Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · ibm.com

IBM watsonx

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskMEDReviewed 2026-08-31
Creator: low · GRC: medium · Counsel: medium
enterprise band
Caution
creator · pending
Dealbreaker · Training without opt-out
Exhibit A · Privacy Policy · verbatim

IBM’s AI models and systems are designed, trained, validated, and tested on data from publicly available sources that may incidentally contain Personal Information. We have implemented safeguards, processes, and tools to mitigate associated impacts and help address responsible development and deployment of trustworthy AI.

highest-risk verified finding on training use — tap for the citation
126 verified findings8 policy surfaces1/2 core docs verified

Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.

Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
61
medium
65
low
1/2
docs
Trains on your data?
Training possible — conditions or opt-outs apply
from 1 cited finding
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →
Risk by role
Select a role to tailor the summary and reorder the findings below.

Scores derived from 57 enriched findings — same verbatim citations as below. AI-generated, not legal advice.

What this means for you
  • IBM watsonx's training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
  • Your outputs and prompts are explicitly yours — IBM watsonx's terms include affirmatively protective IP language.
  • Data handling is conditional — 10 privacy or retention clauses warrant review before using IBM watsonx at scale.

Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.

How to read this page: Overall risk rates what IBM watsonx's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Creator lens
NOT YET ASSESSED

IP/output assessment pending — terms of service not yet verified This lens receives a band only once its source document has been captured and read in full.

Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.

Enterprise lens
Data use, retention, subprocessors, audit
CAUTION
Dealbreaker — Training without opt-out. Your inputs/outputs are used to train models and the policy provides no way to decline. see the clause · and another

Based on 142 verified, verbatim-cited findings below — read the citations.

Automated assessment against a published rubric — not legal advice.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 126 findings); Terms of Service — Capture under review. Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Needs review

A core policy document is captured but requires review before AIRIN can mark the corpus fully verified.

Document status
  • Privacy Policy
    Verified - read in full - 126 citationsstaticLast captured 2026-08-31
  • Terms of Service
    Completeness unconfirmedrendered
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Permits IBM to collect and use personal information derived from use of its services and technologies for product and process development, including developing automated tools and improving underlying technologies.

" We collect information from the use of our business processes, websites, cloud and online services, products, or technologies. This information may include personal information and is used for product and process development. For example, ..."
📍 Privacy Policy › “Learn more”Jump to exact text →
plan language
Privacy & data use

This segment defines the categories of personal information collected in a contractual relationship, including business contact information, IBMid, order details, shipment, payment, implementation, and access-related data, specifying the scope of permissible data collection.

" The information collected in a contractual relationship may include the business contact information of the requester, an IBMid, and the order details. Information that is required for shipment and payment, for the implementation of servic..."
📍 Privacy Policy › “Learn more”Jump to exact text →
plan language
Privacy & data use

These uses are typically covered by legitimate interest or legal obligation bases under GDPR, presenting low risk in standard contexts, though the open-ended 'protect or enforce our rights' phrasing warrants attention.

"We collect and use information from our business systems, which may include personal information, to: protect or enforce our rights, including to detect fraud or other criminal activities (for example, by using information in payment sys..."
📍 Privacy Policy › “Learn more”Jump to exact text →
plan language
Privacy & data use

Imposes obligations on IBM to implement reasonable physical, administrative, and technical safeguards including access controls and encryption, and to require Business Partners, suppliers, and third parties to implement equivalent protective measures against unauthorized access or disclosure.

" To protect your personal information from unauthorized access, use, and disclosure, we implement reasonable physical, administrative, and technical safeguards. These safeguards include role-based access controls and encryption to keep pers..."
📍 Privacy Policy › “Information Security and Retention”Jump to exact text →
plan language
Privacy & data use

Provides concrete examples of contractual necessity processing, including collection of business contact information for purchases, support services, job applications, and pension management, operationalizing the contractual legal basis obligation.

" If you intend to purchase a product or service, we require your business contact information to enter into a contract with you or you may need to create an IBMid (see  Your Account )  to access a purchased product online . When fulfillin..."
📍 Privacy Policy › “Necessary for the performance of a contract with you”Jump to exact text →
plan language
Privacy & data use

Grants the employing/contracting organization the right to inquire about account status, request account settings including personal information, and optionally convert the account to an enterprise ID, conferring specific organizational rights over personal data associated with the account.

" inquire about the status of your account, request your account settings (including your personal information), and, at its option, convert it to an enterprise ID."
📍 Privacy Policy › “Learn more”Jump to exact text →
plan language
Privacy & data use

This segment establishes that IBM collects information about job applicants and prospective candidates, incorporates by reference the Talent Acquisition Privacy Notice, and imposes an obligation to continue processing former employee information for business, contractual, employment, legal, and fiscal purposes—including pension management—after employment ends.

" We are constantly searching for new talent for our organization, and we collect information about job applicants or prospective candidates from several sources. Applicants are referred to the  Talent Acquisition Privacy Notice  for more in..."
📍 Privacy Policy › “Recruitment and Former Employees”Jump to exact text →
plan language
Privacy & data use

Establishes IBM's practice of collecting business operations information, including personal information where necessary, for organizational decision-making, performance reporting, and trend analysis, describing the legal basis and scope of that data use.

" We collect information about our business operations to make informed decisions about the organization, the business, and to report on performance, audits, and trends. For example, we use this information to analyze the costs and quality o..."
📍 Privacy Policy › “Learn more”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 61
Tier-specific - 0
Total citations - 126
Severity
Surface
Document
Tier
Training on your content
CautionHigh
" IBM’s AI models and systems are designed, trained, validated, and tested on data from publicly available sources that may incidentally contain Personal Information. We have implemented safeguards, processes, and tools to mitigate associated impacts and help address responsible development and deployment of trustworthy AI."
Privacy Policy › “Information Security and Retention”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Discloses that IBM's AI models are trained on publicly available data that may incidentally contain Personal Information, and states IBM's obligation to implement safeguards, processes, and tools to mitigate associated privacy impacts and support responsible AI development.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" We collect information from the use of our business processes, websites, cloud and online services, products, or technologies. This information may include personal information and is used for product and process development. For example, we may use this information to increase efficiency, decrease costs, or improve services by developing automated processes and tools, or to develop or improve the technologies on which these are based."
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Permits IBM to collect and use personal information derived from use of its services and technologies for product and process development, including developing automated tools and improving underlying technologies.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" When you visit our websites, cloud and online services, software products, or view our content on certain third-party websites, we collect information regarding your connection and your activity by using various online tracking technologies, such as cookies, web beacons, Local Storage, or HTML5. Information that is collected with these technologies may be necessary to operate the website or service, to improve performance, to help us understand how our online services are used, to determine the interests of our users or to enable access continuity that eliminates repeated form submissions. We use advertising partners to provide and assist in the use of such technologies on IBM and other sites."
Privacy Policy › “Cookies and Similar Technologies”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Describes IBM's collection of connection and activity information via online tracking technologies when users visit IBM websites or third-party content, establishing the scope and purposes of such collection including operational necessity and analytics.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" inquire about the status of your account, request your account settings (including your personal information), and, at its option, convert it to an enterprise ID."
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants the employing/contracting organization the right to inquire about account status, request account settings including personal information, and optionally convert the account to an enterprise ID, conferring specific organizational rights over personal data associated with the account.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" We use this information to improve and personalize your experience with our websites, provide you with content that you may be interested in, create marketing insights, and to improve our websites, online services, and related technologies."
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants IBM permission to use collected website usage information for purposes including personalization, content delivery, marketing insights, and service improvement.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" To opt out of the use of your hashed email for personalization or targeted advertising, you can withdraw your email consent by using any of these options."
Privacy Policy › “Contact you by using email, telephone, or postal mail”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants users the right to opt out of hashed-email-based personalization or targeted advertising by withdrawing email consent through provided options.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" The information that we collect may include any information exchanged during our phone conversations or provided during Live Chat support sessions on our websites. This may include a recording or transcript of your conversations with us. We may use this information to inform you of products or services that are related to your support request. This can include product updates or fixes, and we may combine the information that is collected through other interactions with you or your organization to provide more valuable suggestions in relation to product support, such as any available training regarding the issue."
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment permits IBM to use support-collected information—including call recordings and chat transcripts—to inform users of related products or services such as updates and fixes, and to combine it with other interaction data to provide more relevant product support suggestions, including training recommendations.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" This information may be collected for various purposes, depending on the nature of the products or services, for example, for contractual management and compliance, to provide support, for the improvement or development of our products and services, to contact you for customer satisfaction surveys, and to generate technical and market insights. For more information, see IBM Applications, Cloud and Online Services ."
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment permits IBM to use contractually collected information for multiple stated purposes—contractual management and compliance, support, product improvement, customer satisfaction surveys, and generating technical and market insights—and incorporates by reference the IBM Applications, Cloud and Online Services document for further detail.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" Necessary for the purposes of IBM’s or a third party’s legitimate interest "
Privacy Policy › “Necessary for the performance of a contract with you”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Defines the 'legitimate interest' legal basis for processing personal information, identifying business conduct, marketing, legal protection, IT security, and client requirements as qualifying interests.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" Subject to your preferences, we may use this information to market to you regarding IBM products, services, and offerings. For example, we may:"
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants IBM permission, subject to user preferences, to use collected information to market IBM products, services, and offerings through specified channels.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" Legitimate interests relate to being able to conduct and organize business, which includes the marketing of our offerings, protecting our legal interests, securing our IT environment, or meeting client requirements."
Privacy Policy › “Necessary for the performance of a contract with you”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Further elaborates the definition of legitimate interests by specifying the categories of business activities IBM considers to fall within this legal basis.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" This information is collected to provide you with access, to operate the service, for support, to personalize and improve your experience of the service, to develop other services and technologies, and generate technical and market insights. For more information on the technologies that we use to collect this information, and setting your preferences, see  Cookies and Similar Technologies ."
Privacy Policy › “IBMid information (if signed in),”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants IBM permission to use cloud/online service data for access provision, service operation, support, personalization, service development, and market insights, and incorporates cookie policy by cross-reference.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" Subject to your preferences, we use the information that we collect to communicate with you about relevant products, services, and offerings. We also use this information to personalize your online experience with our content and advertisements and to develop internal marketing and business intelligence. You may submit an opt-out request , or select Unsubscribe at the bottom of each marketing email. To review or set your preferences regarding the information that we collect about you online on our websites, select Cookie Preferences in the website footer."
Privacy Policy › “Marketing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants IBM permission, subject to user preferences, to use collected information for marketing communications, content personalization, advertisements, and business intelligence, and provides users a right to opt out via unsubscribe or cookie preferences.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" We also use this information to develop marketing and business intelligence, which is essential for our business operations. For example, we may:"
Privacy Policy › “Contact you by using email, telephone, or postal mail”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Permits IBM to use collected information for marketing and business intelligence purposes deemed essential to IBM's business operations, introducing examples of such use.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" Combine the information we collect to better understand your interests and potential business needs, Use aggregated data to measure effectiveness of our marketing campaigns and events, and to proceed to informed business decisions and investments, Aggregate the information that is collected about IBM website visitors for the purposes of developing and modelling marketing audiences."
Privacy Policy › “Contact you by using email, telephone, or postal mail”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Permits IBM to combine, aggregate, and model collected user data to understand interests, measure marketing effectiveness, make business decisions, and develop marketing audiences.

AI-generated interpretation, not legal advice.

Moderation & enforcement
CautionHigh
" If a material change is made to this Privacy Statement, the effective date is revised, and a notice is posted on the updated Privacy Statement for 30 days. By continuing to use our websites and services after a revision takes effect, it is considered that users have read and understand the changes."
Privacy Policy › “Privacy Statement Updates”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for material changes to the Privacy Statement — revising the effective date, posting a notice for 30 days — and deems continued use of IBM websites and services after revision as acceptance of the updated terms, creating a binding update and deemed-consent mechanism.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
"We collect and use information from our business systems, which may include personal information, to: protect or enforce our rights, including to detect fraud or other criminal activities (for example, by using information in payment systems) handle and resolve disputes answer complaints and defend IBM in legal proceedings and comply with legal obligations in the countries where we do busines"
Privacy Policy › “Learn more”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

These uses are typically covered by legitimate interest or legal obligation bases under GDPR, presenting low risk in standard contexts, though the open-ended 'protect or enforce our rights' phrasing warrants attention.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We may also store your details from business contact information that you provide to us, or that we collect from your organization, our Business Partners, or our suppliers."
Privacy Policy › “Your Account”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Collection of personal data from third parties raises transparency concerns; individuals may be unaware that IBM holds data about them obtained from partner organisations.

AI-generated interpretation, not legal advice.

Common questions about IBM watsonx's policies

Does IBM watsonx train its AI models on your data?
Training possible — conditions or opt-outs apply — based on 1 verified finding from IBM watsonx's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from IBM watsonx's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

18 verified clauses

Clauses in IBM watsonx's policies that work in your favour — commitments the platform made to you.

  • Audit rights, DPA & residency
    Contractual Clauses, such as those approved by the EU Commission and accepted in several other countries.  Data Privacy Framework Certification. Where applicable, certain designated IBM services (for example, IBM Infrastructure-as-a-Service, Platform-as-a-Ser…

    Enumerates specific cross-border transfer safeguards including Contractual Clauses, Data Privacy Framework Certification, and Binding Corporate Rules for Controllers, describing the procedural mechanisms IBM uses to lawf…

    📍 Privacy Policy › “Facilitating International Transfers”Jump to exact text →
  • Privacy & data useads & tracking use
    You can use the IBM Cookie Manager to learn more about the online tracking technologies we use and to review or set your preferences regarding the information that we collect about you on our websites. The IBM Cookie Manager is either presented as a notificati…

    Describes the procedure by which users can review and set cookie preferences via the IBM Cookie Manager, including its presentation and limitations, providing a user-facing rights exercise mechanism.

    📍 Privacy Policy › “Learn more”Jump to exact text →
  • Privacy & data usesale/sharing of personal data
    subject to applicable law, request access to the personal information that we have on you, or have it updated or corrected. Depending on the applicable law, you may have additional or limited rights concerning your personal information. request to obtain your…

    Enumerates specific data subject rights subject to applicable law, including access, correction, portability, deletion, and opt-out of targeted advertising, granting individuals enforceable entitlements over their person…

    📍 Privacy Policy › “Your Rights”Jump to exact text →
  • Privacy & data usesensitive data (biometric/location/health)
    When you submit a Data Rights (DR) request, you provide us with personal information, including your name and contact details, which we use to respond to your request. In some circumstances, to verify your identity and to ensure we disclose the personal inform…

    Describes the personal information collected when submitting a Data Rights request and the identity verification procedure, including temporary retention of photo ID that is deleted immediately after verification.

    📍 Privacy Policy › “Data Rights Requests Details”Jump to exact text →
  • Privacy & data use
    ask questions related to this Privacy Statement and privacy practices. Your message is forwarded to the appropriate member of IBM’s Data Privacy Team, including the responsible Data Protection Officers. submit a complaint to IBM if you are not satisfied with…

    Specifies the procedural use of the Contact Us form for submitting privacy questions and complaints, identifying routing to IBM's Data Privacy Team and Data Protection Officers.

    • Designated security contact: IBM's Data Privacy Team, including the responsible Data Protection Officers
    📍 Privacy Policy › “Your Rights”Jump to exact text →
  • Moderation & enforcementterms can change anytime
    If a material change is made to this Privacy Statement, the effective date is revised, and a notice is posted on the updated Privacy Statement for 30 days. By continuing to use our websites and services after a revision takes effect, it is considered that user…

    Establishes the procedure for material changes to the Privacy Statement — revising the effective date, posting a notice for 30 days — and deems continued use of IBM websites and services after revision as acceptance of t…

    • Terms changes: advance notice promised
    📍 Privacy Policy › “Privacy Statement Updates”Jump to exact text →

+ 12 more verified clauses of this kind on this platform, cited in full in the report.

📋 Rules you must follow

0 verified clauses

What IBM watsonx requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in IBM watsonx's published policies yet.

What the policies actually cover

9 topics
  • Product telemetry & usage tracking31 clauses
  • Advertising & tracking6 protective20 clauses
  • Sale or sharing of personal data2 protective2 clauses
  • Sensitive data (biometric, location, health)1 protective3 clauses
  • Children's data1 clause
  • Government & law-enforcement disclosure3 clauses
  • Terms can change at any time1 protective1 clause
  • Deletion rights & post-termination survival1 protective4 clauses
  • Breach-notification promises1 clause

60 further verified clauses are cited on this page but not yet assigned a topic.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Information Security and Retention” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Information Security and Retention” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Ambiguity — Caution

Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Information Security and Retention” describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Information Security and Retention” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

577
clauses
52
patterns
52
stances
privacy sharing · 34data retention · 7ip ownership · 6legal burden · 5
data retentionMEDIUMPrivacy Policy › “Information Security and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We only retain personal information as long as necessary to fulfill the purposes for which it is processed, or to comply with legal and regulatory retention requirements. Legal and regulatory retention requirements may include retaining information for: audit and accounting purposes, statutory retention terms, the handling of disputes, and the establishment, exercise, or defense of legal claims in the countries wh...
Open source citation
data retentionMEDIUMPrivacy Policy › “Information Security and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We only retain personal information as long as necessary to fulfill the purposes for which it is processed, or to comply with legal and regulatory retention requirements. Legal and regulatory retention requirements may include retaining information for:
Open source citation
data retentionMEDIUMPrivacy Policy › “Information Security and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We only retain personal information as long as necessary to fulfill the purposes for which it is processed, or to comply with legal and regulatory retention requirements. Legal and regulatory retention requirements may include retaining information for:
Open source citation
data retentionMEDIUMPrivacy Policy › “Information Security and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We only retain personal information as long as necessary to fulfill the purposes for which it is processed, or to comply with legal and regulatory retention requirements. Legal and regulatory retention requirements may include retaining information for:
Open source citation
data retentionMEDIUMPrivacy Policy › “Information Security and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We only retain personal information as long as necessary to fulfill the purposes for which it is processed, or to comply with legal and regulatory retention requirements. Legal and regulatory retention requirements may include retaining information for:
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersdata retentionconditionalMEDIUM12
All applicable tierssubprocessors data sharingconditionalMEDIUM1
Team / Businessdata retentionconditionalMEDIUM1
Team / Businessindemnity liabilityconditionalMEDIUM5
Team / Businessprivacy data useworsensHIGH26
Team / Businesssubprocessors data sharingworsensHIGH5

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

worsenedhigh materialityJun 17Jul 20, 2026

data sharing worsened from medium/third party or vendor sharing to high/sale or sell.

Before · medium
This privacy statement describes how IBM collects, uses, and shares personal information about consumers and other individuals within our clients, business partners, supplier and other organizations with which IBM has or contemplates a business relationship.
Before citation
After · high
If we decide to sell, buy, merge, or otherwise reorganize businesses in some countries, such a transaction may involve disclosing some personal information to prospective or actual business purchasers, or the collection of personal information from those selling such businesses.
After citation
Aug 31, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We may share your personal information internally and externally with suppliers, advisors, or Business Partners for IBM’s legitimate business purposes, and only on a need-to-know basis. This section describes how we share information and how we facilitate that sharing.
Open timeline citation
Aug 31, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

If we decide to sell, buy, merge, or otherwise reorganize businesses in some countries, such a transaction may involve disclosing some personal information to prospective or actual business purchasers, or the collection of personal information from those selling such businesses.
Open timeline citation
Aug 31, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

our business with suppliers may include the collection, use, analysis, or other types of processing of personal information on our behalf. our business model includes cooperation with independent Business Partners for marketing, selling, and the provision of IBM products and services. Where appropriate (for example, when necessary for the fulfilment of an order), we share business contact information with selected Business Partners. we may share personal information with professional advisors, including lawyers, auditors, and insurance companies to receive their services. we may share contractual relationship information with others, for instance, our Business Partners, financial institutions, shipping companies, postal, or government authorities, such as the customs authorities that are involved in fulfillment. We may share personal information with third parties, such as advertising technology partners, data analytics providers and social networks engaged by IBM to deliver targeted IBM advertisements on their platforms, to aggregate information for analysis, and to track engagement with those advertisements.
Open timeline citation
Aug 31, 2026legal burdenMEDIUM

Latest stance: indemnity on indemnity liability

protect or enforce our rights, including to detect fraud or other criminal activities (for example, by using information in payment systems) handle and resolve disputes answer complaints and defend IBM in legal proceedings and comply with legal obligations in the countries where we do business
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-08-31· verified 2026-08-31
  • Terms of Service:Last captured 2026-06-09· verified 2026-06-09not re-verified in 93 days

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↑ 242 more findings this quarter vs last (413 vs 171). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of IBM watsonx's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified IBM watsonx's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from IBM watsonx's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.