Scope of Privacy Statement
Applies to personal data collected via redhat.com and other Red Hat websites.
🌐 www.redhat.com
Clearly lists categories of personal data, limits collection of sensitive data, and describes security safeguards like encryption.
References GDPR, CCPA, Data Privacy Frameworks, provides user rights, verification process, and supervisory authority contact.
Generally fair, but includes broad data use for marketing and AI, and unilateral change clause with only opt-out notice.
Uses plain language, table of contents, and clear sections, but length and legal references may still be challenging for non-lawyers.
- The privacy statement claims a last updated date of January 12, 2026, but the document appears to have been accessed or posted on March 12, 2025, creating confusion about which version is actually in effect.
- The document states it may not apply to open source project websites sponsored by Red Hat, but does not provide clear guidance on how a user can determine which specific websites are excluded from this policy.
- The policy allows Red Hat to combine personal data collected online with data obtained offline, such as during interviews or events, without specifying the scope or limits of such data merging.
- The policy permits the use of artificial intelligence and machine learning to analyze data, identify trends, make predictions, and provide AI-generated responses, but does not explain how individuals can opt out of or contest decisions made by automated processing.
- For users in China (PRC), the policy claims that data necessary for a contract may be collected without express consent, or that providing data is deemed as consent, potentially undermining the principle of voluntary and informed consent.
- The policy states that Red Hat does not sell personal data as commonly understood, but acknowledges that cookie data shared with advertising partners may qualify as a "sale" under some data protection laws, creating legal ambiguity.
- The cookie manager tool described for opting out of targeted advertising may not be present on all Red Hat websites, leaving users without a consistent or reliable method to exercise choice.
- The verification process for privacy rights requests requires at least two or three identifiers, which may be burdensome or impossible for users who do not have a direct account or relationship with Red Hat.
- The policy allows changes to be made at any time and states that continued use of the website after a 30-day notice period constitutes acceptance, which may be considered an unfair or passive consent mechanism.
- The contact and rights options rely heavily on a web form and email, which may not be accessible or user-friendly for individuals who prefer phone or mail communication, especially those without reliable internet access.
Applies to personal data collected via redhat.com and other Red Hat websites.
Includes contact, account, employment, internet activity, location, and inferences.
Used for identification, fulfilling requests, marketing, support, and website enhancement.
Shared with partners, service providers, and as required by law or business transfers.
You can access, correct, delete, or restrict personal data usage.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free