Legal

Privacy Policy

Last updated: June 2026 · Available in English, Română and Русский.

This Privacy Policy explains how ContractsMind (“we”, “us”) collects, uses, stores and protects your personal data when you use our AI contract analysis service. We are committed to the EU General Data Protection Regulation (GDPR) and applicable local data-protection law.

1. Controller

ContractsMind is the data controller responsible for your personal data. For data-protection matters, contact our Data Protection Officer at [email protected].

2. Data we process

3. Purposes & legal bases

We do not use your documents to train AI models. Your files are processed only to produce your report and are deleted per our retention policy.

4. Encryption & storage

Files are encrypted with AES-256-GCM and stored in Cloudflare R2 (EU-oriented setup). Sensitive files use SSE-C with customer-provided keys. Files are accessible only to you via short-lived signed URLs (1 hour TTL). See our Security overview for technical detail.

5. Retention

6. Your GDPR rights

To exercise any right, email [email protected]. We respond within one month (Art. 12).

7. Sub-processors & transfers

We use carefully selected sub-processors under Data Processing Agreements (DPAs), including Cloudflare (R2, EU-oriented), Paddle, Victoriabank MD, AI model providers and SendGrid. See the sub-processor list. Where data leaves the EEA, we rely on appropriate safeguards (e.g. Standard Contractual Clauses).

8. Children

ContractsMind is not intended for users under 16. We do not knowingly process their data.

9. Changes to this policy

We may update this policy. Material changes will be notified in-app and/or by email. The “last updated” date above always reflects the current version.