clause.watch Contracts Recent changes Start monitoring

Monitored company

Traction Guest

clause.watch tracks 1 legal document published by Traction Guest, re-reading each one every six hours. Below is what each document covers, in plain English.

Terms & Conditions

7,087 characters · Read the original

Terms & Conditions Overview

Important limitation: The material provided is primarily the definitions section and introductory language. It references a Data Processing Addendum (DPA), End User License Agreement, Order Forms, and other addenda that were not included. Those documents may contain the most important privacy, security, payment, termination, and liability terms. The conclusions below are therefore limited to this excerpt.

1. Data Collection & Usage

What may be collected

The agreement defines Customer Data broadly as:

  • Content, materials, data, and information entered into the Products by Authorized Users; and
  • Information otherwise provided to SIS in connection with the Products.

“Personal Data” and “Sensitive Data” are defined by reference to the missing DPA, so the excerpt does not identify specific categories such as names, contact details, identification data, biometric data, or employee information.

How data may be used

SIS may monitor access to and use of the Products. The definitions state that information derived from this monitoring forms part of the SIS Materials, except that it does not include Your Personal Data.

SIS may also use Aggregate Information, meaning information about use of the Products that is aggregated and anonymized and does not include Personal Data, to:

  • Compile statistics;
  • Assess or report on Product performance; and
  • Support the provision and operation of the Products.

Aggregate Information is SIS’s Confidential Information, meaning users may not necessarily control or receive rights in it.

2. User Rights Regarding Data

This excerpt does not specify:

  • Whether Customer Data remains owned by the customer;
  • Whether SIS receives a license to process or use Customer Data;
  • Data access, correction, deletion, portability, or objection rights;
  • Retention periods or deletion after termination;
  • Procedures for responding to data-subject requests; or
  • Security-incident notification obligations.

These issues should be reviewed in the DPA and any applicable Order Form. Customers should confirm whether they act as a data controller/business or processor/service provider under applicable privacy laws.

3. Third-Party Sharing

SIS may use third-party services as part of its SIS Systems, including infrastructure, software, hardware, databases, and networks operated by SIS or third parties.

The agreement also recognizes:

  • Affiliates of SIS;
  • SIS-appointed third parties;
  • Customer Integrations, such as third-party applications, APIs, and SDKs; and
  • Resellers.

However, this excerpt does not explain:

  • Which third parties receive data;
  • Whether subprocessors may access Personal Data;
  • Whether data is transferred internationally;
  • Whether third parties may use data independently; or
  • How customers are notified of subprocessor changes.

The DPA and integration-specific terms are essential for evaluating sharing risks.

4. AI/ML Training

The excerpt contains no express statement that Customer Data or Personal Data will—or will not—be used to train artificial-intelligence or machine-learning models.

The permitted use of anonymized Aggregate Information for statistics and Product operation does not, by itself, clearly authorize AI training. Nevertheless, customers should obtain written confirmation that:

  • Customer Data and Personal Data are excluded from model training unless expressly authorized;
  • Prompts, outputs, recordings, or biometric information are not used for training; and
  • Any anonymization standard is sufficient to prevent re-identification.

5. Key User Obligations and Restrictions

By clicking acceptance, signing an Order Form, or using the Products, the customer agrees to be bound. If signing for an organization, the individual represents that they have authority to do so.

The customer is responsible for:

  • Ensuring Authorized Users—employees, contractors, consultants, agents, or others given access—use the Products appropriately;
  • Complying with applicable laws, including privacy and data-protection laws;
  • Managing Customer Integrations and third-party services; and
  • Paying applicable fees, taxes, levies, and other charges specified in the agreement or Order Form.

Use is prohibited if the customer does not accept the agreement. The excerpt does not list detailed prohibited conduct, security obligations, usage limits, or consequences for misuse.

6. Liability and Disputes

The provided text contains no operative liability cap, warranty disclaimer, indemnity, governing-law clause, arbitration requirement, venue provision, or dispute-resolution process.

Those terms may appear in the omitted sections or addenda. Users should specifically check for:

  • Limits on SIS’s total liability;
  • Exclusions for indirect or consequential damages;
  • Customer indemnity obligations;
  • Service-credit-only remedies;
  • Arbitration or class-action waivers; and
  • Suspension or termination rights.

7. Changes and Notice

The excerpt does not explain how SIS may amend the Terms, DPA, or other policies, nor how users will be notified.

Customers should look for provisions addressing:

  • Email or in-product notice;
  • Advance notice periods;
  • Whether continued use constitutes acceptance;
  • The effect of changes on existing subscriptions; and
  • Whether material changes permit termination.

Bottom line: The main practical risk is that the excerpt incorporates several missing documents. Those documents—not this definitions section—likely determine the customer’s substantive privacy rights, permitted data uses, security protections, liability exposure, and dispute options.

Change history

2026-09-05 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Executive Summary

The diff appears to remove nearly the entire substantive Privacy Notice and replace it with a much shorter navigation/contact section. Because the redline is repetitive and appears to include webpage formatting artifacts, the exact final text should be confirmed against the published version. If intentional, this is a significant reduction in disclosure and creates legal and operational risk.

Important Changes and Risks

1. Substantial removal of privacy disclosures

The deleted text included provisions covering:

  • Types of Personal Data, Aggregate Information, and Cookies collected
  • Collection through account registration, service use, communications, uploads, and location features
  • Purposes for processing, including service delivery, analytics, personalization, fraud prevention, marketing, and corporate transactions
  • Disclosures to affiliates, service providers, business customers, authorities, and transaction counterparties
  • International data transfers
  • Security safeguards and breach procedures
  • Data quality, retention, and deletion
  • Children’s data
  • Individual rights, including access, correction, deletion, restriction, portability, and non-discrimination
  • GDPR processor/controller roles
  • California CCPA disclosures
  • Third-party links and privacy-notice change procedures
  • Contact information for the Global Privacy and Data Protection Officer

Removing these provisions may make it unclear whether the company still claims these practices, and may create compliance gaps under privacy laws requiring notice of collection purposes, legal bases, recipients, retention, transfers, rights, and complaint procedures.

2. Contact information appears to be changed or relocated

The replacement text adds or preserves a contact direction stating that users may contact the company regarding privacy, data protection, and information held about them. It also appears to insert the company’s address and identify a “Data Protection Officer.”

However, the diff is fragmented. It is unclear whether the full postal address, officer title, email address, and telephone number remain in the final notice. The final published notice should clearly identify a functioning privacy contact method and, where required, a representative or Data Protection Officer.

3. Affiliates and corporate scope

The deleted notice identified SIS affiliates and explained that “SIS” included affiliated companies. Removing this language may create uncertainty about which entity is responsible for processing data and which affiliates may receive or process it.

4. AI-model training

No express provision regarding AI training was added or retained in the supplied diff. The deleted notice contains general rights to use Aggregate Information for analytics, research, usage trends, and service improvements, but it does not expressly authorize training artificial-intelligence or machine-learning models.

Accordingly:

  • There is no clear new authorization to use customer data to train AI models.
  • There is also no clear prohibition on such use.
  • If AI training is intended, the notice should expressly address whether Personal Data, customer content, usage data, or anonymized/aggregated data may be used; whether training is for internal or third-party models; opt-out rights; retention; human review; and disclosure to subprocessors.
  • Removing the existing “Aggregate Information” provisions could also eliminate the only language potentially supporting analytics or model-development uses.
5. Effective date and change notice

The deleted text included a last-updated date and a process for notifying users of material changes. Confirm that the replacement notice includes an accurate effective date and legally adequate notice mechanism.

2026-09-04 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Summary of Important Changes

1. Major rewrite and expanded scope

  • The Privacy Notice is marked as updated 2 June 2026, replacing the prior navigation/contact content.
  • The notice now applies to Sign In Solutions Inc. and its listed affiliates, including entities in the United States, United Kingdom, Spain, and Denmark.
  • It covers the company’s websites, software, features, enhancements, and related content, collectively defined as the “Services.”
  • The notice expressly covers both customers/users and visitors accessing Services at a customer’s business location.

2. Expanded data collection and use

The revised notice describes collection of:

  • Personal Data, including identity, contact, location, online identifier, and potentially sensitive identity-related information.
  • Aggregate Information about usage, entered data, accessed features, browsers, and usage patterns.
  • Cookies, beacons, device identifiers, and similar tracking technologies.
  • Location information used for sign-in verification, scheduling, and other functionality.

Purposes are broadly stated and include providing, personalizing, improving, administering, analyzing, and developing the Services, preventing fraud, conducting internal business activities, and evaluating corporate transactions.

3. Customer and business-location sharing

  • SIS may share Personal Data with the customer company when access is provided under a company contract.
  • Visitors may share Personal Data with the business location they visit, and that business’s privacy policy governs its subsequent use.
  • SIS disclaims responsibility for the business’s access, use, or disclosure of visitor data.
  • Independently registered users may have their data shared with their company if they confirm that they wish to do so.

These provisions may create customer compliance obligations, particularly where the customer determines the purposes and retention periods for visitor data.

4. AI-model training

  • No express provision authorizes or prohibits using customer data to train artificial-intelligence or machine-learning models.
  • The broad purposes—such as “improve,” “enhance,” “upgrade,” and “analyze” the Services—could create ambiguity about whether data may be used for model development, especially Aggregate Information.
  • The notice states that Aggregate Information is anonymized and cannot identify individuals, but it does not explain anonymization standards, re-identification safeguards, or whether customer-submitted content is included.
  • Customers should seek clarification or contractual restrictions if they require that Personal Data, customer content, or usage data not be used for AI training.

5. Third-party providers and international transfers

  • SIS may use mail, payment, hosting, and other service providers and may transfer data internationally.
  • A provider list is available only on request.
  • The notice permits sharing with affiliates and providers but restricts them to service-related purposes.

6. Retention, rights, and security

  • Retention periods are generally undefined and depend on business need, legal requirements, account status, and— for visitor data—the business location’s policy.
  • Access and deletion rights are subject to exceptions for sanctions, fraud prevention, and legal requirements.
  • SIS disclaims any absolute security guarantee and limits breach notifications to legally required circumstances.

7. Drafting inconsistency

Although the notice is stated to be updated on 2 June 2026, the body still says it was last updated 20 March 2025. This should be corrected to avoid uncertainty about the operative version.

2026-09-04 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Summary of Changes

Overall Change

  • Approximately 3,532 words were removed from the document.
  • Because the deleted language is not provided, it is not possible to identify the exact clauses, obligations, or rights affected.
  • The removal may materially change the agreement, particularly if the deleted provisions addressed data use, confidentiality, liability, security, or termination.

Customer Data and AI Training

  • No specific conclusion can be reached about AI-model training from the available diff.
  • The deletion could have removed:
  • A prohibition or limitation on using customer data to train, fine-tune, or improve artificial-intelligence or machine-learning models.
  • Customer consent or an opt-out right relating to AI training.
  • Restrictions on using customer content to develop products, algorithms, or services.
  • Commitments to de-identify, aggregate, or delete customer data before using it for AI-related purposes.
  • Disclosure of whether human reviewers or third-party AI providers may access customer data.
  • Rights to customer data, ownership provisions, or limits on the provider’s license.

Key Legal Risks Created by the Deletion

  • Unclear data-use permissions: If the removed language limited permitted uses, its deletion may broaden the provider’s ability to use customer data.
  • Loss of customer protections: Deleted confidentiality, security, deletion, or data-retention obligations could reduce contractual safeguards.
  • Reduced control over AI use: Any deleted consent, notice, approval, or opt-out mechanism could allow AI-related processing without additional customer authorization.
  • Ownership and licensing uncertainty: Removing intellectual-property language may create ambiguity regarding ownership of customer inputs, outputs, derived data, or trained models.
  • Compliance exposure: Deleted restrictions may affect compliance with privacy, sector-specific, or data-localization requirements.
  • Remedies may be reduced: The removed text may have contained indemnities, liability allocation, audit rights, or breach-notification obligations.

Recommended Review

The full prior and revised versions should be compared, or the deleted 3,532 words should be supplied. Particular attention should be given to sections titled:

  • Data use, customer content, or service improvement
  • Artificial intelligence or machine learning
  • Confidentiality and security
  • Intellectual property
  • Privacy and data processing
  • Retention and deletion
  • Liability, indemnification, and termination

Until the deleted language is reviewed, the amendment should be treated as potentially significant and its effect on AI training and customer-data rights as undetermined.

2026-09-03 · Terms & Conditions

shrank 84.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-03 · Terms & Conditions

grew 558.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-03 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Summary

The provided diff contains only the statement:

> “Added approximately 3532 words to the document”

It does not include the actual added, deleted, or replaced contractual language. As a result, the legal changes and risks cannot be reliably analyzed.

AI Training and Customer Data

No conclusions can be drawn about whether the contract now:

  • Permits the provider to use customer data, prompts, outputs, or usage data to train AI models;
  • Uses customer data for model improvement, testing, evaluation, or product development;
  • Applies different rules to personal data, confidential information, or de-identified data;
  • Provides an opt-out or requires affirmative consent;
  • Allows subcontractors or third-party model providers to use the data;
  • Retains data after termination for training or other purposes; or
  • Gives the customer rights to delete data or prevent its inclusion in future model training.

Information Needed

Please provide the full marked-up text, including:

  • Additions shown in {...};
  • Deletions shown in [...]; and
  • Replacements shown in [...] {...}.

Without the underlying language, it is not possible to identify the important contractual changes, allocate risks, or determine whether the new provisions materially expand the provider’s rights to use customer data.

2026-09-02 · Terms & Conditions

shrank 84.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Terms & Conditions

grew 558.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Summary of Changes

Overall change

  • Approximately 3,532 words were removed from the document.
  • No replacement language or specific additions were provided.
  • Because the deleted text is not shown, it is not possible to determine which obligations, rights, definitions, or safeguards were removed.

Customer Data and AI Training

  • The diff does not provide enough information to confirm whether the agreement’s AI-training provisions changed.
  • The deleted text could have included provisions addressing:
  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether customer prompts, inputs, outputs, or personal information are retained;
  • Whether data is anonymized, aggregated, or de-identified before use;
  • Whether the provider may use data for product development or analytics;
  • Opt-out rights or restrictions on using customer data for model training;
  • Ownership and permitted use of model outputs or feedback;
  • Confidentiality, security, deletion, and data-retention obligations.

Potential Legal Risks

  • Loss of protections: If the removed language contained confidentiality, security, deletion, or data-use restrictions, customers may have fewer contractual safeguards.
  • Expanded implied permissions: Removing limitations or conditions could make the provider’s remaining rights appear broader, although the precise effect depends on the surviving language.
  • Unclear AI-data rights: The absence of visible language prevents confirmation of whether customer data can be used to train models or whether such use is prohibited.
  • Compliance uncertainty: Deleted provisions may have addressed privacy laws, regulated data, international transfers, subprocessors, or data-subject rights.
  • Reduced remedies or accountability: The deletion may have removed audit rights, notice requirements, warranties, indemnities, liability protections, or breach obligations.

Conclusion

This diff is insufficient for a reliable clause-by-clause legal analysis. The key issue is to obtain the actual deleted 3,532 words and compare them with the surviving agreement. Particular attention should be given to any language concerning training, improving, or evaluating AI models using customer data, as well as data retention, confidentiality, deletion, opt-out rights, and provider ownership or licensing rights.

2026-09-01 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Summary of Important Changes

1. New, comprehensive Privacy Notice

The prior limited contact/privacy wording is replaced with a detailed Privacy Notice covering:

  • Sign In Solutions Inc. and a specified list of affiliates.
  • Website, software applications, features, enhancements, and related content.
  • Customers, users, and visitors accessing a customer’s business location.
  • Collection, use, disclosure, international transfer, retention, security, and individual rights.

The notice states that use or access of the Services constitutes agreement to the collection, use, and disclosure of Personal Data, Aggregate Information, and Cookies. This may create a broad consent theory, although consent may not be sufficient for all jurisdictions or all processing purposes.

2. Expanded data collection and sharing

The notice expressly covers:

  • Names, contact details, identification numbers, location data, online identifiers, and other identifying or sensitive identity-related information.
  • Cookies, beacons, device identifiers, and activity tracking.
  • Location information, including identifying a user’s sign-in at a specific business location.
  • Data voluntarily entered or uploaded by customers or their users.
  • Information obtained through communications, devices, social media profiles, and third-party providers.

SIS may share Personal Data with customers, affiliates, subsidiaries, hosting providers, payment processors, mail relays, and other service providers. A list of service providers is available only upon request. SIS also reserves the right to disclose information in connection with corporate transactions and legally permitted governmental requests.

3. Customer and visitor data roles

For visitor data collected at a customer’s business location, SIS describes itself as a data processor/service provider and the customer as the controller/business responsible for determining retention and use. However, SIS also acts as a business/controller for some direct interactions with individuals.

Customers should ensure their own privacy notices, contracts, instructions, retention policies, and legal bases align with these arrangements.

4. AI-model training

No express provision authorizes using customer data or Personal Data to train, fine-tune, or evaluate artificial-intelligence or machine-learning models. The notice permits broad uses such as improving Services, analyzing usage, generating reports, and creating enhancements or upgrades. Those provisions could arguably support product-development activities, but they do not clearly authorize AI training or explain whether customer content, visitor data, prompts, outputs, or de-identified data may be used.

Customers should seek written clarification or a contractual restriction expressly addressing AI training and model-development use.

5. Other material risks and inconsistencies

  • Retention periods are generally vague and depend on business need, policy, or the customer’s privacy policy.
  • International transfers are permitted subject to applicable law, but specific transfer mechanisms are not identified.
  • Data security is described generally, with an express disclaimer that security cannot be guaranteed.
  • Certain access and deletion rights are limited for sanction-related information.
  • The notice header says it was updated 2 June 2026, but the body still says March 20, 2025, creating an apparent drafting inconsistency.
  • The notice disclaims responsibility for customers’ and third-party websites’ privacy practices.

2026-09-01 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Structured Summary of Important Changes

1. Major Removal of Privacy Notice Content

The diff deletes nearly the entire substantive Privacy Notice, including provisions addressing:

  • Categories of personal, aggregate, and cookie data collected;
  • When and how data is collected;
  • Purposes for using personal data;
  • Sharing with affiliates, service providers, customers, and authorities;
  • Aggregate and anonymized data use;
  • Lawful bases and data-protection principles;
  • Security measures and international transfers;
  • Retention and deletion;
  • Children’s data;
  • Individual privacy rights;
  • GDPR, CCPA, and service-provider/controller roles;
  • External links and privacy-notice changes.

The additions shown are limited largely to navigation wording (“Addenda”) and revised contact-information text. If this diff reflects the operative document, the Privacy Notice has been substantially stripped of disclosures that would normally be expected under applicable privacy laws.

Risk: Customers and data subjects may no longer receive clear information about how their data is collected, used, shared, retained, transferred, or protected. This may create transparency, notice, contractual, and regulatory-compliance risks. It may also make it unclear whether previously stated limitations—such as not selling personal data or restricting third-party use—continue to apply.

2. Changes to Privacy Contact Information

The previous detailed contact section, including the named Global Privacy Officer, email address, telephone number, and full postal address, is deleted. The replacement appears to retain only partial wording concerning contacting SIS about privacy, data protection, and information held about individuals.

Risk: The notice may no longer provide a complete and reliable method for submitting privacy requests or complaints. This could hinder the exercise of access, deletion, correction, objection, or other statutory rights.

3. AI Model Training and Data Use

No express provision concerning artificial intelligence, machine learning, model training, fine-tuning, evaluation, or use of customer data to train AI models appears in the diff.

However, because the prior provisions governing permitted uses of Personal Data and Aggregate Information are deleted, the revised text does not clearly preserve or restrict those uses. In particular, the deletion removes language that limited personal-data use to stated purposes and described aggregate information as anonymized.

Risk: The diff does not affirmatively authorize AI training, but it also removes important guardrails that could have limited secondary use of customer data. The revised notice should expressly state whether customer data, uploaded content, telemetry, or de-identified/aggregated information may be used to train or improve AI models, and whether customers can opt out.

2026-08-31 · Terms & Conditions

shrank 84.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-31 · Terms & Conditions

grew 558.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-29 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Summary

The diff only states that approximately 3,532 words were added, but does not include the actual added language or identify where it appears in the agreement.

AI Training and Data Use
  • No determination is possible regarding whether the new language:
  • Permits the customer’s data to be used to train, fine-tune, or improve AI models;
  • Allows use of customer prompts, outputs, files, metadata, or usage information for model development;
  • Applies data-use rights to human review, third-party providers, or affiliates;
  • Uses customer data in aggregated, de-identified, or anonymized form;
  • Provides an opt-out, consent requirement, or contractual limits on AI training; or
  • Continues data use after termination.
Other Legal Risks

The actual added provisions are required to assess potential changes concerning:

  • Ownership and licensing of customer data and AI outputs;
  • Confidentiality and privacy obligations;
  • Data retention and deletion;
  • Security and breach notification;
  • Subprocessors and third-party disclosures;
  • Intellectual property indemnities;
  • Liability caps and exclusions;
  • Service suspension or termination rights; and
  • Governing law and dispute resolution.
Conclusion

The supplied diff is insufficient for substantive legal analysis. Please provide the full added text—or the original and revised versions of the agreement—to identify the important legal changes and any new risks, particularly those involving the use of customer data to train AI models.

2026-08-29 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Key Changes and Risks

1. Apparent replacement or deletion of the substantive Privacy Notice

The diff appears to remove almost the entire prior Privacy Notice, including provisions addressing:

  • Categories of Personal Data, Aggregate Information, and Cookies;
  • Collection circumstances and purposes of processing;
  • Sharing with affiliates, customers, authorities, and service providers;
  • International data transfers;
  • Security, retention, and data-quality practices;
  • Data-subject rights;
  • GDPR, CCPA, and data-controller/data-processor roles;
  • External links and notice-change procedures.

Only navigation text, introductory contact wording, and a contact address appear in the replacement. If this reflects the complete new notice rather than a formatting artifact, it creates a significant legal and operational risk: the revised notice may no longer transparently disclose required processing activities or provide legally required privacy information.

2. Changes to navigation and linked documents

The detailed list of linked legal documents is replaced with the shorter term “Addenda.”

Risks:

  • Customers may not know which addenda apply to their services.
  • Important contractual or privacy terms may become harder to locate.
  • Incorporation by reference could be challenged if the applicable documents are not clearly identified or accessible.
  • The “Archive (Aug 2025)” reference appears to remain, which may create uncertainty about which version governs.

3. Contact information and privacy officer wording

The wording is reorganized from a general commitment to privacy to a specific statement about contacting the company regarding privacy, data protection, and information held about individuals. The title “Global Privacy and Data Protection Officer” and the corporate address at 150 2nd Ave N, Suite 1540, St. Petersburg, Florida 33701, USA are included.

This is generally helpful, but the diff appears to present the address and contact details in a fragmented or potentially malformed way. The final published notice should clearly state the officer’s name or title, email address, phone number, and postal address.

4. AI model training and use of customer data

No express provision authorizing or prohibiting the use of customer data to train, fine-tune, evaluate, or improve AI models appears in the diff.

The prior text permitted use of data to improve Services, analyze usage, and create enhancements. Depending on interpretation, that language might be broad enough to support some model-development activities, but it did not expressly address AI training, data de-identification, customer-content restrictions, opt-out rights, retention, or human review.

If the substantive notice has been removed, any previous limitations on data use may also have been removed, increasing ambiguity and risk. A specific AI-data-use clause is advisable.

2026-08-28 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Structured Summary of Important Changes

1. Privacy Notice updated and substantially expanded
  • The notice is now stated to have been updated on 2 June 2026. This replaces the prior date of 20 March 2025.
  • The diff appears to replace a short or incomplete privacy-page section with a comprehensive privacy notice covering collection, use, disclosure, security, retention, international transfers, rights, GDPR, and CCPA compliance.
  • The notice lists current SIS affiliates in the United States, United Kingdom, Spain, and Denmark. This expands the entities potentially involved in processing data.
2. Broader description of data collected

The notice expressly covers:

  • Personal Data, including names, contact details, identifiers, location data, online identifiers, and potentially sensitive identity-related information.
  • Aggregate Information, such as usage frequency, data volumes, accessed features, and browser types.
  • Cookies and similar technologies, including beacons and device identifiers.
  • Location information used for sign-in verification, scheduling, and other functionality.
3. Expanded purposes and sharing rights

SIS may use Personal Data to:

  • Provide, personalize, administer, improve, and market the Services.
  • Prevent fraud and abuse.
  • Analyze user and usage patterns.
  • Support corporate transactions, including mergers, restructurings, and asset sales.
  • Comply with legal requirements and protect SIS, users, or others.

SIS may share Personal Data with:

  • Customers or businesses using the Services.
  • Affiliates and subsidiaries.
  • Service providers such as hosting providers, payment processors, and mail relays.
  • Legal authorities where legally required or reasonably believed necessary.

The notice also permits international transfers and allows customers to request a list of service providers.

4. New contractual/privacy allocation risks
  • SIS states that, for visitor data, it is generally a data processor/service provider, while the business customer is the controller.
  • The business customer determines visitor-data retention periods and is responsible for its own privacy policy.
  • Visitors may nevertheless be directed to contact SIS for assistance, creating potential uncertainty over responsibility for access, deletion, and other rights requests.
  • SIS disclaims responsibility for a business customer’s use or disclosure of visitor data.
5. Consent and legal basis provisions
  • Accessing or using the Services is described as agreement to collection, use, and disclosure under the notice.
  • Processing may rely on consent, contract necessity, legitimate interests, or legal obligations.
  • Marketing is stated to require consent and includes an opt-out mechanism.
6. AI model training
  • No express provision authorizes or prohibits using customer data, Personal Data, Aggregate Information, prompts, outputs, or uploaded content to train, fine-tune, or improve AI models.
  • The broad purposes—particularly improving Services, generating reports, analyzing usage, and creating enhancements—could arguably support some product-improvement activities, but they do not clearly address AI training.
  • This ambiguity is a significant risk for customers seeking assurance that their data will not be used for model training. A separate contractual restriction or explicit AI-data-use clause should be requested.
7. Security, retention, and rights
  • SIS disclaims an absolute security guarantee while describing encryption, least privilege, breach procedures, and zero-trust practices.
  • Data may be retained while an account is active and afterward when there is an ongoing business or legal need.
  • New or clarified rights include access, portability, correction, deletion, restriction, and California non-discrimination protections, subject to exceptions for sanctions and legal requirements.

2026-08-27 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Summary of Important Changes

1. Privacy Notice substantially expanded/replaced

The diff replaces the previous short privacy statement with a comprehensive notice covering:

  • Types of information collected, including personal data, aggregate information, cookies, location data, and potentially audio, visual, professional, demographic, and geolocation information.
  • Collection through the Services, communications, user uploads, devices, social media profiles, and third-party providers.
  • Purposes for processing, lawful bases, data-protection principles, security, retention, international transfers, and individual rights.
  • Separate treatment of SIS as a data controller/business and as a processor/service provider for customer-controlled visitor data.

Risk: The new notice is materially broader and may authorize or describe more extensive collection and use than the prior language. Customers should confirm that their customer-facing disclosures, consents, contracts, and data-processing arrangements match these practices.

2. Customer data sharing and third-party access

The notice states that SIS may:

  • Share personal data with the contracting company, subsidiaries, affiliates, and third-party service providers.
  • Transfer personal data internationally.
  • Disclose data for legal, security, fraud-prevention, corporate-transaction, and operational purposes.
  • Provide a list of third-party service providers upon request.

It also states that service providers may not use personal data for purposes other than providing their services, and that SIS does not sell or share personal data with unrelated third parties.

Risk: The language gives SIS flexibility to use affiliates and vendors and to transfer data internationally. The notice does not provide a fixed vendor list, detailed retention periods, or specific international transfer mechanisms. “As SIS deems necessary” may be considered broad.

3. AI-model training

There is no express reference to artificial intelligence, machine learning, generative AI, model training, or using customer data to train AI models.

However, the notice permits use of personal or aggregate information to:

  • Improve features and functionality;
  • Administer, operate, and improve the Services;
  • Generate reports and analyze usage patterns;
  • Research user behavior and trends;
  • Create improvements, enhancements, and upgrades.

Risk: These broad improvement and analytics purposes could potentially be interpreted to include developing or training internal models, particularly using information described as “Aggregate Information.” The notice does not expressly prohibit AI training, explain whether customer content is used for that purpose, require de-identification standards, or provide an opt-out. Customers seeking protection should require express contractual language stating whether customer data may be used for AI training and, if so, under what safeguards.

4. Inconsistencies and drafting concerns

  • The page header says the notice was updated 2 June 2026, while the body says it was last updated 20 March 2025.
  • The notice refers to both a “Privacy Notice” and “Privacy Policy.”
  • The contact information and company-affiliate descriptions appear newly inserted.
  • The notice states SIS will notify affected parties of breaches only where legally required, which may provide less protection than a contractual prompt-notice obligation.

5. Customer action points

Customers should request clarification or amendments regarding:

1. AI/model-training uses and opt-out rights.

2. Whether customer-submitted content is included in aggregate analytics.

3. Vendor identities, subprocessors, and international transfer safeguards.

4. Specific retention and deletion timelines.

5. The correct effective date and governing privacy document.

2026-08-27 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Summary of Important Changes

1. Entire Privacy Notice Replaced

The prior privacy notice has effectively been replaced with a substantially expanded notice. The new version is dated 2 June 2026, replacing the prior date of 20 March 2025.

The notice now expressly applies to Sign In Solutions Inc. and its affiliated companies (“SIS”), and lists affiliates in the United States, United Kingdom, Spain, and Denmark. This broadens the entities potentially involved in collecting, processing, and sharing data.

2. Broader Data Collection and Use Disclosures

The new notice expressly covers:

  • Personal Data, including names, contact details, identification numbers, location data, online identifiers, and sensitive identity-related information;
  • Aggregate Information about use of the Services;
  • Cookies, beacons, device identifiers, and similar tracking technologies;
  • Location information used for sign-ins, scheduling, and other functionality;
  • Data submitted by customers or their Users, including uploaded information.

SIS may use Personal Data to provide, personalize, administer, secure, analyze, market, and improve the Services. It may also use data for internal business purposes and in connection with mergers, restructurings, or asset sales.

Risk: Several purposes—such as “improve,” “enhance,” “analyze,” and “internal business purposes”—are broad and may permit secondary uses beyond the core service, subject to applicable law.

3. Customer and Visitor Data Sharing

Where Services are provided under a company contract, SIS may disclose Personal Data to the customer company. Visitors may also share data with the business location they visit, and that business controls its own use of the data.

SIS states that it acts as a data processor for visitors’ Personal Data, while the business location is generally the controller. However, SIS also states that it is both a business and service provider under the CCPA.

Risk: Customers should confirm that their own privacy notices, contracts, and instructions adequately cover SIS’s collection, use, international transfers, and retention of visitor data.

4. AI Model Training

The revised notice contains no express reference to artificial intelligence, machine learning, generative AI, or training AI models.

It does permit SIS to use Personal Data for broadly worded purposes including improving Services, generating reports, analyzing usage, and creating enhancements or upgrades. It separately permits sharing of Aggregate Information, which SIS describes as anonymized and incapable of identifying individuals.

Key risk: The notice does not clearly state whether customer data, User data, prompts, uploaded content, or usage data may be used to train or fine-tune AI models. The broad improvement language could create uncertainty or be interpreted as covering model development, particularly for de-identified or aggregated data. Customers should seek an express contractual confirmation that their data will not be used for AI training unless specifically authorized.

5. International Transfers, Retention, and Third Parties

The notice permits transfers of Personal Data to other countries and sharing with affiliates and service providers. A list of service providers may be requested.

Retention is based on legal and business needs, with no fixed maximum period. Data may remain after account closure where SIS has an ongoing business need.

Risk: The absence of specific transfer mechanisms, retention periods, or deletion timelines may make compliance and risk assessment more difficult.

6. New Rights and Security Language

The notice adds detailed rights regarding access, portability, correction, deletion, restriction, and California non-discrimination protections. It also includes security commitments, but expressly states that security cannot be guaranteed.

The contact details and privacy officer information have been consolidated and updated.

2026-08-25 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Summary of the Diff

Overall change
  • Approximately 3,532 words were removed from the document.
  • No replacement language or additions were provided.
  • Because the deleted text is not identified, the legal and commercial impact cannot be determined from this diff alone.
Customer data and AI-model training
  • The diff does not show whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
  • It is therefore impossible to determine whether the deletion:
  • Removes a prohibition on using customer data for AI training;
  • Removes a customer consent or opt-in requirement;
  • Removes restrictions on using customer prompts, inputs, outputs, or other content;
  • Removes commitments to de-identify, aggregate, or anonymize data before AI use;
  • Removes limitations on retaining customer data for model-development purposes;
  • Removes audit, deletion, confidentiality, or security obligations relating to AI training; or
  • Removes the customer’s right to opt out of AI training or withdraw consent.
Key legal risks
  • Loss of protections: Deleted language may have restricted the provider’s ability to use, disclose, retain, or commercially exploit customer data.
  • Expanded implied rights: If data-use limitations, purpose restrictions, or ownership language were removed, the provider may have greater flexibility to use customer data, potentially including for AI development.
  • Reduced accountability: Deleted audit rights, reporting obligations, warranties, or remedies could make violations more difficult to detect or pursue.
  • Conflicting-document risk: If the removed provisions addressed precedence, definitions, or incorporated policies, other documents may now control the parties’ rights without clear explanation.
  • Regulatory and confidentiality exposure: Removal of data-handling restrictions could affect privacy-law compliance, confidentiality obligations, sector-specific requirements, and obligations owed to the customer’s own users or clients.
  • Unclear allocation of liability: Deleted indemnities, security commitments, limitation carve-outs, or breach-notification provisions may materially increase the customer’s risk.
Recommended review

The deleted 3,532 words should be supplied, preferably as a full redline or comparison showing the prior and revised text. Particular attention should be given to sections titled:

  • Data use, customer data, content, or confidentiality;
  • Artificial intelligence, machine learning, model training, or service improvement;
  • Retention, deletion, security, or subprocessors;
  • Ownership, license grants, and feedback;
  • Privacy, compliance, indemnification, and liability; and
  • Termination and post-termination data handling.

Bottom line: The diff indicates a potentially significant reduction in contractual protections, but it does not contain enough information to confirm whether customer data may now be used for AI-model training.

2026-08-24 · Terms & Conditions

shrank 84.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-24 · Terms & Conditions

grew 558.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-23 · Privacy Policy

grew 6868.6% · Observed by clause.watch

Summary of Important Changes

1. New and expanded Privacy Notice
  • The notice is newly dated 2 June 2026, replacing the prior 20 March 2025 update date.
  • It substantially expands the description of:
  • SIS and its affiliates;
  • the Services covered;
  • categories of information collected;
  • purposes of processing;
  • disclosures to customers, affiliates, authorities, and service providers;
  • international transfers, retention, security, and data-subject rights.
  • The notice identifies multiple current affiliates in the United States, United Kingdom, Spain, and Denmark. This may broaden the entities potentially involved in processing customer data.
2. Broader data-collection and use provisions

The notice expressly covers:

  • Personal Data, including identity, contact, location, online identifiers, and potentially sensitive characteristics;
  • Aggregate Information about usage, entered data, accessed features, and user behavior;
  • Cookies, beacons, device identifiers, and similar tracking technologies;
  • Location information used for sign-in, scheduling, and access functionality.

SIS may use Personal Data for service delivery, personalization, fraud prevention, internal business purposes, service improvement, usage analysis, marketing with consent, and corporate transactions. The language is broad and may permit substantial secondary use, particularly for “internal business purposes” and improving or upgrading the Services.

3. AI-model training
  • The diff does not expressly add or authorize the use of customer data to train artificial-intelligence or machine-learning models.
  • It also does not expressly prohibit such use.
  • The provisions allowing SIS to use Aggregate Information for research, usage-trend analysis, service improvements, enhancements, and upgrades could potentially encompass analytics or model development, depending on how “Aggregate Information” is created and whether it is genuinely anonymized.
  • The notice states that Aggregate Information “does not have the capacity” to identify an individual, but it does not explain the anonymization methodology or address re-identification risk.
  • Customers should seek clarification on whether customer content, Personal Data, usage logs, or derived data may be used for AI training, whether data is de-identified, and whether customers can opt out.
4. Customer and visitor data sharing
  • SIS may disclose Personal Data to the customer company where access is provided under a company contract.
  • Independently registered users may have their data shared with their company if they confirm they wish to share it.
  • Visitor data is primarily treated as controlled by the business location, potentially shifting responsibility for notices, lawful bases, retention, and rights handling to the customer.
5. Additional legal and operational risks
  • SIS may transfer Personal Data internationally, but the notice provides limited detail about specific transfer mechanisms.
  • Retention periods remain general and depend partly on SIS’s retention policy or the business location’s policy.
  • SIS disclaims absolute security guarantees and limits certain deletion/access rights for sanction-related information.
  • The notice says third-party provider lists can be requested rather than providing the list directly.
  • It states that users agree to collection, use, and disclosure by accessing the Services, which may be problematic where consent is legally required.

2026-08-22 · Privacy Policy

shrank 98.6% · Observed by clause.watch

Structured Summary of Important Changes

1. Privacy Notice content appears to be removed

The diff deletes almost the entire substantive Privacy Notice, including provisions covering:

  • Information collected, including Personal Data, Aggregate Information, Cookies, and location data
  • Purposes for collecting and using data
  • Sharing with affiliates, customers, business locations, service providers, and authorities
  • International data transfers
  • Data security, retention, deletion, and anonymization
  • Data-subject rights and complaint procedures
  • GDPR, CCPA, and children’s privacy provisions
  • Changes to the Privacy Notice
  • Contact details for the privacy officer

No replacement text for these provisions is shown. If this reflects the final published document, the Privacy Notice may now be materially incomplete or fail to provide legally required disclosures.

2. Contact information and privacy-officer language is deleted

The prior description of the company’s commitment to privacy and the detailed contact information for the Global Privacy and Data Protection Officer—including email, phone, and postal address—has been removed. The remaining text appears to contain only an incomplete reference to contacting the company about privacy and data protection.

Risk: Customers and data subjects may lack a clear method to exercise access, deletion, correction, or other statutory rights. This may also create compliance and notice-validity issues.

3. Navigation and archive labels changed

The legal navigation replaces the individual addenda links with a general “Addenda” link. The archive navigation also appears to be shortened.

Risk: Customers may have less visibility into which contractual addenda apply, including data-processing or service-specific terms. The effect depends on whether the consolidated “Addenda” page clearly identifies and preserves the prior documents.

4. AI-model training and use of customer data

The deleted Privacy Notice did not expressly authorize or prohibit using customer data to train artificial-intelligence or machine-learning models. It described broad uses such as improving services, analyzing usage, generating reports, and creating enhancements or upgrades.

Because those provisions are deleted—and no replacement AI-specific language appears—the diff does not establish a new express right to train AI models using customer data. However:

  • The former broad “improve” and “enhance” purposes could potentially have been argued to cover model development, depending on the data and contract.
  • The absence of an explicit AI-training restriction leaves uncertainty about whether customer content, usage data, or personal data may be used for training.
  • Customers should seek express language addressing whether data may be used for AI training, whether it is de-identified, whether opt-out rights exist, and whether third-party AI providers receive access.
5. Overall assessment

This is a high-risk change if intentional: it removes the operational privacy commitments and statutory disclosures without showing a replacement notice. The revised document should not be treated as clarifying AI use; instead, it creates ambiguity and may undermine transparency, consent, data-processing, and customer-rights compliance.

2026-08-18 · Terms & Conditions

shrank 84.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-18 · Terms & Conditions

grew 558.8% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-06-02 · Privacy Policy

Date stated by the publisher in the document

The publisher records this document as revised on this date (“updated on 2 June 2026”).

Between 2023-06-08 and 2024-01-04 · Terms & Conditions

shrank 5.6% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Between 2022-12-02 and 2023-06-06 · Privacy Policy

grew 28.9% · Reconstructed from Internet Archive captures

Summary

Key Change

  • Approximately 3,532 words have been removed from the document.
  • No replacement language or details about the deleted provisions were provided.

AI Training and Customer Data

  • The supplied diff does not show whether customer data may be used to train AI models.
  • It is therefore impossible to determine whether the document:
  • Newly permits or prohibits AI training;
  • Changes consent requirements for using customer data;
  • Expands the definition of data that may be used for model training;
  • Allows use of customer content for service improvement, analytics, or machine learning;
  • Imposes data de-identification, aggregation, retention, or deletion requirements; or
  • Gives the customer an opt-out or objection right.

Legal and Commercial Risks

The deletion of a substantial portion of the document may create significant uncertainty, particularly if the removed text addressed:

  • Data ownership and licensing rights;
  • Permitted uses of customer content, including AI training;
  • Confidentiality and privacy obligations;
  • Security standards and breach notification;
  • Data retention, deletion, and return;
  • Intellectual-property ownership of AI outputs or improvements;
  • Third-party service-provider and subprocessors’ rights;
  • Liability limits, indemnities, and regulatory compliance; or
  • Customer audit, termination, or opt-out rights.

If the deleted provisions previously restricted use of customer data, their removal could materially expand the provider’s rights by omission. Conversely, if the provisions imposed broad data-use permissions or disclaimers, their deletion could reduce the provider’s rights or increase its obligations.

Recommended Review

The full before-and-after text, or at least the deleted provisions and any replacement provisions, is necessary for a reliable legal analysis. Particular attention should be given to sections titled:

  • “Customer Data” or “Customer Content”
  • “Artificial Intelligence” or “Machine Learning”
  • “Data Use” or “Service Improvement”
  • “Confidentiality”
  • “Privacy”
  • “Intellectual Property”
  • “Security”
  • “Deletion and Retention”

Bottom line: The only confirmed change is a large-scale deletion. The available diff does not establish how customer data may be used to train AI models, but the deletion could materially affect those rights depending on what was removed.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free