Privacy Policy
How we handle your data
Last updated: 1 June 2026
1. Introduction
Contract Review AI ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our AI-powered contract analysis platform.
This policy is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What Information We Collect
Information you provide:
- Account data: name, email address, company name, and password when you register
- Contract data: the contracts, agreements, and documents you upload for analysis
- Payment data: billing information (processed securely through our payment provider)
- Communications: any enquiries or support requests you send to us
Information collected automatically:
- Usage data: how you interact with our platform, pages visited, features used
- Technical data: IP address, browser type, device information
- Cookies: session cookies necessary for platform operation, analytics cookies for improvement
3. How We Use Your Information
- To provide and maintain our contract analysis service
- To analyse uploaded contracts and generate risk assessments
- To improve and train our AI analysis engine (anonymised contract data only)
- To communicate with you about your account and our services
- To comply with legal obligations under English law
4. Data Storage and Security
All contract data is stored securely on our servers within the United Kingdom. We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, access controls, and regular security audits.
Uploaded contracts are retained for the duration of your account. If you close your account via the "Close Account" button, all data is deleted immediately.
5. Sharing Your Data
We do not sell your personal data or contract content to third parties. We may share anonymised, aggregated data with:
- Our AI service providers for the purpose of contract analysis only when you initiate an analysis on a plan that includes AI features
- Legal authorities if required by law or to protect our rights
6. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data held by us
- Rectify inaccurate data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
To exercise any of these rights, contact us at privacy@contractreview.ai
7. Cookies
We use only essential cookies necessary for the operation of our platform. We do not use tracking, advertising, or analytics cookies.
| Cookie Name | Purpose | Type | Duration |
|---|---|---|---|
| CRSID | Session authentication — keeps you logged in while you use the platform | Essential / Session | 120 minutes or until browser is closed |
| CRSID (CSRF token) | Security token stored in your session to prevent cross-site request forgery | Essential / Session | Duration of session |
All cookies are strictly necessary for the platform to function. Under UK PECR and GDPR, essential cookies do not require prior consent but we believe in being transparent about their use.
For full details, see our Cookie Policy.
8. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of material changes via email or through our platform.
