Privacy Policy

Privacy Policy for Legal Twin® Contract Insights Office Add-in

Last Updated: October 2025

1. Introduction 

 

Septeo Legal Solutions Deutschland GmbH ("we", "us", "our") places great importance on the protection of your personal data. This Privacy Policy explains how we collect, process, and protect personal data in connection with our Microsoft Add-in "Contract Insights". 

Contract Insights is an add-in for Microsoft Office applications that supports the analysis and processing of contract documents. The processing of personal data is always carried out in accordance with the General Data Protection Regulation (GDPR) and applicable local data protection regulations. 

 

2. Data Controller 

Septeo Legal Solutions Deutschland GmbH 

Brauerstrasse 12 

76135 Karlsruhe 

Germany 

Phone: +49 721 828 15-0 

Fax: +49 721 828 15-555 

Email: info@stp.one 

Website: https://www.stp.one 

 

3. Data Protection Officer 

Raphaël Buchard

Dipeeo SAS

95 avenue du Président Wilson

93100 Montreuil

France

Phone: +33 9 50 39 07 50

Email: contact@dipeeo.com

You may contact our Data Protection Officer at any time with all questions and suggestions regarding data protection. 

 

4. Types of Data Collected 

 

In connection with the use of Contract Insights, the following data may be processed: 

4.1 Document Data 

  • Contents of documents that you process and analyze with Contract Insights 
  • Metadata of documents (e.g., file name, creation date, file size) 

4.2 Usage Data 

  • Technical information about your use of the add-in 
  • Functions that you use 
  • Time and duration of use 
  • Error and diagnostic information 

4.3 Authentication Data 

  • Microsoft 365 User ID (for authentication) 
  • Email address (if required for the service) 

4.4 Technical Data 

  • IP address 
  • Browser type and version 
  • Operating system 
  • Device information 
  •  

5. Purpose of Data Processing 

We process your personal data for the following purposes: 

5.1 Provision of Services 

  • Enabling the functions of Contract Insights 
  • Analysis and processing of contract documents 
  • Provision of analysis results and recommendations 

5.2 Technical Operation and Security 

  • Ensuring the functionality and stability of the add-in 
  • Error diagnosis and resolution 
  • Protection against misuse and cyberattacks 
  • Ensuring data security 

5.3 Improvement and Development 

  • Optimization of add-in functions 
  • Development of new features 
  • Quality assurance 

5.4 Legal Obligations 

  • Fulfillment of statutory retention obligations 
  • Enforcement and defense of legal claims 
  •  

6. Legal Basis for Processing 

 

The processing of personal data is based on the following legal grounds: 

  • Art. 6(1)(a) GDPR – Consent: Where you have given us consent to process personal data 
  • Art. 6(1)(b) GDPR – Performance of Contract: Where processing is necessary for the performance of a contract or for taking pre-contractual measures 
  • Art. 6(1)(c) GDPR – Legal Obligation: Where processing is necessary for compliance with a legal obligation 
  • Art. 6(1)(f) GDPR – Legitimate Interests: Where processing is necessary for the purposes of our legitimate interests, provided that your interests do not override such interests. Where we process personal data on the basis of legitimate interests, this serves in particular the protection against misuse, IT security, and the continuous improvement of our services. Our interests include, in particular, the secure and efficient provision of the add-in, quality assurance, error diagnosis, and the further development of functions. We always take into account your interests, fundamental rights, and freedoms and carry out a balancing of interests. Processing only takes place if your legitimate interests do not override our interests. 

 

7. Data Disclosure and Recipients 

 

7.1 Microsoft 

Contract Insights uses the Microsoft Office platform. Certain data is processed as part of the integration with Microsoft 365. Microsoft's privacy policy applies to processing by Microsoft. As part of the integration with Microsoft 365, authentication data (e.g., Microsoft 365 User ID and email address) and usage data are transmitted via the Microsoft Graph API. Microsoft processes certain data in its own capacity as a controller in accordance with its privacy policy. There is a separate data protection responsibility for processing by Microsoft. Details can be found at https://privacy.microsoft.com. 

7.2 Data Processors 

We may engage service providers to support the provision of our services (e.g., hosting providers, IT support). These process personal data exclusively according to our instructions and on the basis of data processing agreements in accordance with Art. 28 GDPR. An overview of the main data processors (e.g., hosting, IT service providers, maintenance) will be made available to you upon request. Our contractual partners are subject to strict data protection and security standards, which are regularly reviewed. The use of sub-processors always takes place in compliance with the requirements of Art. 28 GDPR and only after appropriate written authorization. 

7.3 No Disclosure to Third Parties 

Your document data will not be disclosed or sold to third parties unless: 

  • You have expressly consented 
  • There is a legal obligation to do so 
  • It is necessary to enforce our rights 
  •  

8. Data Processing and Storage Location 

 

8.1 Processing within the EU 

Your data is generally processed and stored within the European Union or the European Economic Area. 

8.2 Processing outside the EU 

Should a data transfer to third countries be necessary, this will only take place in compliance with the requirements set out in Chapter V of the GDPR and with appropriate safeguards (e.g., EU Standard Contractual Clauses). 

 

9. Retention Period 

 

We store personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by statutory retention periods. 

9.1 Document Data 

Document data is processed only during the active usage session and is not permanently stored unless you have expressly requested this or storage is necessary for functionality. 

9.2 Usage and Log Data 

Technical log data is generally stored for a maximum of 90 days unless longer retention periods are required for legal reasons or to ensure IT security. 

9.3 Statutory Retention Periods 

Data that must be stored due to statutory retention obligations (e.g., commercial or tax law) will be retained for the legally prescribed period. 

 

10. Data Security 

 

We have implemented extensive technical and organizational measures to protect your personal data from unauthorized access, loss, destruction, or manipulation: 

  • Encryption of data transmission (SSL/TLS) 
  • Secure authentication 
  • Regular security reviews 
  • Access controls and authorization concepts 
  • Employee training on data protection 

Please note that the transmission of data over the Internet is never completely secure. We therefore recommend that you also take your own security measures. 

 

11. Your Rights as a Data Subject 

 

You have the following rights under the GDPR: 

11.1 Right of Access (Art. 15 GDPR) 

You have the right to obtain information about your personal data stored with us. 

11.2 Right to Rectification (Art. 16 GDPR) 

You have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data. 

11.3 Right to Erasure (Art. 17 GDPR) 

You have the right to request the erasure of your personal data if the statutory requirements are met. 

11.4 Right to Restriction of Processing (Art. 18 GDPR) 

You have the right to request the restriction of the processing of your personal data. 

11.5 Right to Data Portability (Art. 20 GDPR) 

You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format. 

11.6 Right to Object (Art. 21 GDPR) 

You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you. 

11.7 Right to Withdraw Consent (Art. 7(3) GDPR) 

You have the right to withdraw your consent at any time with effect for the future. You may exercise your right to object pursuant to Art. 21 GDPR and withdraw consent pursuant to Art. 7(3) GDPR directly via the settings in the add-in, alternatively by email to contact@dipeeo.com or in writing to the address stated above. We will confirm receipt of your request and implement it technically without delay. Further information on technical options can be found in the add-in help function. 

11.8 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR) 

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. 

Competent Supervisory Authority: 

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg 

Lautenschlagerstraße 20 

70173 Stuttgart 

Germany 

Website: https://www.baden-wuerttemberg.datenschutz.de 

 

12. Contact for Exercising Your Rights 

 

To exercise your rights or if you have questions about data protection, please contact: 

Email: contact@dipeeo.com 

Phone: +33 9 50 39 07 50 

Post: 

Septeo Legal Solutions Deutschland GmbH 

Attn: Data Protection Officer 

Brauerstrasse 12 

76135 Karlsruhe 

Germany 

 

13. No Automated Decision-Making 

 

We do not employ automated decision-making, including profiling, pursuant to Art. 22 GDPR, which produces legal effects concerning you or similarly significantly affects you. 

 

14. Minors 

 

Contract Insights is intended for business customers and is not intended for use by persons under 18 years of age. We do not knowingly collect personal data from minors. 

 

15. Changes to this Privacy Policy 

 

We reserve the right to amend this Privacy Policy at any time in compliance with applicable data protection regulations. The current version is always available on our website at https://www.stp.one/privacy-policy. 

 

16. Microsoft-Specific Information 

 

16.1 Office Add-in Permissions 

Contract Insights requires the following permissions in Microsoft Office: 

  • Access to the currently open document for reading and analysis 
  • Permission to insert analysis results into the document 
  • Network access to communicate with our servers 

16.2 Microsoft Store 

When installing via the Microsoft Store, Microsoft's privacy policy also applies. Information on this can be found at: https://privacy.microsoft.com 

16.3 Integration with Microsoft 365 

Authentication is carried out via Microsoft 365. We only receive the information from Microsoft that is necessary for the functionality of the add-in. 

 

17. Additional Information 

 

17.1 Provision of Personal Data 

The provision of certain personal data may be necessary for the use of Contract Insights. Without this data, we may not be able to provide the service or may only be able to do so to a limited extent. 

17.2 No Sale of Data 

We do not sell your personal data to third parties. 

17.3 Transparency 

We are committed to full transparency in the processing of your data. If you have any questions or concerns, we are always available to assist you. 

 

Septeo Legal Solutions Deutschland GmbH 

Brauerstrasse 12 

76135 Karlsruhe 

Germany 

Email: info@stp.one 

Website: https://www.stp.one