Privacy Policy
Last updated: March 7, 2026
1. Who we are
Clausul ("we", "us", "our") operates the document comparison service at clausul.com. We are the data controller for the personal data described in this policy. For questions about this policy or your data, contact us at hello@clausul.com.
2. What data we collect
We collect only what is necessary to provide and improve the service:
- Account data: name, email address, and organisation name when you register or join the waitlist.
- Documents: DOCX files you upload for comparison. These are processed and stored according to your retention settings (see Section 5).
- Usage data: pages visited, features used, and comparison metadata. We use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies or collect personal identifiers.
- Communications: messages you send us via email or support channels.
3. How we use your data
- To provide the document comparison service, including parsing, comparison, and export.
- To generate semantic embeddings and AI-powered change summaries (see Section 4).
- To communicate with you about the service, respond to support requests, and send product updates (which you can unsubscribe from at any time).
- To improve the service based on aggregated, anonymised usage patterns.
Legal basis (GDPR Art. 6): performance of a contract (providing the service you signed up for), legitimate interest (service improvement with anonymised data), and consent (marketing communications).
4. AI data processing
Clausul uses AI at two points during document comparison:
- OpenAI: parsed clause text is sent to generate semantic embeddings for clause matching.
- Anthropic Claude: extracted change summaries are sent for change classification and review note generation.
In both cases, only parsed text is transmitted — never raw document files, filenames, or document metadata. Both providers operate under API terms that prohibit using customer inputs for model training. AI processing is transient: text is processed and discarded by the providers.
5. Data retention
You control document retention. Documents can be set to auto-delete after 24 hours or retained for up to 14 days. When a document expires or is manually deleted, the uploaded files, comparison results, and all associated data are permanently removed from storage. There is no soft-delete or hidden archive.
Account data is retained for as long as your account is active. If you close your account, all personal data and documents are permanently deleted within 30 days.
6. Where your data is stored
All infrastructure is hosted in the European Union (Germany). Uploaded documents, comparison results, and account data are stored in encrypted cloud storage and databases subject to EU data protection law (GDPR).
Parsed clause text is sent to Anthropic and OpenAI API endpoints for AI processing (see Section 4). These API calls are transient — text is processed and discarded, not stored by the providers. Raw document files and all other data remain within EU infrastructure.
7. Data security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to customer data by clausul staff requires explicit authorisation and is logged. For more detail, see our Security page.
8. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate personal data.
- Erase your personal data ("right to be forgotten").
- Restrict processing of your personal data.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact hello@clausul.com. We will respond within 30 days.
9. Cookies
Clausul does not use tracking cookies. We use Plausible Analytics, which is fully cookie-free and does not collect personal identifiers. For more detail, see our Cookie Policy.
10. Third-party services
- Plausible Analytics — privacy-friendly website analytics (no cookies, no personal data).
- Formspree — waitlist form submissions.
- OpenAI — semantic embedding generation (API terms prohibit training on inputs).
- Anthropic — change classification (API terms prohibit training on inputs).
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on the service. The "last updated" date at the top reflects the most recent revision.
12. Contact
For questions about this privacy policy or to exercise your data rights, contact us at hello@clausul.com.