Monitored company
Splunk
clause.watch tracks 2 legal documents published by Splunk, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy
Cisco Privacy Statement — User-Friendly Overview
> Scope: Applies to Cisco websites, services, events, support interactions, and other “Solutions” that link to it. A product-specific privacy notice takes priority if it conflicts with this statement. The U.S.-English version controls over translations. Effective revision: April 29, 2026.
1. Data Collection and Use
Information Cisco may collect
Depending on the service and context, Cisco may collect:
- Identity and contact data: name, address, email, phone number, account and subscription details.
- Account data: login credentials, account numbers, and passwords.
- Communications: audio, video, text, forum posts, social-media information, and customer-support interactions.
- Financial data: bank-account and payment-card information.
- Business and preference information: professional interests, opinions, customer relationship records, survey responses, and event participation.
- Technical and usage data: IP and MAC addresses, device identifiers, telemetry, clickstream activity, and information about how websites and Solutions are used.
- Automatically collected data: cookies, pixels, tags, web beacons, embedded links, and similar technologies.
Cisco may obtain information directly from users, automatically through its services, from “trusted” third parties, or through vendors acting on Cisco’s behalf. Data linked with personal information is treated as Personal Data.
Purposes
Cisco may use data to:
- Create and administer accounts, process orders and payments, and deliver services.
- Provide customer support, events, training, certifications, and communications.
- Improve, personalize, analyze, secure, and troubleshoot websites and Solutions.
- Send marketing, satisfaction surveys, and partner communications.
- Protect Cisco, users, systems, property, and other parties.
- Meet legal, compliance, dispute-resolution, and business-retention requirements.
Risk to note: The purposes are broad, including “other legitimate purposes permitted by applicable law,” which gives Cisco substantial flexibility.
2. User Rights and Choices
Where applicable law permits, users may request:
- Access to their Personal Data.
- Correction of inaccurate data.
- Deletion or suppression.
- Objection to certain processing.
- Changes to marketing and communication preferences.
Requests may be submitted through Cisco’s Privacy Request form, Cisco’s profile-management tools, or the listed postal addresses. Cisco says it will generally respond within 30 days, or within the period required by applicable law.
If Cisco acts as a data processor for a customer, users must generally exercise rights through that customer, which is the data controller.
Marketing choices include email unsubscribe links, SMS “STOP,” and Privacy Requests. These choices generally do not stop required service, security, administrative, or legal communications.
California residents have additional rights, including access, correction, deletion, opting out of “sale” or “sharing,” and nondiscrimination. Cisco states it does not sell Personal Data in the traditional sense, but cookie-based advertising and sharing may still be relevant to opt-out rights. Cookie choices may need to be repeated for each Cisco website, browser, and device.
3. Third-Party Sharing
Cisco may share Personal Data with:
- Cisco affiliates worldwide.
- Business partners, vendors, contractors, hosting providers, payment processors, support providers, and authorized agents.
- Partners or vendors for their own marketing, unless the user opts out.
- Third-party app developers, with permission, for app usage and performance data.
- Parties involved in a merger, acquisition, financing, restructuring, or asset sale.
- Government authorities, law enforcement, or others where legally required or necessary to protect rights, safety, or property.
- Recipients of aggregated, anonymized, or de-identified information.
Data may be transferred to and stored in the United States and other countries, potentially with different privacy protections. Cisco relies on mechanisms such as Binding Corporate Rules, Standard Contractual Clauses, the Data Privacy Framework, and other approved safeguards.
4. AI/ML Training
The statement does not say that Personal Data is used to train artificial-intelligence or machine-learning models, nor does it expressly prohibit such use. It refers generally to analyzing, improving, personalizing, and enhancing services. Users should review any product-specific notice or AI terms before submitting sensitive information.
5. Key User Obligations and Restrictions
- Keep Personal Data accurate and current.
- Obtain permission before giving Cisco another person’s information.
- Avoid posting confidential or sensitive information in Cisco forums, communities, or chat rooms; posts may be broadly visible and Cisco disclaims responsibility for information users choose to submit there.
- Review separate privacy policies for linked third-party websites, apps, and services.
- Manage cookies and marketing preferences if desired.
- Continued use after policy changes means acceptance of the revised statement.
6. Liability and Disputes
This document is primarily a privacy notice and does not provide a comprehensive warranty disclaimer, damages cap, governing-law clause, or general limitation of liability. Those terms may appear in the applicable Cisco service agreement or product terms.
For privacy complaints, users may contact Cisco, their local data-protection authority, or—under certain Data Privacy Framework circumstances—JAMS and potentially binding arbitration for unresolved residual claims. Cisco states it uses reasonable physical, technical, and organizational safeguards, but it does not guarantee absolute security.
7. Changes
Cisco may revise the statement by posting an updated version and revision date. For material changes, it may also provide website notices or email notifications. Continued website use after revisions take effect constitutes acceptance. Users should periodically check the statement and any product-specific notices.
Website Terms of Use
Splunk Website Terms of Use — User Overview
*This summary addresses the Terms provided, last updated May 8, 2024. It is not a substitute for reviewing Splunk’s separate Privacy Policy or any service-specific agreement.*
1. Data Collection and Usage
The Terms themselves do not specify exactly what personal data Splunk collects, retention periods, cookies, analytics, or purposes of processing. They state that registration and other personal data are governed by Splunk’s separate Privacy Policy, which is incorporated into the Terms.
The Terms indicate that Splunk may receive:
- Registration information, including information needed to create and maintain an account
- Account credentials, such as usernames and passwords
- Content or information you submit, upload, email, post, or transmit
- AI Search inputs, including text, instructions, and other materials
- Usage-related information associated with account access and Site interactions
Splunk may monitor access to the Site and Contributions, and may disclose Contributions and the circumstances of their transmission to operate the Site, protect users or Splunk, comply with legal obligations, or enforce the Terms.
Practical risk: Do not submit confidential, sensitive, proprietary, or personal information unless a separate agreement expressly protects it. The Terms characterize ordinary Contributions as non-confidential.
2. User Rights Regarding Data
The Terms provide no detailed rights to access, correct, delete, restrict, export, or object to processing. Those rights, if available, must be determined from the Privacy Policy and applicable law, such as the GDPR or California privacy laws.
You retain ownership of your AI Search Inputs, but they are treated as Contributions under the Terms. For other Contributions, you must have sufficient rights to grant Splunk the required license.
3. Third-Party Sharing
Splunk may disclose Contributions:
- To operate and provide the Site
- To protect Splunk, its suppliers, licensees, personnel, and users
- To comply with law, government requests, or legal process
- To enforce the Terms or for other stated operational or protective purposes
The Terms do not provide a complete list of service providers, affiliates, advertising partners, or data-transfer practices; those details should be reviewed in the Privacy Policy.
Links to third-party sites and purchasing platforms are governed by those providers’ own terms and privacy policies. Splunk disclaims responsibility for their content, security, and data practices.
4. AI/ML Training
The Terms do not expressly say whether Inputs or other user data are used to train Splunk’s AI models.
However, AI Search Inputs are Contributions, and Contributions receive Splunk a broad, perpetual, irrevocable, worldwide, sublicensable, royalty-free license to use, copy, modify, publish, distribute, display, and otherwise exploit them. This language could permit broad internal or commercial use, although it does not specifically mention model training.
AI Search Outputs are treated as Splunk-owned Content. Outputs may be inaccurate, biased, harmful, non-unique, or similar to outputs generated for other users. Users must independently review them and may not use AI Search to develop competing machine-learning products or models.
5. Key User Obligations and Restrictions
Users must:
- Provide accurate, current registration information
- Keep credentials confidential and promptly report unauthorized access
- Comply with applicable laws, export controls, and sanctions
- Obtain rights to anything submitted as a Contribution
- Review AI outputs for accuracy, legality, bias, and permitted use
- Avoid sensitive or confidential information in AI Search Inputs
Users may not:
- Upload unlawful, harmful, defamatory, infringing, obscene, or malicious material
- Harvest other users’ personal data
- Spam, phish, impersonate others, hack, disrupt, or introduce malware
- Scrape, data-mine, mirror, frame, or systematically download Site content
- Copy, reverse engineer, modify, resell, or commercially exploit the Site or its Content without authorization
Splunk may remove Contributions or terminate access at any time, with or without notice.
6. Liability and Disputes
The Site and AI Search are provided “as is” and “as available,” without warranties regarding availability, accuracy, security, or fitness for a particular purpose.
Splunk broadly excludes liability for consequential, punitive, incidental, and similar damages, including loss of data, profits, use, or security. Its maximum liability is generally limited to the amount you paid Splunk to access and use the Site.
You must indemnify Splunk for claims arising from your Contributions, violations of the Terms, unlawful use, or AI Search use and Outputs. Disputes are governed by California law and must be brought in courts located in San Francisco County, California. There is no arbitration clause in the provided Terms.
7. Changes to the Terms
Splunk may change the Terms at its discretion. Changes become effective when posted. Account holders may be notified:
- When logging in; or
- By email
Account holders are deemed to accept changes by continuing to use the Site or by failing to request account termination within seven days after notice. Service-specific rule changes are posted in the relevant location and linked or referenced from the service’s main page.
Change history
2026-08-31 · Privacy
Summary of Important Changes
1. Privacy Statement effective date changed
- Previous wording: The Cisco Privacy Statement was effective as of April 29, 2026.
- New wording: It is effective as of August 18, 2026.
- The notice also links to the previous version.
Risk/impact:
The new effective date may change which privacy terms govern data collected on or after August 18, 2026. Customers should compare the full prior and revised Privacy Statements, particularly for changes involving data collection, sharing, retention, rights, international transfers, and AI-related processing. The diff alone does not show substantive changes to those provisions.
2. New cookie consent and preference-management language
The update adds a detailed cookie notice and consent-management interface. It states that:
- Cisco uses cookies to optimize website use.
- Third-party cookies are used for advertising and analytics.
- Visitors may accept, reject, or manage cookie categories.
- Cisco honors an applicable opt-out preference signal.
- Selecting only “Strictly Necessary Cookies” constitutes a request that Cisco not sell or share personal data.
- Blocking cookies may affect website functionality and services.
Risk/impact:
The language expressly acknowledges potential sale or sharing of personal data through cookies and targeted advertising. Third-party advertising partners may use targeting cookies to build profiles of users’ interests and display advertisements on other websites. This may create regulatory compliance obligations, including honoring opt-out rights and maintaining appropriate consent records.
3. Expanded descriptions of cookie categories
The new text describes:
- Strictly Necessary Cookies: Required for site operation, login, forms, and privacy preferences.
- Performance Cookies: Collect site-performance and usability metrics, including page visits, traffic sources, error messages, and potentially replays of visitor interactions.
- Targeting Cookies: Set by advertising partners and used for interest-based advertising across websites.
- Functional Cookies: Provide enhanced functionality and personalization and may be supplied by third parties.
Risk/impact:
Session-replay functionality may capture detailed user interactions and could create privacy or security concerns if sensitive information is recorded. Third-party cookies and cross-site interest profiling may also increase tracking, disclosure, and consent risks.
4. AI-model training
- No express change concerning the use of customer data to train AI models appears in this diff.
- The additions refer to analytics, advertising, personalization, and website usability, but do not state that customer data, prompts, content, telemetry, or other information may—or may not—be used to train AI models.
Key limitation:
The revised effective date indicates that other provisions may have changed outside the supplied excerpt. The full Privacy Statement should be reviewed for any AI-training language not included here.
2026-08-22 · Privacy
Summary of Important Changes
1. Removal of detailed cookie-consent language
The diff appears to remove a substantial cookie notice and consent-management section, including:
- Statements that cookies are used for website optimization, advertising, and analytics.
- Information about third-party cookies.
- Links or references to the Privacy Statement and Cookie Notice.
- Cookie preference controls, including “Reject,” “Accept,” and “Manage cookie settings.”
- Recognition of opt-out preference signals.
- Separate categories for strictly necessary, performance, targeting, and functional cookies.
- Explanations of the purposes and effects of each cookie category.
- The statement that selecting only strictly necessary cookies requests that Cisco not sell or share personal data.
2. Potential legal and compliance risks
Removing this language may create several risks if the website continues using cookies or similar tracking technologies:
- Insufficient notice: Users may no longer receive clear information about what data is collected and why.
- Consent deficiencies: The removed controls and category-specific choices may weaken evidence of valid consent, particularly for targeting and performance cookies.
- Opt-out handling: Removing the express statement that opt-out preference signals are honored could create uncertainty regarding compliance with applicable privacy laws.
- Sale or sharing disclosures: The removed language addressed whether selecting certain settings constitutes a request not to sell or share personal data. Its removal may require replacement disclosures elsewhere.
- Third-party tracking: The removed description of advertising partners’ ability to build interest profiles may obscure the involvement of third parties and the nature of disclosures.
- User-experience and transparency concerns: Users may not be told that blocking cookies can affect website functionality.
3. Data collection language retained or introduced
The remaining text refers to “standard information” sent by a browser, including:
- IP address;
- MAC address;
- Clickstream behavior; and
- Telemetry.
This language is broad and may encompass personal information or identifiable device information, depending on applicable law and how the data is combined or used. The purposes and retention periods for this information are not stated in the excerpt.
4. AI-model training
No express provision in the diff states that customer data, telemetry, clickstream data, cookie data, or other personal information may be used to train, fine-tune, evaluate, or improve AI models.
However, the absence of an AI-training restriction or clarification means the excerpt does not confirm that such data is excluded from model training. If AI-related processing is possible elsewhere in the agreement or privacy documentation, the parties should verify that the permitted uses, data categories, de-identification standards, retention, and opt-out rights are stated clearly.
2026-08-21 · Privacy
Summary of Important Changes
1. Expanded cookie and tracking disclosures
The added text introduces a detailed cookie-consent notice covering:
- Strictly necessary cookies
- Performance and analytics cookies
- Targeting and advertising cookies
- Functional and personalization cookies
- Third-party cookies
- Cookie settings, consent management, and opt-out mechanisms
It specifically states that cookies may collect information about browser activity, device identifiers, page visits, traffic sources, error messages, and interactions with the website.
2. New third-party advertising and analytics uses
The addition states that Cisco uses third-party cookies for advertising and analytics. Targeting cookies may allow advertising partners to:
- Build profiles of users’ interests;
- Use uniquely identifying browser or device information; and
- Display targeted advertisements on other websites.
This expands or clarifies the potential sharing of browsing and device information with advertising partners. Depending on applicable law, this activity could constitute “selling” or “sharing” personal information for cross-context behavioral advertising.
3. Broader behavioral monitoring
The new language says performance cookies may enable “replay of a visitor’s interactions” with the website. This may involve detailed monitoring of clicks, navigation, page behavior, and other session activity. The provision does not identify the specific replay technology, retention period, or whether sensitive information is filtered before recording.
4. Consent and opt-out mechanics
The text adds a consent-management interface allowing users to:
- Reject or accept cookies;
- Select cookie categories;
- Manage settings;
- Have an opt-out preference signal honored; and
- Request that Cisco not “sell or share” personal data by selecting strictly necessary cookies only.
Potential risks include ambiguity about whether the interface records affirmative consent, whether previously placed cookies are deleted after rejection, and whether all vendors honor the user’s choice. Blocking non-essential cookies may also impair website functionality.
5. Data-use and privacy risks
The added text refers users to the Privacy Statement and Cookie Notice but does not itself specify:
- Data retention periods;
- The identity of advertising and analytics providers;
- International transfers;
- Whether cookie-derived data is combined with account or customer data; or
- The legal basis for processing.
6. AI model training
No express change concerning the use of customer data to train AI models appears in this diff. The added cookie language addresses advertising, analytics, personalization, and website performance, but does not authorize or prohibit using customer data, telemetry, or cookie-derived information to train, fine-tune, or evaluate AI models. Any AI-training rights must therefore be assessed under other provisions of the agreement or Privacy Statement.
2026-08-20 · Privacy
Summary of Important Changes
1. Large deletion of cookie notice and consent-management language
The diff removes an extensive cookie banner and consent-management section, including:
- Disclosure that cookies are used for website optimization, advertising, and analytics.
- Reference to Cisco’s Privacy Statement and Cookie Notice.
- Cookie preference controls, including “Reject,” “Accept,” and “Manage cookie settings.”
- Recognition of opt-out preference signals.
- Explanations of cookie categories:
- Strictly Necessary Cookies
- Performance Cookies
- Targeting Cookies
- Functional Cookies
- The statement that selecting only strictly necessary cookies constitutes a request not to sell or share personal data.
- Explanations of behavioral replay, traffic measurement, targeted advertising, personalization, and third-party cookie use.
2. Privacy and compliance risks
Removing this material may create several risks, depending on where the revised text is used:
- Reduced transparency: Users may no longer be told clearly what tracking technologies are used, why they are used, or which third parties receive related data.
- Consent risk: The deleted language described mechanisms for accepting, rejecting, or customizing cookies. Its removal could undermine evidence of valid consent where consent is legally required.
- Opt-out risk: The deletion removes the statement that opt-out preference signals are honored and the explanation that restricting cookies can constitute a request not to sell or share personal data.
- Targeted advertising disclosure: The removed text expressly described advertising partners’ ability to build interest profiles and show advertisements on other websites. Omitting this may make the privacy disclosure incomplete.
- Functional impact: Users are no longer informed that blocking certain cookies may impair website features or services.
- Regulatory inconsistency: The change may create inconsistencies with applicable privacy laws or with the company’s separate Privacy Statement, Cookie Notice, or consent-management practices.
3. Data collection wording
The excerpt retains references to browser-provided information, including clickstream behavior and telemetry. However, “[IP]” appears to be deleted from “Internet Protocol [IP] address.” If literal, the resulting wording may be grammatically defective and may remove an express disclosure that IP addresses are collected. IP addresses can constitute personal information under many privacy laws.
4. AI-model training
No express addition or deletion addresses:
- Use of customer data to train, fine-tune, or evaluate AI models;
- Whether customer content is used for model improvement;
- Opt-out rights concerning AI training;
- Human review or data retention for AI systems; or
- Restrictions on using confidential or personal data in AI models.
Accordingly, the diff shows no identifiable change to AI-training rights or practices. However, if the deleted cookie or analytics language was intended to cover telemetry used for AI development, its removal makes that purpose less transparent rather than affirmatively prohibiting such use.
2026-08-18 · Privacy
Structured Summary of Important Changes
1. SMS opt-in and consent data sharing
The revised language replaces a general reference to the Cisco Privacy Statement with a detailed SMS policy. It states that Cisco will not share a customer’s SMS campaign opt-in data with third parties for purposes unrelated to providing the messaging service.
However, the policy permits sharing of:
- The customer’s SMS opt-in or consent status; and
- Other personal data associated with the SMS service,
with third parties that help deliver text messages, including platform providers, phone companies, and other messaging vendors.
The policy expressly excludes “text messaging originator opt-in data and consent” from this sharing and states that this information will not be shared with third parties.
Risk: The distinction between protected opt-in/originator data and shareable “consent status” or other personal data may be unclear. The language could allow disclosure of related customer information to a relatively broad class of service providers. The policy should clarify exactly what data is shared, for what purposes, and whether vendors may use it for their own purposes.
2. Privacy Statement versioning and notice
The revised text identifies the Cisco Privacy Statement as revised and effective April 29, 2026, and provides a link to the previous version.
Risk: The replacement appears to alter the surrounding “accept and agree” notice. Customers may be deemed to accept revisions without a clearly stated effective-date process, affirmative consent requirement, or explanation of which terms changed. The inclusion of “previous version” language is helpful for comparison but does not itself resolve notice or consent concerns.
3. Cookies and online tracking
The revised material adds or restores extensive cookie-consent language covering:
- Strictly necessary cookies;
- Performance cookies, including interaction replay and behavioral analysis;
- Targeting cookies used by advertising partners to build interest profiles and show advertisements on other websites; and
- Functional cookies supplied by Cisco or third parties.
It also states that selecting strictly necessary cookies only is a request that Cisco not sell or share personal data, and that Cisco honors opt-out preference signals.
Risks:
- Performance tools may record detailed browsing behavior and session interactions.
- Targeting cookies may enable cross-site profiling by advertising partners.
- The relationship between cookie consent, “sale or sharing,” and applicable privacy rights is not fully explained.
- Blocking cookies may impair website functionality or services.
4. AI model training
No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models is identifiable in the supplied diff. The revised text refers to analytics, behavioral analysis, advertising, and service delivery, but does not expressly authorize or prohibit AI training.
Important limitation: The diff is heavily corrupted by inserted website code and concatenated content. Because of that formatting, an AI-training provision could be omitted or obscured. The complete revised Privacy Statement and any product-specific AI terms should be reviewed separately.
5. Drafting and implementation concerns
The diff contains substantial apparent website code, language-selector content, duplicated text, and malformed replacements. This creates a risk that the published policy could be confusing, technically defective, or fail to present legally required notices accurately. A clean, human-readable version should be reviewed before publication.
Between 2023-03-06 and 2024-05-14 · Website Terms of Use
No
2024-05-08 · Website Terms of Use
The publisher records this document as revised on this date (“LAST UPDATED: May 8, 2024”).
Between 2023-10-22 and 2024-04-13 · Privacy
Summary
Key Limitation
The diff only states that approximately 731 words were removed. It does not identify which provisions were deleted or provide the deleted text. As a result, it is not possible to determine the specific legal changes or assess whether customer data may now be used to train AI models.
Potential Risks From Deletions
Removing language from a contract could materially affect:
- Customer data rights: Deleted restrictions on access, copying, retention, disclosure, or other uses of customer data may expand the provider’s practical rights.
- AI model training: Deleted prohibitions, consent requirements, or limitations concerning machine learning, artificial intelligence, model development, or service improvement could permit broader use of customer data—including potentially for training or fine-tuning AI models.
- Confidentiality: Deleted confidentiality obligations, permitted-use limitations, or data-handling requirements may weaken protections for customer information.
- Data retention and deletion: Removed deletion, return, or retention-period provisions could allow data to be kept longer than previously permitted.
- Security and compliance: Deleted security commitments, breach-notification obligations, audit rights, or regulatory compliance language could reduce the customer’s protections and remedies.
- Liability and indemnification: Deletions may remove liability caps, exclusions, indemnities, or remedies that allocated risk for misuse or unauthorized disclosure of data.
- Subprocessors and third parties: Removed approval, notice, or flow-down requirements could allow broader sharing with affiliates, vendors, or other third parties.
AI-Training Assessment
No definitive conclusion can be reached about AI training from the information provided. In particular, the diff does not show whether the removed text included:
- An express ban on using customer data to train AI models;
- A requirement for the customer’s prior consent;
- A distinction between customer content, prompts, outputs, metadata, and de-identified data;
- Limits on using data to improve generally available models;
- Commitments to delete data from training datasets or model-related systems; or
- Rights to opt out of training or service-improvement programs.
Recommended Next Step
Provide the actual 731-word deletion, or a complete before-and-after version of the affected provisions. The deleted language should be reviewed specifically for terms such as “train,” “training,” “fine-tune,” “machine learning,” “artificial intelligence,” “improve,” “develop models,” “content,” “inputs,” “outputs,” “de-identified,” and “service improvement.”
Between 2023-06-01 and 2023-10-22 · Privacy
No
Between 2022-03-11 and 2023-03-06 · Website Terms of Use
No
Between 2021-02-26 and 2022-03-11 · Website Terms of Use
No
Between 2019-04-01 and 2021-02-26 · Website Terms of Use
No
Between 2015-03-25 and 2018-07-02 · Website Terms of Use
No