorizes that access and accepts that Iru is not responsible for a third party’s disclosure, modification, or deletion of the data.
Risk: Third-party products have separate terms, may lack Iru’s warranties or support, and integrations may be discontinued without a refund.
For EEA, UK, and Swiss personal data, the agreement incorporates the Standard Contractual Clauses through the DPA.
4. AI/ML Training
The agreement does not expressly state that Licensee Data is used to train AI or machine-learning models. It permits statistical analysis and creation of anonymized and aggregated data, but does not clearly say whether such data—or customer feedback—is used for AI training.
Iru receives a broad, perpetual, irrevocable, royalty-free license to use and incorporate user feedback into its products and services. The Licensee should obtain clarification in writing if AI training, model improvement, or use of uploaded files for such purposes is a concern.
5. Key Obligations and Restrictions
The Licensee must:
- Control and secure all account logins and is responsible for activity under them
- Follow usage limits, Documentation, Order Forms, and applicable laws
- Obtain necessary privacy consents and notices
- Maintain BYOD policies addressing security, retention, commingling, and destruction
- Export data before Free Services or Free Trials end
The Licensee may not use the Services to store sensitive health, payment-card, or financial data; unlawful or infringing material; personal data violating third-party rights; or malicious code. Resale, sublicensing, reverse engineering, security disruption, and circumvention of usage limits are prohibited.
6. Liability & Disputes
Liability is generally capped at the fees paid for the affected Services during the preceding 12 months. Consequential, indirect, punitive, lost-profit, business-interruption, and data-loss damages are excluded. The cap does not apply to Iru’s intellectual-property infringement obligations or the Licensee’s indemnification obligations.
Disputes first go to mediation, then generally binding JAMS arbitration in Kent County, Delaware. Class and representative actions are waived. The Licensee may opt out of arbitration and the class waiver within 30 days of first acceptance, but Iru then is not bound to arbitrate. Intellectual-property and piracy disputes are excluded from arbitration. Delaware law applies, and the prevailing party may recover reasonable legal fees.
7. Changes and Incorporated Terms
The agreement incorporates online Documentation, Service Specifications, Trust and Compliance materials, and the DPA, all of which may be updated over time. The agreement does not clearly specify how users will be notified of every policy or Documentation change. The current agreement is stated to have been updated October 3, 2025.
Practical step: Review Order Forms, the DPA, online security documentation, renewal notices, and any change-notification process before accepting or renewing.
Privacy Policy
Privacy Policy Overview
Policy dates: Effective January 1, 2023; last modified October 22, 2025.
Applies to: Website visitors, customers, users, and users accessing services through a corporate account.
1. Data Collection and Use
Information collected
Iru may collect:
- Contact and identifying information: Name, email, address, telephone number, username, IP address, device name/model, operating system, serial number, asset tag, and photographic headshot.
- Device and activity data: Enrollment dates, file paths and names, time since last boot, application downloads, installed applications and modification dates, and actions initiated through the service.
- Commercial and financial information: Products or services purchased, considered, or obtained, and payment-related information.
- Internet and tracking data: Cookies, browsing history on the site, interaction with advertisements, time spent browsing, and related usage data.
- Employment information: Job title and employer.
- Customer-controlled content: Corporate customers determine what additional information is uploaded or collected through configured services and devices.
Information may come directly from you, your employer, devices and websites, vendors, and service providers.
Main uses
Iru uses information to:
- Provide, configure, support, secure, and improve its products and services;
- Associate users with devices in corporate accounts;
- Process orders and payments and maintain customer records;
- Conduct marketing, targeted advertising, and analytics;
- Prevent fraud, theft, and misconduct;
- Meet legal obligations and defend legal claims; and
- Use generative AI applications to process customer feedback, which may contain identifying or employment information.
Important risk: Retention is broadly defined as lasting as long as needed to provide services, meet legal obligations, resolve disputes, or enforce agreements. No specific deletion schedule is provided.
2. User Rights
Depending on location, users may have rights to:
- Know what information is collected, its sources, purposes, and recipient categories;
- Obtain a copy, correct inaccuracies, or request deletion;
- Opt out of sale or sharing, targeted marketing, and certain profiling or automated decision-making;
- Limit certain uses of sensitive information;
- Withdraw consent and object to some processing;
- Receive or transfer data in a portable format; and
- Avoid discrimination for exercising privacy rights.
Marketing emails can be stopped using the unsubscribe method or by contacting Iru. Transactional or relationship-related communications may continue.
Requests generally require your name, email, phone number, and mailing address, and deletion requests require additional verification. Corporate-account users should normally contact their employer; Iru will forward the request to the relevant company, which may control the response.
3. Third-Party Sharing
Iru may disclose information to:
- Hosting, analytics, payment, email, support, marketing, operating-system, and other service providers;
- Affiliates and corporate customers;
- Marketing, advertising, analytics, and social-media partners;
- Lawyers, auditors, insurers, banks, and other professional advisors;
- Government or law-enforcement authorities;
- Potential buyers or investors in a merger, sale, restructuring, bankruptcy, or similar transaction; and
- Other parties when you consent or direct the disclosure.
The policy states that Iru has not “sold” or “shared” information under the CCPA, while also describing disclosures to marketing and advertising partners. This may reflect narrow legal definitions, but the wording is potentially confusing and users should review cookie and advertising choices carefully.
4. AI/ML Training
The policy expressly allows generative AI applications to process customer feedback that may include personal, identifying, or employment information. It does not clearly state whether information is used to train Iru’s own models, third-party models, or retained by AI providers for training. Users should seek clarification, particularly before submitting confidential feedback.
5. Key User Obligations and Restrictions
- Provide complete information when exercising rights; missing required details may prevent processing.
- Manage cookies through browser settings or Iru’s preference tool.
- Exercise caution because internet transmission and storage are not guaranteed secure.
- Corporate users should understand that employers may control device configurations, uploaded content, and privacy requests.
- Continued use after policy changes is treated as acceptance of the revised policy.
The policy does not impose detailed user conduct rules, but device and account activity may be monitored and recorded.
6. Liability and Disputes
The policy says security cannot be guaranteed, but it does not contain a detailed limitation-of-liability clause, indemnity, arbitration requirement, governing-law provision, or dispute-resolution process. It does state that information may be used to defend legal proceedings and that EU/UK users may complain to a data-protection supervisory authority.
7. Policy Changes
Iru may change the policy at any time. It will post the revised policy on the website and update the effective date. No individualized notice is promised. Continued website or service use after posting constitutes acceptance, so users should periodically review the policy.
Change history
2026-09-05 · Privacy Policy
2026-09-05 · Privacy Policy
2026-08-28 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-20 · Privacy Policy
2026-08-19 · Privacy Policy
2026-08-18 · Privacy Policy
2025-10-22 · Legal
The publisher records this document as revised on this date (“Last Modified: October 22, 2025”).
Between 2023-06-08 and 2024-02-18 · Privacy Policy
Between 2023-03-21 and 2023-09-30 · Legal
Summary of Important Changes
Overall assessment
The diff is overwhelmingly editorial and formatting-related. It replaces straight quotation marks with typographic quotation marks, standardizes apostrophes, and corrects punctuation around defined terms. No material change to the parties’ rights, obligations, fees, liability, termination rights, or service commitments is apparent from the diff.
Customer data and AI-model training
- No express authorization to use Licensee’s Data to train AI models was added or removed.
- The existing definition of “Licensee’s Data” continues to cover electronic data submitted by or for the customer, including data generated or collected through use of the secure environment, such as logs, session data, telemetry, statistics, potentially malicious files, and derivatives.
- The existing provision allowing Iru to anonymize and aggregate Licensee’s Data to create reports, studies, analyses, and other work products remains substantively unchanged.
- The existing treatment of Aggregate Data as Iru’s Confidential Information also appears unchanged.
- Accordingly, the diff does not clarify whether customer data, inputs, outputs, telemetry, or aggregated data may be used to train, fine-tune, evaluate, or improve generative AI or other machine-learning models. That issue remains governed by the unchanged language and any incorporated documentation, DPA, or policies.
Other notable changes
Defined terms and drafting
- Defined terms throughout the agreement now use typographic quotation marks, including Affiliate, Agreement, Devices, Documentation, Free Services, Free Trial, Iru, Licensee, Licensee’s Data, Order Form, Services, Service Specifications, Third-Party Products, and User.
- Apostrophes and possessives were standardized, including references to Iru’s, Licensee’s, Users’ and Affiliates’ rights or obligations.
- Parentheses and punctuation surrounding defined terms were corrected in several places.
- These changes should not alter legal meaning, assuming the revised punctuation accurately reflects the prior text.
Termination and survival
- The presentation of the list of provisions surviving termination was standardized.
- The Data Protection survival language remains present and substantively unchanged.
Confidentiality and data protection
- References to Confidential Information, Affiliates, subcontractors, and legally compelled disclosures were grammatically standardized.
- Licensee’s Data remains included within Licensee’s Confidential Information.
- The incorporation of the Data Processing Addendum remains unchanged.
Risk conclusion
The main practical risk is not a newly introduced provision, but continued uncertainty: the agreement still does not expressly address AI training or model improvement. Customers requiring limits on AI use should seek an explicit contractual restriction or permission, including rules for de-identification, retention, human review, model training, service improvement, and use of outputs or telemetry.
2023-01-01 · Privacy Policy
The publisher records this document as revised on this date (“Effective Date: January 1, 2023”).