Privacy Policy
Last updated: August 2026
This policy explains what Clause by Clause collects about you, why, and what you can do about it. It is written to meet the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and the ePrivacy Directive as implemented in [COUNTRY OF ESTABLISHMENT].
1. Who is responsible (controller)
The controller of your personal data is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], company number [COMPANY REGISTRATION NO. / VAT ID].
For any privacy question or to exercise your rights, contact [privacy@yourdomain.com]. Our data protection officer is [DPO NAME OR "not required under Art. 37"].
2. What we collect and why
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, work email, company name | To create your account and show counterparties who they are negotiating with | Art. 6(1)(b) — performance of a contract |
| Password | To authenticate you. Stored only as a bcrypt hash, never in readable form | Art. 6(1)(b) |
| Contract titles, clause text, positions and proposals you enter | This is the service itself — the content you are negotiating | Art. 6(1)(b) |
| IP address and timestamps of login and sign-up attempts | To rate-limit password guessing and bulk sign-ups | Art. 6(1)(f) — legitimate interest in securing the service |
Session cookie (PHPSESSID) | To keep you signed in | Strictly necessary — no consent required under the ePrivacy Directive |
Consent choice (cbc-consent, browser local storage) | To remember whether you accepted or declined analytics, so we stop asking | Strictly necessary — it exists only to honour your choice |
Google Analytics cookies (_ga, _ga_*) and the data they carry: pages viewed, approximate location from a truncated IP address, device and browser type, referring site | To understand how the site is used and what to improve | Art. 6(1)(a) — your consent, which you give in the cookie banner and can withdraw at any time |
2a. Cookies and analytics
We use Google Analytics 4 (measurement ID G-Z39JKGCKGP) to count visits and
see which pages are useful. It starts in Consent Mode with analytics storage denied:
no analytics cookies are set and no page-view event is sent unless you press Accept on the
cookie banner. Pressing Decline keeps analytics storage denied. IP addresses are truncated
before storage.
We never send your contract text, clause wording, positions or proposals to Google — analytics sees page addresses and the technical details listed above, nothing from inside a negotiation.
Google Ireland Limited acts as our processor for this, with Google LLC in the United States as a
sub-processor; transfers are covered by the safeguards in section 5. Google's own explanation of the
data it handles is at policies.google.com/technologies/partner-sites.
Changing your mind. Your choice is remembered in this browser. To be asked again — and to withdraw consent — use the button below. It takes effect immediately, and withdrawing does not affect processing carried out before you withdrew (Art. 7(3)).
3. Who can see your contract data
This matters more than usual in a negotiation tool, so it is worth stating plainly:
- Counterparties you invite can see the contract, its clauses, and any proposal published to it.
- Your private positions — preferred, acceptable and redline wording — are visible only to your own company. They are never shown to the other side.
- Our administrator holds read-only access to account and contract records, used strictly for support, security and abuse investigation.
We do not sell your personal data and we do not share it with advertisers.
4. Processors we use
Each of these acts as a processor under Art. 28 and is bound by a data processing agreement:
- Hostinger — web and database hosting. Data is stored in [DATA CENTRE REGION — confirm with Hostinger].
- Cloudflare Turnstile — anti-robot check on the sign-up form, when enabled.
- Google Ireland Limited — Google Analytics 4, only after you consent (see section 2a).
- [TRANSACTIONAL EMAIL PROVIDER, once outgoing email is switched on]
5. Transfers outside the EEA
Where a processor handles data outside the European Economic Area, we rely on the safeguards in Art. 46 — normally the European Commission's Standard Contractual Clauses, together with an adequacy decision where one exists. You can ask us for a copy of the safeguards in place.
6. How long we keep it
- Account and contract data — while your account is active, then deleted within [X months] of closure.
- Login and sign-up logs — 24 hours, then deleted automatically.
- Records kept for legal reasons (e.g. accounting) — [STATUTORY PERIOD], under Art. 6(1)(c).
7. How we protect it
- HTTPS is enforced on every page, with HSTS.
- Passwords are hashed with bcrypt — nobody, including us, can read them.
- Session cookies are
HttpOnly,SecureandSameSite=Lax. - Login attempts are rate-limited and every form is CSRF-protected.
- Access to a contract is re-checked on every request against the companies party to it.
8. Your rights
Under the GDPR you have the right to:
- Access your data and receive a copy (Art. 15);
- Rectify anything inaccurate or incomplete (Art. 16);
- Erasure — be forgotten, where no overriding ground applies (Art. 17);
- Restrict processing while a dispute is resolved (Art. 18);
- Portability — receive your data in a machine-readable format (Art. 20);
- Object to processing based on legitimate interest (Art. 21);
- Withdraw consent at any time, where processing rests on consent (Art. 7(3)).
Write to [privacy@yourdomain.com]. We answer within one month, as Art. 12(3) requires, and will tell you if we need to extend that by up to two further months.
You also have the right to lodge a complaint with a supervisory authority — ours is [SUPERVISORY AUTHORITY OF YOUR COUNTRY] — or with the authority where you live or work (Art. 77).
9. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you, within the meaning of Art. 22.
10. Data breaches
If a breach is likely to result in a risk to your rights and freedoms we notify our supervisory authority within 72 hours (Art. 33), and we notify you directly when the risk is high (Art. 34).
11. Children
This is a business tool. It is not directed at anyone under 16 and we do not knowingly collect their data.
12. Changes
If this policy changes materially we will update the date above and, where the change affects your rights, tell you by email.