Read a SaaS Privacy Policy in 10 Minutes, Project Managers

Project manager reviewing SaaS privacy policy

Scan for the “last updated” date, DPA availability, named sub-processors, retention periods, export options and security disclosures before you sign up. If two or more of those are missing, vague, or buried, pause and send the vendor a direct question rather than clicking accept. A privacy policy with none of these basics covered is a genuine signal to look elsewhere.


TL;DR:

  • Vendors should provide a recent “last updated” date within the past one or two years to ensure the policy reflects current legal standards and practices.
  • Verify that the policy explicitly mentions a Data Processing Agreement, a list of sub-processors, a clear data retention period, and export options to assess transparency and compliance.
  • Look for specific disclosures about data residency, cross-border transfer mechanisms, and encryption standards, avoiding vague language such as “we may share data.”
  • Ask vendors directly for their current DPA, sub-processor list, data location, retention details, and breach notification procedures if their privacy policy lacks this information.
  • Beware of red flags like no named partners, indefinite retention clauses, silent policy amendments, or outdated policies that may signal poor data handling practices.

Seven
Keep Project Data Under Your Control
Seven keeps project work confidential, with flexible collaboration, messaging, file attachments, and no vendor lock-in or data mining.
Explore Seven

Table of Contents

How to read a SaaS privacy policy in 10 minutes

You don’t need to read every clause word for word. You need to find six things, fast, and decide whether what you see is good enough for your team.

  1. Jump to the top or bottom of the page for a plain-English summary or a linked “privacy centre.” Most SaaS providers put one there because regulators expect it.
  2. Check the “last updated” date. Anything with a last updated date older than a year or two, in a market where rules keep shifting, deserves a second look.
  3. Use Ctrl+F (or Cmd+F on a Mac) to search the exact keywords covered in the next section. This alone turns a 4,000-word document into a two minute job, a technique privacy researchers at PIRG recommend for exactly this reason.
  4. Confirm there’s a DPA, a sub-processor list, a stated retention period, and an export option mentioned somewhere.
  5. Score what you find: green (all present and specific), amber (vague or partial), red (missing or contradictory).

Pro Tip: Open the policy in one tab and a plain notes file in the other. Paste in anything that reads as vague, then turn each note into a direct question for sales before you commit.

Keywords and phrases to search for (and what each means)

Search these terms one by one. What surrounds each hit tells you more than the word itself.

A specific disclosure names the sub-processor, the retention period in days, or the encryption standard. Vague boilerplate says “we may share data with partners to improve our services” and stops there. The Markup’s guide to reading policies points out that companies often illustrate broad data rights with a narrow, benign example, so read past the example to the actual clause it sits inside.

Red flags and evasive language to watch for

Some patterns show up again and again in policies written to protect the vendor rather than inform you.

A missing or outdated “last updated” date is one of the most common red flags flagged by Termly’s privacy policy research, precisely because tracking techniques and legal obligations shift every year. For a project manager holding client data, or a freelancer under contractual confidentiality obligations, these gaps aren’t academic. They’re the difference between a vendor you can point to in an audit and one you can’t.

What SaaS privacy policies should actually disclose

A generic consumer app can get away with loose language. A SaaS tool your team relies on for project data cannot, and the policy should show it.

Sub-processors and data separation. Look for a public sub-processor list, ideally one the vendor updates and notifies you about when it changes. Multi-tenant storage (your data sitting alongside other customers’ data on shared infrastructure) isn’t automatically a problem, but the policy should describe how logical separation keeps your workspace isolated from everyone else’s.

Data residency and cross-border transfers. Where are the servers, and what happens if your data crosses borders? A policy worth trusting names the hosting region and, where data moves internationally, the legal mechanism behind it, standard contractual clauses or an adequacy decision are the two most common. LegalForge’s SaaS disclosure standard treats residency and transfer safeguards as baseline requirements, not extras.

Export and backups. Check the format your data comes out in (CSV, JSON, a full database dump) and how long export access stays open after you cancel. Ask separately how long backups persist. A vendor can delete your live data on request and still hold a backup copy for months.

DPA and security markers. A DPA available on request, or built into the signup flow, should cover sub-processor obligations, breach notification timelines, and audit rights. Encryption in transit and at rest, plus a recognised standard like SOC 2 or ISO 27001, are the clearest signals a vendor has actually built security into the product rather than bolting it on. Seven’s own writing on hosting and residency covers how these choices get made on the architecture side, which is worth reading if you want the operational view behind the policy language.

What SaaS privacy policies should actually disclose — overview diagram

Copy-paste questions to send your vendor

When the policy leaves gaps, don’t guess. Ask directly, and use the answers to make the call.

  1. “Can you send me your current DPA?”
  2. “Do you publish a sub-processor list, and will you notify us before adding a new one?”
  3. “Where is our data hosted, and do you use standard contractual clauses for any cross-border transfer?”
  4. “What format does data export use, and is there a demo or sandbox we can test it in?”
  5. “What’s your data retention period after account cancellation, including backups?”
  6. “Do you use customer content to train AI models, yours or a third party’s?”
  7. “What’s your breach notification timeframe under the DPA?”

Pro Tip: Send all seven in one email rather than trickling them out. A vendor’s response time and completeness tells you almost as much as the answers themselves.

Score the replies the same way as the policy itself. A signed DPA on file, a named sub-processor list, and a specific retention number is a green light. Vague answers (“we take privacy seriously”) without documents attached is amber, ask for the DPA and export demo before proceeding. Silence, refusal to provide a DPA, or contradicting the published policy is a red light, walk away.

Why Seven treats privacy as a feature, not a footnote

Why Seven treats privacy as a feature, not a footnote — overview diagram

Most of the checks above exist because too many SaaS vendors treat their privacy policy as legal cover rather than a real description of practice. Seven was built the other way around: no analytics resale, no AI training on customer content, and an explicit commitment to keep project data out of anyone’s data pipeline but the customer’s own. That stance shapes decisions on hosting, retention, and what gets published rather than buried.

We’ve written in more detail about how data ownership actually works in a SaaS contract and the architecture decisions behind data residency, both worth reading if this checklist raised questions specific to your setup.

— Greg

Try a project tool that passes its own checklist

Run Seven’s own policy through the checklist above and you’ll find what you’re looking for: no data mining, no analytics resale, and no AI training on your project content, ever. That’s the concrete difference against most project management tools, where “free” or bundled pricing often means your usage data becomes the product elsewhere.

Seven

Some project management platforms charge monthly fees for individuals and per-user fees for teams, often offering a free trial to test privacy claims before committing. Features typically include flexible workspaces, task and subtask management, built-in messaging, file attachments, and import capabilities, often with a focus on avoiding vendor lock-in. Check pricing for Individual and Teams plans and start the trial to see how an export actually works before you need one.

Sources

FAQ

What’s the fastest way to check a SaaS privacy policy?

Search the document with Ctrl+F for terms like “third party,” “sub-processor,” “retention,” and “DPA,” then check the last updated date. This turns a lengthy document into a five to ten minute review, a method PIRG recommends for cutting through dense legal text.

What is a DPA and why does it matter for SaaS tools?

A Data Processing Agreement is a contract that legally binds a vendor to specific data handling terms, including sub-processor obligations and breach notification timelines. Business customers should always be able to request one; a vendor that can’t provide one likely hasn’t built for B2B compliance.

How do free and paid SaaS tiers differ on privacy?

Free tiers more often monetise usage data through analytics or advertising partnerships, since there’s no subscription revenue covering costs. Paid tiers, particularly ones like Seven that charge a flat $5 to $9 per user, typically have less incentive to sell or mine your data because the subscription itself is the revenue.

How can I tell if a privacy policy is current and legitimate?

Check the “last updated” date against how recently privacy law or the vendor’s product has changed; anything over a year or two old is worth questioning. An outdated policy is one of the most common red flags, since tracking rules and disclosure requirements shift often.

What should I do if a policy doesn’t mention sub-processors?

Ask the vendor directly for a written sub-processor list and whether they’ll notify you before adding new ones. SaaS-specific disclosure standards treat a public sub-processor list as a baseline expectation, not an optional extra.