Hacker News new | ask | show | jobs
by illud_tempus 1644 days ago
> OP made a claim that Drata collects private employee info and resells it. That’s a large claim.

What I know is:

1) They collect mandatory private information. They already know my name and my email, and they used that information to ask me to complete some tasks on their website. I don't know what those tasks are, because I first have to accept their TOS, which contains clauses that is referred to, but not disclosed. I declined.

2) Their "webpage" is part of their service. This is where I supply personal information (presumably more than they already have). So unless they have another TOS, after I accept the publicly available one, that's the rules: I have to give them personal data, because my employer (well, in my case it's my customer, not my employer - Drata have no agreement with my employer) signed a contract with them.

3) They give themselves the right, in the websites TOS, to sell my data.

So: 1 + 2 + 3 = Drata collects private employee info and resells it.