RenewalGuard

Legal

Privacy Policy

We built RenewalGuard with privacy as a first principle. Your contract documents are never stored — only the metadata we extract from them. This policy explains what we collect, why, and how you can control it.

Last updated: August 2026

1. Who We Are

RenewalGuard is a software-as-a-service platform for supplier contract renewal management. The service is operated by RenewalGuard Ltd.

For any privacy-related enquiries, contact us at: privacy@renewalguard.io

2. What Data We Collect

We collect only what is necessary to provide the service:

  • Account information — your name and email address, collected when you create an account via Clerk (our authentication provider).
  • Contract metadata — structured fields extracted from the contracts you upload: supplier name, contract value, renewal date, notice period, cancellation deadline, and auto-renewal clause summary.
  • Usage data — standard server logs including IP addresses, browser type, and pages visited. Used for security and service improvement.
  • Reminder settings — the email addresses you provide for renewal alert delivery.
What we do not collect:

Your source contract documents are deleted from our servers the moment AI extraction is complete. No contract text, clauses, schedules, or document content is stored anywhere in our systems. We only keep the structured metadata fields listed above.

3. How We Use Your Data

  • To provide the RenewalGuard service — tracking your contract portfolio, calculating renewal and cancellation dates, and surfacing upcoming deadlines.
  • To send you renewal reminder emails at the thresholds you configure (e.g. 90, 60, 30, and 7 days before a cancellation deadline).
  • To maintain your account and authenticate you securely.
  • To detect, prevent, and respond to security incidents and abuse.
  • To improve the accuracy of our AI extraction models using anonymised, aggregated signals. No individual contract content is used for training — only anonymised accuracy metrics.

We do not sell your data, share it with advertisers, or use it for any purpose not listed here.

4. AI Processing and OpenAI

When you upload a contract, the document content is sent to OpenAI's API for metadata extraction. This transmission is subject to OpenAI's enterprise privacy terms. OpenAI does not use API-submitted data to train its models.

The document is held in memory only for the duration of the AI call — typically 5–30 seconds. It is never written to disk or stored in any database. After extraction, the in-memory buffer is immediately discarded.

If you have concerns about sending specific documents through an AI model, you can instead add contracts manually using the manual entry form, which does not involve AI processing.

5. Third-Party Services

We use the following third-party services to operate RenewalGuard:

  • Clerk — authentication and user account management. Clerk processes your email address and password (or OAuth tokens). See Clerk's privacy policy at clerk.com/privacy.
  • Resend — transactional email delivery for renewal reminder notifications. Resend processes the recipient email addresses you provide in your reminder settings.
  • OpenAI — AI-powered contract metadata extraction. Document content is transmitted to OpenAI's API and immediately discarded. Not used for model training (API data).
  • Neon / PostgreSQL — secure cloud database for storing your contract metadata and account information.

6. Data Retention

  • Contract documents — deleted immediately after AI extraction. Retention time: <60 seconds in memory only.
  • Contract metadata — retained for as long as your account is active. You can delete individual contracts at any time from the Contract Registry.
  • Account data — retained until you close your account.
  • Reminder logs — kept for 12 months for your audit trail, then automatically purged.
  • Server logs — retained for 30 days for security purposes.

7. Your Rights

Under UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data. You can edit your contract metadata directly in the app.
  • Erasure — request deletion of your account and all associated data. Email privacy@renewalguard.io with the subject "Right to Erasure".
  • Portability — export your contract metadata as a CSV file from the Contract Registry.
  • Restriction — ask us to limit how we process your data in certain circumstances.
  • Objection — object to processing based on legitimate interests.

To exercise any of these rights, contact privacy@renewalguard.io. We will respond within 30 days.

8. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to production systems is restricted to authorised personnel and protected by multi-factor authentication.

We do not store contract documents — this is our most fundamental security measure. Even in the event of a database breach, no contract content would be exposed.

If you discover a security vulnerability, please report it responsibly to security@renewalguard.io.

9. Cookies

We use strictly necessary cookies only — specifically, a session cookie to keep you logged in. We do not use advertising cookies, tracking pixels, or third-party analytics scripts.

You cannot opt out of the session cookie as it is required for the service to function.

10. Changes to This Policy

We will notify you by email if we make material changes to this policy. The date at the top of this page reflects when it was last updated.

Continued use of the service after a policy update constitutes acceptance of the new terms.

11. Contact

For any privacy-related questions, data requests, or complaints:

Email: privacy@renewalguard.io

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.