clause.watch Contracts Recent changes Start monitoring

Monitored company

Otta

clause.watch tracks 1 legal document published by Otta, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

18,728 characters · Read the original

Privacy Policy Overview

1. Data Collection & Usage

Welcome to the Jungle (operated by Otta Technology Ltd) collects information from your direct submissions, automated technologies such as cookies, employers using the platform, and public sources such as LinkedIn.

Types of data collected
  • Identity and contact data: Name, email, address, date of birth, and telephone number.
  • Profile data: Username, password, CV/resume, education, work history, interests, languages, salary information (if provided), preferences, and feedback.
  • Engagement data: Jobs viewed or applied for, interview progress, recruiter messages, and application-related feedback.
  • Technical and usage data: IP address, login details, browser and device information, operating system, location settings, and how you use the website or app.
  • Marketing data: Marketing preferences and communications preferences.
  • Special-category data: Ethnicity, sexual orientation, and gender identity. The policy says that providing this information constitutes consent to its processing.

The data may be used to:

  • Create and manage your account and provide job-matching services.
  • Update your profile using your CV and cover letters.
  • Match you with jobs and allow employers to contact you.
  • Personalize content, recommendations, advertising, and marketing.
  • Analyze and improve the platform, services, and user experience.
  • Operate, secure, troubleshoot, and protect the business.
  • Comply with legal obligations, prevent fraud, enforce legal rights, and support business reorganizations.

The company relies on contractual necessity, legitimate interests, legal obligations, and consent, depending on the activity. It may process data without consent where legally permitted.

2. User Rights

Subject to applicable law, users may:

  • Request access to their personal data.
  • Request correction of inaccurate or incomplete data.
  • Request deletion.
  • Object to processing, including certain legitimate-interest or marketing activities.
  • Request restriction of processing.
  • Request data portability.
  • Withdraw consent, including consent relating to marketing or special-category data.

Requests should be sent to the company or its representatives. The company generally aims to respond within one month, although complex requests may take longer. It may request identity verification and may charge a reasonable fee—or refuse a request—for clearly unfounded, repetitive, or excessive requests.

Users may complain to the UK Information Commissioner’s Office (ICO), although the company asks users to contact it first.

3. Third-Party Sharing

Data may be shared with:

  • Employers and recruiters, who generally act as independent data controllers and may use the information for recruitment.
  • IT, software, hosting, and system-administration providers acting as processors.
  • Lawyers, auditors, insurers, banks, and other professional advisers.
  • Regulators, tax authorities, law-enforcement bodies, and other authorities.
  • Buyers or successor owners if the business is sold, merged, or reorganized.

The policy states that service providers may only process data for specified purposes and under the company’s instructions. However, employers receiving your information may make their own decisions about how to process it. Third-party websites, plug-ins, and applications linked from the platform are outside the company’s control.

Some data may be transferred outside the UK using adequacy decisions or approved contractual safeguards.

4. AI/ML Training

The company uses OpenAI’s large language model to automatically update profiles from CVs and cover letters. It expressly states that personal data processed for this purpose is not used by OpenAI to train or improve its models. This does not necessarily mean the data is never processed by OpenAI or other suppliers; it means it is not used for model training under the stated arrangement.

5. Key User Obligations and Risks

Users should:

  • Keep their personal data accurate and current.
  • Understand that providing a CV may result in automated profile updates.
  • Consider carefully whether to provide sensitive information, salary details, or other optional profile data.
  • Manage cookies through browser settings; disabling them may impair functionality.
  • Use marketing opt-out links to stop marketing or job notifications.
  • Avoid using the service for children; it is not intended for children and the company says it does not knowingly collect children’s data.

A significant practical risk is that employers may receive profile, application, communications, and potentially sensitive data for recruitment purposes.

6. Liability & Disputes

This document is a privacy policy, not a complete contract. It does not state:

  • Liability caps or exclusions.
  • Governing law or jurisdiction.
  • Arbitration or court procedures.
  • Specific compensation or remedies for data breaches.
  • Detailed security guarantees.

The company promises “appropriate” security measures and breach notification where legally required, but no system is guaranteed to be completely secure.

7. Changes to the Policy

The company may update the policy from time to time without notice. If it materially changes how previously collected data is used or shared, it says it will notify users through the website, app, email, or another communication method. Users should periodically review the policy, particularly because ordinary changes may not trigger individual notice.

Change history

2026-09-06 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary

The provided diff states only: “Added approximately 47 words to the document.” It does not include the actual added, deleted, or replaced contractual language.

Key Legal Changes
  • No substantive changes can be identified from the information provided.
  • The nature, scope, and legal effect of the additional 47 words are unknown.
  • No changes can be assessed regarding:
  • Customer data ownership or licensing
  • Data retention or deletion
  • Confidentiality
  • Security obligations
  • Disclosure to third parties
  • Liability or indemnification
  • Audit rights
  • Use of data for artificial intelligence or machine-learning purposes
AI Training and Model Use
  • No AI-related language is visible in the supplied diff.
  • It is therefore not possible to determine whether the new language:
  • Permits the provider to use customer data to train, fine-tune, or improve AI models;
  • Allows use of customer data to train models shared with other customers or the public;
  • Includes customer prompts, inputs, outputs, metadata, or usage analytics within “customer data”;
  • Requires de-identification, aggregation, or anonymization;
  • Gives the customer an opt-out or consent right; or
  • Limits retention or human review of data used for AI development.
Risk Assessment

The principal risk is incomplete information. A reliable legal review requires the actual text of the 47 added words and, preferably, the surrounding provision and prior version. The added language should be specifically reviewed for broad rights to “use,” “process,” “analyze,” “improve,” or “develop” services, as these terms may indirectly authorize AI model training.

2026-09-04 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary of Important Changes

1. New privacy contact and DPO process
  • The policy now states that the organisation has appointed a data privacy manager responsible for privacy-policy questions.
  • It directs users to contact the Data Protection Officer (DPO) at privacy@wttj.co for privacy questions and legal-rights requests.
  • The previous general contact details included notifications@welcometothejungle.com; the revised text appears to replace or reorganise these details. The final policy should be checked to ensure both addresses are presented accurately and consistently.
  • Risk: An incorrect, incomplete, or unclear privacy contact route could hinder data-subject rights requests and create compliance issues.
2. Complaints to the ICO
  • The policy now more clearly states that individuals have the right to complain at any time to the UK Information Commissioner’s Office (ICO).
  • The previous wording said the organisation would “appreciate” being contacted first and referred to dealing with concerns before approaching the ICO. The revised wording preserves an invitation to contact the organisation first but more explicitly recognises the individual’s right to complain directly.
  • This is generally a clarification favourable to individuals and reduces the risk that the policy could be read as requiring users to exhaust the organisation’s internal process before contacting the regulator.
3. EU data-protection representative
  • The revised policy adds that individuals and supervisory authorities in the EU may contact the organisation’s appointed EU data-protection representative under Article 27 GDPR.
  • The representative is identified as Maetzler Rechtsanwalts GmbH.
  • Risk/importance: This is a material compliance disclosure for EU users where Article 27 GDPR applies. The final published policy should include the representative’s complete and accurate contact details, not merely its name.
4. Entity and contact presentation
  • The legal entity remains identified as Otta Technology Ltd, trading as Welcome to the Jungle.
  • The postal address remains the London address, although the revised text reorganises where the address and email details appear.
  • The wording has been substantially reformatted, with some duplicated or awkward text in the diff. The final version should be checked for drafting errors and accidental omissions.
5. AI-model training and use of customer data
  • No changes relating to AI training, machine learning, model development, or use of customer data to train AI models are shown in this diff.
  • The diff does not add or remove any stated right to use personal data, user content, profiles, CVs, communications, or other customer data for AI training.
  • Any AI-training permissions would need to be assessed from other sections or documents not included here.
6. Version update
  • The policy remains version v.103 and adds a last-updated date of 25 September 2025.

2026-09-03 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. Privacy contact and data protection manager

  • The policy now states that Welcome to the Jungle has appointed a data privacy manager responsible for privacy-policy questions.
  • It directs individuals to contact the Data Protection Officer (DPO) at privacy@wttj.co for questions or requests to exercise legal rights.
  • The previous wording listed notifications@welcometothejungle.com as the general contact email. That address appears to have been removed from the contact section.
  • The company’s legal entity and postal address remain materially unchanged: Otta Technology Ltd, trading as Welcome to the Jungle, London address.

Risk/impact: Customers should use the newly stated privacy@wttj.co address for data-protection requests. The policy should clearly distinguish the DPO/privacy contact from any general customer-support address to avoid confusion or missed rights requests.

2. Complaints to the ICO

  • The policy now more directly states that individuals have the right to complain at any time to the UK Information Commissioner’s Office (ICO).
  • The previous wording said the company would “appreciate” the opportunity to address concerns before the individual contacted the ICO.
  • The revised wording retains a request that individuals contact the company first, but no longer frames this as a prerequisite or merely a “chance” to resolve the issue.

Risk/impact: This is clearer and more legally accurate. It reduces the risk that customers interpret contacting the company first as mandatory before approaching the ICO.

3. EU data protection representative

  • The policy now expressly states that individuals and supervisory authorities in the EU may contact the company’s appointed data protection representative under Article 27 GDPR.
  • The representative is identified as Maetzler Rechtsanwalts GmbH.
  • The prior version referred to an EU-appointed DPO at privacy@wttj.co; the revised wording distinguishes the EU representative from the company’s DPO.

Risk/impact: This is a significant compliance clarification for EU individuals. The company should ensure the representative’s contact details are complete and current, since Article 27 representatives generally need to be readily contactable.

4. AI-model training and use of customer data

  • No changes concerning AI, artificial intelligence, machine learning, model training, automated decision-making, or use of customer data to train models are shown in this diff.
  • The diff does not add or remove permission to use customer data, user-generated content, CVs, messages, or other personal information for AI training.
  • Any AI-training terms would need to be reviewed elsewhere in the privacy policy, terms of service, product terms, or a separate AI/data-use notice.

5. Policy version

  • The version reference changes from v.103 to v.103.Last.
  • The policy now records an update date of 25 September 2025.

Overall assessment: The changes primarily update privacy-contact details, clarify complaint rights, and add an Article 27 EU representative. They do not appear to expand or restrict customer-data use for AI training.

2026-09-02 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary

The provided diff does not contain the actual amended contract language. It only states:

> “Added approximately 47 words to the document”

Because the text of those 47 words is missing, the legal effect of the changes cannot be analyzed.

AI Training and Customer Data

No conclusion can be reached about whether the amendment:

  • Permits the provider to use customer data to train AI or machine-learning models;
  • Expands existing rights to use, analyze, or retain customer data;
  • Allows use of customer data to improve products or services;
  • Permits use of customer data for model training, fine-tuning, testing, or evaluation;
  • Allows disclosure of customer data to affiliates, vendors, or AI service providers;
  • Uses anonymized, aggregated, de-identified, or identifiable customer data;
  • Gives the customer an opt-out or objection right; or
  • Imposes deletion, confidentiality, security, or data-isolation obligations.

Key Risk

The principal risk is that the omitted language could materially change the provider’s rights over customer data, including potentially allowing customer data to be used for AI training or related purposes. Without the actual wording, it is not possible to determine whether such use is authorized, limited, optional, or prohibited.

Information Needed

Please provide the full text of the 47 added words and, if applicable, the surrounding provisions or the complete redline. The surrounding language is important because definitions, exceptions, consent requirements, and data-use limitations may affect the interpretation.

2026-09-02 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. New privacy contact and DPO language

  • The policy now states that Welcome to the Jungle has appointed a data privacy manager responsible for privacy-policy questions.
  • It directs users to contact the DPO at privacy@wttj.co for questions or requests to exercise legal rights.
  • The contact details have been reorganized. The legal entity remains Otta Technology Ltd, trading as Welcome to the Jungle, with the same London postal address.
  • The previous email address, notifications@welcometothejungle.com, appears to have been removed or replaced for privacy-related communications.

Risk/impact: Users may be unclear whether privacy requests should be sent to the DPO, data privacy manager, or another contact. The policy should clearly identify the official channel for access, deletion, objection, and other rights requests.

2. Changes to complaints wording

The policy now states that individuals have the right to complain at any time to the UK Information Commissioner’s Office (ICO), rather than merely having the “chance” to do so.

The wording also retains a request that users contact Welcome to the Jungle first, but makes clear that doing so is not a prerequisite to contacting the ICO.

Risk/impact: This is generally more accurate and user-protective. The revised wording reduces the risk that users might interpret the company’s preferred internal-contact process as restricting their statutory right to complain directly to a regulator.

3. EU GDPR representative

The revised text adds that individuals and supervisory authorities in the EU may contact Welcome to the Jungle’s data protection representative under Article 27 GDPR, identified as:

  • Maetzler Rechtsanwalts GmbH

Risk/impact: This expands and clarifies the contact route for EU data subjects and regulators. The policy should ensure the representative’s complete and current contact details are provided elsewhere or in the final version; the extracted diff does not show them.

4. Administrative update

  • The version changes from v.103 to v.103.Last.
  • An update date of 25 September 2025 has been added.

Risk/impact: The unusual “v.103.Last” label may be a drafting or formatting error and could create uncertainty about the policy’s version history.

5. AI-model training and data use

No change relating to AI, machine learning, model training, model fine-tuning, or use of customer/user data for training AI models is shown in this diff.

Accordingly, the diff does not appear to add, remove, or expand any permission to use customer data for AI training. However, this conclusion is limited to the text provided; repeated and malformed diff fragments make it advisable to compare the complete prior and revised policies.

2026-09-01 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary

The supplied diff does not include the actual added, deleted, or replaced contract language. It only states:

> “Added approximately 47 words to the document”

Accordingly, it is not possible to determine what legal rights, obligations, or risks changed.

AI Training and Customer Data

  • No operative language concerning customer data, artificial intelligence, machine learning, model training, or data usage is provided.
  • It cannot be determined whether the amendment:
  • Permits or restricts using customer data to train AI models;
  • Allows use of customer data for service improvement, analytics, or product development;
  • Authorizes retention, de-identification, aggregation, or sharing of customer data;
  • Grants the provider ownership or a license to customer data or model outputs;
  • Applies confidentiality, deletion, security, or opt-out protections to AI-related processing; or
  • Allows data to be transferred to third-party AI providers.

Risk Assessment

No specific new legal risks can be identified without the text of the 47 added words. The missing language could materially affect:

  • Data ownership and permitted uses;
  • Confidentiality and privacy obligations;
  • Compliance with data-protection laws;
  • Customer control over AI training;
  • Use of personal, confidential, or regulated information; and
  • The provider’s ability to retain or reuse derived data and model outputs.

Required Information

Please provide the actual redlined text, including the 47 added words and any surrounding sentence or section. The changes can then be assessed for their effect on customer data and AI-model training.

2026-08-31 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. New privacy contact and DPO wording

The policy now states that Welcome to the Jungle has appointed a data privacy manager/DPO responsible for privacy questions and legal-rights requests.

New contact details include:

  • DPO/privacy email: privacy@wttj.co
  • General email: notifications@welcometothejungle.com
  • Existing legal entity and postal address remain identified as Otta Technology Ltd, trading as Welcome to the Jungle, at the London address.

Risk/impact: This makes the organization’s privacy-contact structure clearer, but the policy should ensure that the listed email addresses are accurate, monitored, and consistent across all privacy notices.

2. Changes to complaints wording

The wording has been changed from saying individuals have the “chance” to address concerns with the company before contacting the ICO to stating that individuals have the “right” to make a complaint at any time to the ICO.

The policy still says the company would appreciate the opportunity to deal with concerns first.

Risk/impact: This is generally more accurate and user-friendly because it avoids suggesting that contacting the company first is a prerequisite to complaining to the regulator. It reduces the risk of the policy being read as restricting statutory complaint rights.

3. EU representative added or clarified

The updated text states that individuals and supervisory authorities in the EU may contact the company’s data protection representative under Article 27 GDPR, identified as:

> Maetzler Rechtsanwalts GmbH

The previous wording referred primarily to an appointed data protection officer and did not clearly identify an EU representative.

Risk/impact: This is a significant compliance clarification for GDPR-covered individuals in the EU. The company should verify that the representative’s full contact details and appointment remain current and that the representative’s role is accurately described.

4. Policy version and date updated

The policy version changes from v.103 to v.103.Last, with a new update date of 25 September 2025.

Risk/impact: The unusual version label may create recordkeeping or version-control ambiguity. The company should ensure that the effective date, publication history, and archived prior version are clear.

5. AI-model training and use of customer data

No express changes concerning AI training, machine learning, model development, automated decision-making, or use of customer data to train AI models are visible in this diff.

The supplied changes focus on privacy contacts, complaints, and EU representation. This diff therefore does not appear to introduce or remove permission to use customer data for AI training. Any AI-related terms would need to be reviewed elsewhere in the policy or in a separate data-use section.

2026-08-30 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary

The supplied diff states only: “Added approximately 47 words to the document.” It does not include the actual added wording or identify where the change appears.

Key Legal Changes
  • Cannot be determined: The substance, scope, and legal effect of the 47-word addition cannot be analyzed without the text itself.
  • No specific rights or obligations are identifiable: The diff does not show whether the addition changes liability, confidentiality, data processing, intellectual property, termination, pricing, or other contractual terms.
AI Training and Customer Data
  • No determination possible: The provided diff does not reveal whether the customer’s data may be:
  • Used to train, fine-tune, or improve AI models;
  • Combined with other customers’ data;
  • Reviewed by humans or shared with service providers;
  • Retained after termination;
  • Used in anonymized, aggregated, or de-identified form; or
  • Excluded from model training or other secondary uses.
Risk Assessment

The main risk is that a potentially important change—particularly one concerning AI training or customer-data usage—cannot be assessed from a word-count description alone. The added language should be reviewed for:

1. Purpose limitations on using customer data;

2. Consent or opt-out requirements for AI training;

3. Ownership and license rights in customer data and outputs;

4. Confidentiality and security protections;

5. Data retention and deletion obligations;

6. Use of de-identified or aggregated data; and

7. Responsibility for personal data, regulatory compliance, and model-generated content.

Please provide the actual 47-word addition, together with the surrounding provision if possible, for a substantive legal analysis.

2026-08-29 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. New privacy contact and data privacy manager
  • The policy now states that Welcome to the Jungle has appointed a data privacy manager responsible for privacy-policy questions.
  • Users are instructed to contact the Data Protection Officer (DPO) at privacy@wttj.co for privacy questions or to exercise legal rights.
  • This replaces or supplements the previous presentation of general company contact details and the statement that users could contact the ICO.

Risk/impact:

The update provides a clearer privacy contact route. However, the policy should ensure that the named contact and role accurately reflect the organisation’s formal GDPR arrangements. It also appears to use both “data privacy manager” and “DPO”; these roles should not be confused unless the individual or entity is formally appointed as a GDPR DPO.

2. Complaint rights clarified

The wording now says that individuals have the right to complain at any time to the Information Commissioner’s Office (ICO), rather than merely having a “chance” to do so.

The policy still asks users to contact Welcome to the Jungle first, but the revised wording makes clear that this does not restrict the right to complain directly to the ICO.

Risk/impact:

This is generally more accurate and user-protective. The policy should avoid language suggesting that contacting the company first is a precondition to approaching a regulator.

3. EU representative added

The revised text states that individuals and data protection supervisory authorities in the EU may contact Welcome to the Jungle’s appointed EU data protection representative under Article 27 GDPR:

  • Maetzler Rechtsanwalts GmbH

Risk/impact:

This is a significant compliance disclosure for processing involving individuals in the EU where an Article 27 representative is required. The representative’s complete contact details should be included or readily accessible; the diff appears to provide only the company name.

4. Company contact information reorganised

The legal entity remains identified as:

  • Otta Technology Ltd, trading as Welcome to the Jungle
  • Postal address: Unit 1.3, 11–29 Fashion Street, London, E1 6PX, England

The email contact appears to change from notifications@welcometothejungle.com to the privacy-specific address privacy@wttj.co for privacy matters.

5. Version and update date
  • Version remains v.103
  • The policy now states: Last updated: 25 September 2025
6. AI training and customer data

No changes in the supplied diff address:

  • use of customer or user data to train AI models;
  • rights to use prompts, content, profiles, or uploaded materials for training;
  • model improvement, automated decision-making, or generative AI;
  • retention or sharing of data for AI purposes.

Accordingly, this diff does not identify any new or changed AI-training rights or risks.

2026-08-29 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary

The supplied diff states only: “Added approximately 47 words to the document.” It does not include the actual added language or identify where the words were inserted.

Key Changes

  • No substantive contractual changes can be analyzed from the information provided.
  • The nature, scope, and legal effect of the 47 added words are unknown.
  • It is not possible to determine whether the addition changes:
  • Customer rights or provider obligations;
  • Data ownership, licensing, confidentiality, or security;
  • Liability, indemnification, warranties, or termination rights;
  • Use of customer data for analytics, product improvement, or artificial intelligence; or
  • Any other contractual term.

AI Training and Customer Data

The diff does not provide enough information to determine whether customer data may be:

  • Used to train, fine-tune, validate, or improve AI or machine-learning models;
  • Combined with other customers’ data for model development;
  • Reviewed by humans or disclosed to AI service providers;
  • Retained after termination for training or related purposes;
  • Used only in de-identified or aggregated form; or
  • Excluded from model training unless the customer opts in or consents.

These issues should be reviewed in the actual added text, particularly for terms such as “train,” “improve,” “develop,” “machine learning,” “artificial intelligence,” “aggregated,” “de-identified,” “service data,” or “usage data.”

Risk Assessment

Because the actual language is missing, no specific new legal risk can be identified. The complete redline or the precise 47-word addition is needed for a meaningful analysis.

2026-08-28 · Privacy Policy

grew 1.9% · Observed by clause.watch

Diff Analysis

Information Provided

The diff states only:

> “Added approximately 47 words to the document”

The actual added language is not included. Because of that, it is not possible to determine what contractual terms changed or whether the changes create new legal risks.

AI Training and Customer Data

No conclusion can be drawn about AI-model training from the information provided. The 47 added words could potentially address:

  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether prompts, inputs, outputs, or usage data may be retained;
  • Whether data is anonymized, aggregated, or de-identified before use;
  • Whether customer consent is required or can be withdrawn;
  • Whether data may be shared with affiliates or third-party AI providers;
  • Whether the customer owns resulting models, improvements, or outputs; or
  • Whether confidential or personal information is excluded from training.

These issues cannot be assessed without the actual text.

Risk Assessment

The change is not assessable based on the supplied diff. In particular, it is unknown whether the added language:

  • Expands the provider’s rights to use customer data;
  • Creates a broad or perpetual license;
  • Permits use for commercial AI training or product development;
  • Overrides confidentiality, data-protection, or security obligations;
  • Applies automatically without customer opt-in; or
  • Limits the provider’s liability for unauthorized data use.

Information Needed

Please provide the actual 47-word addition, preferably with the surrounding deleted and replacement language. The analysis should also identify whether the language applies to:

1. Customer content and confidential information;

2. Personal data;

3. Prompts, outputs, and metadata;

4. Human review or third-party processing;

5. Model training, testing, or improvement; and

6. Retention, deletion, and opt-out rights.

Without the underlying wording, no reliable legal comparison can be made.

2026-08-25 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary of Important Changes

1. Updated privacy-contact structure

The policy now states that a data privacy manager/DPO is responsible for privacy questions and legal-rights requests. It adds:

  • DPO contact: privacy@wttj.co
  • Existing company identity and postal address are retained, although the text is reorganised.
  • The policy now expressly directs individuals to contact the DPO regarding questions and requests to exercise legal rights.

Risk/impact:

This is generally clarifying, but the document should ensure that the named contact is accurate and that the DPO or privacy manager has the authority and resources required under applicable UK/EU data-protection law. The repeated and merged wording in the diff could create formatting or interpretation problems in the published policy.

2. Changes to complaints wording

The previous wording said users had the “chance” to resolve concerns with the company before contacting a regulator. The revised wording says individuals have the “right” to complain at any time to the ICO.

The revised text also:

  • Refers to the ICO as the UK regulator for data-protection issues.
  • Retains the request that users contact the company first, but makes clear this is not a condition of complaining to the regulator.
  • Refers to EU individuals and supervisory authorities.

Risk/impact:

This is more legally accurate and reduces the risk that the policy appears to restrict statutory rights. The company should avoid wording elsewhere that could imply users must exhaust its internal complaints process before contacting a regulator.

3. EU representative wording

The revised policy adds that EU individuals and supervisory authorities may contact the company’s data-protection representative under Article 27 GDPR, identified as:

> Maetzler Rechtsanwalts GmbH

Risk/impact:

This is a significant compliance disclosure for EU-facing processing. The representative’s full contact details, scope of appointment, and continuing availability should be verified. If the company is required to appoint an EU representative, an incomplete or inaccurate designation could expose it to regulatory criticism.

4. Policy version and update date

The policy version changes from v.103 to v.103.Last, and the policy now states:

> Updated: 25 September 2025

Risk/impact:

The unusual version label may be an accidental drafting or system artifact. Versioning should be made clear so users can identify the applicable policy and the effective date.

5. AI-model training

No express changes concerning the use of customer data to train AI models are shown in this diff. The amendments do not add or remove language about:

  • Training, fine-tuning, or improving AI models;
  • Using customer content, profiles, applications, or communications for AI;
  • Sharing data with AI providers;
  • Opt-out rights, retention, anonymisation, or human review.

Accordingly, this diff does not appear to expand or restrict AI-training rights. However, the full policy should be reviewed separately for any existing AI-related provisions, because none are visible in the supplied changes.

2026-08-25 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. New privacy contact and DPO process

  • The policy now states that Welcome to the Jungle has appointed a data privacy manager responsible for privacy-related questions.
  • Users are directed to contact the DPO at privacy@wttj.co for questions and legal-rights requests.
  • The prior presentation of contact details was reorganized. The legal entity remains Otta Technology Ltd, trading as Welcome to the Jungle, with the same London postal address.
  • A general company email address, notifications@welcometothejungle.com, is now listed.

Risk/impact: The change may create ambiguity about whether the “data privacy manager,” DPO, and EU representative are the same or different roles. The policy should clearly identify the relevant contact for each jurisdiction and function.

2. Complaints wording revised

  • The policy now expressly says individuals have the right to make a complaint at any time to the UK Information Commissioner’s Office (ICO).
  • The previous wording said the company would appreciate an opportunity to address concerns first and referred to contacting the company “in the first instance.”
  • The revised language retains a request that users contact the company first, but makes clear that this is not a precondition to complaining to the ICO.

Risk/impact: This is generally more legally accurate and reduces the risk that the policy appears to restrict the user’s statutory right to complain directly to a supervisory authority.

3. EU representative added or clarified

  • The policy now states that individuals and supervisory authorities in the EU may contact an EU data protection representative under Article 27 GDPR.
  • The representative is identified as Maetzler Rechtsanwalts GmbH.
  • The prior text referred only to an appointed data protection officer at privacy@wttj.co.

Risk/impact: This expands and clarifies GDPR compliance arrangements for EU users. The final policy should provide complete and accurate contact details for the representative, not merely its name, to ensure effective service of GDPR-related communications.

4. Version and update date

  • The version reference changes from v.103 to v.103.Last.
  • The policy now states it was last updated 25 September 2025.

Risk/impact: The unusual “v.103.Last” label may be an editorial or document-control error and should be checked.

5. AI-model training and data use

  • No changes concerning the use of customer data to train AI models are visible in this diff.
  • The supplied changes address privacy contacts, complaints, and EU representation only. They do not add or remove permission to use personal data, prompts, uploaded content, or other customer data for AI training, model improvement, or similar purposes.

2026-08-22 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary

Information Provided

The supplied diff states only:

> “Added approximately 47 words to the document”

It does not include the actual added language, deleted language, or replacement text.

Legal and Commercial Impact

The changes cannot be reliably analyzed without the underlying wording. In particular, it is not possible to determine whether the new language:

  • Expands the provider’s rights to access, use, copy, retain, or disclose customer data;
  • Permits customer data to be used to train, fine-tune, validate, or improve AI or machine-learning models;
  • Allows use of customer data for model training on an opt-out or opt-in basis;
  • Applies data-use rights to identifiable data, de-identified data, aggregated data, prompts, outputs, metadata, or usage analytics;
  • Grants the provider ownership or broad license rights over customer data or model outputs;
  • Creates exceptions for safety monitoring, abuse prevention, product improvement, or service analytics;
  • Changes confidentiality, security, deletion, retention, or subprocessors obligations;
  • Expands indemnity, liability exclusions, or customer responsibility for AI-generated content; or
  • Applies retroactively to previously submitted customer data.

AI Training Risk Assessment

No conclusion can be reached regarding AI-model training because the relevant contractual language is missing. The added text should be reviewed specifically for terms such as:

  • “train,” “fine-tune,” “improve,” “develop,” or “enhance” models;
  • “inputs,” “outputs,” “content,” “customer data,” “usage data,” or “de-identified data”;
  • “perpetual,” “irrevocable,” “worldwide,” or “royalty-free” licenses;
  • “aggregated” or “anonymized” information; and
  • opt-out, deletion, retention, or data-isolation mechanisms.

Recommended Next Step

Provide the full redline or the exact 47-word addition, including any deleted or replacement text. Without that language, any assessment of legal effect or AI-training exposure would be speculative.

2026-08-22 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. New privacy manager/DPO contact process

The policy now states that a data privacy manager oversees privacy questions and directs individuals to contact the DPO at privacy@wttj.co for:

  • Questions about the privacy policy; and
  • Requests to exercise legal rights.

This replaces or reorganizes the previous general contact and complaint wording. The company’s legal entity and postal address remain identified as Otta Technology Ltd, trading as Welcome to the Jungle.

2. Complaint wording strengthened

The policy now says individuals have the right to complain to the UK Information Commissioner’s Office (ICO) at any time, rather than merely having a “chance” to do so.

It also retains wording asking individuals to contact the company first before approaching the ICO. This appears to be framed as a request rather than a legal precondition, so it should not restrict the individual’s statutory right to complain directly to a regulator.

3. EU representative added

The policy now refers to a data protection representative for individuals and supervisory authorities in the EU, appointed under Article 27 GDPR, and identifies:

> Maetzler Rechtsanwalts GmbH

This is a significant compliance-related addition for EU data subjects. The extract does not provide the representative’s full contact details, so the final policy should be checked to ensure they are complete and usable.

4. Contact details and formatting changes

The policy reorganizes the contact-details section, including the email address, postal address, DPO/privacy contact, and regulator information. The diff contains repeated and apparently concatenated text, such as duplicated headings and contact information. This creates a risk that the published policy could be unclear, inaccurate, or difficult to use unless the final version is carefully proofread.

5. Updated version date

The policy is now marked:

> Version v.103 — Last updated: 25 September 2025

AI Training and Use of Customer Data

No changes concerning the use of customer data to train AI models are visible in this diff. There is no new or amended language addressing:

  • Training, fine-tuning, or improving AI or machine-learning models;
  • Use of customer content, profiles, applications, or communications for AI training;
  • Whether AI training is opt-in, opt-out, or automatic;
  • Human review or model-development purposes; or
  • Retention or deletion of data used for AI training.

Any AI-training provisions may therefore be unchanged elsewhere in the privacy policy, or may not be covered by the supplied extract.

2026-08-18 · Privacy Policy

shrank 1.9% · Observed by clause.watch

Summary

The supplied diff states only: “Added approximately 47 words to the document.” It does not identify the actual added language, deleted language, or replacement text.

Key Legal Changes

  • No substantive changes can be determined from the information provided.
  • The nature and effect of the 47 added words cannot be assessed without seeing their exact wording and location in the agreement.
  • It is not possible to determine whether the additions modify:
  • Customer data ownership or licensing rights
  • Confidentiality obligations
  • Data retention or deletion
  • Service-provider access to customer content
  • Use of data for analytics, product improvement, or advertising
  • Liability, indemnity, or compliance obligations
  • Restrictions on subcontractors or third-party AI providers

AI Training and Customer Data

  • No change regarding AI-model training can be identified.
  • The provided diff does not indicate whether customer data may be:
  • Used to train, fine-tune, or improve artificial-intelligence or machine-learning models
  • Combined with other customers’ data for model development
  • Reviewed by human trainers or shared with AI vendors
  • Retained after termination for training or model evaluation
  • Excluded from training by default or only upon customer opt-out

Risk Assessment

The available information is insufficient to identify new legal risks. The exact 47-word addition is necessary to determine whether the change creates potentially significant risks, particularly any expanded license or authorization to use customer content for AI training.

Additional text is required for a reliable comparison.

2026-08-18 · Privacy Policy

grew 1.9% · Observed by clause.watch

Summary of Important Changes

1. Privacy contact and governance
  • The policy now states that Welcome to the Jungle has appointed a data privacy manager/DPO responsible for privacy-related questions.
  • The primary privacy contact appears to change from notifications@welcometothejungle.com to privacy@wttj.co.
  • The legal entity and postal address remain identified as Otta Technology Ltd, trading as Welcome to the Jungle, at the London address.
  • Risk/impact: Customers should verify that privacy@wttj.co is an active and monitored address. The revised wording may also create ambiguity because it refers to both a “data privacy manager” and a DPO without clearly distinguishing their roles.
2. Complaints to regulators
  • The previous wording said customers had the opportunity to address concerns with the company before contacting the ICO.
  • The revised wording expressly states that individuals have the right to complain at any time to the Information Commissioner’s Office (ICO).
  • The revised policy still says the company would appreciate being contacted first, but this is no longer framed as a prerequisite or limitation on the customer’s right to complain.
  • The policy continues to identify the ICO and its website as the UK supervisory authority.
3. EU representative
  • The policy adds that individuals and supervisory authorities in the EU may contact the company’s data protection representative under Article 27 GDPR.
  • The representative is identified as Maetzler Rechtsanwalts GmbH.
  • Risk/impact: The excerpt does not provide a clear postal address, email address, or other direct contact details for the representative. This may make the Article 27 contact route difficult to use and could raise transparency or compliance concerns.
4. AI model training and use of customer data
  • No changes relating to AI, machine learning, model training, automated training, or use of customer data to develop AI models are shown in this diff.
  • The diff does not add or remove permission to use customer data, content, profiles, applications, or communications for AI training.
  • Any AI-training terms would need to be reviewed elsewhere in the privacy policy or in a separate product, terms-of-service, or data-processing notice.
5. Versioning
  • The policy remains identified as version 103, with a new update date of 25 September 2025.

Between 2021-07-27 and 2022-01-27 · Privacy Policy

shrank 3.2% · Reconstructed from Internet Archive captures

Summary

The provided diff states only:

> “Added approximately 47 words to the document”

It does not include the actual added language, nor any deletions or replacements. As a result, the legal effect of the amendment cannot be determined.

AI Training and Customer Data

  • The diff does not reveal whether customer data may be:
  • Used to train, fine-tune, or improve artificial intelligence or machine-learning models;
  • Used to develop products, services, or algorithms;
  • Combined with other customers’ data;
  • Reviewed by personnel or shared with service providers for model development;
  • Retained after termination for training or other purposes; or
  • Excluded from training through an opt-out right.
  • No conclusion can be drawn about whether the amendment expands or restricts the provider’s rights to use customer data.

Potential Legal Risks

The missing 47 words could materially affect:

  • Data ownership and licensing: Whether the customer grants the provider a broad license to use, copy, modify, or create derivative works from customer data.
  • Confidentiality: Whether customer data can be used in ways that may expose confidential or personal information.
  • Privacy and regulatory compliance: Whether use for AI training is consistent with applicable data-protection laws and the parties’ stated purposes.
  • Security and disclosure: Whether data may be transferred to affiliates, contractors, or third-party AI providers.
  • Control and remedies: Whether the customer has consent, notice, audit, deletion, or opt-out rights.
  • Post-termination use: Whether the provider may continue using retained data after the agreement ends.

Required Information

To perform a meaningful legal analysis, provide the actual 47-word addition and any surrounding text showing where it was inserted.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free