Monitored company
OneLogin
clause.watch tracks 1 legal document published by OneLogin, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
Scope and effective date. The policy covers Quest and One Identity websites, portals, properties, and designated SaaS products. It applies to information collected through websites, products, subscriptions, recruitment activities, communications, and mobile use. The document contains a date inconsistency: it says the version is effective May 1, 2026, but later says the policy is effective November 1, 2024. Users should confirm the operative version on the website.
1. Data Collection and Use
Quest may collect:
- Identity and contact data: name, email, telephone number, address, company, billing and registration information.
- Account and service data: subscriber and administrator details, and information about end users supplied by a customer administrator.
- Technical and usage data: IP address, browser, operating system, ISP, referring pages, clickstream, timestamps, device type, application and operating-system versions, frequency and duration of use, and approximate device location.
- Tracking data: cookies, web beacons, pixels, email-open and click information, browsing history, and purchase or product-viewing history.
- Communications: recorded audio/video calls, transcripts, chatbot conversations, and emails to sales teams—generally where consent is obtained for call recording.
- Recruitment data: application, biographical, contact, reference-check, background-check, and potentially sensitive government-identification information.
Uses include providing and administering products, processing transactions and payments, customer support, improving services and recruitment, analytics, communications, targeted advertising, fraud/security functions, and complying with legal obligations.
Quest may process SaaS data as a processor/service provider for its customers, which are generally the controllers responsible for determining the purposes of processing.
2. User Rights
Depending on location and applicable law, users may request:
- Access to personal data and information about its use
- Correction or completion of inaccurate data
- Deletion (“right to be forgotten”)
- Restriction of processing
- Data portability
- Objection to processing, particularly direct marketing
- Opt-out of marketing communications and personalized email marketing
- Rights concerning automated decision-making and profiling
Requests can be submitted through the stated privacy-preferences portal or, for California residents, by phone. Quest states it responds to access requests within 30 days and updates information within 10 days, although legal verification and exceptions may apply.
California residents are also told they may request disclosure, deletion, limit certain sensitive-data uses, designate an agent, and opt out of sale. Quest states it does not sell personal data and honors Global Privacy Control (GPC) signals.
3. Third-Party Sharing and Transfers
Data may be shared with:
- Affiliates and subsidiaries
- Business Partners, vendors, subcontractors, resellers, and distributors
- Payment processors, email providers, analytics and advertising providers
- Cloud hosting, storage, networking, maintenance, and other infrastructure providers
- Authorities where legally required
Quest says service providers must provide contractual privacy protections and that it does not disclose data to third parties for their own marketing without consent. However, extensive advertising and analytics partners may receive tracking-related information through cookies, pixels, and web beacons.
Data may be stored or processed internationally, including in the United States. Quest relies on contractual safeguards, Standard Contractual Clauses, and the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks.
4. AI/ML Training
The policy expressly states that AI is used to:
- Analyze call transcripts for summaries, follow-up tasks, and sales analytics
- Analyze chatbot conversations to answer questions and route requests
- Analyze sales emails to assess effectiveness, personalize future communications, schedule calls, and forecast next steps
It does not clearly state whether personal data or conversations are used to train general-purpose AI or machine-learning models. Users should not assume that “AI analysis” is limited to real-time assistance. The policy also says chatbot conversations are saved for future interactions, creating a retention and confidentiality risk.
5. Key User Obligations and Restrictions
- Subscribers are responsible for notifying end users that their information may be collected and shared with Quest.
- Users should obtain appropriate consent before submitting another person’s data or using communications features that may be recorded.
- Do not post confidential or sensitive information in public forums; other users may read, copy, or use it.
- Refusing cookies may impair login and interactive service functionality.
- The policy does not honor browser Do Not Track signals, although it honors GPC for cookie preferences.
- Children under 13 should not submit data without parental involvement.
6. Security, Liability, and Disputes
Quest describes encryption in transit and, commonly, at rest, along with security controls and breach-notification procedures. Nevertheless, it expressly states that it cannot guarantee confidentiality or security and that transmission is at the user’s risk. The policy itself contains no detailed warranty disclaimer, damages cap, indemnity, governing-law clause, or general liability allocation; those terms may appear in separate Terms of Use or service agreements.
Users may complain to Quest, Truste’s dispute-resolution process, or a relevant supervisory authority. EU, UK, and Swiss individuals may ultimately have access to binding arbitration for unresolved Data Privacy Framework complaints. Quest is subject to FTC enforcement for DPF obligations.
7. Changes
Quest may change the policy at any time. For material changes, it says it will post a prominent website notice. Changes become effective when posted, with no stated requirement for individual email notice. Users should periodically review the policy.
Change history
Between 2025-03-12 and 2025-07-26 · Privacy Policy
Between 2024-12-30 and 2025-03-12 · Privacy Policy
Between 2024-05-02 and 2024-12-30 · Privacy Policy
Between 2023-01-31 and 2023-07-27 · Privacy Policy
Between 2021-07-25 and 2023-01-31 · Privacy Policy
Between 2017-10-08 and 2021-07-25 · Privacy Policy