Data Processing Addendum (Summary)
What this document is:
An overview of the data protection framework applicable when organizations deploy Clawscan.
Why this matters:
Clawscan is designed so that the analysis of communications occurs within the client’s own Microsoft 365 and Azure environment. As a result, GOlegal normally does not process the personal data contained in communications analyzed by the system.
Who should read this:
Legal teams, data protection officers (DPOs), compliance teams, and procurement teams.
When to use this:
Vendor onboarding, DPIA preparation, and contractual review.
Overview
The Clawscan Data Processing Addendum (DPA) forms part of the contractual documentation between GOlegal and organizations deploying the Clawscan platform.
Because Clawscan processes communication content within the client’s own infrastructure, GOlegal generally does not process the personal data contained in those communications.
In most deployments:
- communication content remains within the client tenant
- GOlegal infrastructure does not receive email bodies or attachments
- GOlegal does not access communications analyzed by the system
The DPA therefore primarily covers limited situations where GOlegal may process personal data while operating the service.
See:
Processing model
Clawscan follows a Project / System / Vendor responsibility model.
| Level | Responsible party | Description |
|---|---|---|
| Project | Client organization | Defines monitoring objectives and governance policies |
| System | Clawscan platform | Provides technical capabilities to detect compliance signals |
| Vendor | GOlegal | Provides and operates the Clawscan platform |
Under this model, communications analyzed by the system remain under the control of the client organization.
See:
Processing of communications
Clawscan analyzes communication content inside the client’s Microsoft 365 and Azure environment.
This means:
- communication content is not transferred to GOlegal infrastructure
- GOlegal does not store or process email bodies or attachments
- the organization deploying Clawscan remains responsible for the governance of communications analyzed by the system
For this reason, the DPA does not typically apply to the communications analyzed by the Clawscan Engine.
See:
Situations where GOlegal may process personal data
GOlegal may process limited personal data in specific operational situations.
These situations may include:
Platform access and account management
When organizations create accounts to access the Clawscan platform, GOlegal may process professional contact information such as:
- name
- email address
- organization
Platform operation and monitoring
Operational telemetry generated by the system may be processed to ensure reliable operation of the platform.
See:
Support and maintenance
In certain situations, GOlegal may process limited personal data when providing technical support or troubleshooting assistance.
This may occur, for example, during:
- onboarding and setup
- support requests
- troubleshooting sessions
Access to personal data in these contexts is limited to what is necessary to resolve the issue and is freely provided by the client organization.
Purpose of processing
Where GOlegal processes personal data, this processing is limited to purposes such as:
- providing access to the platform
- operating and maintaining the service
- providing technical support
- managing contractual relationships
Processing does not involve analyzing communications for compliance purposes.
Security measures
GOlegal implements technical and organizational measures designed to protect personal data processed as part of the Clawscan service.
See:
Subprocessors
GOlegal may rely on service providers to support the operation of the Clawscan platform.
Where such providers process personal data on behalf of GOlegal, they are bound by contractual obligations consistent with applicable data protection requirements.
A list of subprocessors is available at:
Data retention
Personal data processed by GOlegal is retained only for as long as necessary to operate the Clawscan platform or fulfil contractual obligations.
See:
Access to the full DPA
The full Data Processing Addendum is provided as part of the contractual documentation between GOlegal and the client organization.
Organizations evaluating Clawscan may request access to the DPA during the procurement process.