Privacy Policy
Last updated:
This policy explains how we process personal data. Read it holding two situations apart: your own data on this site and in your account, and the client data your firm uploads to the product, do not sit under the same responsibility.
1. Two different roles
We are the controller for: visits to this website, demo requests, account signup and authentication, billing, support correspondence, security logs, and measurement of how the product is used. This policy covers all of it.
We are a processor for: the matters, filings and client information your firm uploads to the product. Your firm is the controller there; we act only on your firm’s instructions and under the Data Processing Agreement between us. This policy does not replace that agreement.
2. What we collect
Site visits: aggregate measurement such as page views, the country a visit came from, and the referring address. This measurement uses no cookies and does not identify you as an individual.
Demo requests: your name, organisation, work email address, the team size you select, and the message you write. Your IP address is held in memory briefly at the moment of submission to limit abuse of the form; it is not stored.
Account data: name, email address, an irreversible hash of your password, email verification status, your role in the firm, and invitation records.
Session and security data: the application’s session and CSRF cookies, sign-in attempts, and server access logs.
Usage data: records of which feature ran when, and error logs.
Billing data: invoice details if you take a paid plan. Card details never reach us; our merchant of record takes the payment.
Support correspondence: the content of your messages and your contact details when you email us.
Pleading citation check: the text of the document you upload (with detected personal data masked), its file name, your IP address and the email address you give for the report. The original file is not retained in application storage. The document may contain personal data the masking misses, including special category data.
No account is created on this website and no payment is taken here; apart from the citation check, no content that may contain special category data is collected through it.
3. Purposes and legal bases
We process demo requests to contact you and to take pre-contractual steps at your request. That is the legal basis.
We process account, authentication, billing and support data to perform our contract with you.
We process security logs and usage measurement to keep the service safe and to understand whether it works. The legal basis is our legitimate interest.
We ask separately, and optionally, before sending you marketing email. Declining does not affect your demo request, and you can withdraw at any time from the link in any message or by writing to us.
We process citation-check data to prepare and send the report you ask for, and the IP address and an irreversible digest of the email address to limit abuse of the free check. The legal bases are providing the service you request and our legitimate interest.
We do not sell personal data and we do not profile.
4. Cookies
This marketing site sets no marketing or tracking cookies, and our analytics is cookieless.
The application sets two strictly necessary cookies, one to keep you signed in and one to protect against cross-site request forgery. Their names, lifetimes and purposes are listed in the Cookie Policy.
5. Retention
Demo requests are kept until the conversation concludes, and no longer than twenty-four months.
Account data is kept while your account is open. When you close it, uploaded originals are deleted at once and your database records leave the encrypted backups within thirty days. The Security page has the detail.
Billing records are kept for as long as the retention obligations we are subject to require.
Email correspondence is kept for as long as the relationship it concerns continues.
Citation-check records (masked text, extracted claims, file name, IP address and report address) are deleted once 24 hours have passed. An irreversible, keyed digest of the email address is kept indefinitely to enforce one free check per address; the address itself is not kept.
Aggregate measurement is not personal data and may be retained indefinitely in aggregate form.
6. The providers we use
Vercel Inc. (US company; this site runs in its Frankfurt region): hosting for the marketing site and cookieless measurement.
Hetzner Online GmbH (Germany): the servers running the application and its database.
Cloudflare, Inc. (US company; the bucket is in the European Union jurisdiction): object storage holding your uploaded files and the case-law corpus.
Fireworks AI, Inc. (United States): model inference for the AI features, and reranking of search results.
TypeSafe AI, Inc. (United States): classifying the outcome of public court decisions from our case-law corpus. No customer content is sent to it.
Slack Technologies (Salesforce, United States): the workplace messaging platform demo requests are delivered to.
Resend (United States): delivery of verification and notification email.
We keep this list current. When a provider is added, this page is updated and account holders are notified by email. We share personal data with no one else; legally mandatory disclosures are reserved.
7. Where data is held
The application, its database and your uploaded files are held in the European Union.
The AI features are the exception. When you ask a question or run the assistant over a document, that text goes to Fireworks AI in the United States for model inference. The product contains a layer that can mask the text before it is sent; that layer is not switched on.
Demo requests are also passed to US-based messaging and email providers so they reach our team.
These transfers rest on the data processing agreements between us and each provider, together with the European Commission’s standard contractual clauses. For Fireworks that agreement covers no retention of prompts or outputs beyond the request, no training on that data, and thirty days’ notice of a subprocessor change.
A transfer from Türkiye additionally uses the standard contract published by the Personal Data Protection Board, which we sign with your firm and return on request. Clause 11 of the Terms has the detail.
8. Customer content
Access to a matter is scoped to that matter: one client’s documents do not surface while a lawyer works on another. That is the separation professional confidentiality requires, made the default rather than an option.
We do not use customer content to train an AI model.
9. Security
Data is encrypted in transit with TLS. In the object storage holding your uploaded files, content is encrypted at rest by the storage provider, and database backups are encrypted before they leave the server.
We state plainly that the server running the application has no disk-level encryption. We do not imply a protection we do not have.
Access is limited to people who need it to do their work. We hold no security certification.
10. Your rights
You have the right to access your personal data, to have it corrected, to have it erased, to object to processing, to have processing restricted, and to receive your data in a portable form.
To exercise any of these, write to lagel.reitnorf@ofni. We respond within one month at the latest.
You also have the right to complain to the supervisory authority in your country. In Türkiye that authority is the Personal Data Protection Authority.
11. Changes
We may update this policy. The effective date is shown at the top of the page, and material changes are notified separately.
12. Contact
For anything concerning privacy, reach us at lagel.reitnorf@ofni. Users in Türkiye are given the information required under KVKK in a separate notice.