Last updated: 24 June 2026
Transfer impact assessment (TIA)
This transfer impact assessment is maintained by Rated Counsel Limited (t/a clmSpace) and is referenced in our data processing addendum. It assesses the one routine restricted transfer involved in operating the clmSpace platform (the "Service") and explains why that transfer can proceed with appropriate safeguards. All other hosting of customer data remains in the United Kingdom: the API runs in Azure UK South, the read model is held in Neon Postgres (AWS London), and the customer portal is hosted on Vercel (London region).
1. The transfer and its purpose
To extract and analyse contracts, clmSpace sends contract text to our sub-processor Anthropic PBC in the United States for AI inference. The inference produces structured contract intelligence (extraction of terms, obligations and citations, and supporting analysis) that is then returned to the Service. This is the only routine restricted transfer in the processing.
2. Transfer mechanism
The transfer is processor-to-processor: clmSpace acts as processor for the customer (the controller), and Anthropic acts as our sub-processor. It is covered by the UK International Data Transfer Agreement (IDTA), which references the EU Standard Contractual Clauses. This provides the contractual transfer mechanism required for a restricted transfer to the United States.
3. Data categories transferred
The data transferred for inference comprises the contract text itself and, where a contract is supplied as a scanned PDF, page images of that document so its text can be read. Any personal data is that which is incidentally contained in the contracts (such as the names, roles and contact details of signatories and counterparty representatives). No separate account directory or unrelated personal data is sent for inference.
4. Supplementary measures
- No-training commitment.Under Anthropic’s API terms and our commercial agreement, API data is not used to train models.
- Limited retention. Anthropic retains API data for up to 30 days for abuse monitoring only, after which it is removed.
- Encryption in transit. Contract text and page images are transmitted to the inference service over TLS.
- Human-verification gate. AI output is treated as draft contract intelligence and becomes authoritative only after a human verifier confirms or overrides it, so no decision rests on the transferred data alone.
- Data minimisation. Only the contract content needed for extraction and analysis is sent for inference, keeping the transfer to what the purpose requires.
5. Assessment of US law risk
We have assessed, at a level reasonable for this processing, the risk that US law could compel disclosure of the transferred data to public authorities. The data consists of commercial contract text rather than bulk consumer or telecommunications data, the recipient is a private commercial processor, and the data is held only transiently for inference and for the short abuse-monitoring window described above. Against that background, the combination of the IDTA and EU Standard Contractual Clauses, the contractual no-training and limited-retention commitments, encryption in transit, data minimisation and the human-verification gate provides safeguards proportionate to the residual risk. Anthropic also maintains its own independent security attestation (SOC 2 Type 2), available on request.
6. Conclusion
Taking the transfer mechanism and the supplementary measures together, we conclude that the transfer of contract text and page images to Anthropic in the United States for AI inference can proceed with these measures in place. We keep this assessment under review and will update it if the nature of the transfer, the recipient’s commitments or the relevant legal framework changes.
Contact
For questions about this assessment, contact privacy@clmspace.com.