1. Data we process
We process account name, email, password hash, organization and workspace information, role, department, invitations, service activity, support requests, subscription status, and security logs.
How ContractVault handles account information, workspace activity, contract data, service providers, retention, and privacy requests.
Version 2026-07-15 · Effective Date 2026-07-15 · Billing Policy RevisionWe process account name, email, password hash, organization and workspace information, role, department, invitations, service activity, support requests, subscription status, and security logs.
Uploaded PDFs may contain personal or confidential information. We process source documents, OCR text, AI-corrected output, extracted fields, schedules, governance results, corrections, and audit history to provide the service.
We use data to authenticate users, isolate workspaces, process and search contracts, provide schedules and governance review, measure usage, administer subscriptions, answer support requests, prevent abuse, and maintain security.
Lemon Squeezy processes subscription checkout and payment details. ContractVault receives identifiers, status, plan, renewal, and refund information needed to administer access. We do not store full card numbers.
We use cloud infrastructure and encrypted storage, OCR and generative AI services, Lemon Squeezy for payments, notification and support delivery services, and optional analytics only when enabled under the applicable consent settings.
Providers may process data in countries other than your own. We use the provider and contractual safeguards available for the service and disclose material changes to processing locations or providers.
Account and contract data are retained while needed to provide the workspace and are deleted through account, contract, or workspace deletion workflows. Limited payment, tax, fraud, security, and dispute records may be retained where legally required.
We apply workspace-scoped authorization, encrypted transport and storage, one-way password hashing, secure session cookies, role controls, request limits, and audit events for sensitive activity.
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection. Workspace administrators can manage operational data; privacy requests may be sent to help@incode-labs.net.
AI assists with OCR correction, fields, summaries, and risk signals. Users can review source pages, correct results, and should not treat the output as a final legal decision.
Privacy questions and requests may be sent to help@incode-labs.net. We may need to verify identity and workspace authority before fulfilling a request.