This policy is not ready to publish as written. The main problem is not missing boilerplate; it is that several categorical promises do not match Duramata’s apparent data flows. That creates FTC exposure, Google OAuth verification risk, and material diligence problems in an acquisition.
This is a legal-risk review, not legal advice. Privacy counsel should validate the final policy against production configurations, vendor contracts, and actual retention behavior.
| Priority | Issue | Why it matters / recommended change |
|---|---|---|
| Critical | Google data in a sale | Google’s Limited Use rules permit transferring Google user data during a merger or acquisition only with explicit prior user consent. The general corporate-transaction clause is therefore insufficient for Gmail/Calendar data. Plan for affirmative consent, reauthorization, or excluding/deleting that data before transfer. [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user |