Monitored company
Vaadin
clause.watch tracks 2 legal documents published by Vaadin (vaadin.com), re-reading each one every six hours. Below is what each document covers, in plain English.
Community Terms
Vaadin Community Terms — Key User Takeaways
*Updated 25 June 2026, version 1.3. This summary is informational and does not replace the Terms or Vaadin’s separate Privacy Policy.*
1. Data Collection and Use
The Terms themselves provide limited detail about ordinary website and community data collection. Registration requires a personal account, including a username and password. Vaadin’s Privacy Policy, which is incorporated into the Terms, should be reviewed for details such as cookies, technical data, analytics, account information, retention, and legal bases for processing.
Content submitted to the community Service
Publicly submitted “Member Materials”—such as posts, uploads, software, and other contributions—are generally not confidential. Vaadin may:
- Store, reproduce, modify, create derivative works from, publish, distribute, and otherwise use the materials;
- Moderate, remove, or refuse to display content;
- Continue using the materials even after you stop using the Service.
You retain your intellectual-property ownership, but grant Vaadin a worldwide, perpetual, irrevocable, fully paid, unlimited license to use the materials. Do not submit confidential information, personal data, or material unless you are comfortable with this broad license and public availability.
Copilot and Vaadin Start
For the Software Services, Vaadin may process your code, text, configurations, and other inputs (“Content”) to:
- Provide and maintain the services;
- Improve the services;
- Comply with law and enforce the Terms;
- Generate responses or application prototypes;
- Create temporary backup copies.
Vaadin states that it does not use Content to train the AI or machine-learning models used in the Software Services and does not publicize or distribute Content. However, information independently obtained from other sources is not restricted merely because it also appears in generated Output.
You are expressly told not to submit personal data to the Software Services. If you do, you are solely responsible for having a lawful basis and complying with privacy laws, and Vaadin disclaims responsibility for resulting processing.
2. User Rights
- You retain intellectual-property rights in Member Materials and Copilot/Input content, subject to the licenses granted to Vaadin.
- You may use Copilot Output for lawful purposes, including commercially.
- Output is non-exclusive and may resemble results provided to others.
- You may stop using the Service at any time.
- The Terms do not state specific rights to access, correct, delete, export, or object to personal-data processing. Those rights, if applicable, must be determined from the Privacy Policy and mandatory law, including potentially EU GDPR rights.
- Feedback may be used by Vaadin indefinitely, without payment, for any purpose, including service development and statistics.
3. Third-Party Sharing
For Copilot, Content may be shared with and processed by third-party AI providers, currently:
- OpenAI, LLC
- Mistral AI SAS
- Anthropic PBC
Sharing may support response generation, moderation, and other purposes allowed by the Terms. Their separate terms and policies also apply. This is a significant confidentiality and data-transfer risk: do not submit trade secrets, third-party confidential information, personal data, or sensitive code.
Ordinary community submissions are not treated as confidential. Downloaded software may also include third-party components governed by their own licenses.
4. AI/ML Training
Vaadin expressly states that:
- Copilot Content is not used to train the AI models used in the Software Services.
- Vaadin Start inputs are not used to train AI or machine-learning models.
This does not prevent Vaadin from improving the services using Content as otherwise permitted, using feedback, or relying on independently sourced information. AI Providers’ policies should also be reviewed.
5. Key User Obligations and Restrictions
Users must:
- Use the Service only for permitted Vaadin-related purposes and comply with law;
- Protect account credentials and report unauthorized use;
- Ensure submissions are lawful, non-infringing, and appropriate;
- Obtain all necessary rights and licenses for uploaded content or software;
- For published software, test it, identify dependencies and licenses, and select an available license;
- Comply with export controls and sanctions laws;
- Review and test all AI Output, especially generated code.
Users must not misuse, disrupt, reverse interfere with, or use the services unlawfully. Copilot Input must not contain personal data, confidential third-party information, infringing material, or information requiring government authorization for release or export.
6. Liability and Disputes
The Services and AI Output are provided “as is” and “as available.” Vaadin gives broad warranty disclaimers and does not guarantee accuracy, security, availability, or error correction.
Vaadin generally excludes liability for indirect, consequential, punitive, data-loss, business, revenue, and profit damages. Any remaining liability is limited to the lesser of amounts paid to Vaadin or the minimum amount required by mandatory law.
You must defend and indemnify Vaadin and related parties for claims arising from your content, Service use, legal or Terms violations, rights infringements, and violations of AI-provider policies. This obligation survives termination.
Finnish law governs. Disputes generally go to expedited, single-arbitrator arbitration seated in Turku, Finland, in English. Mandatory consumer-protection rules may override the arbitration clause.
7. Changes
Material changes require at least 30 days’ notice on vaadin.com and by email to registered users. Non-material changes take effect when posted. Changes are not retroactive. If you disagree, your remedy is to stop using the Service. Vaadin may also modify or discontinue features or the entire Service.
Privacy Policy
Privacy Policy Overview
*This policy was updated 11 November 2020 (version 2). It describes Vaadin Ltd.’s handling of personal data under the GDPR and Finnish law. It does not appear to be a complete terms-of-service or liability agreement.*
1. Data Collection and Use
Information collected
Vaadin may collect:
- Identity and contact data: name, job title, address, email, telephone number, language, and company details.
- Customer and transaction data: customer number, purchased products/services, delivery information, complaints, seller information, billing, payments, and debt collection details.
- Technical and usage data: IP address, browser, device ID, operating system, visit times, pages viewed, browsing history, login information, and event/user analytics.
- Communications: emails, chat histories, call recordings, contact requests, and forum messages.
- Marketing preferences: consents, objections, preferred communication methods, and related changes.
- Information from other sources: authorities, credit-reporting companies, contact-information providers, public websites, professional social networks, company websites, third parties, and data-enrichment services.
Purposes and legal bases
Vaadin states that it processes data to:
- Provide products and services, manage accounts, orders, support, billing, and contracts (contractual necessity).
- Use cookies and conduct certain other processing where the user has agreed (consent).
- Improve and analyze services, conduct surveys, market and advertise products, personalize content, organize events, prevent misuse, and pursue or defend legal claims (legitimate interests).
- Meet legal obligations, including bookkeeping requirements (legal obligation).
Potential risk: The “legitimate interest” category is broad and includes analytics, marketing, targeting, and advertising. Users may object to processing based on legitimate interests, particularly for personal reasons, but the policy does not explain the objection process in detail.
Cookies
Cookies may collect browsing and device information, including referring webpage, browsing activity, browser details, screen resolution, operating system, and IP address. Vaadin uses necessary, functional, analytical/statistical, and marketing cookies. Persistent cookies may remain for months or years. Disabling cookies may impair website functionality.
2. User Rights
Subject to applicable legal exceptions and the relevant processing basis, users may have the right to:
- Receive information about processing and obtain access to their data.
- Correct inaccurate data.
- Request deletion.
- Restrict processing.
- Object to processing, including certain legitimate-interest processing.
- Withdraw consent (without affecting earlier lawful processing).
- Complain to a data-protection supervisory authority.
Requests should be sent to privacy@vaadin.com. Vaadin may require additional details and reliable identity verification. Rights are not absolute—for example, deletion or objection may be refused where Vaadin must retain or process data for legal, contractual, or claim-related reasons.
3. Third-Party Sharing and International Transfers
Data may be shared with:
- Vaadin group companies.
- Service providers and other subprocessors.
- Authorities where legally required.
- Third-party cookie, analytics, marketing, monitoring, social-media, and plug-in providers.
Vaadin may transfer data outside the EU/EEA, including to the United States. It states that it uses legally recognized safeguards, such as European Commission Standard Contractual Clauses. The policy does not identify all recipients, countries, or specific safeguards for each transfer.
4. AI/ML Training
The policy does not state that personal data is used to train artificial-intelligence or machine-learning models. It mentions analytics, service improvement, targeting, and “data enrichment,” but these terms do not by themselves establish AI training. Users seeking certainty should ask Vaadin directly.
5. Key User Responsibilities and Restrictions
Users should:
- Provide accurate information and update it when necessary.
- Review and manage cookie settings through their browser or consent tools.
- Understand that disabling cookies may reduce functionality.
- Review third-party providers’ own privacy policies, particularly social-media and marketing services.
- Avoid assuming that data will be deleted immediately; customer and community data is typically retained for 10 years after the relevant relationship ends or last login, respectively.
6. Liability and Disputes
This privacy policy contains no detailed limitation-of-liability clause, indemnity, governing-law provision, arbitration clause, or dispute-resolution process. It does state that Vaadin may process data to file and defend legal claims. GDPR complaints may be submitted to the appropriate supervisory authority.
7. Changes
Vaadin reserves the right to change the privacy and cookie policies at any time. It does not promise individualized notice, email notice, or a specific advance-notice period. Users are advised to review the policies regularly.
Change history
2026-09-06 · Privacy Policy
Summary
The provided diff does not include the actual amended legal language. It only states:
> “Added approximately 253 words to the document”
Accordingly, I cannot reliably identify:
- Changes to customer data rights or permitted uses
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models
- New data-sharing or disclosure rights
- Changes to confidentiality, security, retention, or deletion obligations
- New customer consent requirements or opt-out rights
- Allocation of intellectual-property rights in inputs, outputs, or trained models
- Liability, indemnity, or regulatory risks arising from the additions
AI Training Analysis
No specific language regarding AI-model training or related data use is included in the supplied diff. It is therefore not possible to determine whether the amendments:
- Permit use of customer data to train general-purpose or provider-specific models
- Limit training to de-identified, aggregated, or anonymized data
- Allow human review or use by subcontractors and service providers
- Apply training permissions by default or only with customer consent
- Provide an opt-out mechanism
- Restrict use of personal, confidential, regulated, or proprietary information
- Grant the provider ownership or ongoing rights in data-derived models or outputs
Required Information
Please provide the full diff, including the added, deleted, and replacement language using the stated notation. Once provided, the changes can be analyzed for legal effect, commercial risk, and any AI-training provisions.
2026-09-05 · Privacy Policy
Summary of Important Changes
1. AI model training
- No express provision authorizing or prohibiting the use of customer data to train AI models appears in the diff.
- The revised policy substantially expands the categories of information collected, including:
- Product and service usage data
- Browsing history, IP address, device ID, visited pages and visit times
- Chat history, emails and call recordings
- Event and user-analysis data
- Forum messages and other user-submitted information
- Although this information could potentially be relevant to analytics, machine-learning or AI development, the revised wording does not state that personal data, customer content, prompts, outputs or usage data will be used for AI training. It also does not provide opt-out, anonymization, human-review, model-retention or deletion terms for AI training.
- Risk: The policy may be insufficiently specific if Vaadin intends to use customer data for AI training. Customers should seek express contractual clarification that customer content and personal data will not be used for model training unless separately authorized, appropriately anonymized, or based on a valid legal basis and required notice/consent.
2. Expanded data collection and profiling risk
- The permitted data sources are significantly broadened. Vaadin may collect information from authorities, credit-information companies, contact-information providers, public sources, professional social media, websites, third parties, data-enrichment services and product usage.
- New data categories include billing and debt-collection information, marketing preferences and prohibitions, communications, call recordings, login information, browsing history and event/user analytics.
- Risk: This creates a broader data-processing and potential profiling footprint, including collection from sources where individuals may not expect Vaadin to obtain their information.
3. Sharing and international transfers
- The revised policy expressly permits sharing with Vaadin group companies, service providers and other subprocessors, and disclosure to authorities.
- Transfers outside the EU/EEA, including to the United States, remain permitted. The revised wording refers to protection required by applicable privacy law and gives European Commission Standard Contractual Clauses as an example.
- Risk: The policy does not identify specific recipients, transfer mechanisms in each case, or supplementary safeguards. Customers may need more detail for GDPR transfer-risk assessments.
4. Retention
- The prior fixed ten-year retention language is replaced with retention for as long as necessary for the processing purpose and applicable law.
- Customer data is deleted after relevant obligations and claim periods expire; community-member data is generally retained for ten years after the last login.
- Impact: This is more purpose-based but less predictable for customers and may permit retention beyond the former stated period where obligations or claims are asserted.
5. Other changes
- Vaadin’s legal name, business ID, address, privacy email and contact person are added.
- Cookie disclosures are expanded, including definitions, analytics, marketing, social-media and third-party cookies.
- Data-subject rights are reorganized and expressly include access, rectification, erasure, restriction, objection and withdrawal of consent.
2026-06-25 · Community Terms
The publisher records this document as revised on this date (“dated 25 June 2026”).
Between 2023-07-01 and 2024-05-01 · Community Terms
Summary of Important Changes
AI and Customer Data
- Software Services expanded/clarified: Vaadin Copilot and Vaadin Start are expressly identified as AI-powered or software-as-a-service tools. Users may submit code, text, or other material (“Input”) and receive generated results (“Output”), collectively “Content.”
- Third-party AI Providers identified: The services may use OpenAI, Mistral AI, Anthropic, and other providers. This creates additional data-transfer, confidentiality, security, and compliance considerations.
- Confidentiality wording changed materially: The revised terms state that data submitted to or created in Copilot and Vaadin Start is handled under Section 8. Section 8 appears to address the Software Services and applicable AI-provider terms and policies, rather than promising confidentiality.
- No clear AI-training rule in the diff: The amendments do **not expressly state whether customer Input, Output, or other Content may be used to train, fine-tune, evaluate, or improve Vaadin’s or an AI Provider’s models. They also do not clearly state whether training is prohibited, whether data is anonymized, or whether users can opt out.
- Risk: Because the terms incorporate or refer to AI-provider policies, those policies may determine data use and training practices. Users should review the linked provider terms and Vaadin’s Privacy Policy before submitting confidential code, personal data, trade secrets, or regulated information. The absence of an express “no training” commitment is a significant uncertainty.
Confidentiality and Submissions
- The non-commercial Service generally remains non-confidential. Member Materials may be monitored, moderated, or removed.
- Users retain ownership of submissions but remain responsible for having all necessary rights.
- The revised indemnity expressly covers Content submitted to or made available through the Service, including AI Input, and violations of AI-provider terms or policies.
Liability and Warranty
- Disclaimers are substantially expanded. Vaadin disclaims implied warranties and makes no warranty that the Service will be accurate, secure, uninterrupted, error-free, suitable for requirements, or corrected.
- Users bear the risk of downloaded material and related device or data damage.
- Liability exclusions now expressly cover loss of data, profits, revenues, business opportunities, goodwill, business interruption, and third-party damages.
- Vaadin’s remaining liability is capped at the lesser of amounts paid for the Service or the minimum amount required by mandatory law. This materially limits recovery for AI errors, data loss, confidentiality incidents, or service failures.
Indemnity
- The user must defend, indemnify, and hold harmless Vaadin, affiliates, and licensors for broad third-party claims and losses arising from submissions, Software Service use, Terms violations, rights violations, and AI-provider policy violations.
- This obligation survives termination and is in addition to other indemnity obligations.
Other Material Changes
- Vaadin may change the Service, remove features, impose operating limitations, or terminate access at any time.
- Material Terms changes require at least 30 days’ notice; non-material changes take effect upon posting.
- Finnish law applies. Disputes generally proceed by expedited, single-arbitrator arbitration in Turku, Finland, in English, subject to mandatory consumer protections.
Between 2019-09-15 and 2021-07-21 · Privacy Policy
2020-11-11 · Privacy Policy
The publisher records this document as revised on this date (“dated 11 Nov 2020”).