Accruent logo

Accruent

accruent.com
Moderate Risk
Updated July 22, 2026

Accruent is an enterprise software provider for managing physical resources (real estate, facilities, assets), and the available legal documents are a website Privacy Notice (with GDPR/CCPA/LGPD addenda) and website Terms of Use — not an enterprise product/data processing agreement or AI-specific policy. The Privacy Notice is reasonably mature on data subject rights, retention principles, and multi-jurisdiction compliance, but it is explicitly limited to consumer transactions and website use, not the B2B customer data processed within Accruent's actual software products. Critically, there is no AI-specific policy addressing input/output ownership, model training, or human review of prompts, and no enterprise-grade security attestations (SOC 2, ISO 27001) are referenced. Professional and regulated-industry users should not rely on these public documents alone and must obtain a Master Services Agreement and Data Processing Agreement before submitting sensitive or proprietary data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The public Privacy Notice and Terms of Use do not clearly address ownership of customer data submitted into Accruent's software products; the Privacy Notice explicitly excludes the B2B context where such product data would sit. The Terms of Use only address website 'User Contributions,' granting Accruent a broad license to material posted through interactive website features, which is not favorable but is limited to the website rather than the product.

Confidence
35%

Output Data Ownership

Moderate Risk

Neither the Privacy Notice nor the Terms of Use addresses ownership of AI-generated or software-generated output, as these are website/consumer-focused documents. The Terms of Use assert that all website Content is owned by Accruent, but this pertains to Accruent's own materials, not customer-generated results within the products.

Confidence
25%

Training Data Usage

Moderate Risk

The documents are silent on whether customer inputs are used to train or improve AI models, and there is no AI-specific policy available. The Privacy Notice does reference internal research, analytics, and development uses of certain data categories, but this is not specifically tied to AI model training, leaving the question unresolved.

Confidence
30%

Data Retention & Deletion

Moderate Risk

The Privacy Notice states data is retained only as long as reasonably necessary and references internal retention rules, but provides no explicit retention schedules, deletion SLAs, or industry-specific retention obligations (e.g., HIPAA, SOC 2 audit log retention). Deletion can be requested via account login or contacting the legal department, with a general 45-day response window, though deletion is subject to broad exceptions.

Confidence
55%

Third-Party Data Sharing

Moderate Risk

Accruent shares personal information with service providers, its parent company Fortive and affiliated group companies, and in legal/compliance contexts, and states it does not sell personal information. Sharing with the corporate group for 'business and operational purposes' is broad and the categories are disclosed, but users have limited granular control over intra-group sharing, and data may be transferred in a merger, acquisition, or bankruptcy.

Confidence
65%

Opt-Out Rights

Moderate Risk

The policy provides clear opt-out mechanisms for marketing communications (unsubscribe links) and interest-based advertising via industry opt-out pages, and offers GDPR/CCPA/LGPD rights including consent withdrawal and objection to processing. However, the company does not honor 'Do Not Track' browser signals, and opt-out of core operational data processing and intra-group sharing is limited.

Confidence
60%

Compliance & Certifications

Moderate Risk

The Privacy Notice addresses GDPR, CCPA, and LGPD with dedicated addenda and references the Center for Internet Security's Critical Security Controls as a framework basis. However, no third-party attestations or certifications (SOC 2, ISO 27001, HIPAA, FedRAMP, NIST) are referenced in these public documents, which is a notable gap for an enterprise vendor serving regulated industries like healthcare and pharma.

Confidence
60%

Model Explainability & Auditability

High Risk

The documents provide no information about AI model transparency, explainability, or enterprise audit capabilities. The Privacy Notice states Accruent does not perform automated decision-making or profiling in one section, while contradictorily referencing 'profiling related to your Personal Data' in the GDPR and LGPD addenda, creating ambiguity.

Confidence
30%

Security Practices & Breach History

Moderate Risk

The Privacy Notice discloses use of encryption, firewalls, and all 20 CIS Critical Security Controls as a risk-based security program, but provides no detail on penetration testing, bug bounty programs, incident response procedures, or breach history, and references no dedicated trust center or security page. The policy notably includes disclaimer language pre-emptively distancing Accruent from liability for security incidents.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The Privacy Notice explicitly applies only to consumer transactions and website use, and states the B2B context is governed separately — but that separate B2B/enterprise agreement is not among the public documents provided. This means the material data-handling terms for actual enterprise product use are not disclosed publicly and must be obtained through a negotiated contract.

Confidence
45%

Human Review of User Inputs

Moderate Risk

The documents do not address whether staff may access customer prompts or product data, but the Terms of Use reserve broad rights to monitor, review, and disclose website User Contributions at Accruent's sole discretion. There is no AI-specific statement on human review of inputs or outputs within the products.

Confidence
35%

Regulatory & Litigation Exposure

Moderate Risk

The Privacy Notice and Terms of Use disclose that Accruent will cooperate with government requests, subpoenas, and law enforcement, and will disclose user identity to third parties claiming rights violations. No specific litigation history or government data request statistics are provided, but the cooperation language is broad and vendor-favorable.

Confidence
55%

PII & SPI Data Inventory

Moderate Risk

The Privacy Notice discloses collection of contact information, demographic data, product interest, CCTV imagery, and constant mobile app location data, plus free-text field data that could contain anything. Sensitive personal data (e.g., health information) is only processed with explicit consent, and precise/constant geolocation collection via mobile apps is a notable SPI concern, though disclosed.

Confidence
60%

You've read all 15 risk ratings for Accruent. Create a free account to see the exact policy wording behind each rating.