Legal & AI transparency
Every AI claim cites the exact text it is about, or it is discarded server-side. No accuracy claims without a measured eval behind them.
1. AI limitations
- Every AI output in shiftdocs is labeled “Generated by AI — review before accepting” and is advisory only. A human confirms every finding, audit conclusion and obligation before it has any effect.
- AI citations are validated character-for-character against the contract text; anything that does not match verbatim is discarded automatically and never shown.
- We publish no accuracy claims without a measured evaluation behind them. Quality gates run against golden test sets; dismissed findings and reviewer corrections feed those sets continuously.
- shiftdocs does not provide legal advice. You remain responsible for legal decisions about your contracts.
- Clause text and guideline text are processed by Anthropic Claude models for the tasks you trigger (guideline checks, change audits, comment assistance, obligation extraction). API data is not used for model training per provider terms.
2. Privacy summary
- Contract text drafted in a professional capacity is your organisation's corporate record. The personal data layer is attribution and contact information, confined to the locations in our data map.
- Supplier participants join with name, work email and role — recorded with IP and browser for the audit trail, encrypted at rest at field level.
- Erasure requests (GDPR Art. 17) pseudonymize the person and remove their contact data and comment contents after a 30-day cooldown, with a legal-hold pause. Clause versions are retained as corporate record (Art. 17(3)(b)).
- Hosting and inference run in the EU; e-mail delivery uses Resend (EU region).
3. DPA outline
For pilots we sign a data processing agreement covering: roles (customer = controller, shiftdocs = processor), the processing inventory from the data map, sub-processors (Anthropic — AI inference; Resend — transactional e-mail; hosting provider), EU residency, the erasure procedure above, 35-day encrypted backups with a tested restore procedure, breach notification within 72 hours, and audit support. This outline is a template for counsel review, not legal advice.
Last updated 2026-06-12 (S6).