Privacy policy
LAST UPDATED 2026-09-11
This policy covers legalnaut.com and the Legalnaut application. The controller is A2Z WEB PTE. LTD., 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987, registration 202614429R.
1. What we collect
Account data. Name, email address, password hash, workspace membership and role.
Case material. The documents you import, the text extracted from them, and the analysis derived from that text. We treat this as confidential material belonging to you, not to us.
Usage data. Server logs, error reports, and a record of consequential actions in the audit log.
Billing data. Handled by Stripe. We never see or store card numbers.
2. Why we process it
To provide the service you have subscribed to, to bill you for it, to keep the service secure, and to meet our legal obligations. Case material is processed only to provide the service.
3. Sub-processors
| Processor | Purpose | Location |
|---|---|---|
| Language model providers | Document analysis and chat answers | EU / US |
| Cloud hosting and object storage | Application hosting, file storage | EU |
| Amazon Web Services (Textract) | OCR when local extraction fails | EU |
| Stripe | Subscription billing | US / EU |
| Zoho Mail | Inbound document forwarding | EU |
Our agreements with every model provider prohibit training on customer content.
4. Retention
Case material is kept for as long as your workspace exists. Nothing deletes it on a schedule. If a subscription lapses, the workspace becomes read-only; clearing it is a deliberate action taken on request or after a documented period, never automatically. Invoicing records are kept for five years under Singapore tax law. Server logs are kept for 90 days.
5. Your rights
If the GDPR applies to you, you have the right to access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority. Write to contact@legalnaut.com and we respond to verified requests within 30 days.
6. Security
TLS 1.2 or better in transit. Encryption at rest for databases and backups. Hashed passwords. Optional two-factor authentication. Separate database and file storage per workspace. Access to production restricted on the principle of least privilege. SOC 2 Type II certified infrastructure.
No transmission over the internet is completely secure. If you believe an account has been compromised, write to us immediately.
7. Cookies
We set a session cookie needed to keep you signed in, a cookie recording your theme choice, and one recording whether the sidebar is collapsed. None of them track you across sites. Analytics, if enabled, runs only with your consent.
8. Changes
Material changes are announced in the application before they take effect.