1. Data Controller
LegalAnalytics.AI ("we", "us", "our") is the data controller for personal data processed through this platform.
Contact:
Email: privacy@legalanalytics.ai
Address: [TO BE COMPLETED]
Data Protection Officer: [TO BE COMPLETED]
2. Data We Collect
We collect and process the following categories of personal data:
- Account Information: Name, email address, firm name, professional credentials
- Case Data: Case inquiries, claimant information, medical records, expert witness data
- Usage Data: Login times, feature usage, IP addresses, browser information
- Communication Data: Support messages, feedback, correspondence
3. Legal Basis for Processing (GDPR Article 6)
We process personal data under the following legal bases:
- Contract Performance: Processing necessary to provide our AI case evaluation services
- Legitimate Interests: Improving our services, security monitoring, fraud prevention
- Legal Obligation: Compliance with UK legal and regulatory requirements
- Consent: Where explicitly provided (e.g., marketing communications)
4. Special Category Data (GDPR Article 9)
Our platform processes health data (medical records, clinical information) as part of clinical negligence case evaluation.
Legal basis for processing health data:
- Processing necessary for legal claims (GDPR Article 9(2)(f))
- Processing necessary for substantial public interest (UK GDPR Schedule 1)
- Explicit consent from data subjects where required
5. Data Retention
We retain personal data for the following periods:
- Active Cases: Duration of case + 7 years (limitation period for professional negligence claims)
- Closed Cases: 7 years from case closure (SRA compliance)
- Account Data: Duration of account + 2 years
- Usage Logs: 90 days (security monitoring)
See our Data Retention Policy for full details.
6. Your Data Subject Rights (GDPR Chapter III)
Under UK GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data (subject to legal obligations)
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
To exercise your rights, contact: privacy@legalanalytics.ai
7. Data Security
We implement industry-standard security measures:
- Encryption: AES-256 encryption at rest, TLS 1.3 in transit
- Access Controls: Role-based access, multi-factor authentication
- Backups: Daily encrypted backups with 30-day retention
- Monitoring: 24/7 security monitoring and intrusion detection
- Audits: Regular penetration testing and security audits
See our Security & Compliance page for full details.
8. International Data Transfers
[TO BE COMPLETED based on infrastructure]
We use Google Cloud Platform for hosting. Data transfers are protected by Google's Data Processing Agreement and comply with UK GDPR requirements.
9. Third-Party Service Providers
We use the following third-party processors:
- Google Cloud Platform: Hosting and infrastructure (GDPR-compliant DPA in place)
- Google Gemini AI: AI processing for case evaluation (data processed under Google's DPA)
- Firebase: Authentication and database services (Google Cloud DPA)
All processors are vetted for GDPR compliance and bound by Data Processing Agreements.
10. Cookies and Tracking
We use the following cookies:
- Essential Cookies: Authentication, session management (no consent required)
- Analytics Cookies: Usage statistics, performance monitoring (consent required)
You can manage cookie preferences in your browser settings.
11. Right to Lodge a Complaint
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be notified via email and prominently on our platform.
Last updated: 01/11/2025
Contact Us
For any privacy-related questions or to exercise your data subject rights:
Email: privacy@legalanalytics.ai
Data Protection Officer: [TO BE COMPLETED]
Response Time: We will respond to data subject requests within 30 days as required by GDPR.