clause.watch Contracts Recent changes Start monitoring

Monitored company

Proofpoint

clause.watch tracks 1 legal document published by Proofpoint, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

24,817 characters · Read the original

Proofpoint Privacy Policy: Key User Takeaways

*Effective October 10, 2025; last updated December 12, 2025. This is a practical summary, not legal advice.*

1. Data Collection and Use

Proofpoint collects information directly from users and automatically through its websites and cybersecurity services.

Information collected
  • Contact details: Name, job title, company, industry, address, phone, fax, email, company size, and potentially mailbox size.
  • Website and device data: IP address, browser, operating system, internet provider, referring and exit pages, timestamps, clickstream, pages viewed, and search terms.
  • Proofpoint Service data: Depending on the product, this may include usernames, email addresses, IP addresses, phone numbers, SMS/MMS/RCS message content reported as spam, social-media login credentials, department, position, and location.
  • Chatbot information: Conversations may be recorded and may include personal or sensitive information supplied by the user.
  • Cookies and tracking data: Used for preferences, sign-in, authentication, analytics, form pre-filling, site administration, and product improvement.
Purposes

Proofpoint uses data to:

  • Provide, maintain, and support its products;
  • Detect threats, prevent fraud, and develop threat intelligence;
  • Improve services and security capabilities;
  • Analyze website and product usage;
  • Market products and services;
  • Maintain security and comply with legal obligations.

A significant concern is that Log Data may be used “for any purpose,” which is broad and less restrictive than the other stated purposes.

For the Proofpoint Service, your employer, school, or other affiliated organization generally controls the use of the service and determines what data is sent to Proofpoint. Proofpoint may not have a direct relationship with individual users in that context.

2. User Rights and Controls

Subject to applicable law, contract, and the product involved, users may:

  • Request access to personal data;
  • Correct, amend, update, or delete information;
  • Ask Proofpoint to stop using or sharing certain information;
  • Unsubscribe from newsletters and marketing;
  • Control cookies through browser settings;
  • Request removal of personal information posted on the blog.

Requests may be sent to privacy@proofpoint.com. Proofpoint may retain information where necessary for legal compliance, dispute resolution, enforcement of agreements, backups, or ongoing service needs.

If data was provided by your employer or school, you may need to contact that organization, which may be the legal data controller. Proofpoint may refer your request to that organization.

3. Third-Party Sharing

Proofpoint may share information:

  • With your consent or at the direction of your organization;
  • With service providers handling hosting, maintenance, databases, analytics, or other operations;
  • With authorized channel partners for marketing, where consent exists;
  • In aggregated or de-identified form for analytics and industry analysis;
  • With law enforcement, government authorities, or private parties when legally required or needed to protect rights, safety, security, or prevent fraud;
  • In connection with a merger, acquisition, or asset sale.

Service providers are contractually limited to performing services for Proofpoint, but the policy allows broad categories of recipients. Marketing partners may contact you unless you opt out.

Third-party websites, social-media widgets, and linked services have their own privacy policies. Proofpoint does not control their practices.

4. AI/ML Training

The policy does not expressly say that personal data is used to train generative AI models or other AI systems. It does state that Proofpoint may use collected data to improve products, threat detection, threat intelligence, analytics, research, and statistical purposes. Those provisions could potentially encompass machine-learning development, but the policy does not clearly define or limit such use.

Users seeking clarity should ask Proofpoint or their organization whether message content, security telemetry, or other data is used for model training and whether it is de-identified.

5. Key User Obligations and Risks

  • Using the Site or Service constitutes consent to processing under the policy, although this may not replace consent requirements under applicable privacy laws.
  • Do not post sensitive personal information on public blogs; other users may read or misuse it.
  • You are responsible for reviewing third-party site and widget policies.
  • Rejecting cookies may limit site functionality.
  • Interest-based advertising can be disabled through the listed opt-out services, but generic advertising will continue.
  • Users should understand that Proofpoint may process workplace or school communications as part of security filtering.

6. Liability and Disputes

Proofpoint states that it uses reasonable security measures but does not guarantee absolute security. The policy does not provide a comprehensive liability cap, warranty disclaimer, arbitration clause, governing-law clause, or general dispute procedure.

For EU/UK/Swiss data transferred under the Data Privacy Framework, unresolved complaints may be submitted to a free third-party process, and binding arbitration may be available after required steps. Legal disclosures and U.S. national-security requests remain possible.

7. Policy Changes

Changes will be posted on the same webpage. For material changes, Proofpoint says it will provide notice by email or a prominent homepage notice “where appropriate.” Users should check the policy periodically; continued use may expose them to updated practices.

Change history

2026-09-04 · Privacy Policy

shrank 4.2% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-03 · Privacy Policy

grew 4.4% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 129 words to the document”

Because the added text is not shown, it is not possible to determine:

  • What contractual rights or obligations changed;
  • Whether liability, confidentiality, privacy, security, or termination terms were amended;
  • Whether the customer’s data may be used to train, test, fine-tune, or improve AI models;
  • Whether such use is limited to de-identified, aggregated, or anonymized data;
  • Whether the provider may share customer data with affiliates, vendors, or AI subprocessors;
  • Whether the customer has an opt-out, deletion, audit, or approval right; or
  • Whether the new language creates additional legal or commercial risk.

AI-Training Risk Assessment

No specific AI-training provision is visible in the supplied diff. Accordingly, no conclusion can be reached about whether the contract now permits the provider to use customer data for:

  • Training or improving general-purpose AI models;
  • Fine-tuning models for the provider or other customers;
  • Human review or annotation;
  • Product development, analytics, or benchmarking; or
  • Sharing with third-party model providers.

Information Needed

Please provide the actual 129 added words, using the stated notation:

  • Additions: {text}
  • Deletions: [text]
  • Replacements: [old text]{new text}

Once provided, the changes can be reviewed for data-use permissions, confidentiality protections, ownership, model-training rights, opt-out mechanisms, retention and deletion obligations, and related liability risks.

2026-08-29 · Privacy Policy

shrank 4.2% · Observed by clause.watch

Summary of Important Changes

1. Expanded purposes for using information

The revised statement adds broader purposes for processing personal information, including:

  • Providing Proofpoint products, services, and customer support;
  • Improving and enhancing products and services, including threat-detection capabilities;
  • Continuing to develop threat intelligence to protect organizational information;
  • Advertising and marketing to customers and their representatives; and
  • Delivering the privacy and cybersecurity protection customers expect.

Risk: These purposes are broader and less specific than the prior wording. “Improving and enhancing” products and “developing threat intelligence” could permit secondary use of information beyond providing the contracted service, depending on what data Proofpoint considers “personal information.”

2. AI-model training and machine learning

The changes do not expressly state that customer data will be used to train artificial intelligence or machine-learning models. However, the new references to:

  • Improving products and threat-detection capabilities; and
  • Developing threat intelligence

could potentially include machine-learning development, model training, evaluation, or tuning.

The statement does not clearly specify:

  • Whether customer content, email messages, attachments, metadata, or threat-related data may be used;
  • Whether data will be de-identified or aggregated before such use;
  • Whether data may be used to train general-purpose models or only Proofpoint-specific security models;
  • Whether customer data will be shared with AI vendors or other third parties;
  • How long training data or model outputs will be retained; or
  • Whether customers can opt out or contractually prohibit such use.

Key risk: Customers should not assume that the policy prohibits AI training merely because it does not use those words. The revised language may create room for such use, particularly for threat-detection development. The applicable customer agreement, data-processing agreement, service-specific terms, and product documentation should be reviewed for more precise restrictions.

3. Customer control and deletion language revised

The revised text adds that customers can request Proofpoint to stop using or sharing data by contacting Customer Support at privacy@proofpoint.com. It also retains rights to access, correct, amend, or delete information under applicable law and certain conditions.

Risk: The right to stop use or sharing is not stated as absolute. It may be limited by legal requirements, service needs, legitimate interests, security purposes, or contractual obligations. The policy does not explain how such requests affect continued service or data used for threat intelligence or model development.

4. Administrative and contact changes

  • The statement is identified as effective October 10, 2025.
  • Multiple privacy-related contact points are consolidated or updated to privacy@proofpoint.com.
  • References to the EU, UK, Gibraltar, and Swiss privacy frameworks are updated for terminology and punctuation.
  • An EU controller, Proofpoint Limited, is identified, and the Trust site is referenced for GDPR data-processing agreements and Standard Contractual Clauses.
  • Social media widgets are expressly described as a feature of the website.

Overall assessment

The most significant substantive change is the expansion of permitted uses for product improvement and threat intelligence. Although AI training is not expressly authorized, the wording is broad enough that customers should seek written clarification or contractual limitations if they require customer data to be excluded from AI or machine-learning development.

2026-08-28 · Privacy Policy

grew 4.4% · Observed by clause.watch

Diff Analysis

Information Provided

The diff states only:

> “Added approximately 129 words to the document”

It does not include the actual added language, deleted language, or replacement text.

Key Legal Changes

Cannot be determined from the information provided. Without the wording of the amendment, it is not possible to assess changes involving:

  • Customer data ownership or usage rights
  • Data processing, retention, or disclosure
  • Confidentiality obligations
  • Intellectual-property rights
  • Liability, indemnification, or warranties
  • Suspension or termination rights
  • Compliance obligations
  • Changes to governing law or dispute resolution

AI Model Training

No conclusion can be reached about whether the new language permits or restricts using customer data to train AI models.

The added language should be reviewed specifically for terms such as:

  • “train,” “fine-tune,” “improve,” or “develop” models
  • “machine learning,” “artificial intelligence,” or “automated systems”
  • “service improvement” or “product development”
  • “de-identified,” “aggregated,” or “anonymized” data
  • Rights to use customer prompts, inputs, outputs, content, or usage data
  • Whether data may be shared with affiliates or third-party AI providers
  • Whether training is opt-in, opt-out, or automatic
  • Whether the permission survives termination
  • Security, deletion, and confidentiality protections for training data

Assessment

The actual 129 added words are required before any reliable legal analysis can be performed. The complete redline or the text of the added provision should be provided.

2026-08-26 · Privacy Policy

shrank 4.2% · Observed by clause.watch

Summary of Important Changes

1. Expanded purposes for using personal information

The revised statement substantially reframes Proofpoint’s purposes for processing data. It now expressly includes:

  • Providing Proofpoint products, services, and customer support;
  • Improving and enhancing products and services, including threat-detection capabilities;
  • Continuing to develop threat intelligence to safeguard an organization’s information;
  • Advertising and marketing to customers and their representatives; and
  • Delivering the expected privacy and cybersecurity protection.

Risk: These purposes are broader and more operationally focused than the prior wording. “Improving,” “enhancing,” and “developing threat intelligence” could permit additional analysis and reuse of customer-related information beyond merely delivering the service, depending on how the statement interacts with the customer agreement or data-processing agreement.

2. AI-model training and machine learning

The diff does not expressly state that customer data will be used to train artificial-intelligence or machine-learning models. It does, however, add language concerning improvement of threat-detection capabilities and development of threat intelligence.

Potential concern: Those terms could encompass machine-learning development, model evaluation, or training, particularly if customer email, telemetry, threat indicators, or other service data are used. The statement does not clarify:

  • Whether customer content or service data may be used for AI training;
  • Whether data will be aggregated, anonymized, or de-identified first;
  • Whether customer data will be used to train general-purpose models or only Proofpoint-specific security models;
  • Whether data will be shared with AI or cloud providers;
  • How long training data or model-derived information is retained; or
  • Whether customers can opt out.

Customers should seek clarification and confirm that the governing agreement restricts use of customer data to specified service and security purposes.

3. Customer control and data-rights language

The revised wording adds that customers can request Proofpoint to stop using or sharing data by contacting Customer Support at privacy@proofpoint.com. It also retains or clarifies rights to access, correct, amend, or delete personal data under applicable privacy laws.

Risk/limitation: These rights remain subject to “certain conditions,” and the policy does not specify when Proofpoint may deny or limit a request. The right to stop use or sharing may also be limited by contractual, legal, security, or service-retention requirements.

4. Marketing communications

The statement adds a specific process for withdrawing from newsletters and other communications: email privacy@proofpoint.com or use the unsubscribe instructions.

Effect: This provides a clearer opt-out mechanism, but it does not necessarily stop service-related or transactional communications.

5. Other updates

  • The effective date is stated as October 10, 2025.
  • Privacy-related contact details are consolidated at privacy@proofpoint.com.
  • Social-media widgets are expressly disclosed.
  • References to the GDPR data-processing agreement and Standard Contractual Clauses are retained.
  • The policy adds general website copyright/informational language, which has little substantive privacy effect.

2026-08-25 · Privacy Policy

grew 4.3% · Observed by clause.watch

Summary

The provided diff does not include the actual amended contract language. It only states:

> “Added approximately 127 words to the document”

Accordingly, it is not possible to determine:

  • What provisions were added, deleted, or replaced;
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
  • Whether the customer’s prompts, inputs, outputs, personal information, or confidential information may be retained or disclosed;
  • Whether data use is opt-in, opt-out, or automatic;
  • Whether the provider may use data for its own commercial purposes or share it with affiliates or third parties;
  • Any changes to confidentiality, security, intellectual property, ownership, indemnification, liability, deletion, or compliance obligations.

AI-Training Risk Assessment

No specific AI-training change can be identified from the material provided. The statement that approximately 127 words were added does not reveal whether those words:

  • Authorize model training using customer data;
  • Permit de-identification or aggregation followed by model training;
  • Allow human review or vendor access to customer content;
  • Expand use of data beyond providing the contracted services; or
  • Create an opt-out mechanism or impose retention limits.

Needed Information

Please provide the actual redlined text, including the additions, deletions, and replacements. The relevant provisions may be found under headings such as:

  • Data Use or Data Processing;
  • Confidentiality;
  • Artificial Intelligence or Machine Learning;
  • Service Improvement;
  • Content, Inputs, and Outputs;
  • Privacy;
  • Security; or
  • Intellectual Property.

Without the underlying text, no reliable legal-risk analysis can be performed.

2026-08-19 · Privacy Policy

shrank 4.2% · Observed by clause.watch

Summary of Important Changes

1. Expanded stated purposes for using personal information

The revised policy adds or emphasizes that Proofpoint may use information for:

  • Providing Proofpoint products, services, and customer support.
  • Improving and enhancing products and services, including threat-detection capabilities.
  • Continuing to develop threat intelligence to protect an organization’s information.
  • Advertising and marketing to customers and their representatives.
  • Delivering the privacy and cybersecurity protection customers expect.

Risk: These purposes are broader and more operationally focused than the prior language, particularly the references to product improvement and threat-intelligence development. Depending on the information involved, these provisions could support secondary uses beyond simply providing the contracted service.

2. AI-model training and machine learning

The diff does not expressly state that customer data, customer content, emails, or other personal information will be used to train artificial-intelligence or machine-learning models.

However, the new language permitting Proofpoint to use information for:

  • “Improving and enhancing” products;
  • Improving “threat-detection capabilities”; and
  • Developing threat intelligence,

could potentially encompass machine-learning development, testing, tuning, or evaluation unless another agreement limits those activities.

Key uncertainty/risk: The policy does not define whether “information” includes customer-submitted content or data processed through Proofpoint’s security services, nor does it distinguish between:

  • Using aggregated or de-identified data;
  • Using customer data to improve a service for that same customer; and
  • Using customer data to train generalized models benefiting Proofpoint or other customers.

Customers should check the applicable service agreement, data-processing agreement, product terms, and Trust documentation for express restrictions or permissions concerning AI training.

3. Changes to individual control rights

The revised wording states that individuals can:

  • Request that Proofpoint stop using or sharing their data;
  • Access personal data; and
  • Correct, amend, or delete information under applicable privacy laws and certain conditions.

Risk: The right to stop use or sharing appears more explicit, but it is still subject to applicable law and unspecified conditions. The policy does not promise that all requests will be honored or explain how these rights interact with security, legal-retention, or service-delivery requirements.

4. Contact and administrative updates

The policy:

  • Is identified as effective October 10, 2025.
  • Adds “Contact us” to the title/navigation.
  • Adds privacy@proofpoint.com as a contact for privacy requests, security concerns, marketing opt-outs, and other inquiries.
  • Clarifies that Proofpoint Limited is the EU data controller and updates references to the UK Information Commissioner’s Office.
  • Adds a general website disclaimer and social-media-widgets section.

5. Overall assessment

The most significant substantive change is the broader description of product improvement and threat-intelligence uses. No explicit AI-training authorization appears in the diff, but the wording is sufficiently broad that AI or machine-learning use may be possible unless limited elsewhere.

Between 2025-10-24 and 2026-03-01 · Privacy Policy

shrank 14.9% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2025-07-25 and 2025-10-24 · Privacy Policy

grew 3.9% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

2025-10-10 · Privacy Policy

Date stated by the publisher in the document

The publisher records this document as revised on this date (“effective as of October 10, 2025”).

Between 2025-01-14 and 2025-07-25 · Privacy Policy

grew 4.5% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2024-02-28 and 2025-01-14 · Privacy Policy

grew 33.2% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2021-10-20 and 2024-02-28 · Privacy Policy

shrank 4.5% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2019-12-25 and 2021-10-20 · Privacy Policy

grew 11.6% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free