Drafted: 27 August 2026 · Not yet in force · MossMoor Ltd
This document has been drafted to describe how ClausesGuard actually works, but it has not yet been reviewed by a qualified lawyer and is not yet in force. Do not rely on it. It must be reviewed and approved before the Service accepts paying customers.
MossMoor Ltd, registered in Nigeria under the Companies and Allied Matters Act and trading as ClausesGuard, is the data controller for the personal data described here.
Contact for privacy matters: privacy@clausesguard.com.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email address, authentication identifier | You, via Clerk sign-up |
| Plan and usage | Plan tier, plan status, number of analyses and drafts used this period, period start date, billing currency | Generated as you use the Service |
| Payment | Paystack customer and subscription references, transaction reference, amount, currency, status, payment date | Paystack. We never receive your card number |
| Contract text | The text you paste, or text extracted in your browser from a file you upload | You |
| Analysis results | Document name you gave it, risk score, risk level, plain-English summary, clause breakdown with explanations and suggestions | Generated by our AI provider from your Input |
| Drafts | Document name, full agreement text, language, jurisdiction, template type | Generated for you, plus any edits you make |
| Waitlist | Email address and optional name, if you use the sign-up form on our home page | You |
| Technical | IP address, browser type, request logs, error reports | Automatically, via our hosting provider |
We do not ask for and do not want special category data (health, biometric, political, religious and similar). Please do not upload documents containing it.
You can delete any individual analysis or draft from the Documents area at any time, which removes it from our database.
For users in the EU, UK and other jurisdictions applying a lawful-basis requirement:
| Purpose | Lawful basis |
|---|---|
| Creating and running your account; producing the analyses and drafts you ask for | Performance of a contract (GDPR Art. 6(1)(b)) |
| Taking payment, invoicing, handling refunds and chargebacks | Performance of a contract; legal obligation (Art. 6(1)(b), (c)) |
| Enforcing usage limits and preventing abuse of the free plan | Legitimate interests (Art. 6(1)(f)) |
| Security monitoring, error logging and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Keeping accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Adding you to the waitlist, and service emails about your account | Consent for the waitlist (Art. 6(1)(a)); contract for service emails |
Where we rely on consent you may withdraw it at any time. Where we rely on legitimate interests you may object, and we will stop unless we have overriding grounds.
The analysis, risk score and drafts are produced by an AI model without human review. This is the core function of the Service and is what you are asking us to do.
We do not use this processing to make any decision that has a legal effect on you or similarly significantly affects you within the meaning of Article 22 GDPR — the Output is information for you to act on, and every decision about your contracts remains yours. We do not use automated profiling for credit, employment, insurance or eligibility decisions.
We do not sell personal data and we do not share it for advertising. We use the following processors, each under a written data processing agreement:
| Provider | Role | What it receives |
|---|---|---|
| OpenRouter | AI routing | Your contract text or drafting instructions, for the duration of the request, passed on to a model provider below |
| AI processing (via OpenRouter) | Your contract text or drafting instructions, for the duration of the request | |
| Anthropic | AI processing (via OpenRouter), used as a fallback | Your contract text or drafting instructions, for the duration of the request |
| Clerk | Authentication | Name, email, authentication and session data |
| Paystack | Payments | Email address and transaction data. Card details go directly to Paystack |
| Supabase | Database hosting | All stored account, usage, analysis, draft and payment records |
| Vercel | Application hosting and logs | Request data, IP address, error reports |
We may also disclose data where legally required, to establish or defend legal claims, or to a successor entity on a merger or sale of the business (in which case we will tell you).
Our database is hosted in the European Union (Ireland, eu-west-1). Application hosting and AI processing may take place in the United States and other countries.
This means personal data is transferred out of Nigeria, and out of the EEA and UK, to countries that may not have been assessed as providing an equivalent level of protection. For transfers from the EEA and UK we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, plus supplementary technical measures including encryption in transit and at rest.
You can request a copy of the transfer mechanism we rely on for any given provider.
| Data | Retention |
|---|---|
| Contract text you submit | Not retained. Discarded once the request completes |
| Analyses and drafts | Until you delete them, or 12 months after your account is closed |
| Account and profile | For the life of the account, then 30 days after a deletion request |
| Payment and transaction records | 7 years from the transaction, to meet accounting and tax obligations |
| Waitlist entries | 24 months, or until you ask to be removed |
| Security and error logs | 90 days |
| Backups | Up to 30 days after deletion from the live database |
Where we must keep a record for accounting reasons we keep only what is necessary for that purpose and stop using it for anything else.
No system is perfectly secure. We cannot guarantee absolute security, and you share information with us on that understanding.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it. Where the risk to you is high we will notify you directly and without undue delay, and tell you what happened, what data was involved and what to do.
Depending on where you live, you have the right to:
These rights arise under the Nigeria Data Protection Act and, where they apply to you, the EU GDPR and UK GDPR.
You can do some of this yourself, immediately:
For anything else — a full copy of your data, deletion of your whole account, restriction, or objection — email privacy@clausesguard.com. We will acknowledge within 7 days and respond substantively within 30 days. We may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
Please raise it with us first — we would rather fix it. You also have the right to complain to a supervisory authority:
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
See our Cookie Policy. In short: we set only the cookies strictly necessary to keep you signed in, and we run no advertising or analytics trackers.
We may update this policy. For changes that materially affect how we use your data we will give at least 30 days’ notice by email or in-app notice. The version and its date always appear at the top of this page.
Registered in Nigeria under the Companies and Allied Matters Act