Legalnaut

Data handling and compliance

LAST UPDATED 2026-09-16

A case file is confidential by nature, so this page says in plain words where the material goes, who is certified for what, and what the companies we rely on may do with what they receive. The privacy policy, the data processing agreement and the security page carry the same facts in their own form.

Where your material is stored

The application and every case file run on a server at Hetzner Online GmbH in Falkenstein, Germany, inside the European Union. The data centre operates an information security management system certified to ISO/IEC 27001:2022. Each workspace is kept apart from every other.

On the Enterprise plan the application can run on your own servers, in the geographic region you choose, so case material never leaves your infrastructure; the providers for OCR and language models are then chosen with you.

Who we are, and what we are certified for

Legalnaut is operated by A2Z WEB PTE. LTD., a company registered in Singapore. The company is SOC 2 Type II certified: an independent auditor has examined the controls for security, availability and confidentiality over a period of time, not on a single day. The report is available under NDA on request. Where the GDPR applies to you, we act as your processor under a data processing agreement with Standard Contractual Clauses for any transfer outside the EEA; where Singapore's Personal Data Protection Act applies, the same commitments hold.

What leaves the server, and why

Two kinds of work go to another company, and nothing else does.

Reading scanned pages. When a scan cannot be read locally, the page images go to Amazon Textract in AWS's Frankfurt region, which returns the text. Amazon Web Services' own SOC reports cover that service.

Understanding the text. Summaries, chronologies, claims, contradictions, answers and drafts are produced by language models at OpenAI and Anthropic in the United States. The model receives the text of a document, or the part of it the task needs, and returns its analysis. Both providers are bound by processing agreements that prohibit training on customer content.

How the model providers treat what they receive

OpenAI. Data sent to the OpenAI API has not been used to train or improve OpenAI's models since 1 March 2023, unless a customer opts in; we have not. Prompts and responses are retained for up to 30 days for abuse monitoring and then deleted, unless the law requires longer.

Anthropic. Inputs and outputs sent to the Anthropic API are deleted from Anthropic's systems within 30 days of receipt, unless flagged for a violation of its usage policy or retained as the law requires; they are not used to train Anthropic's models.

These are the providers' published commitments as of the date above; we check them when we renew a provider agreement and update this page if they change.

How we use your data

Case material is processed for one purpose: to provide the service to the workspace it belongs to. We do not train models on it, we do not sell it, and we do not show it to anyone outside your workspace. Our staff see it only when you ask for support that requires it or when an incident has to be investigated, and every such access is logged.

How long we keep it

For as long as your workspace exists. No schedule deletes the records of a paid workspace; if a subscription lapses the workspace becomes read-only and stays. The rules for erasure, the grace period and the one exception (a trial nobody came back to) are on the security page. You can export a whole workspace at any time.

What you can ask of us

A copy of the data processing agreement, the SOC 2 Type II report under NDA, the certificates of the data-centre operator, our current list of sub-processors, and help with a data subject request that concerns a file you run. Write to contact@legalnaut.com.