For Legal

The contract review goes faster
when nothing is hidden in it.

Counsel reviewing an AI platform needs three things: to know who processes the data, to see the paper, and to confirm the obligations regulators care about are met by the product — not by a promise. Five questions, answered plainly, with the documents a request away at hello@turtleaicoworker.com.

What you'll want to know

Processing, paper,
and the obligations.

The theme across the answers: oversight and record-keeping aren't compliance features bolted on for the review — they're how execution works. That makes the diligence shorter, because the evidence already exists.

01

Who processes our data?

The subprocessor list is published on the Trust Center, and it's short: infrastructure hosting, and the model providers — who only ever see a prompt when an agent is configured to use them. With BYO keys, model requests run under your own agreement with the provider, not through terms we negotiated for you. No silent additions: the list changes only when the product does.

The subprocessor list
02

Is there a DPA?

Yes — a Data Processing Agreement is available on request, including standard contractual clauses where applicable. We'd rather send you the actual document than paraphrase it on a marketing page, so ask and it arrives.

Request the DPA
03

What about AI-specific obligations?

The two things AI regulation keeps asking for — effective human oversight and complete records of automated decisions — are how the platform already works. Human-in-the-loop approval gates with single-use grants sit in the execution path, and every run and tool call is logged with who authorized it. The Trust Center maps these controls to the EU AI Act and NIST AI RMF in those frameworks' own vocabulary.

The framework mapping
04

Can we meet retention and hold obligations?

Per-workspace retention policies govern audit and compliance data, and a legal hold freezes any purging while exports stay available — for litigation, investigation, or a regulator's clock. Evidence is exportable in the shape a reviewer asks for it: filterable by workspace, worker, integration, user and date.

Audit and retention
05

What does the AI never do?

It never trains on your data — workspace content (tables, knowledge, chats, traces) is never used to train models, ours or anyone else's. Unapproved writes are a no-op: the runtime authorization floor stops them before execution, whatever the prompt said. And a per-workspace PII policy detects emails, phones, SSNs, card numbers, addresses and names, with mask, hash, remove and flag redaction modes.

The enforcement layer
What to take with you

For the file, not the pitch deck.

The documents and mappings your review will actually cite.

The oversight mechanics behind these answers: Approvals for the human-in-the-loop gates, Governance for policy enforcement. Your security counterparts have their own page at /for/it-security.

For your legal review

Request the DPA and start the review.

The DPA, the subprocessor list, and answers to counsel's questions — from someone who can speak to how the product actually enforces what the paper says.

Request the DPA