Data processing statement
For procurement, privacy and information-security reviews
Role of the vendor
Clausery does not process personal data on behalf of customers. The software executes on the customer's devices; no customer content is transmitted to, stored by, or accessible to the vendor. Consequently the vendor is not a processor under Article 28 GDPR (or a service provider under the CCPA) for content handled in the software, and a data processing agreement covering that content is not required. We are happy to sign a short attestation to this effect for your records.
Records of processing
When recording the use of Clausery in a register of processing activities, the accurate description is: "Document assembly software executed locally in employees' browsers; no transfer to the supplier; data stored on managed endpoints under the organisation's device policies."
Sub-processors
None for customer content. The public web host (GitHub Pages) serves the application files and receives standard web-server logs from visitors' browsers; customers who prefer no third party in the delivery path can self-host.
Security measures
See the security overview: client-side architecture, strict content security policy, no third-party code at runtime, optional AES-256-GCM encryption at rest, offline license verification.
International transfers
None by the vendor.
Contact
See the contact page. For a signed attestation, say so in a question and we will arrange a private channel.