Accruent
accruent.comAccruent is an enterprise software provider for managing physical resources (real estate, facilities, assets), and the available legal documents are a website Privacy Notice (with GDPR/CCPA/LGPD addenda) and website Terms of Use — not an enterprise product/data processing agreement or AI-specific policy. The Privacy Notice is reasonably mature on data subject rights, retention principles, and multi-jurisdiction compliance, but it is explicitly limited to consumer transactions and website use, not the B2B customer data processed within Accruent's actual software products. Critically, there is no AI-specific policy addressing input/output ownership, model training, or human review of prompts, and no enterprise-grade security attestations (SOC 2, ISO 27001) are referenced. Professional and regulated-industry users should not rely on these public documents alone and must obtain a Master Services Agreement and Data Processing Agreement before submitting sensitive or proprietary data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The public Privacy Notice and Terms of Use do not clearly address ownership of customer data submitted into Accruent's software products; the Privacy Notice explicitly excludes the B2B context where such product data would sit. The Terms of Use only address website 'User Contributions,' granting Accruent a broad license to material posted through interactive website features, which is not favorable but is limited to the website rather than the product.
Output Data Ownership
Neither the Privacy Notice nor the Terms of Use addresses ownership of AI-generated or software-generated output, as these are website/consumer-focused documents. The Terms of Use assert that all website Content is owned by Accruent, but this pertains to Accruent's own materials, not customer-generated results within the products.
Training Data Usage
The documents are silent on whether customer inputs are used to train or improve AI models, and there is no AI-specific policy available. The Privacy Notice does reference internal research, analytics, and development uses of certain data categories, but this is not specifically tied to AI model training, leaving the question unresolved.
Data Retention & Deletion
The Privacy Notice states data is retained only as long as reasonably necessary and references internal retention rules, but provides no explicit retention schedules, deletion SLAs, or industry-specific retention obligations (e.g., HIPAA, SOC 2 audit log retention). Deletion can be requested via account login or contacting the legal department, with a general 45-day response window, though deletion is subject to broad exceptions.
Third-Party Data Sharing
Accruent shares personal information with service providers, its parent company Fortive and affiliated group companies, and in legal/compliance contexts, and states it does not sell personal information. Sharing with the corporate group for 'business and operational purposes' is broad and the categories are disclosed, but users have limited granular control over intra-group sharing, and data may be transferred in a merger, acquisition, or bankruptcy.
Opt-Out Rights
The policy provides clear opt-out mechanisms for marketing communications (unsubscribe links) and interest-based advertising via industry opt-out pages, and offers GDPR/CCPA/LGPD rights including consent withdrawal and objection to processing. However, the company does not honor 'Do Not Track' browser signals, and opt-out of core operational data processing and intra-group sharing is limited.
Compliance & Certifications
The Privacy Notice addresses GDPR, CCPA, and LGPD with dedicated addenda and references the Center for Internet Security's Critical Security Controls as a framework basis. However, no third-party attestations or certifications (SOC 2, ISO 27001, HIPAA, FedRAMP, NIST) are referenced in these public documents, which is a notable gap for an enterprise vendor serving regulated industries like healthcare and pharma.
Model Explainability & Auditability
The documents provide no information about AI model transparency, explainability, or enterprise audit capabilities. The Privacy Notice states Accruent does not perform automated decision-making or profiling in one section, while contradictorily referencing 'profiling related to your Personal Data' in the GDPR and LGPD addenda, creating ambiguity.
Security Practices & Breach History
The Privacy Notice discloses use of encryption, firewalls, and all 20 CIS Critical Security Controls as a risk-based security program, but provides no detail on penetration testing, bug bounty programs, incident response procedures, or breach history, and references no dedicated trust center or security page. The policy notably includes disclaimer language pre-emptively distancing Accruent from liability for security incidents.
Enterprise vs. Consumer Risk Delta
The Privacy Notice explicitly applies only to consumer transactions and website use, and states the B2B context is governed separately — but that separate B2B/enterprise agreement is not among the public documents provided. This means the material data-handling terms for actual enterprise product use are not disclosed publicly and must be obtained through a negotiated contract.
Human Review of User Inputs
The documents do not address whether staff may access customer prompts or product data, but the Terms of Use reserve broad rights to monitor, review, and disclose website User Contributions at Accruent's sole discretion. There is no AI-specific statement on human review of inputs or outputs within the products.
Regulatory & Litigation Exposure
The Privacy Notice and Terms of Use disclose that Accruent will cooperate with government requests, subpoenas, and law enforcement, and will disclose user identity to third parties claiming rights violations. No specific litigation history or government data request statistics are provided, but the cooperation language is broad and vendor-favorable.
PII & SPI Data Inventory
The Privacy Notice discloses collection of contact information, demographic data, product interest, CCTV imagery, and constant mobile app location data, plus free-text field data that could contain anything. Sensitive personal data (e.g., health information) is only processed with explicit consent, and precise/constant geolocation collection via mobile apps is a notable SPI concern, though disclosed.
You've read all 15 risk ratings for Accruent. Create a free account to see the exact policy wording behind each rating.