Recension

Privacy Policy

Recension

Last updated: 10 March 2026 · Version 1.0

1. Who we are and what this policy covers

Recension (“Recension”, “we”, “us”) captures contract documents that vendors publish at public URLs, keeps every captured version with its source bytes and hash, splits each version into a clause tree with permanent citable URLs, and delivers the record set as a nightly Parquet and JSONL drop into a bucket the licensee owns. We do not read your executed contracts, we do not negotiate with your vendors, and we do not connect to any system of yours.

Registered at Recension Data Ltd, Dockgate, Merchants Road, Galway H91 KV27, Ireland.

This policy explains how we handle personal data in two distinct capacities, which are governed by different rules:

Whose dataOur roleGoverned by
Part AWebsite visitors, prospects, people who contact usController — we decide why and howThis policy
Part BYour watchlist, meaning the list of vendors and documents you ask us to watch, and the review and delivery accounts you nameProcessor — we act only on the customer’s documented instructionsThis policy and the Data Processing Agreement signed with that customer

Where the Data Processing Agreement (“DPA”) and this policy conflict in respect of Part B, the DPA governs.

Part A — When we are the controller

This part covers personal data we collect for our own purposes: running our website, responding to access requests, and communicating with prospective and existing customers.

A.1 What we collect

Information you give us. When you submit the access request form we collect your first name, last name, work email address and company name, together with the fact that you agreed to be contacted. If you email us or talk to us during evaluation or onboarding, we hold the content of that correspondence and any business contact details in it.

Information collected automatically. Our web server records the IP address the request came from, the user agent string, the pages requested, referring URL and timestamp. These logs exist to keep the site available and secure.

We do not knowingly collect special categories of personal data under Article 9 GDPR in this part, and the form should not be used to send us any.

A.2 Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Responding to an access request and evaluating fitForm submissions, correspondenceArt. 6(1)(b) — steps at your request prior to a contract
Administering a customer relationship, billing, supportContact details, correspondenceArt. 6(1)(b) — performance of a contract
Site availability, security, abuse preventionServer logsArt. 6(1)(f) — legitimate interest in operating a secure service
Direct outreach to business contacts about the serviceWork email, companyArt. 6(1)(f) — legitimate interest in B2B marketing, subject to your right to object at any time
Meeting tax, accounting and legal obligationsBilling and contract recordsArt. 6(1)(c) — legal obligation

Where we rely on legitimate interest, we have assessed that interest against your rights and are able to provide the assessment on request.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or UK you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. You may exercise any of these by writing to [email protected]. We answer within one month.

You also have the right to complain to a supervisory authority. If you are in the EEA you may complain to the authority in your country of residence or workplace; our EU representative is identified in section 5.

Part B — When we are the processor

Almost everything in the corpus is a document a vendor published to the open web, and it is not personal data and not yours. Two things are yours and both are more sensitive than they look. The first is the watchlist: which vendors a named company asks us to watch, and when it added them, is a description of that company's live purchases and renewals. The second is the delivery configuration and the people you name to receive digests and pull citations. This part sets out how each is treated.

B.1 What we process, and why it is personal data

Account data, meaning your work email, entity, billing contact and the people you authorize to receive digests, we hold as a controller. Your watchlist, your delivery configuration, your citation requests and the access logs against your bucket we process as your processor, on your instruction, for as long as the license runs.

We take no feed from your systems. There is no connector into your CLM, your ERP, your contract repository or your mailbox, and no read scope on any of them. What we hold about you is a list of vendor names, a delivery target and the people you named.

Do not send us an executed contract. If one reaches us by email we delete it and say so in writing; we are not the right custodian for your signed paper and we hold no scope for it.

A clause URL is public within your license, not public to the world: anyone at your entity, and outside counsel acting for you, can open one, and it is not indexable or resolvable outside that.

B.2 What we do with it

The record set is written to your bucket. Nightly Parquet partitions, the JSONL change file, the source files exactly as fetched and the signed manifest are written to a storage bucket you own, in your account, in the region you choose. We keep the index, the embeddings, the clause tree and the manifest hash chain in S3 in AWS eu-west-1, in Ireland. If you leave, what you have already received stays where it is.

Nothing is silently corrected. An extraction error is fixed by publishing a new version of the clause with an errata note naming what changed and why, never by editing a version already issued. Every version we have ever published stays resolvable, including the wrong one, because a citation taken against it has to keep resolving.

The watchlist is not merged. Watchlists are held per licensee and are not combined, cross-referenced or used to weight what we crawl for anyone else. If two licensees watch the same vendor, neither can learn that from anything we publish.

The alignment corpus contains public documents only. The labeled clause pairs our reviewers produce are shared across the service, and every pair in them comes from documents the vendor published publicly. No watchlist, no delivery configuration and no text of yours enters it, because none of that is a clause pair from a public document. Training on it runs on Azure Machine Learning in Microsoft's North Europe region, also in Ireland.

B.3 Models, inference and training

Where inference runs. Day-to-day inference runs on EC2 GPU instances we control in AWS eu-west-1, in Ireland: the clause-boundary token classifier, the embedding model used to propose cross-version matches, and the similarity scoring. From Q2 2027 it runs on reserved EC2 GPU capacity in the same region. Re-embedding backfills for a new embedding model run on Azure Machine Learning managed GPU compute in Microsoft Azure North Europe, also in Ireland, over public vendor documents only. No third-party inference endpoint is used, no Azure OpenAI, and no fragment of a document, a diff or a watchlist is sent to a hosted model API. Our subprocessor register lists Amazon and Microsoft for the machines and no model vendor at all, because no model vendor is in the path.

Training. We do not train on your data, and here the boundary is precise rather than rhetorical. The one corpus we do train on is the set of labeled clause pairs our reviewers produce: two clause versions from a document a vendor published at a public URL, plus a decision about whether they are the same clause. That corpus is shared across the service, and training on it runs on Azure Machine Learning managed GPU compute in Microsoft Azure North Europe, in Ireland. Your watchlist, your delivery configuration, your citation history and the identity of anyone at your entity are excluded from it entirely and are never used to train, tune or evaluate a model.

Human review. The model proposes an alignment; a person decides whether it holds. An alignment is published only when the embedding match and the token-similarity margin both clear a fixed threshold. Below the threshold nothing is published as a diff: the pair enters a review queue, the affected section is marked unaligned and in review in the delivered file and in the reader, and a named reviewer confirms or corrects it before it ships. There is no automated decision producing legal effects for any individual anywhere in this service. We publish what a document said on a date; every judgment about what that means is made by your people.

B.4 Where the data sits

Processing stays in Ireland. Crawling, extraction, the index, the citation reader, the review queue and model serving run on AWS in eu-west-1; model training and re-embedding backfills run on Azure Machine Learning in Microsoft's North Europe region.

Your delivery bucket is yours and you choose its region. If you place it outside Ireland, the delivered files live there while our index and all processing stay in Ireland.

No inference runs on a third-party endpoint. The models are served on EC2 GPU instances we control in eu-west-1, and trained and re-embedded on Azure Machine Learning compute in North Europe, and no fragment of a document or a watchlist is sent to a hosted model API.

Vendor documents are fetched from the public web over ordinary HTTPS requests, unauthenticated, with a declared user agent. We do not log in to a vendor portal to obtain a document, and we do not accept one from you under NDA.

B.5 Retention, deletion, and the limits of deletion

Captured document versions, source files, clause trees and manifests: for the life of the corpus. These are the record and we do not expire them.

Your watchlist and delivery configuration: for the life of the license, deleted within 30 days of its end.

Citation request logs: 24 months, then aggregated to counts with the identity dropped.

Clause URLs your people cited during the license: resolvable for the license term plus 24 months, so a citation in a closed review ticket does not rot when you stop paying.

Account and billing records: six years after the license ends, as Irish company and tax record rules require.

Delivery and reader access logs, without payloads: 90 days.

B.6 Requests from individuals whose data we process

The corpus itself carries almost no personal data, though a vendor's own published document occasionally names a signatory or a notice contact, and we keep those as published because redacting them would break the citation. About you, we hold your work email, your entity, who added which vendor to the watchlist and who resolved which citation. Write to [email protected] and we will answer within 30 days. If a person named inside a vendor's published document contacts us, we tell them plainly that the source is the vendor's own public page and point them there.

Common provisions

5. International transfers

Recension is incorporated in the United States and serves customers established in the EEA. Personal data transferred outside the EEA is protected by the European Commission’s Standard Contractual Clauses, together with a transfer impact assessment and the supplementary technical measures described in our security documentation. A copy of the clauses is available on request.

EU representative (Article 27 GDPR)

6. Security

We maintain measures appropriate to the risk, including encryption in transit and at rest, credentials scoped to the minimum necessary, access control on the principle of least privilege, isolation of each customer’s data, and audit logging of access to production systems.

We notify affected customers of a personal data breach without undue delay and, in any event, within 36 hours of becoming aware of it, with the information they need to meet their own notification duties.

7. Children

The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.

8. Changes to this policy

We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect, and the version number and date at the top of this page are updated in every case.

9. Contact

Privacy enquiries and general: [email protected]
Postal: Recension, Recension Data Ltd, Dockgate, Merchants Road, Galway H91 KV27, Ireland

← Back

Your request has been received.

Expect a message from Recension. It goes to the address you gave.