Legal
Last updated: 29 July 2026 · UK GDPR / Data Protection Act 2018
This Privacy Policy explains how Contractiv8 collects, uses, shares and protects your personal data, and the rights you have under the UK GDPR and the Data Protection Act 2018. It applies to creators who use the Service, prospective customers, people incidentally named in uploaded contracts, and visitors to our website.
Privacy is built into how the Service works.
Your uploaded contracts are analysed by deterministic, rules-based pattern matching, not by artificial intelligence. They are never processed by a large language model, never used to train any model, and never leave our secured database. Because there is no model-training path in the way the Service is built, this is a property of the system's design rather than a promise.
Contractiv8 is a contract-risk intelligence platform operated by Performance Driven Digital Limited ("Contractiv8", "we", "us", "our"). For the personal data described in this policy, we are the data controller.
Registered address: 124 City Road, London, England, EC1V 2NX
Data protection contact: support@contractiv8.com
We are not required to appoint a statutory Data Protection Officer, and the founder acts as our data protection point of contact. You can read more about how we govern data protection, including our Information Commissioner's Office (ICO) registration, on our Data Protection page.
We collect only the data the Service needs:
We use your data for the purposes below, each with a recorded lawful basis under the UK GDPR:
| Purpose | Lawful basis |
|---|---|
| Creating and operating your account and workspace | Performance of our contract with you |
| Scanning your uploaded contracts and returning results | Performance of our contract with you; our legitimate interests (and the incidental third-party data minimised) to deliver the scan |
| Recording your authority-to-scan and not-legal-advice consent | Performance of our contract and compliance with a legal obligation |
| Taking payment and managing your subscription | Performance of our contract; compliance with a legal obligation to keep financial records |
| Sending transactional and lifecycle service emails | Performance of our contract with you |
| Product analytics to understand usage and improve the Service | Our legitimate interests, with cookie consent where required |
| Security, rate limiting and abuse prevention | Our legitimate interests |
| Beta list and marketing, where you have asked to receive it | Your consent |
Where we rely on legitimate interests, we have considered your rights and interests and will stop that processing where you object and we are required to. The scan is decision-support and not a solely-automated decision with legal or similarly significant effect; you remain the decision-maker, and we explain the reasoning behind every flag.
We use a small number of essential cookies that are needed for the Service to function. We only set non-essential analytics cookies after you have given consent through our cookie banner, and you can decline or withdraw consent at any time. Our analytics identify you only by a pseudonymous identifier, never by name or email, and advertising signals are switched off.
Affiliate referrals. If you arrive through one of our affiliate partners, we set a referral cookie (provided by Affonso) once you consent through the same "Analytics & Affiliates" option in our cookie banner. It lets us credit the creator who referred you if you later subscribe. This cookie lasts up to 60 days, records only the referral and not your name, email or any contract content, and is never set before you opt in. You can decline or withdraw it at any time.
We do not sell your data. We share it only with the service providers (sub-processors) that help us run the platform, each under data-processing terms and chosen with UK or EU hosting where possible:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage and the scan worker | EU (Frankfurt / Ireland) |
| Vercel | Application hosting and content delivery | EU edge; US headquarters |
| Stripe | Payments and subscriptions | UK / EU and US |
| Resend | Transactional email | US |
| Google (GA4, BigQuery, GTM) | Product analytics | EU data location; US |
| Sentry | Error monitoring | EU region |
| Upstash | Rate limiting | See current provider terms |
| Affonso | Affiliate referral tracking (only where you consent to the affiliate cookie) | See current provider terms |
We deliberately exclude our business bank from this list, as it processes the company's own banking rather than your personal data.
Your data is held primarily in UK or EU-based infrastructure. Where a provider transfers data outside the UK or EEA (for example, to the United States), that transfer is covered by an appropriate safeguard such as the UK International Data Transfer Agreement or Addendum, the EU-US and UK-US Data Privacy Framework, or Standard Contractual Clauses.
We keep personal data only for as long as we need it, then delete it securely. In summary:
Where you close your account, deletion propagates to our backups within around 30 days. Full detail is set out in our internal Data Retention and Deletion policy.
Under the UK GDPR you have the right to:
To exercise any of these, contact us at support@contractiv8.com. A request can arrive by any channel and does not need to use the word "GDPR" or a form. We may need to verify your identity proportionately first. We will respond within one month, which we can extend by up to two further months for complex requests, and we will tell you if we do. There is no charge unless a request is manifestly unfounded or excessive.
We protect your data with technical and organisational measures, including row-level security so a creator can only ever reach their own workspace, least-privilege access with a server-only administrative credential, multi-factor authentication on every account that can touch production, encryption in transit (HTTPS/TLS) and at rest, IP-based rate limiting on sensitive endpoints, and error monitoring with personal data scrubbed before it leaves the app.
We log every suspected personal data breach and follow a defined response procedure to contain, recover and assess it. Where a breach is likely to result in a risk to your rights, we report it to the ICO without undue delay and within 72 hours of becoming aware. Where it is high risk to you, we will tell you directly, in plain language.
If you have a question or concern about how we handle your data, please contact us first at support@contractiv8.com and we will do our best to resolve it. You also have the right to complain to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk/make-a-complaint.
We may update this policy from time to time. When we do, we will change the date at the top of the page, and we will tell you about significant changes where it is appropriate to do so.