Last updated: 24 June 2026
Privacy policy
This policy explains how Rated Counsel Limited (t/a clmSpace) ("clmSpace", "we") collects and uses personal data when you visit clmspace.com, request a demo, or use our contract intelligence services (the "Service").
1. Who we are and our role
clmSpace is a company registered in England and Wales (company no. 11812572), with its registered office at 5 Golden Mede, Waddesdon, England, HP18 0NG. For matters relating to your personal data, you can contact us at privacy@clmspace.com. For UK and EU matters, our representative is identified at the same address.
For the contract content and structured contract data that customers process through the Service, the customer is the controller and Rated Counsel Limited is the processor, acting on the customer’s documented instructions under our Data Processing Agreement. For the marketing site, demo requests, and account administration described below, we act as controller for that limited personal data.
2. Personal data we collect
- Account data: name, business email, employer, role, and authentication identifiers (from Microsoft Entra ID single sign-on) when you or a colleague signs in to the Service.
- Customer contract content and derived data: the contracts, templates, and drafts a customer makes available to the Service, and the structured contract data we derive from them (agreements, obligations, citations). The customer is the controller for this category and we process it on their instructions.
- Usage data: pages visited, features used, and interactions with weekly digests, in aggregate and pseudonymous form.
- Technical data: IP address, user agent, and device type, for security and abuse prevention.
- Contact data: the information you provide when you request a demo or contact us, and any correspondence we exchange.
3. How and why we use personal data
We process personal data for the following purposes: to provide and operate the Service, including extracting and analysing contract data and serving dashboards and lists; to authenticate and administer users; to secure the Service and prevent abuse; to respond to demo requests and support enquiries; and to send optional marketing communications where you have opted in. We rely on the following UK GDPR / EU GDPR lawful bases:
- Performance of a contract: to provide the Service to your employer and to administer your account.
- Legitimate interests: to secure, operate, and improve the Service; to contact prospective clients about contract intelligence services relevant to their business.
- Consent: for optional marketing communications and optional website analytics, where you have opted in.
- Legal obligation: to comply with applicable laws and respond to valid legal process.
4. Analytics on clmspace.com and app.clmspace.com
Both surfaces use Vercel Web Analytics and Vercel Speed Insights to understand which pages help buyers most and to monitor real-user performance (Core Web Vitals such as Largest Contentful Paint, Time to First Byte, Cumulative Layout Shift). These services do not set cookies; they derive an anonymous, hashed visitor identifier from your IP address and user-agent on each request and discard the source data immediately. No personal data is stored and no cross-site tracking is performed. Vercel Inc. acts as our processor for this data; see the sub-processor list for transfer mechanism and country of operation.
Although the legal floor under UK PECR / EU e-Privacy does not require consent for cookieless analytics of this kind, we treat analytics as optional and default it to off until you opt in via the cookie banner. Global Privacy Control and Do Not Track signals are honoured automatically. See the cookie policy for the per-category breakdown and how to change your choice.
5. AI processing and sub-processors
The Service uses Anthropic Claude (Sonnet class) to extract, analyse, and review contract data. AI extraction produces draft contract intelligence for professional review: extracted obligations are relied upon only after a human verifier confirms or overrides them, and low-confidence items are flagged. Under Anthropic’s API terms and our commercial agreement, API data is not used to train models; Anthropic retains API data for up to 30 days for abuse monitoring.
AI inference runs on Anthropic’s infrastructure in the United States. This transfer is covered by the safeguards described in section 6. A complete register of every sub-processor that handles customer contract data, the purpose, the categories of data, and the location is maintained on our sub-processor list. We process source contract documents in place within the customer’s own SharePoint or Google Drive through connectors and keep no separate copy of those source files.
6. International transfers
Backend processing, structured contract data, and the read model that powers lists and dashboards are hosted in the United Kingdom (Microsoft Azure UK South and Neon Postgres in AWS London), and the customer portal is hosted in London. The one routine transfer outside the UK and EEA is AI inference by Anthropic in the United States. That transfer is governed by the UK International Data Transfer Agreement, which references the EU Standard Contractual Clauses on a processor-to-processor basis. Where any other transfer outside the UK or EEA is necessary, we rely on the UK IDTA or the EU SCCs, supplemented as required by the relevant transfer-impact assessment.
7. Retention
We retain personal data only for as long as necessary to provide the Service and meet our legal obligations. Client content is deleted within 30 days of termination on request, and deletion is also available on request and through our admin tools. Operational logs are retained for around 90 days.
8. Your rights
Depending on your jurisdiction you may have rights to access, correct, delete, port, restrict, or object to our processing of your personal data, and to withdraw consent where processing relies on it. Where we act as processor for customer contract data, we will assist the customer (as controller) in responding to such requests, and we will refer requests we receive directly to the relevant customer. You can exercise your rights, or raise any privacy question, by writing to privacy@clmspace.com. You can also complain to your data protection authority (in the UK, the ICO).
9. Security
Our security white paper, written for information-security reviewers, describes our controls in detail on the security page. In summary: Microsoft Entra ID single sign-on with platform-issued, tenant-scoped sessions; least-privilege, deny-by-default authorisation with agreement-level access control; per-tenant isolation enforced on every read and write; TLS in transit and encryption at rest across our managed services; managed platform secrets; and audited verification and override actions. These controls are exercised by an automated test suite.
10. Changes
We may update this policy from time to time. Material changes will be notified to account holders. The "Last updated" date above always reflects the current version.