Last updated: 24 June 2026
Data processing addendum (DPA)
This DPA forms part of any Master Services Agreement between you ("Controller") and Rated Counsel Limited (t/a clmSpace), a company registered in England and Wales (company no. 11812572) ("clmSpace", "Processor"), for the provision of the clmSpace platform (the "Service"). Terms not defined here have the meaning given in the UK GDPR and EU GDPR.
1. Roles of the parties
You are the Controller of personal data submitted to or generated within the Service. clmSpace acts as Processor, processing that personal data only on your documented instructions, of which this DPA and the Master Services Agreement form part. For telemetry and security monitoring of the Service itself, clmSpace acts as an independent Controller on a limited basis.
2. Subject-matter, duration, nature and purpose
The subject-matter of the processing is the personal data contained in, or derived from, the contracts and policy documents you make available to the Service. The nature of the processing is the ingestion of those documents from your document store (SharePoint or Google Drive), extraction and analysis of their terms, generation of structured contract intelligence (agreements, obligations and citations), and support for review, authoring and delivery workflows. The purpose of the processing is to provide the Service to you under the Master Services Agreement. Processing continues for the term of the Master Services Agreement and for up to 30 days after termination to allow for return and secure deletion.
3. Categories of personal data and data subjects
The personal data processed comprises: account data relating to your personnel authorised to use the Service (such as name, work email, directory identifier and role); and any personal data incidentally contained in the contracts, policies and contract intelligence outputs you submit or generate (such as the names, roles and contact details of signatories, counterparty representatives and other individuals named in those documents). The categories of data subject are your authorised users, the individuals named within your contracts and policies, and counterparty representatives. We discourage submission of special-category data and will flag suspected special-category content to you for review and removal.
4. Processor obligations and confidentiality
- Process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case we will inform you, where the law permits, before processing).
- Ensure that personnel authorised to process personal data are bound by a duty of confidentiality and are granted access on a least-privilege, need-to-know basis.
- Implement and maintain the technical and organisational measures described in section 6 and in our security page.
- Make available to you the information reasonably necessary to demonstrate compliance with this DPA, and promptly inform you if, in our opinion, an instruction infringes applicable data protection law.
5. Sub-processing
You provide a general authorisation for clmSpace to engage sub-processors to support the provision of the Service. Our current sub-processors, and the role each performs, are listed on our sub-processor page. We impose data protection obligations on each sub-processor by contract that are no less protective than those in this DPA, and we remain responsible to you for each sub-processor’s performance.
We give you at least 30 days’ notice before adding a new sub-processor or materially expanding the scope of an existing one, so that you have an opportunity to review and, where you have a reasonable data protection objection, to raise it with us. You can subscribe to these change notices by emailing privacy@clmspace.com.
6. Technical and organisational measures
clmSpace maintains a documented schedule of technical and organisational measures appropriate to the risk, covering authentication and single sign-on, least-privilege and agreement-level access control, per-tenant isolation, encryption in transit and at rest, managed secrets, auditability of verification and override actions, and an automated test suite that exercises these controls. The current schedule is set out in our schedule of technical and organisational measures, with a fuller narrative on our security page.
7. International transfers
Personal data you submit to the Service is hosted in the United Kingdom: the API runs in Azure UK South, derived structured data sits in a UK-based, tenant-scoped store, and your source documents remain in your own SharePoint or Google Drive.
AI inference is performed by our sub-processor Anthropic PBC in the United States. This processor-to-processor transfer is covered by the UK International Data Transfer Agreement, which incorporates the EU Standard Contractual Clauses, supplemented by the transfer impact assessment we maintain. Under Anthropic’s API terms and our commercial agreement, API data is not used to train models, and Anthropic retains API data for up to 30 days for abuse monitoring only.
8. Assistance to the Controller
Taking into account the nature of the processing and the information available to us, clmSpace will assist you by appropriate technical and organisational measures, insofar as is possible, in:
- fulfilling your obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability and objection;
- ensuring the security of processing, notifying personal-data breaches, carrying out data protection impact assessments, and consulting your supervisory authority where required.
9. Personal-data breach notification
clmSpace will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting your personal data. The notification will describe the nature of the breach, its likely consequences and the measures taken or proposed to address it, and will be supplemented with further information as it becomes available.
10. Return or deletion on termination
On termination or expiry of the Master Services Agreement, at your option, clmSpace will return or delete all personal data processed on your behalf and delete existing copies, except where applicable law requires storage of the personal data. Client content is deleted within 30 days of termination on request, using our admin tooling; operational logs are retained for approximately 90 days.
11. Audit and information rights
clmSpace makes available to you the information necessary to demonstrate compliance with this DPA and, on reasonable notice and during business hours, allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate, no more than once per year unless required by a supervisory authority. To support this, we provide the following assurances on request:
- our security white paper for InfoSec reviewers;
- the schedule of technical and organisational measures;
- the sub-processor register;
- the transfer impact assessment for our US AI sub-processor.
Costs of audits beyond our standard assurance pack are borne by you.
12. Liability
Liability under this DPA is subject to the limitation-of-liability provisions of the Master Services Agreement.
13. Contact
For DPA-related matters, contact privacy@clmspace.com.