clause.watch Contracts Recent changes Start monitoring

Monitored company

Personio

clause.watch tracks 3 legal documents published by Personio (personio.com), re-reading each one every six hours. Below is what each document covers, in plain English.

General Terms and Conditions

101,572 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Legal Notice

3,112 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Privacy Policy

18,858 characters · Read the original

We monitor this document. A plain-English summary has not been published for it yet.

Change history

2026-09-06 · General Terms and Conditions

shrank 9.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Legal Notice

grew 119.3% · Observed by clause.watch

Executive Summary

The diff appears to replace a marketing/navigation-heavy webpage header and footer with a formal legal notice (Imprint) for Personio SE & Co. KG. It also adds detailed disclaimers concerning website content, third-party links, copyright, and the Personio Blog.

No provision in the diff addresses customer data, data processing, AI training, model development, or use of customer content to train AI systems. Accordingly, the diff does not appear to create, expand, or restrict any contractual right to use customer data for AI training. Those issues would need to be reviewed in the privacy policy, data-processing agreement, product terms, AI terms, or other customer contract documents.

Important Changes

1. Replacement of commercial website content with legal notice

The previous content included extensive product and marketing navigation, including:

  • HR products and services;
  • AI Assistant;
  • People Analytics;
  • Payroll, recruiting, performance, and workflow tools;
  • Customer resources, events, reports, and webinars.

This is replaced by an “Imprint / Opt-out / Information according to § 5 Digital Services Act (DDG)” page.

Risk/impact: This appears primarily editorial and structural rather than a change to customer contractual rights. However, users may now be directed to a legal-notice page rather than product or service information.

2. Updated corporate and contact information

The revised text identifies:

  • Personio SE & Co. KG;
  • Seidlstraße 3, 80335 Munich, Germany;
  • Local court: Munich;
  • Commercial-register information;
  • VAT ID;
  • Managing Board Member: Hanno Renner;
  • Chair of the Supervisory Board: Roman Schumacher;
  • Email and website details.

The notice states that it applies to all Personio-operated websites, particularly the referenced website, blog, and help center.

Risk/impact: The broad reference to “all” Personio websites may make the notice applicable across multiple web properties. Confirm that the listed corporate details, registration numbers, responsible persons, and scope are accurate and current.

3. New disclaimer regarding website content

The revised disclaimer states that content was prepared carefully but that Personio does not guarantee its:

  • Correctness;
  • Completeness; or
  • Timeliness.

Risk/impact: This may limit reliance on website content, including product descriptions, guidance, reports, and other informational materials. It should not necessarily override express contractual commitments made in customer agreements.

4. New hosting-provider liability language under the DDG

The added text states that Personio is responsible for its own content under general law but generally has no obligation to monitor stored or transmitted third-party information or investigate suspected illegality. It also states that Personio may become liable after receiving concrete knowledge of a legal violation and will remove unlawful content upon notice.

Risk/impact: This is a statutory safe-harbor disclaimer and may limit expectations regarding proactive monitoring of third-party content. It does not appear to alter data-security, confidentiality, or customer-data obligations under separate agreements.

5. Links, copyright, and blog responsibility

The revised text adds:

  • A disclaimer for external websites linked from Personio’s pages;
  • Copyright restrictions on copying, modifying, or distributing website content;
  • Notice that third-party image and content rights may apply;
  • Identification of Hanno Renner as responsible for the Personio Blog under § 18(2) Medienstaatsvertrag.

Risk/impact: Website users receive stronger restrictions on reuse of materials and reduced reliance on linked third-party content.

AI and Customer-Data Training

No change related to:

  • Training or fine-tuning AI models;
  • Use of customer or employee data for AI development;
  • Anonymization or aggregation for model training;
  • Opt-out rights;
  • Retention of data used for AI;
  • Human review or disclosure of AI-training activities.

No AI-training permission should be inferred from this diff.

2026-08-29 · Legal Notice

shrank 54.4% · Observed by clause.watch

Summary of Important Changes

1. Imprint and corporate-information content appears displaced or removed

The prior text contained Personio’s legal imprint information, including:

  • Full legal name: Personio SE & Co. KG
  • Registered address in Munich
  • Email and website
  • Commercial-register and VAT details
  • Managing board and supervisory board information
  • Notice that the imprint applied to Personio’s websites and web-based software

The replacement text primarily consists of marketing and website-navigation content, including references to:

  • “Platform”
  • “AI Assistant”
  • “People Analytics”
  • “AI at Personio”
  • Payroll, recruiting, performance, compensation, and other products
  • Customer stories, pricing, resources, and events

Although some corporate information appears later in the diff, the document as shown may no longer present the legally required imprint information clearly or consistently. This creates a potential transparency and regulatory-compliance risk under German digital-services and media laws, particularly if the final rendered page omits or obscures mandatory provider details.

2. Scope of websites covered may have changed

The text continues to refer to “all your websites operated by Personio,” including the website, blog, and help center. However, the wording is interspersed with extensive new product and marketing navigation.

Risk: The scope of the notice may be unclear. It may be uncertain whether the legal disclaimer applies only to informational websites, or also to the HR software platform, product interfaces, AI features, customer portals, and linked services.

3. Liability and disclaimer language remains substantially present

The existing disclaimer provisions concerning:

  • Accuracy, completeness, and timeliness of content
  • Liability for third-party links
  • Copyright ownership and infringement notices
  • Responsibility under the German State Media Treaty

appear to remain in the later text. However, the diff makes their location and relationship to the rest of the document difficult to determine.

Risk: Poor structure or accidental omission in the final version could weaken notice effectiveness or create uncertainty about which content is covered.

4. AI-related changes

The additions introduce or prominently reference:

  • “AI Assistant” as a platform feature
  • “AI at Personio”
  • “AI Change Diary”
  • AI-related product and informational content

However, the diff contains no express provision stating that customer data, employee data, prompts, outputs, usage data, or other customer content may be used to train, fine-tune, evaluate, or improve AI models.

Accordingly:

  • There is no identifiable new authorization to use customer data for AI-model training.
  • There is no stated opt-out or opt-in mechanism.
  • There are no limits on retention, anonymization, aggregation, or sharing of AI-related data.
  • The additions may nevertheless create ambiguity because “AI Assistant” and related services suggest processing of HR and potentially sensitive personal data.

The AI references should be reviewed together with the applicable privacy notice, data-processing agreement, product terms, and AI-specific terms. These documents should clearly state whether customer data is excluded from model training by default and whether any exception requires express customer consent.

5. Overall assessment

The apparent primary change is a replacement of legal/imprint content with website-navigation and marketing content. The most significant risks are loss of legal clarity, incomplete imprint presentation, uncertain scope, and insufficient transparency around AI processing.

2026-08-28 · General Terms and Conditions

grew 51.0% · Observed by clause.watch

Summary of Important Changes

1. New Supplemental Terms for AI Features

The most significant change is the addition of Supplemental Terms for AI Features, Version 08-2026. These terms apply when the customer first uses an AI Feature and remain effective for the subscription term.

Customer data and AI model training
  • Personio expressly states that it will not use the customer’s Data, Input, or Output to train or improve AI models.
  • This restriction also applies to Third-Party AI Providers used by Personio.
  • Personio may process Input only to generate the corresponding Output.
  • The customer retains all rights in its Input. Output is treated as the customer’s Data, and Personio does not claim ownership of it.
  • However, Personio does not guarantee that Output is free from third-party intellectual-property rights, and similar or identical Output may be generated for other customers.
  • The wording contains a possible drafting error (“Third-Party AI Providers..”), which should be clarified but does not appear intended to weaken the no-training commitment.
New AI-related customer risks

The customer bears extensive responsibility for:

  • Reviewing Output for accuracy, suitability, and legality;
  • Maintaining human oversight, particularly for decisions affecting individuals;
  • Providing legally required transparency notices to employees, workers, candidates, or other data subjects;
  • Complying with data-protection and employment laws;
  • Maintaining required records and logs;
  • Configuring permissions and approval workflows for AI Actions; and
  • Complying with EU AI Act deployer obligations where an AI Feature is high-risk.

The customer may not use Output as the sole basis for decisions concerning recruitment, performance, compensation, termination, or other legally significant effects. AI Actions performed in the customer’s environment are deemed actions of the customer.

2. AI Credits and Additional Charges

  • AI Features are billed according to AI Credit consumption.
  • Bonus Credits may expire after 30 days; Prepaid Credits may expire after 12 months or at contract end.
  • Unused Credits are forfeited without compensation when they expire or the feature is deactivated.
  • After Credits are exhausted, AI Features continue operating and generate Extra Usage charges billed monthly in arrears.
  • An Admin’s in-product approval is required before Extra Usage begins, but the customer must ensure that the approving Admin is authorised.
  • Admins may set a Spend Limit; usage stops when that limit is reached unless it is increased.

3. New Professional Services Terms

A detailed Professional Services framework has been added. It:

  • Excludes services not expressly stated in an Order;
  • Makes schedules and cost estimates generally non-binding;
  • Disclaims legal, tax, employment, and data-protection advice;
  • Places extensive cooperation, data accuracy, defect-reporting, and backup obligations on the customer;
  • Generally charges by time unless a fixed price is agreed;
  • Requires payment within 14 days; and
  • Limits data-loss liability to the cost of restoration that would have been necessary if the customer had maintained proper backups.

4. Other Commercial and Operational Changes

  • Posting Bundles now include automatic renewals, credit expiry, forfeiture of unused advertisements, advance payment, and possible price changes with an objection mechanism.
  • Payroll terms impose minimum user commitments, overage fees, customer responsibility for data accuracy and payroll approval, and responsibility for extracting data before termination.
  • Several version references and linked document versions have been updated, including the GTC, DPA, and supporting-services terms. The customer should obtain and review the complete referenced documents, not just this diff.

2026-08-28 · General Terms and Conditions

shrank 33.8% · Observed by clause.watch

Structured Summary of Important Changes

1. New Professional Services Terms

The revised document adds comprehensive terms for Personio’s professional services, including implementation, migration, configuration, and related support.

Key changes and risks:

  • Customer must provide complete, accurate, and timely information and cooperate with Personio.
  • For data migration, the customer must create its own backup. Personio’s liability for data loss is limited to the cost of restoration that would have been necessary had the customer maintained proper backups.
  • Service dates and cost estimates are generally non-binding unless expressly agreed otherwise.
  • Personio disclaims responsibility for legal, tax, employment, and data-protection compliance advice, placing the verification burden on the customer.
  • Unless otherwise agreed, services are charged by time, with billing in 15-minute increments. Fixed prices are invoiced when the order is placed.
  • Professional services are generally contractual “services,” not guaranteed results. Where “work services” apply, the customer must inspect them within two weeks and promptly notify Personio of defects.
  • Personio grants only a limited, non-exclusive, non-transferable, and non-sublicensable right to use service deliverables for the agreed purpose.

2. New Posting Bundle Terms

The document adds terms for bundled job-board advertising.

Key changes and risks:

  • Contracts automatically renew for the selected billing period unless terminated with one month’s notice.
  • Unused advertising credits generally expire without refund, subject to limited exceptions.
  • Posting bundles are prepaid, and credits may also expire after carryover periods.
  • Personio may change the service or adjust prices following job-board price changes, with an objection mechanism. Failure to object constitutes acceptance.
  • The customer must comply with each job board’s terms and indemnify Personio for claims arising from unlawful or non-compliant job advertisements.
  • The German version is stated to be legally controlling; the English version is only a courtesy translation.

3. New Payroll Terms

The additions introduce detailed payroll implementation, payment, and customer-responsibility provisions.

Key changes and risks:

  • Payroll depends on an active Personio subscription and ends if that subscription ends.
  • The customer remains responsible for registrations, powers of attorney, data accuracy, payroll approval, and legal compliance.
  • Personio may charge additional fees to correct customer-caused errors or provide out-of-scope services.
  • A minimum user commitment applies throughout the subscription term; reductions generally take effect only on renewal and require 90 days’ notice.
  • Personio may terminate if regulatory or operational changes make the existing plan unsuitable.
  • After termination, the customer must extract its data; Personio has no general obligation to perform further payroll activities.

4. New AI Features Terms

The revised document adds specific terms for AI functionality.

Data Use and AI Model Training
  • Personio expressly states that it will not use the customer’s Data, AI Inputs, or AI Outputs to train or improve AI models.
  • This restriction expressly applies to Third-Party AI Providers as well.
  • Inputs are processed only to generate the corresponding output.
  • The customer retains rights in Inputs. Outputs are treated as customer Data, and Personio does not claim ownership.
  • However, Personio does not warrant that Outputs are free from third-party intellectual-property rights, and similar Outputs may be generated for other customers.
Customer Compliance Obligations and Risks
  • The customer must independently review AI outputs, maintain human oversight, provide legally required transparency notices, and comply with data-protection and employment laws.
  • Customers must not use AI output as the sole basis for significant decisions concerning recruitment, performance, compensation, or termination.
  • If an AI feature is high-risk under the EU AI Act, the customer becomes the “deployer” and assumes applicable compliance duties.
  • AI actions taken through the customer’s environment are deemed actions of the customer.
  • AI outputs may be inaccurate, incomplete, non-unique, or unsuitable for the customer’s purpose. Personio provides no professional, legal, financial, or employment advice.
  • Liability is limited to availability of the AI feature and compliant processing of Inputs.
AI Charges
  • AI use is measured through credits. Credits and bonus credits can expire without compensation.
  • After credits are exhausted, extra usage may continue and be billed monthly, subject to in-product approval by an authorised administrator.
  • Spend limits can be changed immediately by an administrator, creating potential unexpected charges.

2026-08-22 · General Terms and Conditions

grew 95.2% · Observed by clause.watch

Summary

The diff only states:

> “Added approximately 8566 words to the document”

It does not include the actual added, deleted, or replaced contractual language. Therefore, the substantive legal changes and associated risks cannot be analyzed.

AI-Training and Data-Use Changes

No text is provided showing whether the agreement changes:

  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether prompts, outputs, files, personal data, or usage metadata are retained;
  • Whether data is used for service improvement, benchmarking, or product development;
  • Whether customer data is shared with affiliates, vendors, or model providers;
  • Whether the customer can opt out of model training or request deletion;
  • Whether data is de-identified, aggregated, or otherwise anonymized before use;
  • Whether training rights continue after termination; or
  • Whether the provider gives confidentiality, security, ownership, or warranty protections for AI-related data use.

Risk Assessment

The statement that approximately 8,566 words were added is not itself a contractual term and does not identify the content or legal effect of the changes. No reliable conclusions can be drawn about:

  • New customer obligations;
  • Expanded provider rights;
  • Liability or indemnity exposure;
  • Privacy, confidentiality, or regulatory risks;
  • Changes to intellectual-property ownership; or
  • AI model-training permissions.

Please provide the full redlined text or the actual additions, deletions, and replacements to permit a meaningful clause-by-clause review.

2026-08-21 · Privacy Policy

grew 1254.7% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 2778 words to the document”

Accordingly, it is not possible to identify:

  • Which provisions were added, deleted, or replaced;
  • New legal obligations, rights, or liabilities;
  • Changes to fees, termination, warranties, indemnities, confidentiality, or governing law;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether the provider may share customer data with affiliates, subprocessors, or third parties;
  • Data-retention, deletion, security, or anonymization requirements; or
  • Whether the customer has an opt-out, consent, audit, or approval right regarding AI training.

AI-Training Risk Assessment

No conclusion can be drawn from the information supplied about whether the contract permits use of customer data for AI model training. The added language could potentially introduce such rights, but the text is necessary to determine:

1. Scope of data use — whether “customer data,” prompts, outputs, usage data, or personal information may be used.

2. Purpose — whether use is limited to providing the service or extends to model training, product improvement, research, or commercial development.

3. Identification and confidentiality — whether data must be aggregated, de-identified, or anonymized before use.

4. Consent and control — whether use is automatic, opt-in, opt-out, or subject to written customer approval.

5. Retention and deletion — how long training data and derived model artifacts may be retained.

6. Third-party access — whether data may be provided to model providers, subprocessors, or affiliates.

7. Regulatory and ownership implications — responsibility for privacy compliance and ownership of models or outputs trained using the data.

Information Needed

Please provide the full diff, including the text marked as additions, deletions, and replacements. Without the actual language, a substantive legal-risk analysis would be speculative.

2026-08-18 · General Terms and Conditions

shrank 48.8% · Observed by clause.watch

Structured Summary of Important Changes

1. Overall document structure

  • The diff removes the previously displayed full text of several documents, including:
  • Data Processing Addendum (DPA)
  • Professional Services Terms
  • Posting Bundle Terms
  • Payroll Terms
  • Supplemental Terms for AI Features
  • The revised text appears to replace the detailed inline terms with download links or references to updated versions. However, the actual replacement wording is not included in the diff.
  • Because the substantive replacement documents are not provided, it is not possible to determine whether legal protections, limitations, fees, or operational obligations have changed.

2. Data Processing Addendum

  • The DPA link is changed from a link labeled “(DPA)DownloadGeneral” to “(DPA)Download.”
  • The prior inline DPA provisions are deleted from the displayed terms. Those provisions included important protections and obligations concerning:
  • GDPR compliance and precedence over conflicting agreement terms
  • Processing scope and categories of data
  • EU/EEA processing and international transfers
  • Confidentiality
  • Controller instructions and responsibilities
  • Processor assistance, audits, security measures, and breach notifications
  • Sub-processor changes and objection rights
  • Data return/deletion and a 30-day post-termination retention period
  • GDPR liability and German governing law/Munich jurisdiction
  • Risk: If the new DPA is not incorporated clearly and made available to the customer, there may be uncertainty about which data-processing terms apply. The customer should obtain and review the linked DPA, including its version date and change mechanism.

3. AI model training and data use

  • The deleted AI Terms expressly stated that:
  • Personio does not use the customer’s Data, Input, or Output to train or improve AI models.
  • The same restriction applies to third-party AI providers.
  • Input is processed only to generate the corresponding Output.
  • Output is treated as the customer’s Data, although Personio disclaims ownership and does not guarantee freedom from third-party IP claims.
  • No replacement AI wording is shown in braces. Therefore, the diff does not demonstrate that Personio has changed its AI training or data-use policy.
  • Important risk: Because the prior AI terms are removed from the visible text and the replacement terms are not supplied, the continued effectiveness of the “no training/no improvement” commitment cannot be confirmed from this diff alone. The customer should verify that the updated AI Terms preserve this restriction, including for all third-party AI providers and any inputs, outputs, prompts, or derived data.

4. Recommended follow-up

  • Obtain the linked replacement DPA and AI Terms.
  • Confirm their effective dates, incorporation into the contract, precedence over other terms, and amendment procedures.
  • Specifically verify whether customer data may be used for model training, fine-tuning, evaluation, analytics, or product improvement.

2026-08-18 · Privacy Policy

shrank 92.6% · Observed by clause.watch

Summary

The diff only states that approximately 2,778 words were removed. It does not identify which clauses, definitions, rights, or obligations were deleted.

AI Training and Data Use
  • No specific conclusion is possible about changes to the customer’s data or whether it may be used to train AI models.
  • The deleted text could have contained provisions addressing:
  • Whether customer data, prompts, inputs, outputs, or usage data may be used to train or improve AI models;
  • Whether the provider must de-identify, aggregate, or anonymize customer data before using it;
  • Whether customer consent is required;
  • Opt-out or “no training” rights;
  • Restrictions on human review or model evaluation;
  • Ownership and licensing of customer data and AI-generated outputs;
  • Confidentiality, security, retention, or deletion obligations;
  • Use of data by affiliates, subcontractors, or third-party AI providers.
Potential Legal Risks

Because the deleted language is not provided, the principal risk is loss of protections or increased ambiguity. In particular:

  • A deleted prohibition on training could leave the provider free to use customer data to train or improve AI systems.
  • Removal of an opt-out mechanism could eliminate the customer’s ability to prevent such use.
  • Deletion of confidentiality, purpose-limitation, or data-deletion provisions could broaden the provider’s rights and increase privacy and confidentiality risks.
  • Removal of ownership or licensing language could create uncertainty over rights in customer inputs, outputs, or derived model improvements.
  • Deleted liability, indemnity, or security terms could reduce the customer’s remedies if data is misused or exposed.
  • If definitions were removed, terms such as “Customer Data,” “Usage Data,” “De-identified Data,” or “Service Improvement” may now have an uncertain scope.
Assessment Limitation

A reliable legal comparison cannot be performed from a word-count description alone. The full pre-change and post-change text—or at least the actual deleted passages and surrounding clauses—is needed to determine whether the amendment changes AI-training permissions, data ownership, confidentiality, privacy compliance, or customer remedies.

Between 2024-12-19 and 2025-03-28 · General Terms and Conditions

shrank 3.0% · Reconstructed from Internet Archive captures

Summary

The diff indicates that approximately 8,567 words were removed, but it does not identify which provisions were deleted or provide replacement language.

Key Legal Implications
  • A deletion of this size could materially alter important terms, including:
  • Customer and provider obligations
  • Payment, renewal, and termination rights
  • Warranties, disclaimers, and liability limitations
  • Confidentiality and data-protection requirements
  • Intellectual-property ownership and licensing
  • Security commitments and breach-notification duties
  • Governing law and dispute-resolution procedures
  • Audit, suspension, and indemnification rights
  • The diff does not show whether any provisions were added or substituted. Therefore, it is impossible to determine whether the deletions:
  • Remove customer protections;
  • Expand the provider’s rights;
  • Eliminate restrictions or remedies; or
  • Simply remove obsolete or duplicative language.
AI Training and Customer Data

The provided diff contains no text addressing AI, machine learning, model training, data usage, prompts, outputs, or service improvement. Accordingly, it is not possible to determine whether the contract now:

  • Permits or prohibits using customer data to train AI models;
  • Allows use of customer content, prompts, inputs, or outputs for model development;
  • Requires customer consent or provides an opt-out;
  • Limits training to de-identified or aggregated data;
  • Gives the provider ownership or licensing rights in customer data;
  • Requires deletion or segregation of customer data from training datasets; or
  • Applies different rules to human review, analytics, or third-party AI providers.
Conclusion

This diff is insufficient for substantive legal analysis. The full deleted text and any replacement language are required to identify the actual changes, risks, and AI-training provisions.

Between 2024-08-06 and 2025-03-15 · Legal Notice

shrank 1.5% · Reconstructed from Internet Archive captures

Summary

The diff only states that approximately 337 words were removed. It does not identify the deleted language or show any replacement text.

AI Training and Data Use
  • Cannot determine whether the agreement changed how customer data may be used to train AI models.
  • The deleted language could have:
  • Authorized or prohibited training, fine-tuning, or improving AI models using customer data;
  • Defined whether prompts, inputs, outputs, telemetry, or metadata constitute customer data;
  • Provided opt-in or opt-out rights;
  • Limited use to aggregated, de-identified, or anonymized data;
  • Addressed human review, model retention, or use of data to serve other customers;
  • Allocated ownership of models, training data, or generated outputs; or
  • Imposed deletion, confidentiality, security, or data-processing obligations.
Key Legal Risk

Because the deleted text is not provided, there is a significant review gap. Removing language can either reduce customer exposure—for example, by deleting a provider’s right to train models on customer data—or increase exposure—for example, by deleting restrictions, consent requirements, confidentiality protections, or opt-out rights.

The change may also affect:

  • Data privacy and regulatory compliance;
  • Confidentiality and trade-secret protection;
  • Data retention and deletion obligations;
  • Intellectual-property ownership and license scope;
  • Security and incident-response responsibilities; and
  • The provider’s ability to use customer data for product improvement or other customers.
Recommended Follow-Up

Obtain the actual redline or a copy of the 337 deleted words, together with any surrounding provisions. The AI-training provisions should be specifically checked for:

1. Whether customer data may be used to train or improve models;

2. Whether use is automatic or requires customer consent;

3. Whether data must be aggregated or de-identified;

4. Whether inputs and outputs are retained or reviewed by humans;

5. Whether the customer can opt out or require deletion; and

6. Whether the provider receives rights to use data beyond providing the contracted services.

No definitive conclusion about the legal effect of the change can be reached from the description alone.

Between 2024-07-15 and 2025-01-21 · Privacy Policy

grew 9.1% · Reconstructed from Internet Archive captures

Structured Summary of Important Changes

1. Major restructuring and apparent replacement

The diff appears to replace Personio’s previous privacy-notice presentation with a substantially expanded notice and a new “Platform/Core HR” website structure. The new material includes references to:

  • People Analytics
  • AI Assistant
  • Workflow Automation
  • Documents and e-signatures
  • Recruiting and talent-management tools
  • Payroll, integrations, and marketplace services
  • AI at Personio and related publications

Because the diff contains extensive website-navigation text, some provisions may be formatting or scraping artifacts rather than operative legal language. The final published document should be checked carefully.

2. Broader and more detailed processing disclosures

The revised text expressly describes processing of:

  • IP address, location/geolocation, browser and operating-system information
  • Clicking behavior, recurring visits, transaction data, and third-party-service use
  • Contact, company, telephone, email, calendar, and— for customers—bank-account information
  • Community posts, comments, likes, and data-subject-rights requests

Purposes now expressly include website operation, security, statistics, optimization, marketing, customer support, relationship management, lead enrichment, community networking, and provision of services.

Risk: The expanded categories and purposes may permit broader processing than the former high-level notice, particularly for marketing, analytics, and lead enrichment. The legal bases and retention periods should be checked against actual practices.

3. AI-model training and AI use

The diff adds prominent references to AI-related products and content, including “AI Assistant,” “People Analytics,” and “AI at Personio.” However, the substantive privacy text states:

> “We do not profile you or make decisions based on automated processes such as artificial intelligence.”

There is no express clause authorizing Personio to use customer data, employee data, prompts, outputs, or usage data to train, fine-tune, or improve general-purpose or Personio AI models.

Important risk/ambiguity: The notice does not explain:

  • Whether data submitted to AI features is retained or used for model training
  • Whether prompts, outputs, or telemetry are shared with AI providers
  • Whether customer data is segregated from training datasets
  • Whether customers can opt out of AI training or AI improvement
  • Whether AI features involve automated decision-making or profiling

The “no AI decision-making” statement may not address model-training or product-improvement uses. Contractual terms, the DPA, and AI-product documentation should be reviewed for those matters.

4. Third parties and international transfers

The revised text expressly permits disclosure to affiliates, service providers, lead-enrichment providers, and authorities. It adds detailed reliance on adequacy decisions, Standard Contractual Clauses, and the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks.

It also says customer data is “exclusively stored in the European Union,” while permitting transfers of other personal data outside the UK/EEA/Switzerland.

Risk: “Customer data” is not clearly defined. It should be confirmed whether AI-service providers or support vendors can access or process customer content outside the EU.

5. Rights, retention, and governance

The revised notice adds:

  • External DPO details
  • Data-subject-rights procedures and a web form
  • JAMS dispute resolution under the Data Privacy Framework
  • Retention periods ranging from sessions/30 days to two years or the customer relationship plus statutory periods

Risk: Some wording is duplicated or grammatically defective, which may reduce transparency and create uncertainty about scope, retention, and applicable rights.

Between 2024-01-05 and 2024-08-06 · Legal Notice

shrank 33.5% · Reconstructed from Internet Archive captures

Summary

The provided diff does not include the actual contract language. It only states:

> “Added approximately 337 words to the document”

Accordingly, it is not possible to determine:

  • What contractual provisions were added or changed;
  • Whether liability, confidentiality, privacy, security, intellectual-property, or termination rights changed;
  • Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether data may be shared with affiliates, subprocessors, or third-party AI providers;
  • Whether customer data is retained after termination or used in aggregated or de-identified form; or
  • Whether the customer has any opt-out, deletion, audit, or approval rights.

AI Training Review

No substantive AI-related language is visible in the supplied material. The phrase indicating that approximately 337 words were added is not enough to establish whether the contract now permits or restricts:

  • Training or fine-tuning models using customer data;
  • Use of prompts, inputs, outputs, or usage metadata for model improvement;
  • Human review or labeling of customer data;
  • Combining customer data with other customers’ data;
  • Use of de-identified or aggregated data;
  • Disclosure to AI vendors or subprocessors; or
  • Retention of data for future training.

Required Information

Please provide the actual redlined text, using the stated notation:

  • Additions: {added text}
  • Deletions: [deleted text]
  • Replacements: [old text]{new text}

Without the underlying wording, any assessment of legal risk would be speculative.

Between 2023-04-01 and 2024-02-01 · Privacy Policy

shrank 72.2% · Reconstructed from Internet Archive captures

Executive Summary

The diff replaces largely promotional website text with a detailed privacy notice for website visitors, prospects, community users, and individuals exercising privacy rights. It identifies Personio SE & Co. KG as controller and adds GDPR-focused processing disclosures, rights, transfers, cookies, vendors, and retention periods.

Important Changes and Risks

1. Scope and covered activities
  • The notice now covers personal data processed when individuals:
  • Visit Personio websites;
  • Contact Personio;
  • Receive marketing or educational content;
  • Express interest in Personio services;
  • Join the Personio Community; or
  • Exercise data-subject rights.
  • It expressly states that the policy does not apply to recruiting activities. This creates a potential scope gap: recruiting-related processing may be governed by a separate notice, which should be identified and made available.
2. New processing purposes and data categories

The notice describes collection of substantial information, including:

  • IP address, location, browser and device information, geolocation, clicking behavior, recurring visits, transaction data, and use of third-party services;
  • Contact details, company information, requests, calendar items, and— for customers—bank account details;
  • Community posts, comments, and likes;
  • Information supplied in rights requests.

Purposes include website operation, security, analytics, marketing, customer relationship management, lead generation, and enrichment of prospect information by third-party providers. Lead enrichment creates additional transparency, accuracy, profiling, and lawful-basis risks.

3. AI model training and automated decision-making
  • The new notice states: “We do not profile you or make decisions based on automated processes such as artificial intelligence.”
  • There is no express authorization or disclosure that customer data, personal data, user content, community content, or HR data may be used to train, fine-tune, evaluate, or improve AI models.
  • Accordingly, the diff does not appear to add a customer-data-to-AI-training right. However, the broad purposes—such as “optimization,” service improvement, analytics, and third-party processing—could create ambiguity if Personio later uses data for AI development.
  • The statement that Personio does not use AI for profiling or automated decisions may not address non-decision-making AI uses, including model training, product improvement, generative AI assistance, or human-reviewed outputs. A separate contractual or product-specific AI/data-use policy may therefore still be necessary.
4. Third-party disclosures and international transfers
  • Personio may share data with service providers, affiliates, and authorities, including providers for marketing, support, surveys, chat, maps, videos, cookies, community search, and lead enrichment.
  • The notice says customer data is exclusively stored in the EU, while also allowing personal-data disclosures and transfers outside the UK/EEA/Switzerland. The distinction between storage and access/processing should be clarified.
  • Transfers rely on adequacy decisions, Standard Contractual Clauses, consent, and the EU-U.S./UK/Swiss Data Privacy Frameworks. The DPF language creates additional compliance commitments, complaint procedures, and possible binding arbitration.
5. Retention and rights

Specific retention periods are added, including two years for prospects and marketing content, session/up to 30 days for certain website data, and customer data for the relationship plus statutory periods. Rights to access, correction, deletion, restriction, portability, objection, and consent withdrawal are expressly described.

Overall Risk Assessment

The notice materially improves transparency but is unusually broad and contains possible inconsistencies, particularly concerning EU-only customer-data storage, overseas processing, AI-related statements, and the boundary between website data and customer/HR data.

Between 2023-03-14 and 2024-01-05 · Legal Notice

shrank 3.3% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2022-03-19 and 2023-04-01 · Privacy Policy

grew 13.2% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2021-10-25 and 2023-03-14 · Legal Notice

grew 62.6% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2020-10-06 and 2022-03-19 · Privacy Policy

grew 61.2% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2019-05-18 and 2020-10-06 · Privacy Policy

grew 10.5% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2018-03-20 and 2020-10-04 · Legal Notice

grew 9.5% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free