1. Who is the controller
JDBventures Ltd, trading as ClauseFlow, a company registered in England and Wales, is the data controller for personal data processed through this service. For privacy questions you can contact us through the support channel inside the app.
2. Personal data we collect
- Account data — email address, hashed password (or social sign-in identifier), display name.
- Document data — the legal pack PDFs and related files you upload, and the AI-generated reports derived from them.
- Usage data — credit balance, actions performed (analyses, chat messages, comparisons), timestamps.
- Technical data — IP address, browser/device identifiers and a device fingerprint used to prevent abuse of the free-credit allowance.
- Support data — messages you send us.
- Payment data — handled directly by Paddle. We receive only confirmation, customer ID, and product/price purchased; we do not see your card details.
3. Purposes & legal basis
- Provide the service (account creation, running AI analyses, storing reports) — performance of a contract.
- Process payments and grant credits — performance of a contract.
- Security and fraud prevention, including device-fingerprint checks to stop abuse of free credits — legitimate interests.
- Service improvement and aggregate analytics — legitimate interests.
- Customer support — legitimate interests / contract.
- Legal and tax obligations (e.g. invoicing records) — legal obligation.
4. Who we share data with
- Paddle.com Market Ltd — our Merchant of Record. Paddle processes all sales, subscription management, payments, tax compliance, and invoicing, and acts as a separate controller for that activity.
- Hosting and infrastructure providers — used to host the database, run server code, and store uploaded documents (acting as processors on our behalf).
- AI model providers — uploaded document text is sent to a large language model provider to generate the review. Document content is not used to train their public models.
- Professional advisers — legal and accounting advisers where necessary.
- Authorities — where required by law.
5. International transfers
Some recipients (e.g. AI and hosting providers) may process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as the UK Addendum to the EU Standard Contractual Clauses or an adequacy decision.
6. Retention
We keep account data for as long as your account is active. Uploaded documents and generated reports are retained while you have an account so you can revisit them; you can delete reports from your dashboard at any time. Payment and invoicing records are retained for the periods required by tax law (typically 6 years). Logs and technical data are kept for a short period for security and debugging, then deleted or anonymised.
7. Security
We use appropriate technical and organisational measures including encryption in transit, access controls, and row-level security on the database. No system is perfectly secure, so we cannot guarantee absolute security.
8. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port, or object to processing of your personal data, and to withdraw consent where processing is based on consent. You can exercise most of these directly in your account, or contact us through the support channel. We aim to respond within one month. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
We use essential cookies and local storage to keep you signed in and to remember settings. We do not use marketing cookies. Paddle may set cookies when you check out; see Paddle's privacy notice for details.
10. Changes
We may update this notice. Material changes will be communicated through the app.