How clausul protects your documents
Legal teams handle sensitive client information. This page explains exactly where your data goes, what AI sees, and what controls you have. No vague assurances — just the architecture.
Where your data goes
When you upload two documents for comparison, here is exactly what happens:
1. Upload & parsing
Your DOCX files are uploaded to clausul servers in the EU (Germany). The raw document bytes are parsed into structured text by our own document engine. The raw files never leave our infrastructure.
2. AI processing
Extracted clause text is sent to OpenAI (for semantic matching between clauses) and Anthropic Claude (for change classification and review notes). Only parsed text is sent — never raw files, metadata, or filenames. Both providers operate under API terms that prohibit using your data for model training.
3. Storage & retention
Uploaded files are stored in encrypted cloud storage in the EU. Comparison results are stored in an encrypted database. Both are subject to your configured retention window (24 hours to 14 days) and permanently deleted on expiry.
Security controls
Encryption
TLS 1.2+ in transit. AES-256 at rest for all uploaded documents, comparison outputs, and database records.
No model training
AI providers (Anthropic, OpenAI) operate under API terms that prohibit using customer inputs for training. Your documents do not improve their models.
Retention controls
Configure auto-deletion from 24 hours to 14 days. Expired data is permanently removed — no soft-delete, no hidden archive.
EU-hosted infrastructure
All infrastructure is hosted in the European Union (Germany), governed by GDPR. US-region hosting available on request for enterprise clients.
Frequently asked questions
Questions we hear from IT, compliance, and procurement teams.
Need more detail?
We're happy to walk through the architecture with your IT or compliance team, provide a DPA, or complete your vendor risk questionnaire.
Contact usStart now
Ready to evaluate clausul?
Try it with sample documents first. No client data required.
Product updates only. Unsubscribe anytime.