clause.watch Contracts Recent changes Start monitoring

Monitored company

Umbraco

clause.watch tracks 1 legal document published by Umbraco, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy policy

1,787 characters · Read the original

Umbraco Privacy Statement — User-Focused Overview

> Scope and limitation: This statement is brief and does not provide the detail usually found in a full GDPR privacy notice. It does not identify all vendors, retention periods, cookies, complaint mechanisms, or detailed user rights. Users may need to consult Umbraco’s broader policy pages or contact GDPR@umbraco.com for clarification.

1. Data Collection and Use

Umbraco says it collects information that users provide in connection with transactions or interactions, including:

  • Name
  • Company name
  • Telephone number
  • Postal address
  • Email address
  • Other information depending on the transaction

The examples given include data connected with:

  • Accounting and business records
  • Newsletter subscriptions
  • Product trials
  • Software licenses
  • Training-ticket purchases
  • Job applications

Umbraco states that it processes data where it has:

  • A legal obligation to do so
  • The user’s explicit consent
  • Another “explicit relevant purpose”
Important gaps

The statement does not clearly explain:

  • Specific processing purposes for each data category
  • How long different types of data are retained
  • Whether website usage, device, cookie, analytics, or marketing data is collected
  • Whether providing data is mandatory or optional
  • The legal basis used for each processing activity
  • Whether automated decision-making or profiling occurs

2. User Rights

The statement does not expressly list individual rights. Because Umbraco refers to GDPR compliance, users may potentially have rights such as:

  • Accessing their personal data
  • Correcting inaccurate or incomplete data
  • Requesting deletion
  • Restricting or objecting to certain processing
  • Receiving portable data in certain circumstances
  • Withdrawing consent where processing is based on consent
  • Complaining to a data-protection regulator

These rights are subject to legal exceptions and may not apply in every situation. The statement provides GDPR@umbraco.com as a contact, but does not explain the procedure, response times, identity checks, or supervisory authority to contact.

3. Third-Party Sharing and International Transfers

Umbraco says, broadly, “We don’t share data.” However, it also states that:

  • It uses suppliers and subprocessors
  • All suppliers are said to be GDPR compliant
  • Umbraco has Data Processing Agreements with suppliers
  • Some subprocessors are located outside the EU
  • Standard Contractual Clauses (SCCs) are used for third-country transfers
  • Transfer Impact Assessments (TIAs) have been completed for subprocessors in countries considered insecure

This means data may still be accessible to service providers, even if Umbraco does not sell or broadly disclose it. The statement does not identify the vendors, countries, services provided, categories of data shared, or whether government/legal disclosures may occur.

4. AI/ML Training

The statement is silent on artificial intelligence and machine-learning training. It does not say whether user data is:

  • Used to train Umbraco’s own AI models
  • Shared with AI providers for model training
  • Excluded from model training
  • De-identified before such use

Users should request a direct clarification if this issue is important.

5. Key User Obligations and Restrictions

The document imposes no detailed user obligations, such as account-security duties or restrictions on submitted content. In practice, users should:

  • Provide accurate information
  • Avoid submitting unnecessary sensitive personal data
  • Obtain permission before providing another person’s information
  • Review separate terms governing products, licenses, trials, training, or employment applications

6. Liability and Disputes

The privacy statement contains no provisions addressing:

  • Liability for data breaches or misuse
  • Warranties or disclaimers
  • Indemnities
  • Governing law or jurisdiction
  • Arbitration or court procedures
  • Complaint escalation

Those matters may be covered in separate contractual terms. This statement’s security assurances—such as “need to have” access and safeguards against unauthorized disclosure—are descriptions of practices, not necessarily guarantees of absolute security.

7. Changes to the Policy

The statement does not explain:

  • How changes will be made
  • Whether users will receive email or other notice
  • When changes become effective
  • Whether continued use constitutes acceptance

Users should check the policy page periodically or ask Umbraco how material changes are communicated.

Change history

2026-09-02 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary

The diff only states that approximately 27 words were removed, without identifying the deleted language or showing the surrounding provisions.

Legal and AI-Related Impact

  • Cannot determine the substantive effect of the deletions from the information provided.
  • In particular, it is not possible to assess whether the removed words:
  • Authorized or restricted the use of customer data to train, fine-tune, or improve AI models;
  • Limited use of customer data to service delivery or internal business purposes;
  • Addressed whether customer data may be anonymized, aggregated, or de-identified for model training;
  • Required customer consent for AI training or disclosure to third-party model providers;
  • Imposed confidentiality, security, retention, deletion, or opt-out obligations; or
  • Clarified ownership of inputs, outputs, models, or derivatives.

Potential Risk

Removing language from a data-use or AI provision could either reduce the provider’s rights to use customer data or inadvertently remove customer protections, depending on what was deleted. Without the actual text, the direction and significance of the change cannot be determined.

Information Needed

Please provide the precise deleted wording and, ideally, the full redline or the surrounding section. The exact language is necessary to evaluate changes to:

1. Customer-data ownership and permitted uses;

2. AI model training and improvement rights;

3. Anonymization or aggregation permissions;

4. Third-party processing and data disclosures;

5. Confidentiality, security, and deletion obligations; and

6. Customer consent, notification, or opt-out rights.

2026-08-31 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary of Important Changes

1. No substantive change to access controls
  • The wording changed from “need to have” not “nice to have” to “need to have” not “nice to have”.
  • This appears to be only a quotation-mark formatting change and does not alter the stated access standard.
  • The provision continues to indicate that access is limited to people who need the data for their role.
2. No substantive change to data sharing
  • “We don’t share data” replaces “We don’t share data.”
  • This appears to be a formatting or punctuation correction only.
  • The statement remains broad and potentially significant: it says that data is not shared, but the surrounding text refers to subprocessors and international transfers. The policy should clarify whether “share” excludes disclosures to subprocessors, affiliates, service providers, or authorities.
3. New privacy contact and policy reference

A new sentence has been added:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

This provides:

  • A specific email address for privacy-related questions.
  • A reference to the company’s privacy policy.

Risks and drafting issues:

  • The sentence is grammatically awkward, particularly “where further is written.”
  • It does not identify the relevant policy page by URL or explain whether the email address is intended for data-subject rights requests, complaints, or general inquiries.
  • If this address is not monitored or does not handle formal GDPR requests, customers may misunderstand how to exercise their rights.
4. International transfers and subprocessors
  • The existing references to Standard Contractual Clauses (SCCs) with subprocessors and Transfer Impact Assessments (TIAs) for subprocessors in “unsecure third countries” appear unchanged.
  • “Unsecure third countries” is not standard legal terminology. “Countries lacking an adequacy decision” or “restricted third countries” may be clearer and more legally precise.
  • The wording should also clarify what supplementary safeguards apply where required following a TIA.
5. AI model training
  • No provision in the supplied diff changes how customer data may be used to train AI models.
  • The diff does not add or remove any express right to use customer data for AI training, model improvement, profiling, or automated decision-making.
  • Accordingly, the existing contract or privacy policy should be reviewed separately for any AI-training language.

2026-08-30 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary

The provided diff only states that approximately 27 words were removed from the document. It does not identify:

  • Which words or provisions were deleted;
  • Whether the deletion is a replacement, removal, or formatting change;
  • Whether any language concerning customer data, AI training, confidentiality, or data rights was affected.

AI Training and Customer Data

No reliable conclusion can be drawn about changes to AI-model training or customer-data usage because the actual deleted text is not provided. The removed language could potentially have addressed:

  • Permission to use customer data to train, fine-tune, or improve AI models;
  • Restrictions or opt-out rights concerning AI training;
  • Ownership or licensing of customer inputs, outputs, or usage data;
  • De-identification, aggregation, or anonymization requirements;
  • Confidentiality and security obligations;
  • Retention, deletion, or disclosure of customer data.

If any of these provisions were deleted, the change could materially affect the customer’s control over its data and the provider’s rights to use it.

Risk Assessment

Current assessment: Unable to determine. The deletion itself may be legally significant, but the risk cannot be evaluated without the exact text removed and any surrounding provisions.

Information Needed

Please provide the actual redlined language, including:

1. The deleted 27 words;

2. Any replacement wording;

3. The surrounding paragraph or section; and

4. The document version before and after the change, if available.

This is necessary to determine whether the change expands or narrows rights to use customer data for AI training.

2026-08-29 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary of Important Changes

1. No apparent change to AI-model training rights
  • The diff does not add or remove any language addressing whether customer data may be used to:
  • Train, fine-tune, or evaluate AI models;
  • Develop machine-learning products;
  • Create aggregated or de-identified datasets; or
  • Share data with AI providers for training purposes.
  • On the text provided, there is therefore no express change to the company’s rights to use customer data for AI training. Any such rights would need to be assessed by reviewing the surrounding provisions and the complete privacy or data-processing policy.
2. “Need to have” access standard retained
  • The wording changes from typographic quotation marks to straight quotation marks:

[“need to have” not “nice to have”] → {"need to have" not "nice to have"}

  • This appears to be a formatting or punctuation correction rather than a substantive legal change.
  • The underlying promise remains that access to data is limited to individuals who have a genuine business or legal need to access it. However, the clause should ideally clarify:
  • Who determines whether access is necessary;
  • Whether contractors and subprocessors are covered; and
  • Whether access is reviewed or revoked periodically.
3. Minor wording correction concerning data sharing
  • “don’t” replaces “don’t” using a different apostrophe style. This is not a substantive change.
  • The statement that the company does not share data remains unchanged. This statement may be potentially misleading if data is shared with subprocessors, affiliates, professional advisers, authorities, or service providers under the agreement. The broader contract should be checked for exceptions.
4. Subprocessor transfer safeguards retained
  • The references to:
  • Standard Contractual Clauses (SCCs) with subprocessors; and
  • Transfer Impact Assessments (TIAs) for subprocessors in “unsecure third countries”

appear unchanged.

  • These provisions indicate an intended safeguard for international data transfers. However, “unsecure third countries” is not a precise legal term. It would be clearer to refer to countries not benefiting from an adequacy decision or otherwise lacking an adequate level of protection.
  • The clause should also clarify whether SCCs and TIAs apply to all relevant onward transfers and whether customers receive notice or objection rights regarding new subprocessors.
5. New customer-contact language

A new sentence states:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

This is a helpful addition because it provides a privacy contact route and directs customers to further information. However:

  • It is informal and grammatically awkward;
  • “Policy page” is not identified by a specific URL; and
  • It does not state whether the address is intended for data-subject requests, security incidents, or general inquiries.
Overall assessment

The changes are primarily editorial, with one useful addition providing contact information. No new AI-training permission or restriction is visible in this excerpt.

2026-08-28 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary of Important Changes

1. No apparent change to AI-model training or data use
  • The diff contains no express provision authorizing, restricting, or otherwise changing the use of customer data to train AI models.
  • It does not state whether customer data, prompts, outputs, or usage data may be used for:
  • Training or fine-tuning AI models;
  • Improving models or services;
  • Human review or evaluation; or
  • Creating aggregated or de-identified datasets.
  • Accordingly, the diff does not provide a clear customer protection or permission regarding AI training. Any such terms would need to be reviewed elsewhere in the agreement or privacy documentation.
2. Access to customer data
  • The phrase “need to have” not “nice to have” is unchanged in substance; only the quotation marks were changed from straight to typographic quotation marks.
  • The wording continues to indicate that access is limited to persons who have a genuine business or operational need to access the data.
  • This is generally a positive data-minimization and access-control commitment, although the clause should ideally define who determines that need and whether access is logged or reviewed.
3. Data sharing
  • The statement “We don't share data” is unchanged in substance; the apostrophe was changed typographically.
  • The surrounding text indicates that the provider uses subprocessors and has entered into Standard Contractual Clauses (SCCs) with them. Therefore, “we don’t share data” should not be read as an absolute prohibition on disclosure: data may still be made available to subprocessors as necessary to provide the services.
  • The scope of permitted sharing, including whether it covers affiliates, service providers, support personnel, or legal authorities, is not clarified by this diff.
4. International transfers
  • The text continues to refer to SCCs with subprocessors and Transfer Impact Assessments (TIAs) for subprocessors located in “unsecure third countries.”
  • This appears to preserve the existing international-transfer safeguards rather than introduce a new obligation.
  • “Unsecure third countries” is imprecise terminology. The legal assessment generally depends on whether the destination is outside an approved data-protection framework and whether the transfer mechanism and supplementary safeguards are adequate.
5. Removal of contact and policy reference
  • The sentence allowing customers to contact GDPR@umbraco.com or visit the privacy policy for further information has been deleted.
  • This removes an expressly stated communication channel and direct reference to additional privacy information.
  • The deletion may reduce transparency and make it less clear how customers can ask questions or exercise privacy-related rights, unless equivalent contact details appear elsewhere in the agreement or policy.

Overall Risk

The main practical change is the removal of the privacy-contact and policy-reference language. There is no explicit AI-training change, but the diff also does not resolve whether customer data may be used for AI-related purposes.

2026-08-27 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary

The provided diff only states:

> “Added approximately 27 words to the document”

It does not include the actual 27-word addition, nor any surrounding contract language. Therefore, no substantive legal changes can be identified.

AI Training and Customer Data

  • The diff provides no information about whether customer data may be:
  • Used to train, fine-tune, or improve AI models;
  • Shared with affiliates, vendors, or third-party AI providers;
  • Anonymized, aggregated, or de-identified before use;
  • Retained for model-training purposes;
  • Excluded from training by default or only upon customer opt-out; or
  • Used to generate outputs that may be incorporated into future models.

Accordingly, it is not possible to determine whether the amendment creates any new customer-data, confidentiality, privacy, intellectual-property, or regulatory risks.

Needed Information

To perform the requested analysis, provide the actual added, deleted, and replacement language, including enough surrounding text to determine how the amendment operates within the agreement.

2026-08-25 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary

The diff only states that approximately 27 words were removed from the document. It does not identify:

  • Which words or clauses were deleted
  • Whether any provisions were added or replaced
  • Whether the deletion changes legal rights or obligations
  • Whether customer data may be used to train, fine-tune, evaluate, or improve AI models

AI-Training and Data-Use Impact

No specific change concerning AI model training or customer data use can be identified from the information provided.

In particular, the diff does not show whether the document now:

  • Permits or restricts using customer data to train AI models
  • Allows use of customer content for model improvement or product development
  • Distinguishes between customer content, usage data, metadata, or anonymized data
  • Requires consent, opt-out, or prior notice for AI training
  • Limits retention, sharing, or disclosure of data to AI providers or subprocessors
  • Provides confidentiality, deletion, or data-isolation protections

Risk Assessment

The legal significance of removing approximately 27 words cannot be determined without the actual deleted language and its surrounding context. A short deletion could nevertheless materially affect:

  • Data-use permissions
  • Confidentiality obligations
  • Ownership or licensing rights
  • Liability and indemnification
  • Compliance commitments
  • Customer opt-out or consent rights
  • Restrictions on AI training

Information Needed

Please provide the actual redlined text, including the deleted words and the surrounding clause. Without that text, no reliable assessment of the contractual changes or AI-training risks is possible.

2026-08-25 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary of Important Changes

1. Access to customer data
  • The wording changes from “need to have” not “nice to have” to “need to have” not “nice to have”.
  • This appears to be a formatting or quotation-mark correction only and does not materially change the access standard.
  • The underlying commitment remains that access is limited to individuals who are legally permitted to access the data and have a genuine business need.
2. Data sharing
  • The wording changes from “don’t” to “don't”.
  • This is only an apostrophe/typographical change and does not alter the stated position that the provider does not share data.
  • However, the statement remains broad and should be read together with the rest of the privacy terms, including permitted disclosures to subprocessors, legal authorities, or other third parties. The excerpt does not clarify those exceptions.
3. International data transfers
  • The text refers to Standard Contractual Clauses (SCCs) with subprocessors and Transfer Impact Assessments (TIAs) for subprocessors located in “unsecure third countries.”
  • No substantive change to these obligations is shown in the diff.
  • The phrase “unsecure third countries” is imprecise; the legally relevant issue is generally whether a country lacks an adequacy decision or presents transfer risks. The effectiveness of the safeguards will depend on the actual SCCs, TIAs, supplementary measures, and enforcement practices.
4. New contact and policy language

The following sentence is added:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

This provides a privacy contact address and directs customers to the provider’s policy page. It is helpful operationally, but:

  • It does not itself create a new substantive privacy right or remedy.
  • The referenced policy page should be reviewed because it may contain additional rules governing data use, retention, disclosures, subprocessors, or international transfers.
  • The wording is informal and somewhat vague regarding what information the policy page contains.
5. AI-model training
  • No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models is included in this diff.
  • The statements that the provider “doesn’t share data” and limits access do not necessarily address internal use of data for AI training.
  • If AI training is important, the contract should expressly state whether customer data, prompts, outputs, telemetry, or metadata may be used for model training or improvement, and whether the customer can opt out.

2026-08-24 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary of Important Changes

1. No substantive change to data-access standard
  • The phrase “need to have” not “nice to have” remains substantively unchanged; only quotation marks were changed from straight to typographic quotation marks.
  • The provision continues to indicate that access to customer data is limited to individuals who have a genuine business need.
  • The opening text appears incomplete in the supplied diff (“anyone not legally allowed to access your data”), so the precise scope of the access restriction cannot be fully assessed.
2. No apparent change to data-sharing position
  • The statement “We don’t share data” remains substantively unchanged; the apostrophe was changed from a straight apostrophe to a typographic apostrophe.
  • The surrounding wording refers to removing data that is not relevant for legal or other relevant purposes. This may be intended as a data-minimization commitment, but the excerpt does not explain:
  • What data may be retained;
  • For how long;
  • Whether data may be shared with service providers, affiliates, authorities, or other third parties; or
  • Whether “share” excludes disclosures made through subprocessors.
3. International-transfer wording remains, but may be ambiguous
  • The text continues to state that the provider has signed an SCC with its subprocessors and has completed Transfer Impact Assessments (TIAs) for subprocessors located in “unsecure third countries.”
  • No substantive wording change to these commitments is visible in the diff.
  • Potential risk: “an SCC” may be imprecise because the applicable Standard Contractual Clauses and relevant transfer module(s) should generally be identified clearly. “Unsecure third countries” is also not standard legal terminology and may create uncertainty about which countries or transfers are covered.
4. Deletion of privacy-contact and policy reference

The following sentence was deleted:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

This removes:

  • A specific privacy contact email address; and
  • A direct reference to the provider’s privacy policy.

Risk: Customers may have less clarity about how to raise privacy questions or locate additional information. Depending on the document’s purpose and applicable law, removing contact information could also make it harder to demonstrate transparent communication regarding data-protection rights and practices.

5. AI-model training
  • No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models is shown in this excerpt.
  • The wording does not expressly prohibit AI training use, nor does it expressly authorize it. If AI-related use is addressed elsewhere, that language should be reviewed separately.

2026-08-23 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary of Changes

1. No substantive change to data-access standard
  • The phrase “need to have” not “nice to have” was changed only from typographic quotation marks to straight quotation marks.
  • The apparent meaning remains the same: access to customer data should be limited to people who have a genuine business or legal need to access it.

Risk: No material legal change identified.

2. No substantive change to data-sharing statement
  • “don’t share data” was changed to “don't share data.”
  • This is an apostrophe/formatting change only. It does not alter the stated position that the company does not share data.

Risk: No material legal change identified. However, the statement remains broad and could potentially be read as inconsistent with the later references to subprocessors, SCCs, and international transfers unless “share” is understood not to include processing by contracted subprocessors.

3. New customer-contact and policy-reference language

The following sentence was added:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

Effect:

  • Provides a specific privacy contact email address.
  • Directs customers to a policy page for additional information.

Potential risks/issues:

  • The wording “where further is written” is awkward and vague. It would be clearer to identify the specific privacy policy and provide a direct link.
  • The clause does not state whether the email address is intended for data-subject rights requests, general privacy inquiries, or both.
  • If this text is part of a privacy notice, the referenced policy should be readily accessible and consistent with the contract.
4. AI-model training and use of customer data
  • No change expressly addresses AI, machine learning, model training, model improvement, or use of customer data for training.
  • The diff does not add a prohibition on using customer data to train AI models, nor does it grant such permission.
  • The unchanged statements about limited access, data removal, and non-sharing do not necessarily resolve whether data may be used internally for AI training or product improvement.

Key risk: If AI training is a concern, the contract should expressly state whether customer data, prompts, outputs, telemetry, or derived data may be used to train, fine-tune, validate, or improve AI models, and whether any such use requires consent or de-identification.

2026-08-23 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary

The provided diff only states that approximately 27 words were removed from the document. It does not identify:

  • Which words or provisions were deleted;
  • The section or clause affected;
  • Whether the deletions were replaced with different language; or
  • Whether any changes concern customer data, AI training, confidentiality, ownership, or permitted use.

AI Training and Customer Data

No conclusions can be drawn from the available information about whether the agreement now:

  • Permits or restricts using customer data to train, fine-tune, or improve AI models;
  • Allows use of customer prompts, inputs, outputs, or personal information for model development;
  • Requires customer consent or provides an opt-out;
  • Anonymizes or aggregates data before AI use;
  • Gives the provider ownership or broad usage rights over customer data; or
  • Imposes deletion, retention, confidentiality, or security obligations.

Because the deleted language is not shown, it is possible that important restrictions were removed—for example, a prohibition on AI training, a confidentiality obligation, or a requirement to obtain consent. Conversely, the deletion may have narrowed the provider’s rights or removed an overly broad permission.

Risk Assessment

Current assessment: indeterminate. The notation “removed approximately 27 words” is insufficient to evaluate the legal effect or identify new risks. In particular, it cannot establish whether the customer’s data may be used to train AI models.

Information Needed

Please provide the actual redline showing the deleted text, preferably with:

  • Deletions in brackets or strikethrough;
  • Additions in braces or underline;
  • The surrounding clause and section heading; and
  • Any replacement language.

Without the deleted wording and its context, a reliable legal or AI-data-use analysis is not possible.

2026-08-22 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary of Changes

1. No apparent change to AI-training rights or data use
  • The diff does not add, remove, or modify any language about using customer data to train, develop, fine-tune, or improve AI models.
  • There is also no change to language concerning:
  • Whether customer data may be used for model training;
  • Whether data is anonymized or aggregated before such use;
  • Opt-out or consent requirements;
  • Retention of data used for AI purposes; or
  • Disclosure of AI providers or subprocessors.

Risk assessment: No new AI-training risk is apparent from this excerpt. However, the absence of AI-specific restrictions means the broader agreement or privacy policy should be reviewed to determine whether AI use is addressed elsewhere.

2. Minor wording and formatting changes
  • [“need to have” not “nice to have”] was changed to {"need to have" not "nice to have"}.
  • [don’t] was changed to {"don't"}.

These appear to be formatting or typographical changes only. They do not materially alter the stated access or data-sharing commitments.

3. New customer-contact language

The following sentence was added:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

Effect:

  • Provides a specific privacy contact email address.
  • Directs customers to an external policy page for additional information.
  • Does not itself create a clear new substantive privacy right or impose a specific response deadline.

Potential risks or points to clarify:

  • The referenced “policy page” is not identified in the diff. Its contents could contain additional terms that affect data use, retention, international transfers, or AI processing.
  • The phrase “where further is written” is vague and should ideally identify the relevant URL or policy document.
  • The wording “questions as to the privacy of your data” is broad but does not expressly confirm that the address may be used for data-subject rights requests or security incidents.
4. Existing commitments retained

The diff does not appear to change the existing statements that:

  • Data access is limited on a “need to have” basis;
  • Data is not shared; and
  • Standard Contractual Clauses and Transfer Impact Assessments apply to relevant subprocessors in third countries.

2026-08-22 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary

The diff only states that approximately 27 words were removed from the document. The actual deleted language is not provided.

Legal and Risk Assessment
  • Substantive impact cannot be determined: Without the removed wording, it is impossible to assess whether the changes affect liability, confidentiality, data rights, termination, security, intellectual property, or other contractual obligations.
  • AI-training provisions: The diff does not reveal whether the deleted text addressed:
  • Use of customer data to train, fine-tune, or improve AI models;
  • Whether customer data may be used for provider-wide model training;
  • Use of de-identified, aggregated, or anonymized data;
  • Customer consent or opt-out rights;
  • Restrictions on using prompts, inputs, outputs, or uploaded content for training;
  • Retention, deletion, or human-review practices associated with AI systems.
  • Potential risk: If the deleted language limited the provider’s ability to use customer data—or granted the customer an opt-out or other protection—its removal could materially expand permitted data use. Conversely, if the deleted language authorized such use, its removal could restrict the provider’s rights. The direction of the change cannot be determined from the information supplied.
Required for a Reliable Analysis

Please provide the actual 27 deleted words, preferably with the surrounding clause or the complete before-and-after text. Without that language, no reliable conclusion can be reached regarding changes to AI-model training or other legal obligations.

2026-08-20 · Privacy policy

grew 8.3% · Observed by clause.watch

Summary of Changes

1. No substantive change to access controls
  • The phrase “need to have” not “nice to have” has been retained, with only the quotation marks/formatting changed.
  • This continues to state that access to customer data is limited to persons with a genuine business need.
  • Risk: The wording remains informal and does not clearly define who may access data, for what purposes, or how access is reviewed and revoked. If this is intended as a contractual commitment, more precise language may be preferable.
2. No substantive change to data sharing
  • The wording “don’t share data” has only been changed from a typographic apostrophe to a straight apostrophe.
  • There is no apparent change to the stated position that data is not shared.
  • Important limitation: This statement may conflict with other provisions allowing access by subprocessors, service providers, affiliates, or authorities. It should be read consistently with the full agreement and any subprocessors list.
3. International transfers and safeguards
  • The text continues to refer to:
  • Signing Standard Contractual Clauses (SCCs) with subprocessors; and
  • Completing Transfer Impact Assessments (TIAs) for subprocessors located in “unsecure third countries.”
  • No substantive wording change appears in this portion.
  • Potential risk: “Unsecure third countries” is not a precise legal term. The agreement should identify the applicable transfer mechanism and explain what happens if SCCs or TIAs become invalid, inadequate, or require supplementary safeguards.
4. New privacy contact and policy reference

A new sentence has been added:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

This provides:

  • A dedicated privacy contact email; and
  • A reference to an external privacy policy.

Risks and considerations:

  • The email address and linked policy should remain current and accessible.
  • The policy may contain terms that materially affect the customer’s rights or the provider’s obligations. Incorporating it by reference could create uncertainty unless the applicable version and hierarchy of documents are clearly stated.
  • The sentence is informal and grammatically unclear; it should specify what information the policy contains and whether it forms part of the contract.
5. AI-model training
  • No language in the supplied diff addresses whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
  • The existing statements that data is not shared and is accessed only on a “need to have” basis do not expressly prohibit AI training or clarify whether customer data, prompts, outputs, metadata, or telemetry may be used for that purpose.
  • If AI use is relevant, a specific provision should state whether customer data is excluded from model training and identify any exceptions.

2026-08-19 · Privacy policy

shrank 7.7% · Observed by clause.watch

Summary

The provided diff states only: “Removed approximately 27 words from the document.”

Because the actual deleted text is not included, it is not possible to determine:

  • What contractual rights or obligations changed
  • Whether liability, confidentiality, privacy, security, or termination terms were affected
  • Whether customer data may now be used differently
  • Whether any restrictions on artificial intelligence or machine-learning model training were removed
  • Whether consent, opt-out, ownership, or data-retention provisions changed

AI Training and Customer Data

No specific change concerning the use of customer data to train AI models can be identified from the information provided. The deleted 27 words could potentially have addressed:

  • Permission to use customer data, prompts, inputs, or outputs for AI training
  • De-identification or aggregation requirements
  • Restrictions on using data to improve products or models
  • Customer consent or opt-out rights
  • Ownership of data or model outputs
  • Confidentiality and security obligations
  • Retention or deletion of training data

Risk Assessment

The risk is indeterminate. A reliable legal analysis requires the actual text removed and, preferably, the surrounding unchanged language. In particular, the deleted wording should be reviewed for terms such as “train,” “improve,” “develop,” “machine learning,” “artificial intelligence,” “inputs,” “content,” “customer data,” “aggregate,” “de-identify,” “consent,” and “service improvement.”

Please provide the full before-and-after text or the specific 27 deleted words for a meaningful assessment.

Between 2024-09-21 and 2024-12-15 · Privacy policy

shrank 29.3% · Reconstructed from Internet Archive captures

Summary of Important Changes

1. No substantive change to data-access standard
  • The phrase “need to have” not “nice to have” replaces the same wording with typographic curly quotation marks.
  • This appears to be a formatting/editorial change only. It continues to indicate that access to customer data should be limited to personnel who have a genuine need to access it.
  • The surrounding wording remains incomplete in the supplied diff, so the exact contractual obligation should be checked in the full document.
2. No substantive change to data-sharing statement
  • “don't” has been changed to “don’t.”
  • This is only a typographical change and does not alter the apparent statement that the provider does not share data.
  • However, the statement should be reviewed for consistency with the provider’s use of subprocessors, legal disclosures, and any other permitted transfers. An absolute statement that data is not shared could be misleading if subprocessors or other third parties receive or process the data.
3. International-transfer language remains
  • The reference to signing Standard Contractual Clauses (SCCs) with subprocessors and completing Transfer Impact Assessments (TIAs) for subprocessors in “unsecure third countries” appears unchanged.
  • These mechanisms address certain international-transfer compliance requirements but do not, by themselves, guarantee that transfers are lawful in every circumstance.
  • “Unsecure third countries” is not the usual legal terminology; the agreement may more accurately refer to countries without an adequacy decision or jurisdictions presenting transfer risks.
4. Removal of privacy contact and policy reference

The following sentence has been deleted:

> “You can contact us at GDPR@umbraco.com if you have any questions as to the privacy of your data, or visit our policy page where further is written.”

Potential effects include:

  • Removal of a clearly identified privacy contact email.
  • Reduced transparency about where customers can obtain privacy information or raise questions.
  • Possible practical or compliance concerns if the email address was intended to support data-subject requests, customer inquiries, or regulatory transparency obligations.
  • The deletion does not necessarily eliminate any legal obligation to provide contact details elsewhere, but customers may have more difficulty locating the appropriate contact route.
5. AI-model training
  • No express change concerning the use of customer data to train, fine-tune, evaluate, or improve AI models.
  • The diff neither grants nor removes a permission to use customer data for AI training.
  • Any AI-training rights must be reviewed in other sections of the agreement, privacy policy, product terms, or subprocessor terms.
Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free