09 Legal
Privacy policy
How we handle personal data and contract content, written to be read rather than skimmed.
Last updated: 30 July 2026
Who we are
Clauzy Technologies B.V. ("Clauzy", "we", "us") is a company registered in the Netherlands under KvK number 89 214 771, with its registered office at Keizersgracht 62, 1015 CS Amsterdam. We provide software that reviews commercial contracts against a customer-defined playbook.
This policy explains what personal data we collect, why we collect it, how long we keep it and what rights you have. It covers our website at clauzyai.com and the Clauzy review service. For questions, write to privacy@clauzyai.com.
Controller and processor roles
The distinction matters because it determines who is responsible for what.
We are the controller for personal data about our website visitors, prospects, account administrators and users: names, work email addresses, organisation details, billing information and product usage records.
We are a processor for the contract documents our customers upload. Those documents frequently contain personal data such as signatory names, contact details and employee references. We process that data only on the documented instructions of the customer, who remains the controller. Our data processing agreement, incorporating the current Standard Contractual Clauses, governs that relationship.
What we collect
- Account data. Name, work email, organisation, role, password hash, and single sign-on identifiers where used.
- Contract content. The documents you upload for review, together with the ledgers, redlines and decision records generated from them.
- Usage data. Which features are used, document counts, error reports and performance metrics, associated with an account rather than published to third parties.
- Billing data. Company name, VAT number, billing address and payment method token. Card numbers are handled by our payment processor and never reach our systems.
- Website data. Pages viewed, referring source, approximate country derived from IP address, and browser type. Analytics is only collected where you have consented through the cookie banner.
- Correspondence. Messages you send to our sales, support, security or press addresses, retained so we can answer and evidence what was agreed.
The free clause analyzer on this website runs entirely in your browser. Clause text you paste there is not transmitted to us, not logged and not stored.
Why we process it, and on what legal basis
- To provide the service (performance of a contract): account creation, document review, exports, support.
- To secure the service (legitimate interests): abuse detection, audit logging, incident investigation.
- To improve the product (legitimate interests): aggregated, de-identified usage statistics. Customer contract content is never used for product improvement or model training.
- To bill and account (legal obligation and contract): invoicing, tax records, statutory retention.
- To market responsibly (consent or legitimate interests): product emails to existing customers, and marketing analytics only where you consented.
Automated processing and model providers
Review is performed using large language models operated by us and by named sub-processors, executed in European Union regions. Our agreements with those providers include zero data retention, meaning your document content is not stored by them and is not available for their training.
Clauzy does not make decisions that produce legal or similarly significant effects about individuals. The output is a proposal for a human reviewer to accept, amend or reject, and every finding records who decided.
Who we share data with
We do not sell personal data, and we do not share it for advertising. We use a small set of sub-processors, each bound by written terms and each listed on our sub-processor page: cloud hosting in the EU, model inference in the EU, payment processing, transactional email, error monitoring and customer support tooling.
Customers receive thirty days of written notice before a sub-processor is added or replaced and may object on reasonable data protection grounds. We also disclose data where legally compelled, in which case we notify the affected customer unless prohibited from doing so.
International transfers
Primary processing and storage take place in the European Union. Where a sub-processor requires a transfer outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses together with a transfer impact assessment and supplementary technical measures, principally encryption in transit and at rest and strict access controls.
How long we keep things
- Contract documents: for the retention period configured by the customer, from 24 hours to 7 years. The default is 30 days after review.
- Ledgers and decision records: for the life of the account, because they are the audit trail of who approved what.
- Account data: for the life of the account and 12 months afterwards.
- Billing records: 7 years, as required by Dutch tax law.
- Website analytics: 14 months.
- Support correspondence: 24 months.
Deletion is real. Data removed from live systems is removed from backups on the next rotation, which completes within 35 days.
Security measures
TLS 1.2 or higher in transit and AES-256 at rest. Role-based access with least privilege, mandatory multi-factor authentication for staff, and access to customer content restricted to a small named group and logged in every case. Annual third-party penetration testing, continuous dependency scanning, and a documented incident response process. Where we are processor, we notify affected customers without undue delay and in any case within 48 hours of confirming a personal data breach.
Your rights
If we are the controller of your data you may request access, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Write to privacy@clauzyai.com. We respond within 30 days. If your data reached us inside a customer's contract document, we are the processor and will refer you to that customer, who is the controller.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority in your country of residence.
Changes to this policy
Material changes are announced by email to account administrators at least 30 days before they take effect, and the revision date at the top of this page is updated. Previous versions are available on request.