Proviso is a contract review tool for in-house lawyers, distributed as a Microsoft Word add-in. It is operated by Proviso REVIEW NEEDED — confirm legal entity name and state of incorporation.
Questions about this policy? Email us at [email protected].
Account information. When you create an account, we collect your name, email address, and optionally your company name.
Billing information. Payment processing is handled entirely by Stripe. We receive a customer ID and subscription status from Stripe — we never see or store your full credit card number. Stripe's privacy policy applies to payment data: stripe.com/privacy.
Usage signals. We may collect anonymized, aggregated usage data (feature interactions, error logs) to improve the product. This cannot be linked to specific documents or contracts.
Support correspondence. If you contact us, we retain that correspondence to help you and improve our support.
Your contract text is never sent to Proviso's servers. Document processing happens entirely within the Word add-in on your device. Contract content goes directly from Word to your LLM provider (Anthropic, OpenAI, or Proviso's managed API connection). Proviso never sees it, touches it, or stores it.
We do not collect or store:
Proviso supports two modes of AI processing:
Bring Your Own Key (BYOK). You provide your own Anthropic or OpenAI API key. Your contract text goes directly from the Word add-in to that provider using your credentials. Proviso does not intermediate that request. Your data is governed entirely by Anthropic's or OpenAI's data policies. You are responsible for managing your key and any associated costs.
Managed plan. Proviso routes requests through our enterprise API connection with Anthropic. We have a data processing agreement with Anthropic that prohibits using customer data for model training. Contract text is not retained after the API call completes. REVIEW NEEDED — confirm DPA terms with Anthropic before going live with managed plan
In either mode: Proviso does not log, store, or have access to your contract content. The distinction is only which infrastructure routes the API call.
We use the information we collect to:
We do not use your data for advertising. We do not build behavioral profiles for third-party purposes.
We share your data only with the following service providers, and only to the extent needed to operate Proviso:
We do not sell, rent, or trade your personal data. We do not share data with advertisers or data brokers.
We may disclose data if required by law, court order, or regulatory process, or to protect the rights and safety of our users — but we will notify you where legally permitted to do so.
We retain your account information for as long as your subscription is active. If you cancel and request deletion, we will purge your personal data within 30 days — except where we are required to retain it for legal or financial compliance (e.g., transaction records that Stripe may retain under their own policies).
Because we never store contract content, there is nothing to delete on the document side.
Depending on your location, you may have the right to:
To exercise any of these rights, email [email protected]. We will respond within 30 days.
REVIEW NEEDED If Proviso serves customers in the EU or UK, a formal GDPR/UK GDPR compliance review is warranted. Consider whether an Article 27 representative or Data Protection Officer designation is required.
We use encrypted connections (HTTPS/TLS), secure credential storage, and appropriate access controls to protect your account data. No system is perfectly secure. If you believe your account has been compromised, contact us immediately at [email protected].
The Proviso marketing site uses minimal cookies necessary for site functionality. We do not use third-party advertising cookies or behavioral tracking tools. REVIEW NEEDED — confirm analytics tools in use (if any) and update accordingly before publishing
The Word add-in itself does not use cookies.
Proviso is a professional tool intended for licensed attorneys and in-house counsel. It is not directed at children under 13, and we do not knowingly collect data from minors. If you believe a minor has created an account, contact us at [email protected] and we will delete it promptly.
We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the site before the changes take effect. The current version is always at proviso.legal/privacy.
Email [email protected]. We read everything and respond within one business day.