Legal & AI transparency
Every AI claim cites the exact text it is about, or it is discarded server-side. No accuracy claims without a measured eval behind them.
1. AI limitations
- Every AI output in shiftdocs is labeled “Generated by AI — review before accepting” and is advisory only. A human confirms every finding, audit conclusion and obligation before it has any effect.
- AI citations are validated character-for-character against the contract text; anything that does not match verbatim is discarded automatically and never shown.
- We publish no accuracy claims without a measured evaluation behind them. Quality gates run against golden test sets; dismissed findings and reviewer corrections feed those sets continuously.
- shiftdocs does not provide legal advice. You remain responsible for legal decisions about your contracts.
- Your document text and your guideline text are processed by Anthropic Claude models for the tasks you trigger (guideline checks, change audits, comment assistance, obligation extraction). API data is not used for model training per provider terms.
2. Privacy summary
- Contract text drafted in a professional capacity is your organisation's corporate record. The personal data layer is attribution and contact information, confined to the locations in our data map.
- Supplier participants join with name, work email and role — recorded with IP and browser for the audit trail, encrypted at rest at field level.
- Erasure requests (GDPR Art. 17) pseudonymize the person and remove their contact data and comment contents after a 30-day cooldown, with a legal-hold pause. Document versions are retained as corporate record (Art. 17(3)(b)).
- shiftdocs runs on one server in Germany, rented from Hostinger International Ltd. Your documents, the database and its backups all live on that machine.
- The AI tasks you trigger send the document text you point them at to Anthropic PBC, which processes it in the United States. Where any sub-processor handles your data is named in the data processing agreement, and changing that list is a change to the agreement.
- Transactional e-mail — sign-in links, invitations, reminders — is delivered by Resend.
3. DPA outline
For pilots we sign a data processing agreement covering: roles (customer = controller, shiftdocs = processor), the processing inventory from the data map, each sub-processor with the place it processes in (Hostinger International Ltd. — hosting, data centre in Germany; Anthropic PBC — AI tasks, United States; Resend — transactional e-mail), the erasure procedure above, database backups with a tested, documented restore drill and 35-day retention, breach notification within 72 hours, and audit support. This outline is a template for counsel review, not legal advice.
Last updated 2026-09-16 (T-037).