Agmt Verbatim · Draft legal document

Privacy notice

Scope and roles

This draft concerns Agmt Verbatim, a service that converts Word agreements into structured legal text. The product specification describes Agmt as acting as a processor when a customer submits a document. The owner and counsel must confirm the parties’ roles, applicable jurisdictions, controller instructions, and the entity responsible for this service before this notice is approved.

Privacy contact: [Owner to provide and verify the legal entity name, postal address, and privacy contact.]

Documents and temporary uploads

According to the current product design, document plaintext is parsed in Worker memory and is not written to application logs or databases. This is a statement about the specified application behavior; production configuration and operations must be reviewed before it is treated as a verified public commitment.

If a user chooses the browser upload flow, the upload is held as encrypted ciphertext. Access ends after 15 minutes. Physical deletion is asynchronous, and no physical-deletion deadline has been verified for this deployment. Do not read the access period as a promise that the stored ciphertext has already been physically deleted.

The service may process document text, revisions, comments, author names, clause references, and document properties to provide the requested output. The draft does not claim that a document contains no personal information.

Account and service metadata

The product specification identifies these retained metadata categories:

These are metadata, not document plaintext, but some may relate to an identifiable person. Retention periods, purposes, access controls, and a deletion process for each category still need to be documented and approved. This draft makes no retention-period promise for them.

Service providers and processing location

The product specification names the following subprocessors and scopes:

Processing is designed to occur in memory at the nearest Cloudflare location. The service does not pin processing to a particular region. The owner must confirm the deployed provider configuration and complete any required provider, transfer, and subprocessor disclosures before publication.

Requests, cookies, and other details to complete

[Counsel and the owner to add verified instructions for privacy requests, applicable statutory rights and response periods, cookies or similar technologies, analytics, account closure, complaints, and any required notices under the India Digital Personal Data Protection Act 2023 and, where applicable, the GDPR.]

[Add the effective date and a process for notifying customers about changes after the legal entity and operating procedures are confirmed.]