1. Data Controller
- [LEGAL ENTITY / INDIVIDUAL FULL NAME]
- [REGISTERED ADDRESS]
- VAT: [VAT NUMBER]
- Email: privacy@contractsummary.eu
2. What data we process and why
a) Browsing data
IP address, browser type, pages visited, timestamps.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Retention: up to 30 days.
b) Order data
Name, email, billing address, country, VAT number (if provided), the contract file, and payment identifiers (we do not store full card numbers).
- Purpose: executing the contract, producing the summary, invoicing.
- Legal basis: performance of a contract, legal obligation.
- Retention: invoice data 10 years; contract file deleted 30 days after delivery; summary kept 90 days then deleted.
c) Contract content
Files stored on EU-located, access-restricted servers. If a third-party AI provider is used, the file may be transmitted to that provider under a DPA. We do not use your contracts to train any model.
d) Communications
Support emails retained up to 24 months.
e) Cookies
Only strictly-necessary technical cookies. See Cookie Policy.
3. Sharing your data
| Recipient | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Web hosting, storage | EU |
| [PAYMENT PROVIDER] | Payment processing | EU / USA (SCCs) |
| [AI PROCESSOR] | Generating the summary | USA (SCCs + DPA) |
| [EMAIL DELIVERY] | Sending the summary | EU / USA (SCCs) |
| [ACCOUNTANT] | Invoicing, tax compliance | EU |
Non-EEA transfers protected by Standard Contractual Clauses.
4. Automated decision-making
The summary is automated but does not produce legal or similarly significant effects under Art. 22 GDPR – the decision whether to sign is always yours. Human review available on request.
5. Your rights
Access, rectification, erasure, restriction, objection, portability, withdraw consent, complaint to the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).
Contact: privacy@contractsummary.eu
6. Security
TLS encryption, access controls, audit trails. Breach notification within 72 hours.
7. Children
Not for under-16s.
8. Changes
Material changes notified by email; “Last updated” date reflects revisions.
9. Contact
privacy@contractsummary.eu