# Contract Analysis

### Overview

The Contract Analysis tab found in Vendor and Lifecycle ROPAs provide insights and annotations that are extracted from contracts associated with the vendor. Content on this tab is static, please see this article on [Editing your ROPA](https://support.relyance.ai/hc/en-us/articles/16917561711117).

For more information about what kind of contracts Relyance ingests, please refer to the article [Understanding the Types of Contracts Ingested by Relyance](/docs/introduction-to-relyance-ai/understanding-the-types-of-contracts-ingested-by-relyance/).

Data on this tab represents your *'contractual reality'*.

![ContractAnalysis-16.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15429373606797.png)

### Processing Details

This section of the Contract Analysis tab provides data processing information.

![ContractAnalysis-17.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15483063370637.png)

#### Personal Data Types

Relyance scans your contracts for personal data types using a Relyance-built list of keywords relating to all personal data types under GDPR.

![ContractAnalysic-1.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15389931697805.png)

#### Special Categories of Personal Data

Relyance scans your contracts for personal data types using a Relyance-built list of keywords relating to all personal data types that fall into special categories of data under GDPR.

![ContractAnalysis-2.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15389935859213.png)

#### Other Data Types

Other Data Types are custom data types added to the Data Classification settings. Please see the [Data Classification](https://support.relyance.ai/hc/en-us/articles/7109657991181) article for more info.

![ContractAnalysis-3.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15389935857805.png)

#### Nature and Purpose of Processing from DPA

Relyance scans your contracts as part of the contract integration, and extracts the nature and purpose of processing by identifying and analyzing the active DPA from the documents ingested.

![ContractAnalysis-4.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15390245710733.png)

#### Data Subject Categories

For each processing activity, Relyance makes a prediction about which data subject categories are most likely to correlate to a processing activity by leveraging built-in machine learning models. Please see the [Data Subject Categories](/docs/terms-and-definitions/data-subject-categories/) article for a list of Data Subject Categories and their descriptions.

![ContractAnalysis-5.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15390394840589.png)

#### Basis of Data Transfers

Data transfer is an intentional sending of personal data to another party or making the data accessible by it, where neither sender nor recipient is a data subject. Under GDPR and other data protection regimes, cross-border data transfer to third countries is permissible only if such transfer relies on a limited number of mechanisms that ensure that the transfer to third countries does not lessen the level of personal data protection.

Relyance scans your contracts as part of the contract integration and extracts what transfer mechanism the contract relies on: Privacy Shield, Standard Contractual Clauses (and if so, which version), and/or Binding Corporate Rules. In the event that the basis of transfer mechanism is out of date or invalid (e.g. Privacy Shield or old versions of Standard Contractual Clauses), Relyance will proactively surface an [Intelligent Insight](https://support.relyance.ai/hc/en-us/articles/4415371630221) as an alert.

![ContractAnalysis-6.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15390407124749.png)

#### Location of Data Processing

Relyance scans your contracts as part of the contract integration, and extracts the Location of Data processing.

![ContractAnalysis-7.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15390407120525.png)

### Security

Security measures, frequently included in DPAs, Security Addenda/Exhibits, and MSAs, represent a data processor's contractual pledge detailing the protection measures for a data controller's personal data. Please see Understanding the Types of Contracts Ingested by Relyance for more information.

This includes security controls, the timeline for responding to a security breach, and the duties of each party following a security incident. These aspects are elaborated upon in the Contract Analysis tab under the Security section, as we'll discuss in more detail below.

![ContractAnalysis-18.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15483424110221.png)

#### Security Measures

Relyance scans your contracts as part of the contract integration, and extracts any Security Measures outlining how a data controller’s personal data is protected. Please see the [Security Measures](/docs/terms-and-definitions/security-measures/) article for a list of security measures and their descriptions.

![ContractAnalysis-8.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15392073636237.png)

#### Incident Response Notification Timeline

Relyance reviews your DPAs and Quasi-DPAs during the contract integration process, and extracts essential information on Incident Response Notification Timelines.

![ContractAnalysis-9.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15392045174029.png)

#### Security Breach Provisions

Relyance scans your contracts as part of the contract integration, and extracts any Security Breach Provisions.

![ContractAnalysis-10.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15392073500813.png)

### Data Subject Requests

This section of the Contract Analysis tab provides Data Subject Request information.

![ContractAnalysis-19.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15487926147981.png)

#### Data Subject Requests

Relyance comprehensively scans your Data Processing Agreements (DPAs) or Quasi-DPAs during the contract integration phase, diligently extracting any provisions related to Data Subject Requests, including the pertinent rights of data subjects and the corresponding obligations of the involved parties to address and comply with the exercise of those rights.

![ContractAnalysis-11.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15417048450573.png)

### Data Retention Period And Agreement Termination

This section of the Contract Analysis tab provides information regarding Data Retention policies.

![ContractAnalysis-20.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15488084097933.png)

#### Data Retention Period

Relyance scans your vendor contracts as part of the contract integration and extracts the Data Retention Period. This information helps you determine how long data must be preserved and when it must be deleted, according to the terms of the relevant contract. It also aids you in complying with both contractual obligations and privacy requirements.

If no matching label can be extracted due to ambiguous language, the entire provision is presented as summary text instead of being assigned a specific label.

![ContractAnalysis-12.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15417054108685.png)

#### Contract Return & Deletion

Relyance scans your vendor contracts as part of the contract integration, and extracts any Contract Return & Deletion policies.

![ContractAnalysis-13.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15429721983757.png)

### Subprocessors

This section of the Contract Analysis tab shows any identified Subproccessors.

![ContractAnalysis-14.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15428424898701.png)

### Legal & Compliance Documents

This section of the Contract Analysis tab shows all relevant Legal & Compliance Documents.

![ContractAnalysis-15.png](https://assets.relyanceuat.xyz/images/docs/15381166025613/15428573956749.png)

You can upload relevant documents using the **Upload Document** button.

Only PDFs will be ingested by the Relyance platform.

### Viewing Additional Context From Contract Excerpts

This feature simplifies and enhances the user experience by automatically extracting important contract details and presenting them clearly in the user interface using tooltips.

![Screenshot](https://assets.relyanceuat.xyz/images/docs/15381166025613/16103914785549.gif)

This allows users to easily verify the source of the information taken from the ingested documents. This feature embodies our "trust but verify" principle, providing users with both confidence and transparency.

Once a document has gone through our QC process, yellow highlights will also appear in the tooltips.

![Screenshot](https://assets.relyanceuat.xyz/images/docs/15381166025613/16103891600909.png)
