Monitored company
Sitecore
clause.watch tracks 2 legal documents published by Sitecore, re-reading each one every six hours. Below is what each document covers, in plain English.
Legal Hub
Privacy
Sitecore Privacy Policy — User Overview
Effective date: March 24, 2026
This policy applies to Sitecore’s websites, products, services, events, training, marketing, and customer-support activities. It incorporates the Terms of Use and Cookie Policy.
1. Data Collection and Use
Information collected
Sitecore may collect:
- Contact and business information: name, job title, email, physical address, employer and professional details.
- Account information: user ID, password, profile details, account balances, purchase history and license information.
- Payment information: billing and transaction details for paid services, events and training. Sitecore states that credit-card information is handled by a third-party processor and is not stored by Sitecore.
- Communications: messages submitted through forms, chat, email, phone calls and support channels. Sitecore may retain communications it receives.
- Technical and usage data: IP address, browser and operating system, device identifiers, login activity, browsing and search history, referring URLs, cookies and similar tracking data.
- Location information: approximate location inferred from IP address or device permissions.
- Marketing and third-party data: information from public databases, partners, lead-generation companies, social-media platforms and enrichment services.
- Event information: registration details, attendance, voice and image recordings or other information collected at events.
- Inferences: conclusions about interests, preferences, company information or likely product relevance.
Sitecore uses this information to provide and support services, process transactions, manage licenses, prevent fraud, improve products and websites, personalize experiences, conduct research and analytics, send marketing, maintain security, recruit employees and comply with legal obligations.
Sitecore says it generally does not collect sensitive data or protected health information unless specifically agreed in a contract or order form.
Tracking technologies
Cookies, pixels, web beacons, device identifiers and advertising tags may recognize users across services and devices, measure communications, personalize content and support targeted advertising. Cookies can be managed through Sitecore’s cookie controls or browser/device settings, although disabling them may reduce functionality.
2. User Rights and Choices
Depending on location and applicable law, users may have the right to:
- Access personal information.
- Correct inaccurate or incomplete information.
- Delete information, subject to legal and operational exceptions.
- Receive portable, machine-readable data.
- Restrict or object to processing.
- Withdraw consent where processing relies on consent.
- Opt out of marketing communications.
- Opt out of the “sale” or sharing of information for cross-context behavioral advertising, particularly under certain U.S. laws.
- Appeal a denied U.S. privacy request.
- Avoid discrimination for exercising privacy rights.
Requests may be submitted through Sitecore’s privacy-rights form, privacy@sitecore.com, or the toll-free number 1 (800) 461-9330. Sitecore may require identity verification and may refuse requests it cannot verify or is not legally required to fulfill.
Transactional, security, support, software-update and legally required communications generally cannot be disabled through the marketing unsubscribe process.
3. Third-Party Sharing
Sitecore may share information with:
- Sitecore affiliates worldwide.
- Service providers and subprocessors supporting customer service, outsourcing, analytics, data visualization, payments, marketing and operations.
- Advertising and ad-technology providers, including providers using cookies, hashed identifiers and remarketing tags. Sitecore states that it may “sell” or share information for targeted advertising under certain U.S. definitions.
- Event sponsors, partners and conference providers, which may contact attendees under their own privacy policies.
- Technology and implementation partners involved in joint sales or promotions.
- Social-media platforms and other linked third-party services.
- Buyers or prospective buyers in a merger, sale or change of control.
- Authorities or other organizations where required by law, fraud prevention needs or protection of legal rights and safety.
International transfers may occur using mechanisms such as EU Standard Contractual Clauses, UK and Swiss addenda, and the Data Privacy Framework.
4. AI/ML Training
Sitecore and its providers may use AI or generative AI to analyze data, identify trends, predict outcomes, generate content and assist customer support.
Important limitations stated in the policy:
- Marketing AI tools may process limited personal data but are not used to train or improve their models.
- Customer-support interactions are not used for model tuning, training or secondary purposes, unless separately assessed, disclosed and legally permitted.
- AI tools assist human support personnel and are not intended to make legally or similarly significant decisions.
- Users may request interaction with a human agent where appropriate.
The policy does not provide a blanket assurance that every third-party AI system is technically incapable of retaining data; users should review applicable service agreements and subprocessors.
5. Key User Obligations
Users are responsible for:
- Protecting passwords and account credentials.
- Keeping account information accurate and current.
- Obtaining appropriate consent before submitting another person’s information or transferring it across borders.
- Obtaining required consent before submitting customer end-user data through support channels.
- Reviewing third-party, partner, event-sponsor and social-media privacy policies.
- Complying with Sitecore’s Terms of Use and license requirements.
6. Security, Liability and Disputes
Sitecore describes safeguards including encryption, firewalls, access controls, physical security and monitoring. However, it expressly states that no internet transmission is completely secure and does not guarantee that breaches, hacking, loss or unauthorized access will never occur.
The policy does not itself provide a comprehensive liability cap or general damages limitation; those terms may appear in the Terms of Use or customer contract. Sitecore disclaims responsibility for information shared with third parties through an account connection authorized by the user.
Users should first contact Sitecore at privacy@sitecore.com. EU/UK/Swiss individuals may escalate unresolved matters to their local data-protection authority, and certain Data Privacy Framework complaints may ultimately qualify for binding arbitration.
7. Policy Changes
Sitecore may revise the policy for legal, technological or business reasons. Changes become effective when posted online. The updated effective date appears at the top, and continued use of Sitecore sites or content after publication is treated as acceptance of the revised policy.
Change history
2026-09-06 · Privacy
2026-09-05 · Legal Hub
Summary
The diff only states that approximately 26 words were removed, but does not identify:
- Which words were deleted;
- The surrounding contract language;
- Whether the deletions were replaced with different wording; or
- Whether the changes concern data use, artificial intelligence, confidentiality, security, or other obligations.
AI Training and Customer Data
No conclusions can be drawn about whether the agreement now permits, restricts, or changes the use of customer data to train AI models. The missing text could potentially affect issues such as:
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether de-identified, aggregated, or anonymized data may be used;
- Whether prompts, outputs, usage data, or metadata are retained for training;
- Whether customer consent is required;
- Whether an opt-out right exists;
- Whether data may be shared with affiliates or third-party AI providers; and
- Whether confidentiality and security obligations apply to model training.
Risk Assessment
Because the actual deleted language is not provided, the legal impact and risk level cannot be assessed. A deletion could be immaterial, or it could remove an important customer protection—particularly if it eliminates a prohibition, consent requirement, data-use limitation, or obligation to delete customer data.
Information Needed
Please provide the actual before-and-after wording, or the full redline showing the 26 deleted words and their surrounding provisions. The clauses addressing data ownership, permitted data use, AI training, confidentiality, security, retention, and subcontractors should be included.
2026-09-05 · Legal Hub
Key Changes
1. Revised agreement introduction and terminology
- The opening provisions have been substantially redrafted.
- “Master subscription terms and conditions” is replaced with “Master Terms”, expressly including the Data Processing Addendum (“DPA”) and other Addendums.
- The agreement is now described as being entered into by Sitecore and Customer as of the date the last party signs the first Order—the “Effective Date.”
2. Clearer framework for Orders
- The revised language expressly states that the Master Terms apply to all Orders entered into between Sitecore and Customer.
- It adds or clarifies that:
- “Order” is defined in Section 1.
- All Orders are governed by the terms and conditions contained in the Master Terms.
- This may broaden or reinforce the application of the Master Terms to future Orders, rather than limiting them to Orders existing at the initial signing.
3. DPA and Addendums incorporated into the Agreement
- The revised text more clearly states that the Master Terms, DPA, and all Orders together constitute the “Agreement.”
- Because the DPA and Addendums are expressly incorporated, their data-processing, security, liability, and other obligations may become contractually binding across all Orders.
- Customers should confirm:
- Which version of the DPA applies;
- Whether Addendums can be updated or replaced;
- Which document controls if the Master Terms, DPA, and an Order conflict.
4. Product and service descriptions
- The substantive descriptions of Sitecore’s SaaS, hosted, and on-premise software offerings appear largely unchanged.
- References to Sitecore’s products and services have been standardized grammatically from “Sitecore’s” to “Sitecore’s” using a straight apostrophe. This does not appear to change legal meaning.
AI Training and Customer Data
- No express change concerning the use of Customer data to train AI models is visible in this diff.
- The excerpt does not add language authorizing Sitecore to:
- Use Customer Data or Usage Data to train, fine-tune, or improve AI models;
- Share Customer Data with model providers;
- Use de-identified, aggregated, or derived data for AI training; or
- Retain data for model-training purposes after termination.
- However, because the DPA and Addendums are expressly incorporated into the Agreement, any AI-training provisions located there may now apply more clearly to all Orders. Those documents should be reviewed separately.
Overall Risk Assessment
The main changes appear structural and definitional rather than substantive. The principal customer risks are the broader, explicit application of the Master Terms to all Orders and the incorporation of the DPA and Addendums. The diff supplied does not itself establish any new AI-training permission.
2026-09-04 · Privacy
2026-09-03 · Legal Hub
Key Changes and Risks
1. Agreement structure and scope
- The introductory language is substantially rewritten to clarify that the Master Terms apply to Orders between Sitecore and Customer.
- The Master Terms, the Data Processing Addendum (DPA), and all Orders are now expressly defined together as the “Agreement.”
- Orders may cover multiple categories of Sitecore products and services, rather than simply referring generally to Sitecore products or services.
Risk: Incorporating the DPA and all Orders into the defined “Agreement” may make obligations in those documents contractually binding as part of the main agreement. The revised text should be reviewed for conflicts among the Master Terms, DPA, Orders, and addenda, including any order-of-precedence provision.
2. New and expanded product/service categories
The revised structure separately identifies:
- SaaS Products — subscription-based software-as-a-service products, including Sitecore Technology made available with them.
- Hosted Services — platform-as-a-service, infrastructure-as-a-service, and other cloud hosting services.
- Software — subscription-based on-premise software, including patches, updates, and upgrades.
- Consulting Services — professional services provided remotely or onsite.
- Training Services — remote, web-based, onsite, public, customer-specific, and eLearning training.
Each category is subject to a different additional addendum.
Risk: Customers may become subject to different terms depending on the products or services listed in an Order. The inclusion of patches, updates, upgrades, and related technology may broaden what is covered by the applicable terms.
3. Addendum reorganization and renumbering
The addenda have been reorganized as follows:
- Addendum A: SaaS Products and/or Hosted Services
- Gen AI Addendum: Gen AI Functionality
- Addendum B: Software
- Addendum C: Consulting Services
- Addendum D: Training Services
- Addendum E: Governing Law, Jurisdiction, and Geo-Specific Terms
The prior references to Addendum A, B, C, and D have accordingly shifted.
Risk: Cross-references may be inaccurate or create uncertainty if older Orders or incorporated documents refer to the former addendum numbering. Existing customers should confirm which version of each addendum governs.
4. Artificial intelligence and customer data
The diff newly references a “GEN AI ADDENDUM: Additional Terms Relating to Gen AI Functionality” for Orders involving SaaS Products and/or Hosted Services.
However, the supplied changes do not state:
- whether Customer Data may be used to train Sitecore’s or a third party’s AI models;
- whether prompts, inputs, outputs, or usage data may be retained or used for model improvement;
- whether data will be anonymized, aggregated, or shared with third-party AI providers;
- whether Customer consent or an opt-out is required; or
- whether customer-specific models or outputs will be isolated.
Important risk: The new cross-reference signals that AI functionality may be governed by separate terms, but the substantive AI and training provisions are not included in this diff. The Gen AI Addendum should be obtained and reviewed before accepting the revised terms, particularly for any authorization to use Customer Data, personal data, confidential information, prompts, or outputs to train or improve AI models.
2026-09-02 · Privacy
2026-09-02 · Privacy
2026-09-01 · Privacy
2026-09-01 · Legal Hub
Summary
The diff states only that approximately 26 words were added, but it does not include the actual wording of those additions.
Legal and Risk Analysis
- Unable to identify substantive changes: Without the added language, it is not possible to determine whether the amendment changes obligations, liability, confidentiality, intellectual property, data rights, or termination provisions.
- AI-model training: The diff does not reveal whether customer data may be:
- used to train, fine-tune, or improve AI models;
- shared with affiliates, vendors, or other third parties for model development;
- retained after the customer relationship ends;
- aggregated, anonymized, or de-identified for training; or
- excluded from training unless the customer opts in or out.
- Potential risk: If the added words concern AI training or data use, even a short addition could materially expand the provider’s rights to use customer content or personal data. Key issues would include consent, purpose limitation, confidentiality, data ownership, deletion, security, and compliance with privacy laws.
- Contract interpretation: The effect may also depend on where the words were inserted and whether they override or qualify existing provisions.
Information Needed
Please provide the actual 26 added words, together with enough surrounding text to show where they were inserted. A reliable legal analysis cannot be performed from the description of the change alone.
2026-08-31 · Privacy
2026-08-31 · Privacy
2026-08-30 · Privacy
2026-08-29 · Legal Hub
Change Summary
1. Agreement structure and scope
- The introductory language is substantially reorganized and simplified.
- The Master Terms are now expressly stated to apply to Orders between Sitecore and Customer.
- The Master Terms, Data Processing Addendum (“DPA”), and all Orders are expressly defined together as the “Agreement.”
- The revised wording clarifies that Orders may cover different categories of Sitecore products and services, rather than referring generally to products listed in a table.
Risk: The Agreement’s incorporation of the DPA and all Orders may broaden the contractual package. Customers should confirm that every Order and referenced addendum is actually provided, reviewed, and subject to a clear order-of-precedence clause.
2. New product and service classifications
The revised text creates separate categories, each tied to a different addendum:
- SaaS Products: Subscription-based software-as-a-service products, including Sitecore Technology made available with the SaaS Products.
- Hosted Services: Platform-as-a-service, infrastructure-as-a-service, and other cloud-hosting services.
- Software: On-premise subscription-based software, including patches, updates, and upgrades.
- Consulting Services: Professional consulting, whether remote or onsite.
- Training Services: Remote, web-based, onsite, public, customer-specific, and eLearning training.
The addendum mapping is revised as follows:
- Addendum A: SaaS Products and/or Hosted Services
- Addendum B: Software
- Addendum C: Consulting Services
- Addendum D: Training Services
- Addendum E: Governing law, jurisdiction, and geo-specific terms
Risk: The new classifications may affect which legal terms apply to a particular Order. Some services could arguably fit more than one category, creating uncertainty about applicable obligations, warranties, limitations of liability, and data protections.
3. AI-related changes
- A new “GEN AI ADDENDUM: Additional Terms Relating to Gen AI Functionality” is expressly identified.
- The excerpt does not include the substantive Gen AI Addendum provisions.
- No express language in the provided diff states:
- whether Customer Data may be used to train Sitecore’s or third-party AI models;
- whether prompts, inputs, outputs, telemetry, or usage data are retained;
- whether data is used for model improvement;
- whether training is opt-in, opt-out, or automatic;
- whether data is anonymized, aggregated, or shared with AI providers; or
- whether Customer Data is segregated from other customers’ data.
Key risk: Although no direct training authorization appears in this excerpt, the new Gen AI Addendum creates a specific contractual framework that may contain material permissions or restrictions elsewhere. Customers should obtain and review it before enabling any Gen AI functionality, with particular focus on an express prohibition or consent requirement for using Customer Data to train general-purpose or shared AI models.
4. Drafting and implementation concerns
- The diff appears to include duplicated navigation or document-template text, suggesting possible formatting or compilation errors.
- References to Addenda have changed significantly; incorrect numbering or missing attachments could cause incorporation disputes.
- The revised definition of SaaS Products appears to exclude some former hosted-service concepts, which are now separately categorized.
Recommended action: Confirm the final clean version, all addenda, the DPA, and the order-of-precedence provisions before signature or renewal.
2026-08-29 · Privacy
2026-08-27 · Privacy
2026-08-23 · Privacy
2026-08-22 · Privacy
2026-08-21 · Privacy
2026-08-20 · Privacy
2026-08-20 · Privacy
2026-08-19 · Privacy
2026-08-18 · Legal Hub
Summary
Apparent change
- The heading “Training Services” is replaced with “ADDENDUM E: Governing Law, Jurisdiction and Geo-Specific Terms.”
- The deleted text consists entirely of CSS/style rules, including formatting for headings, numbered lists, and bullet lists.
Legal significance
- No substantive contractual terms are shown in this diff.
- The new heading suggests that the relevant section may now be categorized or presented as an addendum addressing:
- Governing law;
- Jurisdiction; and
- Location-specific or geo-specific terms.
- However, the diff does not include the operative provisions under that heading. Therefore, it is not possible to determine whether there has been any actual change to:
- Applicable law;
- Venue or dispute resolution;
- Regional compliance obligations;
- Customer or provider rights; or
- Country-specific data-processing terms.
AI training and customer data
- No change concerning the use of customer data to train AI models is visible.
- The diff contains no language addressing:
- Whether customer data may be used for model training;
- Whether inputs or outputs are retained;
- Opt-in or opt-out rights;
- De-identification or aggregation;
- Human review;
- Ownership of training data or model outputs; or
- Restrictions on using customer content to improve services.
Risk assessment
- Low apparent legal risk from the text shown, because the deleted material appears to be presentation code rather than contractual language.
- Potential review risk: The heading change could signal that substantive geo-specific terms were moved, renamed, or are located elsewhere. The complete addendum should be reviewed to confirm whether governing-law, jurisdiction, or regional data-use provisions have changed.
- If the CSS deletion affects document rendering, some legal text—particularly lists or headings—could display incorrectly, but that is a formatting issue rather than a change in contractual obligations.
2026-03-24 · Privacy
The publisher records this document as revised on this date (“EFFECTIVE DATE: March 24, 2026”).
Between 2024-02-27 and 2024-11-12 · Legal Hub
Summary
The provided diff only states that approximately 55 words were removed, but does not show the actual deleted language or its location in the agreement.
Key Legal Impact
- Cannot determine the substantive changes without seeing the specific text removed.
- The deletion could affect important provisions, including:
- Customer data ownership and usage rights
- Permission to use customer data to train, fine-tune, or improve AI models
- Confidentiality and security obligations
- Data retention and deletion requirements
- Liability, indemnification, or regulatory compliance
- Restrictions on sharing data with service providers or third parties
AI Model Training
No conclusion can be reached about whether the agreement’s treatment of AI training has changed. In particular, the available diff does not show whether language was removed that:
- Authorizes or prohibits training AI models on customer data
- Permits use of customer inputs, outputs, prompts, or usage data for model improvement
- Requires customer consent or provides an opt-out
- Limits training to aggregated, anonymized, or de-identified data
- Grants the provider rights to retain or reuse data after termination
- Addresses ownership of models, improvements, or training outputs
Risk Assessment
The deletion itself may create legal risk if it removes a customer protection, restriction, consent requirement, or provider obligation. However, the direction and seriousness of the risk cannot be assessed from the description alone.
Additional information needed: the actual 55 deleted words, the surrounding unchanged language, and any replacement text.
Between 2024-04-25 and 2024-09-09 · Privacy