ContractRabbit Docs
Security & Privacy

Data Privacy

How ContractRabbit handles customer data ownership, access, export, deletion, residency, retention, AI processing, and auditability.

Privacy posture

ContractRabbit processes confidential contract documents and extracted legal data on behalf of customers. Customers retain control over their workspace data, and ContractRabbit applies safeguards for access, storage, processing, export, deletion, retention, and auditability.

Contract-specific privacy obligations, retention periods, support procedures, subprocessors, and data processing terms are governed by the applicable customer agreement, data processing agreement, or order form.

Data categories

Data categoryExamplesPrimary purposeStandard handling
Customer contentUploaded contracts, generated documents, document versions, extracted text, and source files.Contract review, extraction, search, workflow, and reporting.Stored in managed cloud data stores with encryption at rest and in transit.
Structured metadataParties, dates, monetary values, citations, governing law, renewal terms, duration, obligations, and other extracted fields.Search, filtering, review workflows, analytics, and reporting.Stored as workspace-scoped application records.
Derived dataClassifications, recommendations, embeddings, search indexes, analytics records, and AI-generated outputs.Retrieval, clause analysis, matching, review assistance, and product functionality.Treated as customer data when derived from customer content.
Workflow and audit dataDocument lifecycle events, user actions, matter relationships, stage history, approvals, and audit log entries.Governance, traceability, support, and customer reporting.Retained according to product settings and applicable customer agreement.
Account and access dataUsers, invitations, organization membership, roles, authentication identifiers, and API keys.Authentication, authorization, tenant access control, and account administration.Access is restricted by role, tenant, and operational need.
Operational dataLogs, diagnostics, job status, queue state, performance telemetry, and support context.Security, reliability, debugging, incident response, and service operation.Access is limited to authorized personnel and operational use.

Processing purposes

PurposeDescription
Provide the serviceUpload, store, parse, analyze, search, classify, compare, and manage contract documents.
Improve workspace workflowsSupport document lifecycle management, auditability, review routing, and reporting.
Secure the platformAuthenticate users, enforce tenant access, monitor system activity, investigate incidents, and prevent misuse.
Support customersDiagnose issues, respond to support requests, and maintain service reliability.
Meet contractual obligationsProvide exports, deletion workflows, retention controls, audit records, and enterprise support commitments where applicable.

Customer control and export

Customers can request export of application data associated with their workspace. Available exports may include:

Export areaExamples
DocumentsUploaded files, generated documents, document versions, and related file records.
Extracted dataStructured document metadata, clauses, entities, citations, dates, monetary values, and review outputs.
Enrichment dataExternal enrichment records associated with extracted entities where applicable.
Workflow dataMatter records, lifecycle state, review history, and document relationships.
Audit recordsUser actions, administrative events, and document activity history where supported.

Enterprise export scope, delivery format, support process, and timing may be defined by contract.

Deletion and retention

Administrative data management controls support deletion of workspace documents and associated records. Deletion is intended to remove related customer data across application records and storage systems, including cached data where applicable.

Deletion behavior may be subject to legal, security, backup, billing, audit, or contractual retention obligations. Customer-specific deletion commitments should be reviewed in the applicable agreement.

AreaStandard postureEnterprise agreement topics
Workspace document deletionCustomer administrators can delete documents and related application records where supported.Deletion SLA, approval process, and deletion evidence.
Derived dataDerived records such as extracted metadata, classifications, embeddings, and search records are treated as customer data when derived from customer content.Scope of derived-data deletion and exception handling.
Audit logsAudit history may be retained to preserve security, governance, billing, or legal records.Audit log retention period and export requirements.
BackupsBackups may retain deleted data until backup expiration or overwrite.Backup retention period, recovery objectives, and post-termination deletion.
Legal or security holdsDeletion may be delayed where required by law, security investigation, or contractual obligation.Hold process, notice, and release procedure.

Data residency

ContractRabbit supports customer choice of data residency for database storage and blob storage. Supported residency options include the United States, European Union / EEA, China for approved enterprise deployments, or another customer-specific deployment boundary where agreed.

Redis caching is currently U.S.-only. Regional Redis caching can be reviewed as part of a customer-specific deployment plan.

Residency optionDatabase storageBlob storageRedis caching
United StatesUnited StatesUnited StatesUnited States
European Union / EEAEuropean Union / EEAEuropean Union / EEAUnited States
ChinaChina for approved enterprise deploymentsChina for approved enterprise deploymentsUnited States
Other deployment boundaryCustomer-specificCustomer-specificUnited States unless otherwise agreed

Residency commitments must define which data categories are in scope, including customer content, structured metadata, derived data, embeddings, AI prompts and responses, logs, backups, support records, and operational data.

Data areaResidency scopeDeployment considerations
Customer contentIn scope.Stored in the selected blob storage residency boundary.
Structured metadataIn scope.Stored in the selected database residency boundary.
Derived data and embeddingsIn scope when derived from customer content.Region-specific vector storage, search indexes, and AI processing controls.
AI prompts and responsesIn scope when generated from or sent with customer content.Provider selection, processing region, retention, no-training commitments, and fallback restrictions.
Redis cache dataCurrently U.S.-only.Regional cache deployment can be reviewed for customer-specific deployments.
Logs and telemetryScoped by agreement.Log redaction, geographic storage, retention limits, and access controls.
Backups and disaster recoveryIn scope for strict residency commitments.Backup region, replication boundaries, retention, and recovery objectives.
Support accessScoped by agreement.Named support team, geographic access restrictions, approval workflow, and customer notice.

AI processing

ContractRabbit uses AI-assisted processing to analyze documents, extract structured data, classify clauses, generate recommendations, and support natural-language search and review workflows.

ProviderUnited StatesEuropean Union / EEAChina
Google Gemini / Vertex AIUnited StatesEU/EEA regional endpoint where configured
OpenAIUnited StatesEurope data residency where configured
VoyageUnited States where configuredEU/EEA only where provider terms and endpoint configuration support the deployment boundary
DeepSeekChina
Qwen / DashScopeChina
TopicStandard postureEnterprise review topics
Model inputsCustomer content, extracted text, metadata, prompts, and task instructions may be sent to configured AI providers as needed to provide the service.Which data categories may be sent to each provider.
Model outputsAI-generated extracted fields, classifications, summaries, recommendations, and review assistance are stored as customer data.Retention, export, deletion, and auditability of AI outputs.
EmbeddingsVector embeddings may be generated to support search, matching, clustering, and retrieval.Embedding provider, storage region, deletion behavior, and portability.
Provider routingProviders may vary by feature, deployment, and availability.Approved provider list, fallback behavior, region controls, and customer-managed credentials.
Retention and trainingProvider-specific retention, abuse monitoring, and training commitments are governed by the applicable provider terms and customer agreement.No-training commitments, zero-retention options, and data residency configuration.

Subprocessors and transfers

ContractRabbit uses third-party service providers to deliver hosting, storage, authentication, AI processing, support, security, billing, and operational capabilities. The authorized subprocessor list, transfer mechanisms, and regional commitments are provided through the applicable customer agreement or security package.

Review areaEnterprise review expectation
Subprocessor identityProvider name, service purpose, and relevant product area.
Data categoriesCustomer content, metadata, derived data, account data, operational data, or billing data.
Processing locationRegion or country used for storage, processing, support, and backup where applicable.
Transfer mechanismContractual mechanism for international transfers, such as SCCs, an applicable international transfer addendum, adequacy decision, or Data Privacy Framework participation where applicable.
Notice and objectionCustomer notice process for new or replacement subprocessors.

Access to customer data

ContractRabbit limits production data access using role-based access controls and least-privilege principles. Administrative access is restricted to authorized personnel, logged where supported, and reviewed.

Where production data access is required for support, security, or operational purposes, access is governed by internal approval controls and customer-specific contractual requirements.

Auditability

ContractRabbit logs user actions and document history so customers can review activity in their workspace and export records to external governance systems where supported.

Audit areaExamples
User activitySign-in activity, document actions, workflow changes, and review activity where supported.
Document historyUpload, version, lifecycle, extraction, and review events.
Administrative activityWorkspace governance events and privileged actions where supported.
ExportabilityAudit log exports may be available for enterprise review or downstream governance workflows.

Enterprise privacy review

For privacy diligence, customers should review the applicable agreement and request any required security or data processing materials.

TopicTypical diligence question
DPA rolesIs ContractRabbit acting as processor, subprocessor, or independent controller for each data category?
Data categoriesWhich customer data, account data, derived data, and operational data are processed?
SubprocessorsWhich providers process customer data, in which regions, and for what purpose?
TransfersWhat legal mechanism supports transfers outside the customer's required geography?
ResidencyDoes the customer require U.S., EU/EEA, China, or another deployment boundary?
DeletionWhat data is deleted immediately, what remains in backups, and what deletion evidence is available?
AI processingWhich AI providers, models, regions, retention terms, and fallback paths are permitted?
Support accessWho can access production data, from where, under what approval flow, and with what logging?

On this page