Monitored company
SaleCycle
clause.watch tracks 2 legal documents published by SaleCycle, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
1. Data Collection and Use
SaleCycle acts primarily as a “Data Processor” for its business clients. The client whose website you visited is generally the “Data Controller” and decides why and how your data is processed.
Data potentially collected
Depending on the client’s setup, SaleCycle may collect:
- Name, salutation, email address, and phone number
- IP address and device information
- Cookie and local-storage data concerning website activity
- Shopping and browsing information, such as:
- Basket or order ID
- Products viewed or purchased
- Prices, discounts, tax, shipping, currency, categories, and product URLs
- Unsubscribe records received from clients
- Additional information requested by a client
The notice states that SaleCycle may, in rare cases, be able to identify special-category data—sensitive data such as health or religious information—but does not specify what safeguards apply in each situation.
Purposes
Data may be used to:
- Send marketing by email, SMS, or other messaging channels
- Personalize content shown on client websites
- Produce reports measuring SaleCycle’s services
- Combine website activity with partner data to deliver advertisements on third-party websites or emails
- Create customer profiles to tailor marketing
SaleCycle says it does not use the information for its own independent purposes, but only according to client instructions. The relevant client’s privacy notice is therefore important for understanding the full processing, legal basis, retention period, and marketing practices.
2. User Rights and Choices
Under GDPR, users may generally have rights to:
- Access their personal data
- Correct inaccurate data
- Delete data
- Restrict or object to processing
- Receive data in a portable format
- Withdraw consent where consent is the legal basis
- Complain to a data-protection regulator
Requests and complaints should normally be directed to the relevant client, as Data Controller. SaleCycle says it will assist the client.
You can:
- Block or restrict cookies and similar technologies through browser settings
- Use the client’s cookie-management tool
- Click “unsubscribe” in marketing communications
Blocking all cookies, including essential cookies, may prevent access to some website features. Opting out of communications may not necessarily stop all data collection or website personalization.
3. Third-Party Sharing and Transfers
SaleCycle says it does not sell personal data. It shares data with:
- Sub-processors supporting its services
- Advertising or other partners, where the client requests such services
- Cloud-storage and technology providers
A list of sub-processors is referenced but not included in the notice. Users should review that list to identify the companies involved and their roles.
Data is stored in the UK and EU, but may be transferred outside the European Union to sub-processors. SaleCycle states that GDPR-compliant safeguards and contractual protections will be used, but the notice does not identify the transfer mechanisms or destination countries.
4. AI/ML Training
The notice does not state that personal data is used to train artificial-intelligence or machine-learning models. It says aggregated, anonymous statistical information may be used for reporting, service effectiveness, and anomaly detection. This does not expressly authorize AI training, but the policy does not provide a specific, detailed prohibition either. Users seeking certainty should ask the relevant client or SaleCycle directly.
5. Important User-Related Terms
- Data collection may depend on accepting cookies or local storage.
- Marketing and advertising may be based on browsing, basket, and purchase activity.
- Partners or SaleCycle may create customer profiles.
- Retention is determined by contractual arrangements with the client; no specific deletion period is provided.
- The client is responsible for establishing the lawful basis for processing.
- Users should consult each client’s privacy and cookie notices for additional obligations and choices.
6. Liability and Disputes
The notice contains no detailed liability limitation, compensation terms, indemnities, or dispute-resolution procedure. It also does not promise that security will eliminate all risks.
SaleCycle describes security controls, including ISO/IEC 27001:2013-aligned measures, and says it will notify clients and regulators of breaches where legally required. The client—not necessarily SaleCycle—will generally notify affected users.
For privacy complaints, users should contact the client first. The relevant regulators identified are the UK Information Commissioner’s Office (ICO) and France’s CNIL, depending on circumstances.
7. Changes
The notice states it was last updated on 30 November 2023, but does not explain how users will be notified of future changes. Users may need to check the notice periodically. A significant concern is that the policy does not specify whether changes will be posted prominently, emailed, or treated as effective immediately.
Service Privacy Notice
Service Privacy Notice: Key Points for Users
1. Data Collection and Use
SaleCycle acts primarily as a “Data Processor”: it processes information on behalf of the companies whose websites you visit. Those companies are the Data Controllers and generally decide why and how your data is used.
Data that may be collected
Depending on the client’s setup, SaleCycle may collect:
- Name, salutation, email address, and phone number
- IP address and device information
- Website activity and cookie/local-storage data
- Shopping and product information, such as:
- Basket or order ID
- Products, product IDs, prices, categories, tax, discounts, shipping, and currency
- URLs and details of items viewed or purchased
- Unsubscribe records received from clients
- Potentially additional information requested by a client
- In rare cases, information that could qualify as special-category data (sensitive data)
Data is collected through client websites when you approve cookies or similar technologies, and may also be supplied directly by clients.
Purposes
SaleCycle may use the data to:
- Send marketing by email, SMS, or other messaging channels on behalf of clients
- Personalise content shown on client websites
- Produce performance and effectiveness reports for clients
- Support targeted advertising on third-party websites or in third-party emails
- Create or support customer profiles used to tailor marketing
- Produce aggregated, anonymous statistics and detect data anomalies
SaleCycle states that it does not use the personal data for its own independent purposes, but follows client instructions. Users should therefore read the relevant client’s privacy and cookie notices for the full explanation of processing and legal basis.
2. User Rights and Choices
Under GDPR, users may generally have rights to:
- Access their personal data
- Correct inaccurate data
- Request deletion
- Restrict or object to processing
- Receive data in a portable format
- Withdraw consent where consent is the legal basis
- Complain to a data protection regulator
Requests and complaints should normally be directed to the relevant client, as Data Controller. SaleCycle says it will assist the client in responding.
You can:
- Block cookies or similar technologies through browser settings
- Use the client’s cookie-management platform
- Unsubscribe from marketing using the link in communications
Blocking all cookies—including essential cookies—may impair access to some website functions. Opting out of marketing does not necessarily stop all other processing.
3. Third-Party Sharing and Transfers
SaleCycle says it does not sell or otherwise disclose personal data except as described. It shares data with:
- Sub-processors needed to provide its services
- Partners that may assist with advertising, profiling, or data combination
- Client companies that control the processing
A sub-processor list is referenced but not included in the notice itself. Data may be transferred outside the EU, although SaleCycle says it uses GDPR-compliant safeguards and contractual protections.
SaleCycle uses EU- and UK-based data centres and cloud storage, maintains supplier security controls, and states that its security framework aligns with ISO/IEC 27001:2013.
4. AI and Machine-Learning Training
The notice does not say that personal data is used to train artificial-intelligence or machine-learning models. It mentions profiling, personalisation, advertising, reporting, and anomaly detection, but does not describe AI training, model development, or automated decision-making in detail.
Users should ask the relevant client or SaleCycle for clarification if AI-based profiling or automated decisions are a concern.
5. Important User Responsibilities and Restrictions
Users are responsible for:
- Managing cookie consent through browser or client settings
- Using unsubscribe mechanisms for marketing communications
- Contacting the correct Data Controller for rights requests or complaints
The notice does not impose significant contractual obligations on users, but declining cookies may reduce website functionality. The client—not SaleCycle—is responsible for establishing a lawful basis for processing and explaining its broader use of the data.
6. Liability and Disputes
The notice contains no detailed liability cap, indemnity, governing-law clause, arbitration provision, or dispute-resolution process. It also does not promise compensation for misuse or security incidents.
SaleCycle says it has security measures and breach procedures. Where legally required, it will notify clients and regulators; the clients are responsible for notifying affected users. This means users will generally need to pursue privacy complaints through the client or applicable regulator, rather than relying on this notice as a direct compensation agreement.
7. Changes to the Notice
The notice states it was last updated on 30 November 2023. It does not explain how users will be notified of future changes, whether prior notice will be provided, or whether continued website use constitutes acceptance. Users should check the notice periodically and review the relevant client’s privacy notice for updates.
Change history
2026-09-06 · Service Privacy Notice
2026-09-05 · Service Privacy Notice
Summary
The diff indicates that approximately 79 words were added, but it does not include the actual wording of those additions.
Legal and Commercial Impact
Because the new language is not provided, it is not possible to determine:
- Whether the additions change the parties’ rights or obligations.
- Whether they create new warranties, disclaimers, indemnities, limitations of liability, or termination rights.
- Whether they alter confidentiality, intellectual-property ownership, data protection, security, or regulatory obligations.
- Whether they introduce material risks for the customer.
AI Training and Customer Data
No specific conclusion can be reached about the use of customer data to train AI models. The diff does not reveal whether the additions:
- Permit or prohibit using customer data, prompts, content, or personal information to train, fine-tune, or improve AI models.
- Distinguish between customer data and anonymized, aggregated, or de-identified data.
- Require customer consent or provide an opt-out.
- Allow use of data after termination or deletion.
- Give the provider ownership or broad usage rights over outputs, feedback, or usage data.
- Address human review, model providers, or sharing data with third parties.
- Impose security, deletion, confidentiality, or data-location restrictions applicable to AI training.
Assessment
The provided diff is insufficient for a meaningful legal analysis. The exact 79 added words are required to identify any new rights, obligations, or risks—particularly those involving AI model training and the use of customer data.
2026-09-05 · Service Privacy Notice
Key Changes and Risks
1. Expanded description of data collected
The notice changes from a general statement about using data centres and collecting data to a more detailed list of information collected when individuals visit clients’ websites or interact with the services, including:
- Name, salutation, email address and phone number
- IP address and device information
- Information about products and services of interest
- Transaction and order information, including order IDs, subtotals, titles, currency, discounts, shipping, items, product IDs, URLs, prices, categories and tax
Risk: The revised wording is materially broader and more specific. It may create additional transparency obligations, particularly regarding the purposes, retention periods, lawful bases and sharing arrangements for transactional and technical data.
2. Greater reliance on client-specific configurations
The notice now states that the information collected varies depending on the client’s service setup and recommends contacting the relevant Data Controller for further details.
Risk: This may make the notice less complete from the service provider’s perspective. Individuals may not be able to understand precisely what data is collected without contacting another party. The respective responsibilities of the service provider and each client should be clearly defined.
3. Special category and sensitive data wording
The previous wording said the service provider might be able to determine or capture additional personal data, including special category data, but that this was “rare and where identified.” The revised wording states that it is “also possible” that the services may capture additional information, including special category data, and that this is rare where identified. It also says the provider may determine such data and work with clients to implement additional safeguards.
Risk: The revised language could be read as acknowledging a broader or more realistic possibility of collecting special category data. It should explain the circumstances, lawful basis, Article 9 condition, safeguards, access restrictions and deletion procedures. “Additional safeguards” is vague and may be insufficient as a transparency statement.
4. Security and hosting statements retained or reorganised
The revised notice continues to refer to EU and UK data centres, contractual controls with suppliers, due diligence and ISO/IEC 27001:2013 security standards. These statements are reorganised and framed as the provider’s own security controls.
Risk: References to certification or standards should be accurate and current. The wording should not imply that ISO certification guarantees compliance or security in every circumstance.
5. No express AI-model training provision identified
The supplied diff contains no express reference to artificial intelligence, machine learning, model training, automated training datasets, prompts, outputs, or use of customer data to train models.
Accordingly, no direct change to AI-training rights or restrictions can be identified from this diff. However, the broader collection language could potentially cover data used for other purposes unless the notice separately limits purposes. The final notice should expressly state whether customer or website-visitor data:
- Is used to train or fine-tune AI models;
- Is excluded from model training;
- May be shared with AI providers; and
- Is retained in prompts, logs or model outputs.
6. Administrative updates
The notice adds a privacy contact email address and states that it was last updated on 30 November 2023. The address formatting also appears corrected or altered.
Risk: The date and contact details should be verified, and the notice should be reviewed for formatting or drafting errors before publication.
2026-09-02 · Service Privacy Notice
Key Changes and Legal Risks
1. Broader description of data collection
The notice changes the description from collecting data through “data centres” and related arrangements to collecting information about individuals when they visit clients’ websites or interact with the services.
The listed information is expanded to include:
- Salutation, name, email address and telephone number;
- IP address and device information;
- Products and services of interest; and
- Detailed order and transaction information, including order ID, subtotal, title, currency, discounts, shipping, items, product ID, client product ID, URL, single-item price, category and tax.
Risk: This is a material expansion and clarification of the categories of personal data processed. The notice should accurately identify the purposes, legal bases, retention periods and relevant recipients for each category. The wording should also distinguish data collected directly from individuals from data received from client organisations.
2. Potential collection of additional and sensitive data
The revised wording states that the company may capture additional information depending on how the client’s services are configured. It expressly states that the company may capture personal data, including special category data, although this is described as rare and subject to additional safeguards.
Previously, the wording indicated that the company might be able to “determine” such data and that additional safeguards could be implemented. The new wording more directly acknowledges actual capture of the data.
Risk: Special category data triggers heightened UK/EU GDPR requirements, including an Article 9 condition, appropriate safeguards and potentially a documented risk assessment. Saying that such collection is “rare” does not remove those obligations. The notice should explain the circumstances, lawful basis and safeguards with sufficient specificity.
3. Greater reliance on client configuration and the Data Controller
The revised notice states that the information collected varies from client to client depending on the setup of the services and directs individuals to contact the relevant Data Controller for full details.
Risk: This may be appropriate where the client determines the purposes and means of processing, but it does not remove the company’s own transparency obligations. The parties’ controller/processor or joint-controller roles should be clearly documented, particularly where the company independently determines purposes, uses data for analytics, or retains data beyond the client’s instructions.
4. Hosting and security statements
The notice retains or restates that data centres and cloud storage are located in the EU and UK, with contractual controls for suppliers and due diligence over supplier security. It also refers to the company’s own controls and ISO/IEC 27001:2013 security standards.
Risk: “EU and UK” hosting does not address all onward transfers, remote access or international suppliers. The notice should identify applicable transfer mechanisms where data leaves those regions. References to ISO certification should be accurate and not imply certification beyond its scope or current validity.
5. AI model training
No express change concerning AI, machine learning or the use of customer data to train AI models appears in this diff.
The revised categories of order, browsing, device and potentially special category data could nevertheless be valuable for analytics or model development. If the company uses any customer or client data to train, fine-tune, evaluate or improve AI models, that purpose is not disclosed here and should be addressed expressly, including the legal basis, data minimisation, opt-out or objection rights, retention, anonymisation and disclosure to AI providers.
6. Administrative changes
The notice adds a privacy contact email and states that it was last updated on 30 November 2023. The address formatting also appears corrected or expanded.
Drafting concern: The diff contains repeated and malformed fragments. The final notice should be checked carefully for duplication, broken headings and inaccurate inserted field names before publication.
2026-09-02 · Service Privacy Notice
Summary
The supplied diff states only that approximately 79 words were added. It does not include the text of those additions or identify where they appear in the agreement.
Legal and Commercial Impact
- No specific changes can be analyzed regarding liability, confidentiality, intellectual property, data protection, service levels, termination, or other legal terms.
- The legal effect depends entirely on the missing 79 words and their interaction with the existing agreement.
- The addition could potentially introduce new obligations, permissions, disclaimers, or limitations, but none can be confirmed from the information provided.
AI Training and Customer Data
- The diff does not reveal whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- It is therefore not possible to determine whether the amendment:
- Permits use of customer content, prompts, outputs, personal data, or usage data for model training;
- Requires customer consent or provides an opt-out;
- Applies training restrictions only to certain services or data categories;
- Allows use of de-identified, aggregated, or pseudonymized data;
- Permits sharing with affiliates, subprocessors, or third-party model providers;
- Changes ownership or licensing rights in customer data or model outputs; or
- Adds retention, deletion, security, or confidentiality exceptions for AI development.
Risk Assessment
Assessment: Indeterminate. The statement that 79 words were added is insufficient to identify new legal risks. The actual inserted language, surrounding provisions, and any defined terms are required for a meaningful review.
Please provide the full redline text—including the additions, deletions, and replacements—for a substantive analysis.
2026-08-31 · Service Privacy Notice
Summary
The provided diff does not include the actual added or deleted contractual language. It only states:
> “Added approximately 79 words to the document”
Accordingly, it is not possible to determine:
- What contractual provisions changed;
- Whether the customer assumed new obligations or liabilities;
- Whether the provider obtained broader rights to use customer data;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether data may be shared with affiliates, vendors, or other third parties;
- Whether confidentiality, security, retention, deletion, or opt-out protections changed; or
- Whether the changes affect ownership or intellectual-property rights.
AI Training and Data-Use Risk
No conclusions can be drawn about AI-model training from the information supplied. The actual 79-word addition could materially change the agreement if it includes language permitting the provider to:
- Use customer content or prompts to train or improve models;
- Use data in aggregated, de-identified, or anonymized form;
- Retain data for model development or evaluation;
- Permit human review of customer data; or
- Transfer data to subprocessors or third-party AI providers.
These rights should be reviewed carefully, particularly if the customer’s data contains personal information, confidential business information, regulated data, or proprietary materials.
Information Needed
Please provide the full redline or the exact 79 words, including the surrounding clause and any deletions or replacements. Without the actual text, a legally meaningful comparison is not possible.
2026-08-30 · Service Privacy Notice
Key Changes and Risks
1. Expanded description of data collected
The notice now states that information may be collected when individuals:
- Visit clients’ websites; or
- Interact with the company’s services.
The listed data has been expanded to include:
- Salutation, name, email address and phone number;
- IP address and device information;
- Information about products and services of interest; and
- Client- or order-related information, including order ID, subtotal, title, currency, discounts, shipping, items, product ID, client product ID, URL, single-item price, category and tax.
Risk: This is a materially broader and more specific description of collection. The company should ensure that each category is actually collected, necessary for the stated purposes, supported by an appropriate legal basis, and reflected in retention, security and data-subject rights procedures.
2. Greater reliance on client-specific configurations
The revised wording says that the information collected “varies from client to client depending on the setup of our services.” It directs individuals to contact the relevant Data Controller for further information.
Risk: This may make the notice less transparent if it does not clearly explain which data is collected in each use case, why it is collected, and who determines the purposes and means of processing. Responsibility between the company and its clients should be clearly allocated.
3. Special-category data wording changed
The previous wording stated that the company “may capture additional personal data, including special category data,” but that this was rare and that additional safeguards could be implemented.
The new wording states that the company may capture “additional information,” explains that the information may vary, and then says it may capture additional personal data, including special-category data, where this is rare and identified. It also states that the company works with clients to implement additional safeguards.
Risk: The change may reduce clarity about the circumstances in which special-category data is processed and the safeguards applied. Under data-protection law, special-category processing generally requires a specific additional legal condition, not merely unspecified “safeguards.” The notice should identify the relevant categories, purposes, legal conditions and protection measures where applicable.
4. Security and hosting statements
The revised text retains or clarifies that:
- Data centres and cloud storage are based in the EU and UK;
- Contractual controls are maintained with suppliers;
- Supplier security due diligence is conducted; and
- Internal security controls follow ISO/IEC 27001:2013 standards.
Risk: These are potentially significant representations. They should remain accurate, particularly regarding all suppliers, backups, support access, international transfers and the precise scope of ISO certification or alignment.
5. AI-model training
No express change concerning the use of customer data to train, fine-tune, evaluate or improve AI models is shown in this diff. The revised data categories could encompass information that might later be used for AI-related purposes, but no such purpose is added here.
If AI training is permitted elsewhere in the agreement or privacy notice, that language should be reviewed separately. If not, the company should avoid using customer data for model training without clear purposes, legal basis, contractual authorization and appropriate safeguards.
6. Drafting and formatting defects
The diff contains apparent corruption, including terms such as “Basket ID,” “Subtotal,” “Title,” and “Order,” and missing spaces or punctuation. The final notice should be carefully reconstructed and proofread before publication.
A privacy contact address and a “last updated” date of 30 November 2023 are added. Both should be verified and kept current.
2026-08-30 · Privacy Policy
2026-08-29 · Service Privacy Notice
Summary of Important Changes
1. Expanded description of information collected
The notice changes the wording from using “data centres” and storing data to describing information collected when individuals:
- Visit clients’ websites; or
- Interact with the company’s services.
The listed data now expressly includes:
- Salutation, name, email address and phone number;
- IP address and device information; and
- Information about products and services of interest.
It also adds extensive transaction and product-related information, including order ID, subtotal, title, currency, discounts, shipping, items, product ID, client product ID, URL, single-item price, category and tax information.
Risk: This is a material expansion and clarification of the categories of personal data covered. The notice should accurately reflect all data actually collected and explain the purposes and lawful bases for each category.
2. Client-specific collection is emphasized
The revised wording states that the information collected varies depending on the client’s service setup. It directs individuals to contact the relevant Data Controller for a full understanding of the data collected.
Risk: This may make the notice less transparent if it does not clearly identify the relevant controller, explain the company’s role (for example, processor or controller), and provide an accessible client-specific privacy notice. Responsibility for compliance may otherwise be unclear.
3. Potential collection of additional and sensitive data
The wording changes from saying the company may be able to “determine” additional personal data to saying it may “capture” additional information. It retains that this may include personal data and special category data, while stating that this is rare and that additional safeguards will be implemented with clients where identified.
Risk: “Capture” suggests direct receipt or processing and may broaden the company’s apparent processing activities. Special category data requires a valid Article 9 condition, strict necessity, appropriate safeguards and clear transparency. The notice does not specify what sensitive data may be collected, why, under what legal basis, or what safeguards apply.
4. Security and storage wording
The revised text retains references to EU and UK data centres, contractual controls with suppliers, due diligence, and ISO/IEC 27001:2013-aligned security controls. It now presents these as the company’s own controls rather than primarily describing storage arrangements.
Risk: References to ISO certification or compliance should not overstate the company’s actual certification status or the protection provided by the controls.
5. AI-model training
No express change concerning AI, machine learning, generative AI, model training, profiling for AI, or use of customer data to train models appears in the supplied diff.
The expanded categories of website, device, transaction and product data could potentially be relevant to AI development, but the revised wording does not authorize or explain such use. If customer data is used for training, fine-tuning, evaluation or improving AI models, that purpose should be stated expressly, with applicable legal bases, retention, sharing, opt-out rights and safeguards.
6. Administrative changes
The notice adds a privacy contact email (privacy@salecycle.com) and states that it was last updated on 30 November 2023.
2026-08-29 · Privacy Policy
Summary of Important Changes
1. Broader description of data collected
The notice changes the wording from using “data centres” to stating that the company collects information about individuals when they visit clients’ websites or interact with the company’s services.
The listed information is expanded or clarified to include:
- Salutation, name, email address and phone number;
- IP address and device information;
- Information about products and services of interest;
- E-commerce and transaction-related information, including:
- Order ID;
- Subtotal, currency and discounts;
- Shipping and items;
- Product ID and client product ID;
- Product URL, single-item price, category and tax information.
Risk/impact
This is a significant expansion in the transparency around the types of personal and transactional data processed. It may increase compliance obligations concerning notice, lawful basis, data minimisation, retention and data-subject rights. The wording also makes clear that the data collected can vary depending on how the client configures the services.
2. Potential collection of sensitive personal data
The revised wording states that the company may capture additional information, including personal data and special category data. It says this is rare and that additional safeguards will be implemented where identified.
Risk/impact
This is a material risk expansion. Special category data receives enhanced protection under data-protection laws, generally requiring both a lawful basis under Article 6 UK GDPR and an additional condition under Article 9. The notice does not explain:
- What types of special category data may be collected;
- The specific lawful conditions relied upon;
- What safeguards will apply;
- How long such data will be retained;
- Whether clients or the company are responsible for ensuring compliance.
The statement that safeguards “may” or “will” be implemented is relatively general and may not be sufficient as a detailed privacy disclosure.
3. Clarification of client-dependent processing
The revised notice says the information collected depends on the setup of the services and recommends contacting the relevant Data Controller for further information. It also states that the company may work with clients to determine additional personal-data safeguards.
Risk/impact
This places greater emphasis on the client’s role and may help allocate transparency responsibilities, but it could create uncertainty for individuals about whether the company or the client is responsible for particular processing activities.
4. Security and hosting language
The revised text states that data centres and cloud-based storage are located in the EU and UK, with contractual controls for suppliers. It also refers to the company’s own security controls and ISO/IEC 27001:2013 standards.
Risk/impact
The wording is more focused on security governance and supplier due diligence. However, an ISO reference is not itself a guarantee of compliance or security, and the notice does not explain international-access risks, retention periods or specific technical safeguards.
5. AI-model training
No express change or provision addresses the use of customer or personal data to train, fine-tune, evaluate or improve AI models. The diff does not add a right for the company to use data for AI training, nor does it prohibit such use. If AI training is intended, this notice appears incomplete and should address purpose, legal basis, data categories, opt-out rights (if applicable), anonymisation, retention and disclosures concerning providers.
6. Administrative changes
The notice adds a privacy contact email—privacy@salecycle.com—and states that it was last updated on 30 November 2023.
2026-08-29 · Service Privacy Notice
Summary
Information Provided
The diff states only that approximately 79 words were added, but it does not include the actual added language or identify where those words appear.
Legal and AI-Training Analysis
Because the text of the additions is missing, it is not possible to determine:
- Whether the customer grants permission to use its data to train, fine-tune, evaluate, or improve AI models.
- Whether such use is limited to de-identified, aggregated, or anonymized data.
- Whether customer data may be shared with affiliates, vendors, or other third parties for AI development.
- Whether the provider may use customer prompts, inputs, outputs, usage data, or metadata.
- Whether the customer can opt out of AI training or revoke consent.
- Whether the new language changes confidentiality, data ownership, intellectual-property rights, or security obligations.
- Whether the provider may retain customer data after termination for model training or other purposes.
- Whether the provider receives a broad license to customer content or model outputs.
- Whether the customer bears additional regulatory, privacy, or third-party-rights risks.
Risk Assessment
The addition could materially expand the provider’s rights if it authorizes use of customer data for model training or product improvement. However, no reliable conclusion can be reached without the actual 79 added words and their placement in the agreement.
Needed for Complete Review
Please provide the redlined language itself, including:
1. The exact added text in {braces}.
2. Any deleted text in [brackets].
3. Any replacement text in []{}.
4. The surrounding section or clause headings, if available.
Once provided, the changes can be assessed for AI-training permissions, data ownership, confidentiality, privacy, retention, third-party sharing, and opt-out rights.
2026-08-29 · Privacy Policy
Summary
The diff does not include the actual 79 added words—only a statement that approximately 79 words were added. As a result, it is not possible to determine:
- What contractual obligations or rights changed;
- Whether liability, confidentiality, security, ownership, or termination provisions were modified;
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such data use is optional, subject to consent, or automatic;
- Whether customer data may be anonymized, aggregated, shared with affiliates or vendors, or retained after termination; or
- Whether the customer receives any notice, opt-out, deletion, or audit rights.
AI Training-Related Risk
No conclusion can be reached about AI-model training because the relevant added language is not provided. The full text of the additions, including any surrounding clause needed for context, is required to assess whether the agreement:
- Authorizes training or improvement of general-purpose or customer-specific models;
- Permits use of prompts, inputs, outputs, personal information, or confidential information;
- Applies training rights by default or only with express consent;
- Restricts human review or access by service providers;
- Requires de-identification or aggregation; or
- Limits the provider’s responsibility for data leakage or model memorization.
Please provide the actual redlined text or the 79-word addition for a substantive legal analysis.
2026-08-28 · Privacy Policy
Summary
The provided diff does not include the actual amended contract language. It only states:
> “Added approximately 79 words to the document”
Because the text of those additions is not provided, it is not possible to determine:
- What contractual provisions changed;
- Whether new obligations, rights, limitations, or liabilities were added;
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether data may be shared with affiliates, vendors, or third-party AI providers;
- Whether the customer can opt out of AI training or withdraw consent;
- Whether confidential, personal, or regulated data receives special protection;
- Whether the provider may retain data after termination; or
- Whether indemnity, security, confidentiality, intellectual-property, or liability provisions were affected.
AI Training and Data-Use Review
No conclusion can be reached regarding AI-model training because the added 79 words are not shown. The missing language should be reviewed for terms such as:
- “train,” “fine-tune,” “improve,” “develop,” or “evaluate” models;
- “inputs,” “outputs,” “customer data,” “content,” or “usage data”;
- rights to use data in “de-identified,” “aggregated,” or “anonymized” form;
- sharing data with service providers or third-party model providers;
- opt-out or deletion rights; and
- ownership or licensing rights in data and model outputs.
Risk Assessment
The principal risk is that the diff is incomplete. A reliable legal analysis requires the exact inserted and deleted wording, including the surrounding provision and any defined terms. The statement that approximately 79 words were added does not establish whether those words create a material change.
Information Needed
Please provide the actual 79-word addition, together with any relevant surrounding language and defined terms. Once provided, the changes can be assessed for:
1. Scope of permitted data use;
2. AI-training rights and opt-out protections;
3. Confidentiality and privacy implications;
4. Intellectual-property ownership;
5. Data retention and deletion;
6. Third-party access; and
7. Allocation of liability and regulatory risk.
2026-08-28 · Service Privacy Notice
Summary
Available Information
The diff only states: “Added approximately 79 words to the document.” It does not include the actual added language or identify where the changes appear.
Legal and Risk Analysis
Because the text of the 79-word addition is missing, it is not possible to determine:
- Whether the change creates new contractual obligations or rights.
- Whether liability, indemnification, warranties, confidentiality, security, or termination provisions have changed.
- Whether pricing, service levels, intellectual-property ownership, or audit rights are affected.
- Whether the customer’s data may be accessed, retained, disclosed, transferred, or used for purposes beyond providing the services.
- Whether customer data, prompts, outputs, or usage information may be used to train, fine-tune, evaluate, or improve AI models.
- Whether the customer can opt out of AI training or require deletion of data used for that purpose.
- Whether the provider may use data in de-identified, aggregated, or pseudonymized form.
- Whether the provider gives assurances regarding human review, model confidentiality, data localization, or third-party AI providers.
AI Training Issues to Check
The missing language should be reviewed specifically for terms such as:
- “train,” “fine-tune,” “improve,” “develop,” or “evaluate” models;
- “customer content,” “inputs,” “outputs,” “usage data,” or “telemetry”;
- “de-identified,” “aggregated,” or “ anonymized” data;
- rights granted to affiliates, subprocessors, or third-party model providers;
- opt-out mechanisms or restrictions on using data for model training;
- retention and deletion periods; and
- ownership or licensing rights in data and model outputs.
Required for Further Analysis
Please provide the actual 79-word addition, using the stated notation for additions, deletions, and replacements. Without the substantive text, no reliable legal-risk assessment can be made.
2026-08-25 · Service Privacy Notice
Structured Summary of Important Changes
1. Scope and purpose of the notice
- The wording changes the document from referring generally to a “Website Privacy Notice” to a broader privacy notice.
- It now states that information is collected when individuals:
- Visit clients’ websites; or
- Interact with the company’s services.
- Risk: This potentially expands the notice’s scope and the company’s asserted data-collection activities beyond its own website. The notice should clearly identify the relevant controller, purposes, lawful bases, and applicable rights for each processing activity.
2. Expanded categories of personal data
The revised text expressly lists:
- Salutation, name, email address, and phone number;
- IP address and device information;
- Information about products and services of interest;
- E-commerce or transaction-related information, including:
- Order ID;
- Subtotal;
- Title;
- Currency;
- Discounts;
- Shipping and items;
- Product ID;
- Client product ID;
- URL;
- Single-item price;
- Category; and
- Tax information.
- Risk: This is a significant expansion and clarification of the data collected. The company should ensure that each category is necessary, has a documented lawful basis, is covered by retention rules, and is disclosed to data subjects at the appropriate time.
3. Special-category data
- The revised wording states that the company may capture “additional information” and potentially “personal data, including special category data.”
- It says this is rare and that additional safeguards will be implemented with clients where identified.
- Risk: This creates an express acknowledgement that sensitive data may be processed. “Rare” and “additional safeguards” are not sufficient by themselves. The parties should identify the relevant Article 9 condition (where UK/EU GDPR applies), allocation of controller/processor responsibilities, security measures, retention, and breach procedures.
4. Data sources and client involvement
- The notice now says information is obtained directly from clients’ websites and may vary depending on the setup of the services.
- It directs individuals to contact the Data Controller directly for further information.
- Risk: The wording may create uncertainty about whether the company or its clients are controllers, joint controllers, or processors. This could result in incomplete transparency and unclear responsibility for data-subject requests.
5. Security and hosting statements
- The revised text states that data centres and cloud-based storage are located in the EU and UK, with contractual controls for suppliers and due diligence on supplier security.
- It also references ISO/IEC 27001:2013 security standards.
- Risk: These statements may be interpreted as contractual assurances. They should be accurate, current, and qualified where hosting, transfers, or suppliers fall outside the EU/UK. The ISO reference may also be outdated or misleading if certification is not current.
6. AI-model training
- No express change concerning the use of customer or personal data to train, fine-tune, evaluate, or improve AI models was identified.
- The revised categories of data are broader, however. If any such data is used for AI development or model improvement, the notice should expressly disclose that purpose, legal basis, safeguards, retention, and opt-out or objection rights.
7. Drafting and publication issues
- The diff contains serious formatting and wording defects, including missing spaces and apparent corruption such as “ISO/IEC Basket ID / Order ID.”
- It adds a privacy contact email, a last-updated date of 30 November 2023, and changes the address formatting.
- Risk: The notice should not be published without a full clean-up and legal review, as errors may undermine transparency and credibility.
2026-08-25 · Service Privacy Notice
Important Changes
1. Expanded description of information collected
The notice replaces general references to collecting “data” with more specific descriptions of collecting “information” when individuals:
- Visit clients’ websites; or
- Interact with the provider’s services.
The listed information now expressly includes:
- Salutation, name, email address and phone number;
- IP address and device information;
- Information about products and services of interest; and
- E-commerce/order information, including:
- Order ID;
- Subtotal, title, currency and discounts;
- Shipping and item information;
- Product ID and client product ID;
- URL, single-item price, category and tax information.
Risk: This is a material expansion and clarification of the categories of personal data collected. The notice should ensure that all listed data is covered by an appropriate lawful basis, retention period, purpose, and individual-rights process.
2. Greater flexibility to collect additional information
The revised wording states that the information collected varies depending on the client’s service setup and that, at clients’ request, the provider may capture additional information. It also retains the possibility of collecting personal data, including special-category data, but describes this as rare and requiring additional safeguards.
The previous wording suggested the provider might “determine” additional personal data; the new wording more directly says it may “capture” it.
Risk: “Additional information” is broad and potentially open-ended. The notice does not specify clear limits, examples, purposes, lawful bases, or safeguards for such additional collection. Special-category data requires particularly careful legal justification and security controls.
3. Responsibility shifted more clearly toward the client/Data Controller
The revised notice repeatedly states that collection depends on the client’s setup and directs individuals to contact the Data Controller for more information.
Risk: This may create uncertainty about the provider’s own role and responsibilities, particularly where it determines purposes or means of processing, or where individuals cannot easily identify the relevant client controller. The controller/processor allocation should be consistent with the underlying contracts and privacy notices.
4. Security and hosting language repositioned
References to EU/UK data centres, contractual controls with suppliers, supplier due diligence, and ISO/IEC 27001:2013 security standards have been moved and incorporated into the general description of the provider’s own security controls.
Risk: The revised wording may be read as a general assurance rather than a specific commitment regarding data location, international transfers, or supplier controls. It should not imply that all processing necessarily occurs only in the EU and UK unless that remains accurate.
5. AI-model training
No express change concerning AI or training models is visible in the supplied diff. The revised text does not grant or remove any right to use customer or personal data to train, fine-tune, evaluate, or improve AI models.
If AI training is addressed elsewhere in the notice or contract, that provision should be reviewed separately. The expanded categories of collected information could nevertheless increase the data potentially available for any separately authorised analytics or AI-related use.
2026-08-24 · Privacy Policy
Summary of Important Changes
1. Broader and more specific data collection
The revised notice replaces general references to collecting “data” with “information about you” and provides a more detailed list of data that may be collected, including:
- Salutation, name, email address and telephone number
- IP address and device information
- Information about products and services of interest
- Transaction and order information, such as:
- Order ID and subtotal
- Title, currency and discounts
- Shipping and items
- Product ID, client product ID and URL
- Single-item price, category and tax information
Risk: The notice now expressly covers a wider range of customer, browsing and transactional information. The list also includes “etc.”, which may leave the scope open-ended and create transparency concerns under data-protection law.
2. Potential collection of sensitive personal data
The revised wording states that, depending on how a client configures the services, the company may capture “additional information” and may capture personal data, including special category data. It says this is rare and that additional safeguards will be implemented where identified.
Risk: This is a significant compliance issue. Special category data—such as health, biometric, religious or political information—requires heightened legal protections, a specific processing condition, and appropriate safeguards. The notice does not explain:
- What types of special category data may be processed
- The legal basis or special condition relied upon
- What safeguards apply
- How long such data is retained
- Whether the company acts as controller or processor for that data
The wording also shifts from saying the company might be able to “determine” additional personal data to saying it may “capture” it, which may imply more direct collection.
3. Greater reliance on client-specific configurations
The revised notice makes clear that the information collected varies according to the client’s setup of the services and recommends contacting the relevant Data Controller for further details.
Risk: Individuals may not receive a complete explanation of processing from this notice alone. The allocation of responsibility between the company and each client should be clearly documented, particularly where the company processes data on behalf of clients.
4. Security and hosting language retained or clarified
The revised text continues to state that:
- Data centres and cloud storage are located within the EU and UK
- Appropriate contractual controls are maintained with suppliers
- Supplier security due diligence is conducted
- The company maintains ISO/IEC 27001:2013-aligned security controls
This is generally positive, although it does not address international access or transfers that could occur through suppliers or support personnel.
5. AI model training
No express change relating to AI, machine learning or use of customer data to train AI models appears in the supplied diff. The revised notice does not grant or remove an AI-training right, nor does it explain whether customer information may be used for model training, testing, improvement or human review.
Recommended action: Confirm separately in the contract or privacy notice that customer data will not be used to train AI models unless expressly authorised, with clear limits, opt-out rights and confidentiality safeguards.
6. Drafting and publication issues
The diff contains apparent formatting or text-corruption errors, including “Basket ID,” “Subtotal,” “Title,” and “Currency” appearing in place of security-standard wording. These should be corrected before publication because they may make the notice unclear or legally unreliable.
2026-08-23 · Privacy Policy
Summary of Important Changes
1. Expanded and more specific description of collected data
The notice changes from a relatively general statement about collecting data through websites and suppliers’ services to a more detailed list of information, including:
- Salutation, name, email address and phone number
- IP address and device information
- Information about products and services of interest
- E-commerce and transaction-related data, including:
- Order ID
- Subtotal and currency
- Discounts
- Shipping and items
- Product ID and client product ID
- Product URL
- Single-item price
- Category and tax information
Risk: The revised wording gives the organisation a broader and more explicit basis for collecting transactional and behavioural information. The notice should ensure that each category is necessary, supported by an appropriate lawful basis, and covered by suitable retention and transparency disclosures.
2. Greater reliance on client-specific configurations
The revised notice states that the information collected “varies from client to client depending on the setup of our services” and that additional information may be captured at clients’ request.
Risk: This creates a potentially open-ended scope of collection. Individuals may not be able to understand what data is collected in a particular implementation unless the relevant client’s privacy notice provides the necessary detail. The allocation of responsibility between the organisation and each client should be clear, particularly regarding controller/processor roles and responding to data-subject rights requests.
3. Special-category data wording retained but reframed
The previous wording stated that the organisation “may capture additional personal data, including special category data,” but described this as rare and said additional safeguards would be implemented.
The revised wording still permits the capture of additional information and special-category data, stating that this is rare and that additional safeguards will be implemented where identified. It also directs individuals to the Data Controller for further information.
Risk: Special-category data requires a specific legal condition under data-protection law, in addition to a general lawful basis. “Rare” and “additional safeguards” do not themselves establish legal compliance. The notice should identify who determines the purposes and legal basis for such processing and how individuals can obtain meaningful details.
4. Security and hosting statements retained, but reorganised
The revised text continues to state that:
- Data centres and cloud storage are located within the EU and UK
- Appropriate contractual controls are maintained with suppliers
- Supplier security due diligence is conducted
- The organisation maintains its own security controls in accordance with ISO/IEC 27001:2013 standards
This is largely a clarification and reorganisation rather than a clear reduction in protections. However, the wording should not imply that ISO certification alone guarantees compliance or security.
5. AI-model training
No express change concerning the use of customer data to train, fine-tune, evaluate or improve AI models is visible in this diff. There is no new AI-training permission, restriction, opt-out, anonymisation commitment or statement about whether customer data is used for generative-AI development.
If AI processing is intended, this notice does not appear to disclose it adequately. A specific provision should address purposes, data categories, model providers, safeguards, retention, human review and applicable opt-out or objection rights.
6. Administrative changes
The notice adds a privacy contact email address and states that it was last updated on 30 November 2023. The address formatting also changes from “3DF” to “3DFFor,” which appears to be a drafting or formatting error requiring correction.
2026-08-23 · Service Privacy Notice
Summary
The provided diff only states that “approximately 79 words” were added. It does not include the actual added language, deleted language, or replacement terms.
AI Training and Data-Use Review
Because the text of the amendment is missing, it is not possible to determine whether the changes:
- Permit the customer’s data to be used to train, fine-tune, or improve AI models;
- Expand the definition of “customer data” to include prompts, outputs, metadata, usage data, or personal information;
- Allow data to be retained after termination or deletion;
- Permit use of data for service improvement, analytics, benchmarking, or model evaluation;
- Allow sharing of data with affiliates, vendors, or third-party AI providers;
- Create opt-out, consent, confidentiality, or data-deletion rights; or
- Change ownership or intellectual-property rights in customer inputs, outputs, or trained models.
Risk Assessment
No substantive legal risks can be assessed from the information provided. The actual 79 added words—and any surrounding language they modify—are necessary to evaluate whether the customer has granted broader data-use rights or accepted additional privacy, confidentiality, security, or intellectual-property obligations.
Please provide the full redlined text, including the words shown in {additions}, [deletions], and []{replacements}, for a meaningful analysis.
2026-08-22 · Service Privacy Notice
Summary
The provided diff does not include the actual amended contractual language. It only states:
> “Added approximately 79 words to the document”
Because the new words, deleted words, and replacements are not shown, it is not possible to determine:
- What contractual obligations or rights changed;
- Whether liability, indemnity, confidentiality, security, or termination provisions were affected;
- Whether the customer’s data may be accessed, retained, disclosed, or transferred differently; or
- Whether the provider may use customer data to train, fine-tune, evaluate, or improve AI models.
AI Training and Data-Use Risk
No conclusion can be drawn about AI-model training from the information provided. The key language to review would include terms such as:
- “train,” “fine-tune,” “improve,” “develop,” or “optimize” models;
- “customer data,” “content,” “inputs,” “outputs,” or “usage data”;
- Rights to use data on an aggregated, anonymized, de-identified, or unrestricted basis;
- Opt-out or consent requirements;
- Data retention and deletion obligations;
- Restrictions on human review or disclosure to subprocessors; and
- Ownership or licensing rights in data, inputs, outputs, or trained models.
Risk Assessment
Assessment: Unable to determine. The actual diff is required to identify any new or important legal risks.
Please provide the full redline or the 79 added words, including the surrounding provisions and any deleted or replaced text.
2026-08-20 · Privacy Policy
Summary
The provided diff does not include the actual contractual language. It only states that approximately 79 words were added. As a result, it is not possible to determine:
- What contractual obligations or rights changed;
- Whether liability, indemnity, confidentiality, security, or termination provisions were affected;
- Whether the customer’s data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether customer data may be shared with affiliates, vendors, or third parties for AI-related purposes;
- Whether the customer can opt out of AI training or request deletion of data used for training;
- Whether any new data-retention, ownership, licensing, or confidentiality risks were introduced.
AI Training and Data-Use Risk
No specific change concerning AI-model training or use of customer data can be identified from the information provided. The statement that 79 words were added does not reveal whether the additions:
- Authorize training on customer content, prompts, inputs, or outputs;
- Permit use of data in aggregated, de-identified, or identifiable form;
- Grant the provider a broad license to customer data;
- Allow human review or vendor access to customer data;
- Make AI-training rights automatic rather than subject to consent or an opt-out; or
- Impose limits on retention, deletion, or reuse.
Needed Information
To perform a legal comparison, the actual added text—and, ideally, the surrounding unchanged provisions—must be provided. The additions should be marked with {}, and any deletions or replacements should be shown using the stated notation.
2026-08-20 · Service Privacy Notice
Key Changes
1. Privacy notice scope and wording
- The opening wording is reformatted from “Website Privacy Notice” to “Website Privacy Notice. This privacy notice…”.
- The notice now more clearly describes information collected when individuals:
- Visit clients’ websites; or
- Interact with the company’s services.
- “Data” is generally replaced with “information,” which may be broader and less technically precise.
2. Expanded and more specific data categories
The revised text expressly lists information that may be collected, including:
- Salutation, name, email address and telephone number;
- IP address and device information;
- Information about products and services of interest;
- Order and transaction information, including:
- Order ID;
- Subtotal, currency and discounts;
- Shipping and items;
- Product ID and client product ID;
- URL, single-item price, category and tax information.
This is a material expansion in transparency and may also indicate a broader or more detailed scope of processing than the previous wording.
3. Client-specific variation in data collection
- The revised notice states that the information collected “varies from client to client depending on the setup of our services.”
- Individuals are directed to contact the relevant Data Controller for full details.
Risk: This may make the notice less complete from a transparency perspective if the company itself determines the purposes or means of processing. A generic reference to the client’s notice may not sufficiently explain all processing activities, retention periods, legal bases or data-sharing arrangements.
4. Special category and sensitive personal data
- The previous wording stated that the company “may capture additional personal data, including special category data,” but described this as rare and said safeguards could be implemented.
- The revised wording says the company “may capture additional information,” then separately states that additional personal data, including special category data, may be captured and that safeguards will be implemented where identified.
Risk: The revised wording is less direct about the circumstances in which special category data may be processed and the safeguards applied. It should identify the relevant legal condition, purposes and protections under applicable data-protection law, particularly for UK GDPR purposes.
5. Security and hosting information
- The revised text retains statements that data centres and cloud storage are located in the EU and UK, suppliers are subject to due diligence and contractual controls, and security controls align with ISO/IEC 27001:2013.
- The wording now presents these as the company’s own security controls rather than primarily as client-requested measures.
6. AI-model training
- No express provision has been added or removed concerning the use of customer or personal data to train, fine-tune, evaluate or improve AI models.
- The revised notice does not grant an AI-training right, but it also does not expressly prohibit such use. If AI training is relevant to the services, a specific purpose, lawful basis, data categories, safeguards, opt-out position and third-party disclosures should be added.
7. Administrative updates
- The company’s address is corrected or reformatted.
- A privacy contact email (
privacy@salecycle.com) is added. - The notice states that it was last updated on 30 November 2023.
2026-08-20 · Privacy Policy
Key Changes and Risks
1. Broader and more detailed description of collected information
The notice changes from a general reference to collecting data through “data centres” and cloud storage to describing information collected when individuals:
- Visit clients’ websites; or
- Interact with the company’s services.
The revised list expressly includes:
- Salutation, name, email address and phone number;
- IP address and device information;
- Information about products and services of interest; and
- E-commerce/order data, including order ID, subtotal, currency, discounts, shipping, items, product ID, client product ID, URL, single-item price, category and tax information.
Risk: The notice now describes a materially broader range of personal and transactional data. The company should verify that this list is complete, accurate and consistent with actual processing activities, client instructions and applicable privacy notices.
2. Greater reliance on client-specific processing
The revised wording states that the information collected varies according to the client and the setup of the services. Individuals are directed to contact the relevant Data Controller for further details.
Risk: This may make the company’s role and responsibilities less clear. The notice should clearly distinguish whether the company acts as a processor, controller or joint controller for each activity, and identify the appropriate source of information about purposes, legal bases, retention and individual rights.
3. Special category and additional personal data
The revised text states that the company may capture “additional information” and may, through its services, capture personal data including special category data. It describes this as rare and says that, where identified, the company works with clients to implement additional safeguards.
This replaces wording suggesting that the company might be able to “determine” such data and implement safeguards.
Risks:
- “May capture” is broader and could imply proactive collection rather than incidental receipt.
- The notice does not identify the types of special category data, purposes, legal conditions or safeguards used.
- Saying processing is “rare” does not remove the need for a documented lawful basis and appropriate Article 9 condition under UK/EU GDPR.
- The wording should explain what happens if such data is received unintentionally.
4. Security and hosting language
The revised notice retains references to EU/UK-based data centres, contractual controls with suppliers, supplier due diligence and ISO/IEC 27001:2013-aligned security controls. However, these statements are reorganised and now appear linked more directly to the company’s own services and controls.
Risk: The notice should not imply that all data is exclusively hosted in the EU and UK unless that is always true, including for backups, support access and subprocessors.
5. AI model training
The diff contains no express provision authorising, describing or restricting the use of customer or personal data to train AI models. It also does not state that data will not be used for AI training.
Risk: If customer data, website data, transactional data or special category data may be used for training, fine-tuning, evaluation or improvement of AI models, that purpose is not transparently disclosed in this text and should be addressed separately. Consider expressly stating whether such use is prohibited, permitted only on anonymised data, or subject to client consent and contractual controls.
6. Administrative changes
The notice adds a privacy contact email and states that it was last updated on 30 November 2023. The diff also appears to contain formatting or drafting corruption, including duplicated text and truncated wording, which should be corrected before publication.
2026-08-19 · Service Privacy Notice
Summary of Important Changes
1. Expanded description of data collected
The notice now describes collecting information when individuals:
- Visit clients’ websites; or
- Interact with the company’s services.
The listed information includes:
- Salutation, name, email address, and phone number;
- IP address and device information;
- Information about products and services of interest; and
- E-commerce/order information, including order ID, subtotal, title, currency, discounts, shipping, items, product ID, client product ID, URL, single-item price, category, tax, and similar data.
Risk: The scope of data is substantially more detailed and potentially broader than the previous wording. The notice should clearly explain the purposes, lawful bases, retention periods, recipients, and whether each category is necessary for the relevant service.
2. Potential collection of additional and sensitive data
The revised language states that, depending on how a client configures the services, the company may capture “additional information.” It now expressly refers to:
- Additional personal data; and
- Special category data.
The text says this is rare and that additional safeguards will be implemented with clients where identified.
Risk: This is a material privacy risk. Special category data requires heightened legal safeguards under data protection law, including an applicable Article 9 condition and appropriate technical and organisational measures. The wording does not specify what safeguards are used, who determines whether processing is lawful, or how individuals are informed. “Rare” does not itself satisfy transparency or legal-basis requirements.
The statement also shifts from saying the company may “determine” additional data to saying it may “capture” it, which more directly acknowledges actual processing.
3. Revised storage and security language
The notice now states that data centres and cloud storage are located within the EU and UK, with contractual controls in place with suppliers. It also states that the company conducts supplier security due diligence and maintains its own controls in accordance with ISO/IEC 27001:2013 security standards.
Risk: These are useful assurances, but they may create contractual or regulatory exposure if data is accessed or transferred outside the EU/UK, including through suppliers, support teams, or cloud subprocessors. The notice should address international transfers and applicable transfer mechanisms.
4. Data-controller relationship
The revised text repeatedly directs individuals to the relevant client/Data Controller for further information and says collection varies according to the client’s service configuration.
Risk: Responsibility between the company and its clients should be clearly defined. Ambiguity over controller/processor roles may complicate compliance with transparency, data-subject requests, security obligations, and liability allocation.
5. AI-model training
No express change concerning AI or the use of customer data to train, fine-tune, evaluate, or improve AI models is visible in this diff. The revised language does not grant an explicit AI-training right, nor does it expressly prohibit such use.
Risk: If customer data may be used for AI purposes elsewhere in the agreement or service terms, this privacy notice does not clearly disclose that processing. A specific provision should address whether customer data, personal data, confidential information, or special category data may be used for AI training and whether opt-out, deletion, or human-review rights apply.
6. Drafting and publication issues
The diff contains apparent formatting or redlining artefacts, including “Basket ID,” “Subtotal,” “Title,” and concatenated headings. It also adds a privacy contact email and states that the notice was last updated on 30 November 2023.
Risk: These errors could make the notice unclear or undermine its credibility and transparency. The final published version should be carefully cleaned and legally reviewed.
2026-08-19 · Privacy Policy
Summary
The provided diff does not include the actual added, deleted, or replaced legal language. It only states:
> “Added approximately 79 words to the document”
Accordingly, it is not possible to determine:
- What contractual terms changed;
- Whether the customer’s data may be used to train AI models;
- Whether any new data-usage rights, licenses, or permissions were added;
- Whether confidentiality, privacy, security, or ownership protections changed;
- Whether the customer assumed additional liability or obligations; or
- Whether termination, deletion, retention, or opt-out rights were modified.
AI Training and Data Use
No conclusion can be reached about AI-model training from the information provided. The 79 added words could potentially address AI training, but the actual wording is necessary to assess whether the change:
- Permits the provider to use customer data, content, prompts, outputs, or metadata to train or improve models;
- Allows use of data in de-identified, aggregated, or identifiable form;
- Grants the provider a broad, perpetual, worldwide, or irrevocable license;
- Applies the permission by default or only with customer consent;
- Provides an opt-out or deletion mechanism; or
- Limits use to service provision, security, analytics, or product improvement.
Key Limitation
Because the substantive text of the diff is missing, no reliable legal-risk analysis can be performed. Please provide the actual additions, deletions, and replacements—preferably with the surrounding clause or section headings—for a meaningful comparison.
2026-08-18 · Service Privacy Notice
Summary
The provided diff states only that approximately 79 words were added, but it does not include the actual added language or identify where it appears in the agreement.
AI Training and Data Use
- There is insufficient information to determine whether the new language:
- Permits the customer’s data to be used to train, fine-tune, or improve AI models;
- Allows use of customer data for product development, analytics, or benchmarking;
- Distinguishes between customer content, usage data, metadata, or de-identified data;
- Requires customer consent or provides an opt-out;
- Limits retention, disclosure, or human review of data; or
- Grants the provider ownership or broad license rights over outputs or derived data.
Risk Assessment
The legal and commercial impact cannot be assessed without the actual 79 added words. In particular, it is not possible to determine whether the amendment creates new risks involving:
- Confidentiality and privacy;
- Use of personal or regulated information;
- Intellectual-property ownership;
- Model training or service improvement;
- Data retention and deletion; or
- Third-party disclosure.
Required Information
Please provide the actual redlined text, including the surrounding existing language. The added wording is necessary to identify the precise changes, obligations, permissions, and risks.
2026-08-18 · Service Privacy Notice
Diff Analysis
Overall Assessment
The diff does not include the text of the approximately 200 added words. It only states that content was added. As a result, it is not possible to identify the legal effect of the changes or determine whether they introduce new risks.
Customer Data and AI Training
- No language is provided addressing whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Used to evaluate or test AI systems;
- Combined with other customers’ data;
- De-identified, anonymized, or aggregated before use;
- Retained after termination for model-training purposes; or
- Shared with affiliates, subprocessors, or third-party AI providers.
- Accordingly, no conclusion can be reached about whether the contract’s permissions regarding AI training have expanded or narrowed.
Other Legal Risks
The missing text could potentially affect important issues such as:
- Data ownership and usage rights;
- Confidentiality obligations;
- Privacy and data-protection compliance;
- Security requirements;
- Intellectual-property ownership;
- Service-provider or subprocessors’ rights;
- Data retention and deletion;
- Liability, indemnification, or limitations of liability; and
- Termination rights.
Information Needed
Please provide the actual added language, including any surrounding provisions needed to understand its context. The changes should be shown using the stated notation:
- Additions:
{new text} - Deletions:
[deleted text] - Replacements:
[old text]{new text}
Without the actual contractual language, any assessment of new rights, obligations, or risks—including AI-model training rights—would be speculative.
Between 2024-01-13 and 2025-03-17 · Service Privacy Notice
Key Changes and Risks
1. Change of regulatory/company reference
- The reference to CNIL (France’s data protection authority) appears to be replaced with “CNIL.1BEYABLE”.
- The wording is corrupted and does not clearly identify:
- The applicable supervisory authority;
- The relevant data controller or processor;
- BEYABLE’s legal role; or
- Whether the company information relates to BEYABLE or another entity.
Risk: The revised text may fail to clearly identify the responsible organization and applicable regulator, creating transparency and GDPR notice-compliance issues.
2. New cookie and tracking description
The revised text adds a description stating that BEYABLE:
- Identifies visitors when they connect to a website;
- Collects information about their navigation;
- Processes that information on servers in Europe;
- Uses the information to provide clients with anonymous statistical data about site traffic; and
- Operates under stated security and confidentiality conditions.
Risks:
- “Identifies a visitor” may imply use of persistent identifiers or cookies, even though the data is later described as “anonymous.”
- The notice does not clearly explain:
- What categories of data are collected;
- The legal basis for processing;
- How long data is retained;
- Whether data is shared with clients or other providers;
- Whether the data is genuinely anonymous or merely pseudonymous; or
- The specific European countries hosting the servers.
- Processing on servers “in Europe” is vague and may be insufficient for a complete GDPR transparency notice.
3. New opt-out mechanism
The revision adds an opt-out process using the URL fragment:
#beyable-optout=1
It states that this prevents future collection and signals BEYABLE not to contact its servers.
However, the notice also says:
- Existing cookies may not be deleted;
- The opt-out must be repeated if cookies are cleared;
- The opt-out may be lost if the browser or computer is changed.
Risk: This is a browser/device-specific opt-out rather than a durable, account-level privacy choice. It may be less effective than a consent-management mechanism and could create user-expectation or compliance concerns, particularly where consent is legally required before cookies are placed or read.
4. Company contact information and update date
The contact details for the registered company, office address, and privacy email are retained but substantially reordered and duplicated. The notice continues to state that it was last updated on 30 November 2023.
Risk: The corrupted formatting may make the notice difficult to understand and could undermine its legal effectiveness.
5. AI-model training
No express change concerning AI training was identified.
The revised language discusses visitor identification, navigation data, site-traffic statistics, cookies, servers, and opt-out rights, but it does not state whether customer or visitor data is used to train, fine-tune, validate, or improve AI or machine-learning models.
Recommendation: Add an explicit statement confirming either that such data is not used for AI-model training, or describing the data, purposes, legal basis, safeguards, opt-out rights, and retention rules if it is used.
Between 2023-07-18 and 2024-01-13 · Service Privacy Notice
Between 2019-04-02 and 2022-05-26 · Privacy Policy