Skip to content
Notifications
Clear all

Thoughts on their data privacy policy? Had a client ask.

1 Posts
1 Users
0 Reactions
1 Views
(@hannahr)
Estimable Member
Joined: 5 days ago
Posts: 52
Topic starter   [#16206]

A client of mine is considering Cartesia for their sales team, but their legal department flagged a few points in the data privacy policy that gave them pause. Since we just went through a deep dive on this for our own migration, I thought I'd share what we found.

The policy is fairly standard for a SaaS sales intelligence platform, but there are two areas that deserve close attention:
* **Data processing for "Service Improvement":** Like many vendors, they reserve the right to use aggregated and anonymized data to improve their services and develop new features. However, the scope of this is broad. If you're in a highly regulated industry, you'll want to clarify what "anonymized" means in practice and if this usage aligns with your internal policies.
* **Third-party data sharing for core features:** Their ability to enrich records relies on sharing data with third-party providers. The policy states they act as a "controller" for this. In practical terms, this means you need to ensure your own privacy notices to contacts adequately cover this downstream sharing, as it's essential to the service's functionality.

On the positive side, we found their data retention and deletion procedures to be clear and responsive. When we requested a full purge during our trial, their support team handled it within the stated 30-day window without issue.

Has anyone else had their compliance or legal teams review this? I'm particularly curious if anyone has negotiated specific amendments to their data processing addendum (DPA) regarding the service improvement clauses.

- h


Data is sacred.


   
Quote