clause.watch Contracts Recent changes Start monitoring

Monitored company

SAS

clause.watch tracks 2 legal documents published by SAS, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Statement EU/UK

18,984 characters · Read the original

SAS EU/UK Privacy Statement: Practical Overview

*Applies to residents of the EEA, Switzerland and the UK. Revised October 1, 2023.*

1. Data Collection and Use

Data collected

SAS may collect:

  • Identity and contact data: name, address, telephone number and email.
  • Professional information: professional interests, experience and interactions with SAS products.
  • Business and marketing data: language, communication and marketing preferences.
  • Transaction data: purchases, orders, contracts, billing, delivery and technical-support details.
  • Technical and usage data: IP address, device and browser details, pages visited, session activity and interaction with emails.
  • Security data: authentication and fraud-prevention information.
  • Information from other sources: social media, public sources, trade shows, events, third parties and affiliated SAS systems.

Collection may occur through profiles, forms, cookies, pixels, mobile apps, surveys, customer support, sales activity, social-media interactions and automated analytics. SAS may combine online data with information obtained offline or from affiliates.

Main uses

SAS uses data to:

  • Provide subscriptions, software, services, support and requested information.
  • Manage customer, vendor and business relationships.
  • Send news, product information, events, offers and marketing.
  • Personalize websites, advertising and content through analytics and profiling.
  • Operate forums and communication channels.
  • Secure systems and detect fraud or prohibited activity.
  • Improve or develop products and services, including through statistical analysis.
  • Meet legal obligations and establish or defend legal claims.

The stated legal bases include contract performance, legal obligations, SAS’s legitimate interests and consent. Marketing consent may be required in some circumstances, and marketing emails generally include unsubscribe options.

2. User Rights

Subject to legal exceptions, users may request:

  • Access to their personal data.
  • Correction of inaccurate, incomplete or outdated data.
  • Portability of data they provided, where legally required.
  • Objection to certain processing, particularly processing based on legitimate interests.
  • Deletion, although SAS may retain data for legal obligations, claims or other permitted purposes.
  • Restriction of processing during certain disputes or requests.
  • Withdrawal of consent at any time, without affecting earlier lawful processing.
  • Marketing opt-out through unsubscribe links or SAS profile settings.

Requests are generally free, but SAS may refuse or charge for requests that are unfounded, excessive or repetitive. Identity verification may be required. SAS may reject requests made through automated or third-party tools unless directly validated by the individual.

Users may complain to a data-protection authority in their country of residence, workplace or where the alleged infringement occurred. Requests can be made through SAS’s Data Privacy Rights Form or at privacyrights@sas.com.

3. Third-Party Sharing and International Transfers

SAS states that it does not sell, rent or lease personal data. It may nevertheless share data with:

  • SAS subsidiaries, affiliates and business units.
  • Vendors, subcontractors, processors and business partners.
  • Buyers or transferees involved in a corporate sale or asset transfer.
  • Other users where information is voluntarily posted in SAS communities.
  • Government or law-enforcement authorities where considered necessary or appropriate.
  • Parties needed to protect SAS’s rights, property, websites or security.

Data may be transferred to and processed in the United States and other countries outside Europe. SAS relies on Standard Contractual Clauses and other lawful transfer mechanisms. Users may request copies of applicable clauses, subject to redactions.

4. AI/ML Training

The Statement does not expressly say that personal data is or is not used to train artificial-intelligence or machine-learning models. It permits statistical analysis, profiling, product development, service improvement and automated inferences about product interests. These provisions could potentially support analytics or model development, but they do not clearly define whether customer data is used for generative-AI or ML training, whether data is anonymized first, or whether users can opt out.

Users seeking clarity should request a specific explanation from SAS, particularly regarding data used in support interactions, websites, analytics and product-improvement programs.

5. Key User Responsibilities and Restrictions

Users should:

  • Provide accurate information where necessary to receive services or exercise rights.
  • Avoid posting information in public SAS forums unless comfortable sharing it with other participants.
  • Review separate notices and agreements governing Hosted Managed Services, technical support, consulting and CI 360 data; this Statement does not govern those categories.
  • Review the privacy policies of linked third-party websites. SAS does not control or accept responsibility for them.
  • Understand that some information may be necessary to provide a product or respond to a request.

6. Liability and Disputes

The Statement describes security measures but does not guarantee absolute security or specify a particular compensation regime, liability cap, governing law or court/arbitration process. It does not appear to create a detailed contractual dispute-resolution procedure.

Privacy complaints may be submitted to SAS or a supervisory authority. Separate SAS contracts may contain additional liability, governing-law and dispute terms.

7. Changes to the Statement

SAS says it will post updates on the relevant website and change the revision date. Continued website use after changes are posted is stated to mean acceptance of the changes. The policy does not promise individualized notice by email, so users should periodically review it.

Terms of Use

30,691 characters · Read the original

SAS Terms and Conditions: User Overview

*This summary is based only on the supplied Terms and Conditions, revised October 18, 2018. It is not a substitute for legal advice. The separate SAS Privacy Statement is important, especially for privacy rights and broader data practices.*

1. Data Collection & Usage

The Terms do not provide a comprehensive privacy notice. They mainly identify the following data practices:

  • Account and registration data: Users must provide and maintain current, accurate, and complete information when registering for an account.
  • Account and security information: SAS may process information associated with login credentials and accounts. Users are responsible for all activity conducted through their accounts.
  • Customer information: Certain password-protected services may display customer information, such as names and product information. By registering, users consent to this display and accept the risk of unauthorized access.
  • Private Area data and cookies: For private web areas, SAS may collect and process personal data needed to administer security. It may also store and retrieve session information through cookies to support login/logout and prevent unauthorized access.
  • Community profiles and postings: Users may voluntarily include personal information in community profiles or postings. The Terms warn users not to disclose sensitive information such as Social Security numbers or credit card numbers.

The Terms state that Private Area data may be retained until the relevant purpose ends or under SAS’s applicable retention policy. For other processing, users must consult the separate SAS Privacy Statement.

2. User Rights

The document does not clearly describe rights to:

  • Access, correct, delete, or export personal data;
  • Withdraw consent;
  • Object to processing or restrict processing; or
  • File privacy complaints.

Those rights, if available, are governed by the SAS Privacy Statement and applicable law—not this document.

Users can generally control who sees some profile information through privacy settings. However, even information marked private may be accessible to SAS and third parties depending on their access level.

3. Third-Party Sharing

The Terms permit or contemplate access by:

  • SAS affiliates and service providers, including third-party software used to create or administer Private Areas;
  • Other community users, because postings are generally intended to be shared;
  • Third parties with access to community profiles, depending on privacy settings and access permissions; and
  • Courts or government authorities, potentially as required by applicable law, although this document does not detail disclosure procedures.

Community content is expressly treated as generally non-confidential and not governed by the SAS Privacy Statement unless a written agreement says otherwise.

4. AI/ML Training

The Terms contain no express statement about whether user data, postings, profile information, or uploaded content is used to train artificial intelligence or machine-learning models.

However, community postings and unsolicited submissions receive extremely broad licenses allowing SAS to use, copy, modify, publish, distribute, and create derivative works from them worldwide, perpetually, irrevocably, and without royalties. This could permit broad use of content, but it does not specifically confirm AI training. Users should seek clarification from SAS before posting confidential, proprietary, personal, or commercially sensitive material.

5. Key User Obligations and Restrictions

Users must:

  • Keep account credentials confidential and promptly report security breaches;
  • Avoid using another person’s account;
  • Ensure postings are lawful, accurate, non-defamatory, non-infringing, and free of malware;
  • Avoid disclosing confidential information, third-party personal data, or regulated information;
  • Follow U.S. export controls, sanctions, and restrictions on encryption, weapons-related technology, and controlled technical data;
  • Avoid harvesting user information or sending unsolicited email;
  • Use website materials only for permitted personal, educational, or other non-commercial purposes unless authorized;
  • Not copy, modify, frame, mirror, redistribute, or use SAS materials to develop competing products.

A particularly serious provision imposes $75,000 in liquidated damages per instance of certain prohibited use, in addition to possible copyright damages. SAS may terminate access at its sole discretion.

6. Liability and Disputes

  • Website content, software, products, and services are provided “as is,” with broad warranty disclaimers.
  • SAS disclaims liability for direct, indirect, consequential, special, incidental, lost-profit, lost-revenue, lost-data, and loss-of-use damages, subject to any separate agreement.
  • Users must indemnify SAS and its affiliates for claims arising from their use, submitted content, or violations of the Terms or others’ rights.
  • Disputes are governed by U.S. federal law or North Carolina law and must generally be brought in state or federal courts in Raleigh or Wake County, North Carolina.
  • SAS may seek injunctions and other equitable relief for confidentiality or PartnerNet breaches.

7. Changes to the Terms

SAS may change the website, services, products, or Terms at any time without further notice. Continued use after changes constitutes acceptance. Users should periodically review the Terms; the document identifies October 18, 2018 as its revision date.

Change history

2026-09-06 · Privacy Statement EU/UK

grew 44.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Privacy Statement EU/UK

grew 4.2% · Observed by clause.watch

Summary of Important Changes

1. New use of personal data with workplace AI tools

The most significant change adds that SAS processing may involve both automated and manual methods, including use of workplace AI tools such as Microsoft 365 Copilot to review information provided by individuals, including:

  • Emails; and
  • Transcripts of recorded meetings.
Risks and implications
  • This expressly authorizes AI-assisted processing of personal data for the stated purposes, including understanding marketing preferences and tailoring offerings.
  • The language is broad and does not identify:
  • Whether customer data may be used to train SAS’s or a provider’s AI models;
  • Whether prompts, uploaded content, emails, or transcripts are retained by the AI provider;
  • Whether data is used to improve third-party AI services;
  • What de-identification, access controls, or human-review safeguards apply; or
  • How long AI-generated or AI-processed information is retained.
  • The change does not expressly say that customer data will be used to train AI models. However, it permits customer-provided information to be submitted to a workplace AI tool. Depending on the applicable Microsoft or other provider terms, this could create uncertainty about secondary use, retention, international transfers, and model-improvement practices.
  • Customers should clarify contractually whether their data, including support communications, emails, meeting recordings, and transcripts, may be used for AI training or service improvement. Ideally, use for generalized model training should be expressly prohibited without prior written consent.

2. Broader sharing and international transfers

The revised language replaces a more limited description of sharing with broader wording permitting disclosure to:

  • Other SAS entities;
  • SAS affiliates and business partners;
  • Vendors, subcontractors, processors, and other third parties; and
  • Entities located in or operating across many countries, rather than specifically the United States or another defined country.

The statement now expressly says personal data may be transferred across borders and stored or processed in countries where SAS or related entities maintain facilities.

Risks
  • The geographic scope is less specific and may make it harder to determine where data will be processed.
  • Sharing with “business partners” may expand the group of recipients beyond service providers.
  • Cross-border transfers may expose data to jurisdictions with different privacy protections and government-access rules.

3. Revised hosted-services terminology and scope

“Hosted Managed Services (HMS)” is replaced with “Managed Cloud Services (MCS),” with reference to the “SAS Managed Cloud Services Privacy Policy.”

Customers should verify that the replacement policy covers the same services and does not change the allocation of controller/processor responsibilities or permitted uses of customer-controlled data.

4. Other notable changes

  • The statement clarifies that data may be collected through badge scans, in addition to business cards.
  • Disclosures to law enforcement, government officials, affiliates, processors, and business partners are reorganized and appear more expressly stated.
  • International transfer information is supplemented with a link to SAS’s Trust Center.
  • The statement is marked as last revised and reviewed August 1, 2026.

2026-08-19 · Privacy Statement EU/UK

shrank 25.7% · Observed by clause.watch

Summary

The provided diff states only that approximately 75 words were added, but does not include the actual added language.

Legal and Commercial Impact

  • No substantive changes can be identified from the information provided.
  • It is not possible to determine whether the additions affect:
  • Customer data ownership or control
  • Permitted data uses
  • Confidentiality obligations
  • Data retention or deletion
  • Disclosure to third parties
  • Security or privacy obligations
  • Liability, indemnification, or compliance requirements
  • Termination rights or post-termination data handling

AI Training and Model-Development Review

The available diff does not show whether customer data may be used to:

  • Train, fine-tune, or improve artificial-intelligence or machine-learning models
  • Develop products, services, algorithms, or analytical tools
  • Create or retain prompts, outputs, embeddings, logs, or other derived data
  • Combine customer data with data from other customers
  • Permit human review or third-party access for model improvement
  • Use data after termination of the agreement
  • Opt the customer in or out of AI-training activities

Accordingly, no conclusion can be reached about changes to AI-training rights or related risks.

Recommended Next Step

Provide the actual 75-word addition, including any surrounding or replaced language. The precise wording is necessary to assess whether the change:

1. Grants a new license or broadens existing data-use rights;

2. Allows use of customer data for AI training or model improvement;

3. Treats de-identified, aggregated, or derived data as outside customer restrictions;

4. Removes consent, notice, or opt-out requirements; or

5. Expands the provider’s ability to retain or disclose data.

Between 2019-03-11 and 2020-10-20 · Privacy Statement EU/UK

grew 2.9% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2018-04-03 and 2018-07-02 · Privacy Statement EU/UK

grew 22.1% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2016-04-03 and 2018-03-18 · Terms of Use

grew 2.8% · Reconstructed from Internet Archive captures

Summary

Scope of the Diff

The provided diff states only:

> “Added approximately 51 words to the document”

It does not include the actual added language, deleted language, or replacement text.

Important Legal Changes

No specific legal changes can be identified from the information provided. In particular, it is not possible to determine whether the added language affects:

  • Customer obligations or rights
  • Data ownership or licensing
  • Confidentiality
  • Privacy or security commitments
  • Liability, indemnification, or warranties
  • Termination rights
  • Use of subcontractors or service providers
  • Compliance with applicable laws

AI Model Training and Customer Data

The diff does not reveal whether customer data may be:

  • Used to train, fine-tune, or improve artificial-intelligence models
  • Combined with other customers’ data for model development
  • Reviewed by humans for model training or quality assurance
  • Retained after termination for training or research
  • Shared with affiliates, vendors, or model providers
  • Used in de-identified, aggregated, or identifiable form
  • Excluded from training unless the customer opts in or opts out

Accordingly, no conclusion can be reached about whether the document introduces a new permission to train AI models on customer data, expands an existing permission, or imposes new restrictions.

Risk Assessment

The principal risk is that the actual 51-word addition may contain a broad data-use authorization that is not visible here. Any language granting rights to “use,” “process,” “analyze,” “improve,” or “develop” services should be reviewed carefully to determine whether it includes AI training and whether those rights survive termination.

Information Needed

Please provide the actual 51 words added, together with any surrounding sentence or paragraph. The full redline is preferable, because the legal effect may depend on definitions, exceptions, consent requirements, and other provisions elsewhere in the agreement.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free