232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Clay's trust-center changed

Notable
CHANGED BETWEEN 21 AUG 2026 AND 10 SEPT 2026FIRST SEEN 10 SEPT 2026 · 15:33 UTC
SCORE
35
PARAGRAPHS CHANGED
24 (4 added, 10 removed)
SNAPSHOTS COMPARED
486 hours apart
FAMILIES TOUCHED
jurisdiction ×11 · optout ×2 · retention ×2 · subprocessor ×22 · tier ×1

What actually changed

Clay Go to market with unique data-and the ability to act on it. Access 100+ premium data sources and AI research agents in one platform, then automate growth workflows to turn insights into revenue. Note: To request a signed Data Processing Agreement (DPA) by Clay, please email security@clay.com . FAQ Sources Of Lead Data

ADDEDIntegration partners. Clay provides its customers with tools that enable them to connect with more than seventy third-party data providers and obtain data directly from them. Websites. Clay's HTTP API tool allows Clay's customers to download data from public websites. Proprietary Data. Clay maintains proprietary databases containing data it has acquired from third parties. Clay provides its users with data from three types of sources. Integration partners. Clay provides its customers with tools that enable them to connect with more than seventy third-party data providers and obtain data directly from them. Websites. Clay's HTTP API tool allows Clay's customers to download data from public websites. Proprietary Data. Clay maintains proprietary databases containing data it has acquired from third parties. You can find a list of Clay's integration partners here - https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit Opens in new tab . This list includes location of data sources. We work with more than seventy integration partners who use industry-standard practices to collect lead data from a wide array of sources. Some sources are public. Others may be private or proprietary. For specific questions, we would invite you to reach out to the data provider directly. You can find a list of our data providers here - https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit Opens in new tab ). While we are not in a position to monitor each provider's specific practices, we expect and assume each of them obtains any permissions they would be required to obtain under the law - if any permission is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary Opens in new tab - they accept upon signing up: When you share information on our Services, you understand that others can see, copy and use that information." If you have questions about a specific provider, we would invite you to reach out to that provider directly. You can find a list of our data providers here https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit Opens in new tab . We would not work with data providers who break the law. While we are not in a position to assess each provider's specific practices, we work with data providers who have established strong reputations and employ industry-standard practices to gather the lead data they provide. If you have questions about a specific provider, we would invite you to reach out to that provider directly. We work with more than seventy integration partners who use industry-standard practices to collect lead data from a wide array of sources. Some sources are public. Others may be private or proprietary. While we are not in a position to assess each provider's specific practices, we work with data providers who have established strong reputations and employ industry-standard practices to gather the lead data they provide. If you have questions about a specific provider, we would invite you to reach out to that provider directly. Clay works with more than seventy third-party data providers. While we are not in a position to monitor each provider's specific practices, it is possible that some of the data they provide to Clay customers is collected in other countries. Insofar as that is the case, Clay relies on each provider to ensure the lawful transfer of data. To the extent Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses. Notice, Consent and Opt-Out We would only notify people where required to do so by law. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, we would rely on the third-party data provider (or other data controller) to provide any required notifications. Clay customers are, of course, free to provide notifications to people whose data they collect. We leave it to each data provider or customer to make its own assessment about any legal obligations they might have in this regard. We would only obtain consent where required to do so by law. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, we would rely on the third-party data provider (or other data controller) to obtain any required consent. While we are not in a position to monitor each provider's specific practices, we expect and assume each of them obtains any permissions they would be required to obtain under the law - if any permission is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary Opens in new tab - they accept upon signing up: "When you share information on our Services, you understand that others can see, copy and use that information." We rely on each third-party data provider to determine whether notice may be required, and provide any notice that may be required. If you have questions about a specific provider, we would invite you to reach out to that provider directly. We rely on each third-party data provider to determine whether any consent would be required, and to obtain any such consent if any consent is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary Opens in new tab - they accept upon signing up: "When you share information on our Services, you understand that others can see, copy and use that information." When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, Clay is not in a position to discharge the obligations of a data controller and cannot delete or remove data controlled by other parties. In regard to data contained in Clay's proprietary databases, Clay will honor all requests to delete, correct, or not sell a consumer's data. For more information on the rights data subjects and consumers have, and how to exercise these rights, please review our Privacy Policy - https://privacy.clay.com/policies Opens in new tab . We rely on each third-party data provider to determine the choices it offers. If you have questions about a specific provider's options relating to personal information, we would invite you to reach out to that provider directly.

CCPA / Data Broker

ADDEDYes. Please review our Privacy Policy for specific CCPA disclosures, and information on how consumers can exercise their rights under CCPA. Here is our privacy policy - https://privacy.clay.com/policies Opens in new tab Our Privacy Policy contains specific information on consumers' data rights and how to exercise them. https://privacy.clay.com/policies Opens in new tab Yes. Clay is registered as a data broker in California, Nevada, Oregon, Texas, and Vermont. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a service provider. As such, it is not engaged in the sale of personal information. When Clay makes personal information available to its customers from its proprietary databases, Clay is engaged in the sale of personal information. Consumers can opt-out by submitting a request here - https://privacy.clay.com/policies Opens in new tab . For more information on data rights and how to exercise them, please see our Privacy Policy - ( https://privacy.clay.com/policies Opens in new tab .

GDPR

ADDEDYes. Please review our Privacy Policy ( https://privacy.clay.com/policies Opens in new tab ) for specific GDPR disclosures, and information on how data subjects can exercise their rights under the GDPR. You can also request a copy of our standard data processing agreement on this trust page. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, Article 14 does not apply to Clay. When Clay makes personal information available to its customers from its proprietary databases, Clay provides the disclosures required by Article 14(1) and 14(2) in its Privacy Policy and the GDPR disclosures included in the Privacy Policy. Clay does not maintain a presence in Europe and therefore does not transfer data from Europe to other countries. Clay and its subprocessors process customer data in the United States. Clay does not currently offer alternative processing locations. For more information please see our Privacy Policy ( https://privacy.clay.com/policies Opens in new tab ). Clay and its subprocessors process customer data in the United States. You can find a complete list of Clay's subprocessors here https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit Opens in new tab . For more information please see our Privacy Policy ( https://privacy.clay.com/policies Opens in new tab ). Clay and its subprocessors process customer data in the United States. You can find a complete list of Clay's subprocessors here ( https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit Opens in new tab ). Insofar as Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses. Please review our Privacy Policy ( https://privacy.clay.com/policies Opens in new tab ) for information on how data subjects can exercise their rights under the GDPR. a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or a systematic monitoring of a publicly accessible area on a large scale. No. GDPR requires data controllers to conduct data protection impact assessment where the controller's processing activities are "likely to result in a high risk to the rights and freedoms of natural persons." GDPR Art. 35(1). Examples of this include processing activities which involve: a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or a systematic monitoring of a publicly accessible area on a large scale. GDPR Art. 35(3). When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, Article 35 does not apply to Clay.. When Clay acts as a controller and makes personal information such as email addresses or telephone numbers available to its customers from its proprietary databases, Clay is not engaged in "high risk" processing activities referenced in Article 35. In both cases, no DPIA is required from Clay. A customer may be required to conduct a DPIA based on how the customer decides to use any personal data it obtains from Clay. Clay can't anticipate or account for every possible use our customers make of data obtained via Clay, so we rely on our customers to assess and fulfill their data protection obligations based on how they decide to use the personal data they obtain via Clay. Clay has integrations with Anthropic and OpenAI that let Clay customers use these providers to draft personalized outbound emails, or perform other tasks, as directed by the customer. It would therefore be up to the customer to decide whether it wants to use these AI integrations, and how it wants to use them, in conjunction with the data the customer obtains via Clay. In doing so, the customer would be acting as the data controller and it would be up to the customer to determine whether its particular uses require a DPIA. If the customer determines its uses do require a DPIA it would likewise be up to the customer to conduct a DPIA based on how it chooses to use data obtained via Clay. We can't anticipate or account for every possible use our customers make of data obtained via Clay, so we rely on our customers to assess and fulfill their data protection obligations based on how they decide to use the personal data they obtain via Clay. The GDPR requires the appointment of a Data Protection Officer where the data controller or the data processor where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10. GDPR Article 37(1). Clay does not meet any of these three criteria and is therefore not required to appoint a Data Protection Officer. Clay assesses its data privacy and data compliance framework regularly, and may choose to appoint a DPO as Clay's business evolves and if the need emerges. No. Clay does not make customer tables available to third parties. If Clay were to decide at some future date to make customer tables available for AI training, it would provide a mechanism for customers to opt out.

Other FAQs

ADDEDClay is not registered under the EU-US Privacy Framework. Insofar as Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses.

Top All FAQs Is Clay registered under the EU-US Privacy Framework?

REMOVEDClay is not registered under the EU-US Privacy Framework. Insofar as Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses.

https://trust.clay.com/faq?s=ttmki5nwdkybnrzn7sf2k Where does Clay get its data? Clay provides its users with data from three types of sources. * Integration partners. Clay provides its customers with tools that enable them to connect with more than seventy third-party data providers and obtain data directly from them. * Websites. Clay's HTTP API tool allows Clay's customers to download data from public websites. * Proprietary Data. Clay maintains proprietary databases containing data it has acquired from third parties. https://trust.clay.com/faq?s=xetu0yb9ndfavya823y6uo Who are your third-party data providers? You can find a list of Clay's integration partners here -https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit. This list includes location of data sources. https://trust.clay.com/faq?s=q883xi2i8lnamlwhwknrtf Where do your third-party data providers get their data? We work with more than seventy integration partners who use industry-standard practices to collect lead data from a wide array of sources. Some sources are public. Others may be private or proprietary. For specific questions, we would invite you to reach out to the data provider directly. You can find a list of our data providers here - https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit). https://trust.clay.com/faq?s=54job8cibm9zpdafj87oo Do your third-party data providers get consent to collect and share contact information? While we are not in a position to monitor each provider's specific practices, we expect and assume each of them obtains any permissions they would be required to obtain under the law - if any permission is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary - they accept upon signing up: When you share information on our Services, you understand that others can see, copy and use that information." If you have questions about a specific provider, we would invite you to reach out to that provider directly. You can find a list of our data providers here https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit. https://trust.clay.com/faq?s=7x5ljkiu0xli1ft9cxqx5w Do your third-party data providers obtain their data lawfully? We would not work with data providers who break the law. While we are not in a position to assess each provider's specific practices, we work with data providers who have established strong reputations and employ industry-standard practices to gather the lead data they provide. If you have questions about a specific provider, we would invite you to reach out to that provider directly. https://trust.clay.com/faq?s=ppyxe2s6p6xe7txkgh59x0 Do your third-party data providers scrape data from other platforms in violation of those platforms' terms of service?

REMOVEDWe work with more than seventy integration partners who use industry-standard practices to collect lead data from a wide array of sources. Some sources are public. Others may be private or proprietary. While we are not in a position to assess each provider's specific practices, we work with data providers who have established strong reputations and employ industry-standard practices to gather the lead data they provide. If you have questions about a specific provider, we would invite you to reach out to that provider directly.

https://trust.clay.com/faq?s=ndruos1pxqb8s9380fclv Do your third-party data providers transmit or receive personal data from countries outside the United States? Clay works with more than seventy third-party data providers. While we are not in a position to monitor each provider's specific practices, it is possible that some of the data they provide to Clay customers is collected in other countries. Insofar as that is the case, Clay relies on each provider to ensure the lawful transfer of data. To the extent Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses. https://trust.clay.com/faq?s=n7rharwade6uk1ld6jf7b Do you notify people that you have their contact information?

REMOVEDWe would only notify people where required to do so by law. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, we would rely on the third-party data provider (or other data controller) to provide any required notifications. Clay customers are, of course, free to provide notifications to people whose data they collect. We leave it to each data provider or customer to make its own assessment about any legal obligations they might have in this regard.

https://trust.clay.com/faq?s=5y6a6kyr16nzpwl0cieevt Do you get consent to collect and share contact information? We would only obtain consent where required to do so by law. When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, we would rely on the third-party data provider (or other data controller) to obtain any required consent. While we are not in a position to monitor each provider's specific practices, we expect and assume each of them obtains any permissions they would be required to obtain under the law - if any permission is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary - they accept upon signing up: "When you share information on our Services, you understand that others can see, copy and use that information." If you have questions about a specific provider, we would invite you to reach out to that provider directly. https://trust.clay.com/faq?s=jygyvrz7rmsisx8hqn7k0m Do your third-party data providers notify people they have their contact information?

REMOVEDWe rely on each third-party data provider to determine whether notice may be required, and provide any notice that may be required. If you have questions about a specific provider, we would invite you to reach out to that provider directly.

https://trust.clay.com/faq?s=qmrr79ob21fhvty1p561tm We rely on each third-party data provider to determine whether any consent would be required, and to obtain any such consent if any consent is required at all. In many cases, people may have already acknowledged and agreed their information may be copied when they share it on platforms like LinkedIn based on the User Agreement - https://www.linkedin.com/legal/user-agreement-summary - they accept upon signing up: "When you share information on our Services, you understand that others can see, copy and use that information." If you have questions about a specific provider, we would invite you to reach out to that provider directly. https://trust.clay.com/faq?s=has26lxw7vcig2pups1m9 Can people opt-out and have their contact information removed from Clay? When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, Clay is not in a position to discharge the obligations of a data controller and cannot delete or remove data controlled by other parties. In regard to data contained in Clay's proprietary databases, Clay will honor all requests to delete, correct, or not sell a consumer's data. For more information on the rights data subjects and consumers have, and how to exercise these rights, please review our Privacy Policy - https://privacy.clay.com/policies. https://trust.clay.com/faq?s=wlzg6namscl4leqg12a17c Can people opt-out and have their contact information removed from your third-party data providers?

REMOVEDWe rely on each third-party data provider to determine the choices it offers. If you have questions about a specific provider's options relating to personal information, we would invite you to reach out to that provider directly.

https://trust.clay.com/faq?s=na2ivyfkqi6qbhnyqswawh Do you comply with CCPA? Yes. Please review our Privacy Policy for specific CCPA disclosures, and information on how consumers can exercise their rights under CCPA. Here is our privacy policy - https://privacy.clay.com/policies https://trust.clay.com/faq?s=68vg04iwkussmwl31ve8co Where can Clay consumers exercise their data rights? Our Privacy Policy contains specific information on consumers' data rights and how to exercise them. https://privacy.clay.com/policies https://trust.clay.com/faq?s=v5d301nrljzkqd7ahihecw Is Clay a data broker?

REMOVEDYes. Clay is registered as a data broker in California, Nevada, Oregon, Texas, and Vermont.

https://trust.clay.com/faq?s=csaqig0a074eleu9f07p85 Is Clay registered as a Data Broker? https://trust.clay.com/faq?s=4b3wa60fiergu54evtsdw Does Clay sell my data? When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a service provider. As such, it is not engaged in the sale of personal information. When Clay makes personal information available to its customers from its proprietary databases, Clay is engaged in the sale of personal information. Consumers can opt-out by submitting a request here - https://privacy.clay.com/policies. For more information on data rights and how to exercise them, please see our Privacy Policy - (https://privacy.clay.com/policies. https://trust.clay.com/faq?s=hg3xj4g5px2bm8rw2iq1m Do you comply with GDPR? Yes. Please review our Privacy Policy (https://privacy.clay.com/policies) for specific GDPR disclosures, and information on how data subjects can exercise their rights under the GDPR. You can also request a copy of our standard data processing agreement on this trust page. https://trust.clay.com/faq?s=elf4zb6vvxg5yuq8frxt6h Do you notify data subjects you have their personal data per to Article 14? When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, Article 14 does not apply to Clay. When Clay makes personal information available to its customers from its proprietary databases, Clay provides the disclosures required by Article 14(1) and 14(2) in its Privacy Policy and the GDPR disclosures included in the Privacy Policy. https://trust.clay.com/faq?s=ux1avyn36g6po7z72w1n Does Clay transfer data from the EU to other countries?

REMOVEDClay does not maintain a presence in Europe and therefore does not transfer data from Europe to other countries.

https://trust.clay.com/faq?s=ckl77u4ql2ssekf98nml3b Can clients define the legal jurisdictions where their data can be transmitted, processed or stored? Please provide details? Clay and its subprocessors process customer data in the United States. Clay does not currently offer alternative processing locations. For more information please see our Privacy Policy (https://privacy.clay.com/policies). https://trust.clay.com/faq?s=7sq71cwh94k7iylkwnhmu Please provide the full list of where (countries) you and the subprocessors process customer data. Clay and its subprocessors process customer data in the United States. You can find a complete list of Clay's subprocessors here https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit. For more information please see our Privacy Policy (https://privacy.clay.com/policies). https://trust.clay.com/faq?s=y1epwwp9dz4lzsfmm0fw2 In case you or your subprocessors process personal data in third countries, what legal ground do you use to transfer the personal data to the third countries? Clay and its subprocessors process customer data in the United States. You can find a complete list of Clay's subprocessors here (https://docs.google.com/document/d/1hl1q4iyTt0SVSmwKqBOozbAq4_A9UcoAN7t6Ob4yYzA/edit). Insofar as Clay is required to legitimize data transfers pursuant to the GDPR, it does so using Standard Contractual Clauses. https://trust.clay.com/faq?s=czlyxrmuxxwyjyk7yb772v Where can Clay customers exercise their data subject rights? Please review our Privacy Policy (https://privacy.clay.com/policies) for information on how data subjects can exercise their rights under the GDPR. https://trust.clay.com/faq?s=v1e9vt8ddw2npeskfuelw9 Has Clay conducted a Data Processing Impact Assessment (DPIA) under GDPR? No. GDPR requires data controllers to conduct data protection impact assessment where the controller's processing activities are "likely to result in a high risk to the rights and freedoms of natural persons." GDPR Art. 35(1). Examples of this include processing activities which involve: 1. a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; 2. processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or 3. a systematic monitoring of a publicly accessible area on a large scale. GDPR Art. 35(3). When Clay connects its users with third-party data providers, or provides tools that enable its customers to collect data from websites, Clay is acting as a data processor or service provider, not a data controller. In those cases, Article 35 does not apply to Clay.. When Clay acts as a controller and makes personal information such as email addresses or telephone numbers available to its customers from its proprietary databases, Clay is not engaged in "high risk" processing activities referenced in Article 35. In both cases, no DPIA is required from Clay. A customer may be required to conduct a DPIA based on how the customer decides to use any personal data it obtains from Clay. Clay can't anticipate or account for every possible use our customers make of data obtained via Clay, so we rely on our customers to assess and fulfill their data protection obligations based on how they decide to use the personal data they obtain via Clay. https://trust.clay.com/faq?s=yceyclqp9jeptbcbdf7rv But Clay uses AI and the UK ICO says using AI usually requires a DPIA.

REMOVEDClay has integrations with Anthropic and OpenAI that let Clay customers use these providers to draft personalized outbound emails, or perform other tasks, as directed by the customer. It would therefore be up to the customer to decide whether it wants to use these AI integrations, and how it wants to use them, in conjunction with the data the customer obtains via Clay. In doing so, the customer would be acting as the data controller and it would be up to the customer to determine whether its particular uses require a DPIA. If the customer determines its uses do require a DPIA it would likewise be up to the customer to conduct a DPIA based on how it chooses to use data obtained via Clay. We can't anticipate or account for every possible use our customers make of data obtained via Clay, so we rely on our customers to assess and fulfill their data protection obligations based on how they decide to use the personal data they obtain via Clay.

https://trust.clay.com/faq?s=vzmf9xt6x9c1ofq22256sc Has Clay appointed a Data Protection Officer? The GDPR requires the appointment of a Data Protection Officer where the data controller or the data processor where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10. GDPR Article 37(1). Clay does not meet any of these three criteria and is therefore not required to appoint a Data Protection Officer. Clay assesses its data privacy and data compliance framework regularly, and may choose to appoint a DPO as Clay's business evolves and if the need emerges. https://trust.clay.com/faq?s=pnqiuc05gh1vtc7dpackp7 Will Clay use our data for any AI training purposes?

REMOVEDNo. Clay does not make customer tables available to third parties.

https://trust.clay.com/faq?s=o70mj513rk6lh3oqec9aaq Can we opt-out of having our data used for AI training?

REMOVEDIf Clay were to decide at some future date to make customer tables available for AI training, it would provide a mechanism for customers to opt out.

https://trust.clay.com/faq?s=bn53hjjgvmjgpe61eq10o